Contents
Let’s Encrypt will shorten its default SSL/TLS certificate lifetime from 90 days to 64 days on February 10, 2027. Website owners should review their renewal automation, certificate deployment, and expiration alerts before the change takes effect.
In its October 7 announcement, Let’s Encrypt confirmed that certificates issued or renewed from that date will use the shorter lifetime unless subscribers select a 45-day or six-day certificate profile.
Existing certificates will remain valid until their original expiration dates. The change takes effect when a new certificate is issued, including during renewal.
The Let’s Encrypt certificate lifetime timeline
The move to 64-day certificates is an intermediate step toward default lifetimes of 45 days in 2028.
| Date | What changes |
|---|---|
| October 14, 2026 | Let’s Encrypt’s staging environment begins issuing 64-day certificates for testing. |
| February 10, 2027 | Default production certificates move from 90-day to 64-day lifetimes. |
| May 11, 2027 | Let’s Encrypt expects the last 90-day certificate to expire. |
| February 16, 2028 | Default certificate lifetimes decrease again, to 45 days. |
The production milestones apply to Let’s Encrypt’s default classic ACME profile. Its shorter-lifetime profiles follow their own settings, as explained in the published roadmap.
These dates are separate from the industry-wide maximum validity schedule for publicly trusted certificates. For that broader timeline, see our guide to SSL certificate validity changes.
Why is Let’s Encrypt shortening certificate lifetimes?
Shorter lifetimes reduce the period during which a compromised private key or an incorrectly issued certificate can remain usable.
For website owners, the operational consequence is more frequent renewal. Reliable automation becomes increasingly important because each certificate has a smaller window for identifying and fixing problems before expiration.
Let’s Encrypt will not revoke valid certificates as part of this transition. The change also leaves ACME endpoints, issuance chains, and rate limits unchanged.
How to prepare your certificate renewal automation
Check whether your ACME client supports ARI
Let’s Encrypt recommends using an ACME client that supports ACME Renewal Information (ARI). ARI allows the certificate authority to communicate a suggested renewal window to the client.
Check your client’s documentation to confirm whether your installed version supports ARI and whether any configuration is required.
Review fixed renewal schedules
For clients without ARI, Let’s Encrypt recommends renewing approximately two-thirds of the way through the certificate’s actual lifetime.
For a 64-day certificate, that means renewal around day 43, leaving approximately 21 days before expiration.
Review scheduled jobs, wrapper scripts, and runbooks for assumptions based on 90-day certificates. Renewal timing should adapt to the certificate’s lifetime rather than depend on a fixed interval that becomes unsuitable as lifetimes shrink.
Test renewal and deployment together
Use the staging environment to test the complete workflow:
- Request and renew a certificate.
- Deploy it to the relevant servers, proxies, and load balancers.
- Reload services where required.
- Verify that public endpoints serve the replacement certificate.
- Confirm that renewal failures generate an actionable alert.
Issuing a replacement certificate is only part of the process. Visitors benefit once the infrastructure actually serves it.
Authorization reuse is changing too
Let’s Encrypt will reduce its authorization reuse period from 30 days to 10 days in February 2027, then to seven hours in February 2028.
This is the period during which an earlier domain validation can be reused to issue another certificate. It is separate from the certificate’s validity period.
Most users will not need to make specific changes unless their ACME integration was designed to rely on authorization reuse.
Should you change your SSL expiration alerts?
Review your expiration alert thresholds alongside your renewal schedule. If a 64-day certificate renews around day 43, it will still have approximately 21 days remaining. A reminder configured for 30 days before expiration would therefore arrive before the expected renewal—even when automation is working correctly.
Distinguish an approaching expiration date from a failed renewal. Keep expiration alerts as a safety net, monitor renewal failures separately, and verify the certificate presented by your public endpoints after deployment.
Let’s Encrypt also stopped sending certificate expiration reminder emails on June 4, 2025. Website owners should ensure their renewal automation and monitoring provide their own alerts, rather than relying on an email from Let’s Encrypt.
Our guide to monitoring SSL certificate expiration explains how to check expiration dates and build monitoring into your certificate management workflow.