- Let's Encrypt will issue 64-day certificates by default from February 10, 2027, and will test the change in staging from October 14, 2026.
- Automated renewals that support ACME Renewal Info should be fine. Scripts with hard-coded renewal dates are the exposed part.
- Teams should test in staging, search scripts and runbooks for fixed day counts, and add alerts for failed renewals.
A certificate was often handled once a year or so, then roughly once a quarter. Let's Encrypt is now making it a heartbeat. The risk is shifting from the certificate itself to the assumptions people built around it years ago. Those assumptions sit in cron jobs, wrapper scripts and runbooks that nobody has opened in a long time.
What Let's Encrypt announced
On October 7, 2026, Let's Encrypt said that from February 10, 2027 its default certificate lifetime will be 64 days. Any certificate it issues or renews on or after that date gets the shorter life. Subscribers can still choose 45 or 6 days, options the organisation announced earlier.
The final 90-day certificate should run out on May 11, 2027, by the organisation's own estimate. It says it will not revoke valid certificates as part of the change. Its staging environment, built for testing, moves to 64 days on October 14, 2026.
How the mechanism works
A certificate is the digital ID that lets a browser trust a website. Software called an ACME client asks Let's Encrypt for a new one before the old one expires. ACME is the standard protocol for that exchange.
Many teams told their client to renew on a fixed schedule. Let's Encrypt describes a better method, called ACME Renewal Info, or ARI. With ARI, the certificate authority tells the client when to renew. Let's Encrypt says automated setups whose client supports ARI should be fine.
Fixed schedules are the problem. A script that waits 80 days before renewing works for a 90-day certificate. It misses a 64-day one, because the certificate expires first. Let's Encrypt advises renewing at about two-thirds of the lifetime. For 64 days, that is roughly day 43.
The company suggests searching cron jobs, wrapper scripts and runbooks for numbers such as 83, 80 or 60. Moving to a two-thirds rule now also helps with the 45-day default lifetimes planned for 2028.
A second change hides in the notice
Let's Encrypt is also shortening how long it trusts an earlier domain check, from 30 days to 10. Before issuing a certificate, the authority checks that you control the domain. It remembers that proof for a time, so repeat requests skip the check.
A further cut follows in 2028, when that memory window falls to just seven hours. Let's Encrypt links this to an industry-wide limit on validation reuse that tightens in 2029. It also ends the need for "CAA rechecking", where the authority must repeat part of validation if the data is more than seven hours old.
Most teams need to do nothing here. Let's Encrypt says only clients specifically designed to rely on validation reuse must change.
What this means for an organisation
The stated goal is lower risk. Let's Encrypt says shorter lifetimes reduce the chance of key compromise and mis-issuance. A stolen key is useful to an attacker for a limited time, roughly until the certificate expires or is revoked, so a shorter life narrows that window.
The cost lands on operations. A 90-day cycle left room for slow, manual fixes. A 64-day cycle, and later a 45-day one, gives a missed renewal less room to hide. The person paged about an expired certificate is dealing with the gap between a policy and a forgotten script.
The lesson here is that automation is not the same as being ready. A renewal job can run for years and still carry a fixed number that assumed a world that no longer exists. Let's Encrypt itself frames the change as a moment to automate reload and deployment, and to alert on failed renewals.
Questions to put to your team
Ask whether every certificate renewal runs through a client that supports ARI. If you do not know, ask someone to check the client's documentation.
Ask who has searched scripts, cron jobs and runbooks for hard-coded renewal day counts. Ask whether the team has a plan to test in staging once it switches to 64-day certificates on October 14.
Ask what happens after renewal. A new certificate that is issued but not reloaded into the server still fails. And ask who is alerted when a renewal fails, and how soon.
Let's Encrypt says rate limits, ACME endpoints and issuance chains are unaffected. It anticipates a smooth transition. For teams with tested automation, the date should pass quietly. A quiet date is the aim.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Let's Encrypt.





