By 2029, the maximum lifetime for a public TLS certificate drops to 47 days. If you are still tracking certificates in a spreadsheet, that number should make you uncomfortable. You need to know where every certificate lives, when it expires, and how fast you can replace it before it takes a service down.