Published on
August 8, 2026
On July 30, 2026, the CA/Browser Forum formally adopted Ballot SMC017v2, "Increase Minimum RSA CA Key Size", following an Intellectual Property Review period that closed without any exclusion notice. The ballot amends the Baseline Requirements for the Issuance and Management of Publicly-Trusted S/MIME Certificates, now published as S/MIME BR version 1.0.15. Proposed by Martijn Katerbarg (Sectigo) and endorsed by Ben Wilson (Mozilla) and Stephen Davidson (DigiCert), the measure passed with a result that speaks for itself: 18 certificate issuers and 4 certificate consumers voted in favor, with zero votes against and zero abstentions. Apple, Microsoft and Mozilla all approved.
The change is easy to summarize and significant in its consequences. Publicly trusted S/MIME certificate authorities are moving away from 2048-bit RSA at the CA level, on a schedule that is now fixed. For an ecosystem that has treated RSA 2048 as the default for nearly two decades, Ballot SMC017v2 marks the moment where that default officially begins its retirement, at least where it matters most: the keys that sign everything else.
What Ballot SMC017v2 Actually Changes
The ballot introduces two deadlines, and the distinction between them deserves attention.
The first deadline concerns key generation. RSA keys created after September 15, 2026 for Root and Subordinate CA certificates in the S/MIME hierarchy are subject to a minimum size of 4096 bits, up from the previous 2048-bit floor. Any new key ceremony for an S/MIME issuing CA from that date onward produces a 4096-bit key or larger. Subscriber certificates, the end-entity certificates that individuals and organizations use to sign and encrypt email, keep their 2048-bit minimum. The ballot targets the trust infrastructure, not the leaves.
The second deadline concerns issuance from existing hierarchies. From September 15, 2027, the S/MIME Baseline Requirements prohibit issuing Subscriber certificates from any Subordinate CA whose RSA key modulus is smaller than 3072 bits. In plain terms, this sunsets issuance from legacy 2048-bit Sub-CAs. Existing 2048-bit intermediates do not become invalid overnight, and certificates already issued remain unaffected, but their role as active issuers ends. Certificate authorities operating such intermediates have a little over a year from the ballot's effective date to stand up replacements.
The two-step design is deliberate. It stops the creation of new undersized CA keys immediately while giving the ecosystem a defined window to migrate live issuance chains, an approach that avoids both a cliff-edge revocation event and an indefinite grandfathering of legacy keys.
Why the CA Level, and Why Now
The cryptographic reasoning is well established. RSA 2048 delivers roughly 112 bits of classical security, below the 128-bit level that RSA 3072 provides and that guidance from NIST and from European agencies such as ANSSI and BSI has recommended as the floor for keys protecting long-lived assets. The asymmetry the ballot exploits is one of exposure time. A subscriber certificate lives for a year or two. A CA key can sign for a decade or more, and every certificate beneath it inherits the consequences of its compromise. Strengthening the top of the hierarchy yields the largest security return for the smallest number of key ceremonies.
Take control of your PKI infrastructure
See how Evertrust simplifies certificate lifecycle management.
Get StartedThere is also a quantum-era subtext worth naming. Ballot SMC017v2 does not introduce post-quantum algorithms; that work began separately with Ballot SMC013, "Enable PQC Algorithms for S/MIME", adopted in 2025. Larger RSA keys do not resist a Cryptographically Relevant Quantum Computer, and nobody at the CA/Browser Forum pretends otherwise. What the ballot does is ensure that the classical component of trust hierarchies remains robust during the transition years, precisely the period in which hybrid and composite approaches will layer post-quantum algorithms on top of classical ones. A hierarchy re-keyed in 2026 will still be operating when those hybrid chains arrive, and a 4096-bit classical anchor is the appropriate partner for them. Viewed this way, SMC017v2 is less an isolated hardening measure than one move in a longer sequence of cryptographic modernization across the S/MIME requirements.
The unanimous vote is itself informative. Root programs and certificate issuers rarely align without friction on anything that imposes operational cost. Here, all 22 voting members agreed that the cost is justified, which suggests the industry regards the 2048-bit CA era as finished business.
Operational Implications for PKI Teams
For publicly trusted CAs, the work plan is clear: schedule key ceremonies for 4096-bit replacements, obtain new Sub-CA certificates, migrate issuance, and manage the coexistence of old and new intermediates through the transition. The deadlines leave adequate but not generous room, particularly for organizations whose ceremony logistics involve external auditors, hardware security module procurement, or multi-party approval chains.
The more interesting question concerns everyone downstream. Enterprises consuming publicly trusted S/MIME certificates will see their issuing chains change between now and late 2027. Certificate pinning against intermediate CAs, hardcoded chain validation, gateway configurations that bundle specific intermediates, and archival verification setups all deserve review before the new hierarchies go live. Larger CA keys also mean marginally larger chains and slower RSA operations at the CA level, a negligible cost for email but a reminder that key size decisions propagate through every system that touches the certificate.
Operators of private PKI face no formal obligation, since the S/MIME Baseline Requirements bind publicly trusted issuance. The direction of travel, however, is unambiguous, and private hierarchies tend to follow public trust practice with a lag. An internal CA created today with a 2048-bit RSA key is a hierarchy built below the bar the industry has just set for itself. Organizations planning internal root or intermediate renewals have every reason to adopt the 4096-bit floor now, or to consider elliptic curve alternatives where their ecosystem supports them.
Above all, Ballot SMC017v2 is a live test of a capability that will be exercised repeatedly in the coming decade: the ability to re-key and re-issue at the hierarchy level without disrupting production. An organization that knows which certificates chain to which intermediates, which applications pin which keys, and which devices tolerate which algorithms can absorb this change as routine maintenance. An organization discovering its dependencies during the migration will experience the same change very differently. The post-quantum transition will ask the same question at far greater scale.
The European Perspective
For European organizations, the ballot lands on familiar ground. ANSSI's RGS referentials and BSI's TR-02102 technical guideline have recommended RSA moduli of 3072 bits or more for years, so the CA/Browser Forum is aligning public trust with positions European agencies reached some time ago. Regulated entities under DORA and NIS2, which face explicit obligations around cryptographic inventory and risk management, will find that documenting exposure to the SMC017v2 timeline is exactly the kind of exercise those frameworks expect. And for organizations relying on qualified or regulated email signature services in the eIDAS ecosystem, the ballot reinforces a broader European convergence: key sizes, like algorithms, now carry expiry dates, and governance frameworks increasingly demand proof that an organization can act on them.
Closing Thoughts
Ballot SMC017v2 changes two numbers in a requirements document, and yet it captures the state of the industry rather precisely. The unanimous adoption, the phased deadlines, and the quiet sunsetting of a key size once considered permanent all point in the same direction: cryptographic parameters are now managed on explicit timelines, and the infrastructure of trust is expected to keep pace. September 15, 2026 and September 15, 2027 are the dates to put in the migration plan. The organizations best placed to meet them, and the larger transitions behind them, are those for which re-keying a hierarchy is an automated, inventoried, rehearsed operation rather than an exceptional event.