Published on
October 6, 2026
On September 10, 2026, SSL.com published a compliance update announcing the revocation of a subset of its TLS certificates, about 2,700 across DV, OV and EV types, completed within the short window the industry rules require. The cause was neither a breach nor a mississuance. An internal audit found that for these certificates, the company could not evidence that domain control had been corroborated from multiple network perspectives, a requirement in force since March 2025. Primary domain validation had been performed, and SSL.com reports no indication of compromise or of incorrect validation. The certificates were revoked because the WebPKI holds certificate authorities to a demanding standard: validation needs to be provable, certificate by certificate, not merely performed.
It is worth saying clearly at the outset that SSL.com handled this the way the system intends. The company identified the gap through its own audit, disclosed it publicly, notified affected subscribers, and completed the revocation on schedule. This is the WebPKI's compliance model functioning, and the event is interesting not as a story about one CA, but as a window into how modern public trust works and what it asks of everyone who relies on it.
What MPIC Is, and Why the Rule Exists
Multi-Perspective Issuance Corroboration (MPIC) entered the CA/Browser Forum's Baseline Requirements through Ballot SC-067, adopted in August 2024 and enforced since March 15, 2025. The threat it answers is well documented: when a certificate authority checks that an applicant controls a domain, an attacker positioned on the network path, typically through BGP manipulation, can intercept that check from a single vantage point and pass it fraudulently. MPIC closes that door by requiring the CA to corroborate domain control from multiple network perspectives in different regions, with a quorum that rises on a published calendar: three perspectives since March 2026, four since June, five from December.
MPIC is one of the quiet structural upgrades that keep public trust robust, and this event is an early illustration of how seriously it is enforced. The requirement covers not only performing the corroboration but retaining the evidence of it. When that evidence could not be confirmed, the conservative path was the correct one, and it is the path SSL.com took.
The Part That Concerns Everyone Else
The operational lesson of the event sits downstream of the CA, and it applies to every organization that consumes publicly trusted certificates, from any provider.
Take control of your PKI infrastructure
See how Evertrust simplifies certificate lifecycle management.
Get StartedThe Baseline Requirements leave certificate authorities very little discretion on revocation timelines, by design. Browsers and root programs hold every CA to the same clock, because consistency is what keeps the trust model credible. The practical consequence is that when a compliance finding occurs anywhere in the chain, subscribers receive a replacement notice with a deadline measured in hours or days, regardless of how carefully they run their own operations. The trigger sits entirely outside the subscriber's control.
This is why replacement events of this kind are best understood as a normal, recurring feature of the WebPKI rather than an exception. The ecosystem has seen several in recent years, affecting customers of different CAs for different reasons, and the pattern is structural: strict rules, strictly enforced, with short timelines absorbed downstream. Organizations with a complete certificate inventory and automated replacement in place, through ACME or equivalent protocols, handle such an event routinely: affected certificates are reissued and redeployed quickly, with little manual effort. For organizations still handling replacement manually, these events are a useful prompt to assess how long a short-notice replacement would take across their estate, and whether the deployment locations of every certificate are known. That assessment is far more comfortable to run on a quiet day than during an actual event.
The direction of travel reinforces the point. Certificate lifetimes are on a published path toward 47 days in 2029, domain validation reuse windows are shrinking in parallel, and the MPIC quorum rises again in December. Each of these changes increases the number of certificate events an organization handles per year, and each assumes that the subscriber side keeps pace. Replacement readiness is becoming a standing capability of certificate operations rather than an exceptional procedure.
Closing Thoughts
The September 10 event ends with the system in a healthier state than it began: a validation evidence gap found and closed, affected certificates replaced, and a requirement reaffirmed that protects every relying party on the Internet. For certificate owners, the takeaway is neither alarm nor blame. It is a planning assumption: in the modern WebPKI, short-notice replacement is part of the operating environment, whichever CA you work with, and the organizations that fare best are the ones that have made it routine.