Let’s Encrypt will reduce the validity period of free SSL/TLS certificates from 90 days to 64 days starting February 10, 2027, in a move aimed at pushing website administrators to rely fully on automated renewal rather than fixed schedules or manual procedures.
Testing of the new certificates will begin on October 14, 2026, allowing users who wish to do so to examine their renewal systems before production implementation begins. Environments using modern ACME clients that support the ACME Renewal Information feature, known as ARI, are expected to transition to the change without significant intervention. By contrast, systems relying on scheduled tasks with fixed values or manual processes may face unexpected certificate expiration.
Why is Let’s Encrypt moving to shorter validity periods?
When Let’s Encrypt launched in early 2016, it adopted 90-day certificates instead of periods that had previously reached one or three years. The goal was to encourage automated renewal, reduce the period during which websites are exposed if a private key is stolen or a certificate is issued incorrectly, and accelerate HTTPS adoption.
Reducing the period to 64 days continues the same approach. Let’s Encrypt plans to reach a default period of 45 days in 2028, making reliance on manual renewal processes less sustainable.
What will change in practice for website administrators?
Let’s Encrypt recommends reviewing cron jobs and operational procedures for fixed values such as 83, 80, and 60, which are common values in previous renewal configurations for certificates with 90-day validity. These settings should be adjusted to renew the certificate before it expires, targeting renewal at approximately two-thirds of the certificate’s validity period.
- Verify that the ACME client in use supports ARI, or update renewal scripts when necessary.
- Enable alerts for renewal failures or an approaching certificate expiration.
- Use the testing period beginning October 14 to examine automation before the deadline.
ARI allows the certificate authority to inform the client of the appropriate time for renewal instead of relying on a pre-calculated date. However, some environments still use fixed time intervals, so the approximately four-month period until February 10 represents an opportunity to review and test configurations.
Additional changes to validation
In parallel with shortening certificate validity, Let’s Encrypt will reduce the reuse period for authorization data from 30 days to 10 days, eventually reaching seven hours by 2028. This may reduce the need to repeat CAA checks, but its impact may be felt by operators whose ACME clients rely on temporarily stored validation data.
In practice, the change is not limited to issuing shorter-lived certificates; it also increases the cost of maintaining non-automated renewal processes. Systems lacking monitoring and alerts will be more vulnerable to website outages if renewal fails, while the October test provides an early window to identify these problems before the February policy is implemented.