47 days. The countdown has started.
In March 2029, public certificates move to a 47-day validity period. For your SBCs, that means eight renewals a year instead of one. With zero service interruption. Across your entire fleet.

What changes in March 2029
The CA/Browser Forum has ratified a progressive reduction of public certificate validity, capped at 47 days starting March 2029. Concretely, what used to be renewed once a year must now be renewed eight times a year. Across dozens, sometimes hundreds of devices.
For voice infrastructures — SBCs, SIP trunks, registration front-ends — the risk is direct: a forgotten certificate means a P1 telecom outage. The topic sits at the intersection of PKI and telecom teams, with tooling and lifecycles historically designed in parallel rather than together.
The front-line platforms are the ones every decision-maker has in mind: Microsoft Teams (via Direct Routing), Genesys Cloud, and more broadly unified communications and cloud contact center services. All of them rely on SBCs that present public certificates to carriers and cloud services. Every missed renewal takes a trunk down.
Today, enterprise PKI tools don't natively talk to SBCs. Homegrown scripts die with their author. Most large enterprises are not ready.
The CA/Browser Forum trajectory
Yesterday
398 days
March 15, 2026
200 days
March 15, 2027
100 days
March 15, 2029
47 days
The workflow
Certificate Automation Bridge is a module of SIPify Pulse. It does one thing, and does it well: industrialize the certificate lifecycle on voice infrastructures, without human intervention, without service interruption.
Automatic inventory
Discovery of certificates deployed across the entire SBC fleet — by device, interface, and usage.
Pre-renewal audit
Verification of algorithm compatibility, chain of trust, expiry dates and dependencies before any action.
End-to-end orchestration
CSR generation, CA submission, deployment on the device, automatic rollback in case of failure.
Functional post-checks
Call tests after switchover. We don't just validate that a file is in place — we validate that voice traffic actually flows.
Compliant audit log
Who, when, what. Output ready for CISO teams and internal control.
In-house script vs CAB
Why a product module rather than a homegrown script
| In-house script | CAB |
|---|---|
| Written by an expert who eventually leaves | Maintained and versioned by SIPify, Tier-1 support by NXO |
| Mono-technology or mono-version | Multi-tech SBC, vendor-agnostic |
| No rollback, no post-check | Automatic rollback + post-switchover call tests |
| To be rewritten on every SBC upgrade | Product updates delivered by the SIPify workshop |
| Compliance not demonstrable | Audit log ready for CISO / internal control |
CAB is not a roadmap item. It's a workflow we coded to answer a concrete need.
SIPify Pulse is the agile voice workshop. A team of VoIP experts, an AI-augmented code factory, and the capacity to turn a business need into a delivered automation in a few weeks — not two years.
Where large vendors push generic platforms with frozen roadmaps, we start from the client's workflow. AutoDialer, Traffic Guardian, SBC Config Utility, CAB: these aren't products, they are the first workflows that came out of the workshop. The next one could be yours.
Distributed by NXO
SIPify Pulse is distributed exclusively by NXO, a large-account integrator. Dedicated sales team, trained Tier-1 support, industrial deployment on sensitive infrastructures. The agility of a workshop, the solidity of a major group.
Frequently asked questions
How long would this workflow take at your company, with your current vendor?
Personalized demo on your SBC perimeter. 30 minutes. No pre-installation required.
You can also go through your usual NXO contact.