Skip to main content

Let’s Encrypt Will Switch to 64-Day SSL Certificates in February 2027

Posted by UptimeObserver Team on October 8, 2026

Contents

Let’s Encrypt will shorten its default SSL/TLS certificate lifetime from 90 days to 64 days on February 10, 2027. Website owners should review their renewal automation, certificate deployment, and expiration alerts before the change takes effect.

In its October 7 announcement, Let’s Encrypt confirmed that certificates issued or renewed from that date will use the shorter lifetime unless subscribers select a 45-day or six-day certificate profile.

Existing certificates will remain valid until their original expiration dates. The change takes effect when a new certificate is issued, including during renewal.

The Let’s Encrypt certificate lifetime timeline

The move to 64-day certificates is an intermediate step toward default lifetimes of 45 days in 2028.

DateWhat changes
October 14, 2026Let’s Encrypt’s staging environment begins issuing 64-day certificates for testing.
February 10, 2027Default production certificates move from 90-day to 64-day lifetimes.
May 11, 2027Let’s Encrypt expects the last 90-day certificate to expire.
February 16, 2028Default certificate lifetimes decrease again, to 45 days.

The production milestones apply to Let’s Encrypt’s default classic ACME profile. Its shorter-lifetime profiles follow their own settings, as explained in the published roadmap.

These dates are separate from the industry-wide maximum validity schedule for publicly trusted certificates. For that broader timeline, see our guide to SSL certificate validity changes.

Why is Let’s Encrypt shortening certificate lifetimes?

Shorter lifetimes reduce the period during which a compromised private key or an incorrectly issued certificate can remain usable.

For website owners, the operational consequence is more frequent renewal. Reliable automation becomes increasingly important because each certificate has a smaller window for identifying and fixing problems before expiration.

Let’s Encrypt will not revoke valid certificates as part of this transition. The change also leaves ACME endpoints, issuance chains, and rate limits unchanged.

How to prepare your certificate renewal automation

Check whether your ACME client supports ARI

Let’s Encrypt recommends using an ACME client that supports ACME Renewal Information (ARI). ARI allows the certificate authority to communicate a suggested renewal window to the client.

Check your client’s documentation to confirm whether your installed version supports ARI and whether any configuration is required.

Review fixed renewal schedules

For clients without ARI, Let’s Encrypt recommends renewing approximately two-thirds of the way through the certificate’s actual lifetime.

For a 64-day certificate, that means renewal around day 43, leaving approximately 21 days before expiration.

Review scheduled jobs, wrapper scripts, and runbooks for assumptions based on 90-day certificates. Renewal timing should adapt to the certificate’s lifetime rather than depend on a fixed interval that becomes unsuitable as lifetimes shrink.

Test renewal and deployment together

Use the staging environment to test the complete workflow:

  • Request and renew a certificate.
  • Deploy it to the relevant servers, proxies, and load balancers.
  • Reload services where required.
  • Verify that public endpoints serve the replacement certificate.
  • Confirm that renewal failures generate an actionable alert.

Issuing a replacement certificate is only part of the process. Visitors benefit once the infrastructure actually serves it.

Authorization reuse is changing too

Let’s Encrypt will reduce its authorization reuse period from 30 days to 10 days in February 2027, then to seven hours in February 2028.

This is the period during which an earlier domain validation can be reused to issue another certificate. It is separate from the certificate’s validity period.

Most users will not need to make specific changes unless their ACME integration was designed to rely on authorization reuse.

Should you change your SSL expiration alerts?

Review your expiration alert thresholds alongside your renewal schedule. If a 64-day certificate renews around day 43, it will still have approximately 21 days remaining. A reminder configured for 30 days before expiration would therefore arrive before the expected renewal—even when automation is working correctly.

Distinguish an approaching expiration date from a failed renewal. Keep expiration alerts as a safety net, monitor renewal failures separately, and verify the certificate presented by your public endpoints after deployment.

Let’s Encrypt also stopped sending certificate expiration reminder emails on June 4, 2025. Website owners should ensure their renewal automation and monitoring provide their own alerts, rather than relying on an email from Let’s Encrypt.

Our guide to monitoring SSL certificate expiration explains how to check expiration dates and build monitoring into your certificate management workflow.

FAQ

Frequently Asked Questions

This announcement applies to Let’s Encrypt. Other certificate authorities set their own lifetimes within the applicable industry requirements. Check your provider’s schedule rather than assuming the same February 2027 deadline applies.

An existing 90-day certificate remains valid until its original expiration date. From February 10, 2027, newly issued certificates on the default profile including renewals will have 64-day lifetimes.

Not necessarily. If your client supports ARI and your renewal automation works correctly, Let’s Encrypt says you should be ready for the transition. Otherwise, verify that renewal timing adapts to shorter lifetimes and test the complete deployment process before the production change.

Monitor. Be alerted. Sleep easy.

Try UptimeObserver now. Setup in 2 minutes.