iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Starting February 10, 2027, Let’s Encrypt plans to issue certificates with 64-day lifetimes by default under its classic ACME profile, down from the 90-day lifetime used today. Certificates issued or renewed before that date are not changed, and Let’s Encrypt says it will not revoke valid certificates because of the switch. The real risk is not the shorter validity itself. It is renewal automation built around a 90-day schedule that keeps running on that old timing after certificates start expiring sooner.
What changes on February 10, 2027
- Effective date: February 10, 2027, for certificates issued or renewed under the default classic ACME profile, according to Let’s Encrypt’s October 7, 2026 announcement.
- Default lifetime: 64 days. Subscribers who have already chosen a shorter-lived profile, such as the opt-in tlsserver or shortlived profiles, keep that selection. The 64-day default applies to the classic profile.
- Scope: The change applies to certificates issued or renewed on or after the date. It is not retroactive, so a certificate issued in January 2027 keeps the lifetime it was issued with.
- Authorization reuse: The reuse period for domain validation drops to 10 days at the same February 2027 milestone. It drops to seven hours in February 2028, according to the October 2026 announcement and the December 2, 2025 timeline post.
Timeline
The dates below are the ones Let’s Encrypt had published as of October 9, 2026. Check the official blog for later operational changes before you schedule work.
| Date | Planned change | Source |
|---|---|---|
| May 13, 2026 | Opt-in tlsserver profile moves to 45-day certificates | December 2, 2025 timeline post |
| October 14, 2026 | Staging switches to 64-day issuance so operators can test | October 7, 2026 announcement |
| February 10, 2027 | Default classic profile moves to 64-day certificates and 10-day authorization reuse | October 7, 2026 announcement; December 2, 2025 timeline post |
| May 11, 2027 | Expected expiration of the last 90-day certificate | October 7, 2026 announcement |
| February 16, 2028 | Default classic profile moves to 45-day certificates and seven-hour authorization reuse | December 2, 2025 timeline post |
What does not change
- Existing valid certificates: Let’s Encrypt says it will not revoke valid certificates as part of this transition.
- ACME endpoints and issuance chains: Let’s Encrypt says these will not change.
- Rate limits: Let’s Encrypt says rate limits are not affected by the 64-day change.
The May 11, 2027 date is the point at which the last 90-day certificate is expected to expire. After that, every certificate from the default classic profile is on the shorter schedule, and the 90-day renewal habits that still work today will stop being safe.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsWhy Let’s Encrypt is shortening lifetimes
Let’s Encrypt says shorter lifetimes reduce how long a mis-issued certificate, or one whose private key has been compromised, stays valid. It also says shorter lifetimes encourage operators to automate certificate management. Its certificate lifetime rationale page, last updated July 22, 2026, ties the 45-day target to changes in the CA/Browser Forum Baseline Requirements.
#1 Best Overall
Sarah Gran, author of the October 7, 2026 announcement, puts the operational point directly: “If your renewals are hard-coded to a date from expiration you should update them to renew at approximately ⅔ of the lifetime instead.”
Let’s Encrypt has not published an independent measurement of how much shorter lifetimes reduce risk. The figures in this article are the scheduled values for lifetimes and reuse periods, not study results.
How to prepare your renewal automation
- Test in staging first. Let’s Encrypt’s staging environment switches to 64-day certificates on October 14, 2026. Run your renewal flow against it and confirm that the certificate it returns has a 64-day lifetime before production changes.
- Confirm ARI support in your ACME client. ACME Renewal Information (ARI) lets the certificate authority tell the client when to renew. Check your client’s documentation for ARI support. Let’s Encrypt says compatible automated clients should be ready for the change because ARI tells them when to renew.
- Search for hard-coded renewal intervals. Look in cron jobs, wrapper scripts, configuration management, and runbooks for fixed renewal timing. Let’s Encrypt specifically suggests checking for values such as 83, 80, or 60. Those numbers are typical of a 90-day lifecycle, where renewing 83 days after issuance means renewing seven days before expiry. On a 64-day certificate, a fixed value of 83 can never trigger before the certificate expires.
- Move fixed timing to about two-thirds of the lifetime. For a 64-day certificate, that is roughly day 43 after issuance. For the planned 45-day default in 2028, it is roughly day 30. Let’s Encrypt says this prepares systems for the 64-day stage and sets up the 45-day default.
- Alert on failed or missed renewals. A renewal that fails silently is now a real outage risk because the margin before expiry is smaller.
- Automate deployment and service reload. Renewing a certificate on disk does not help if the web server or service keeps using the old one. Where deployment or reload is still a manual step, automate it.
Warning signs after the switch
- Renewal logs show no activity for long stretches of a 64-day certificate’s life, while the monitoring dashboard still reports a healthy certificate.
- A server keeps presenting a certificate whose remaining validity is shrinking, even though a newer certificate exists on disk.
- Scripts that assume a 90-day expiry date stop matching the expiry date reported by the certificate itself.
If you see any of these, compare the certificate’s actual issue and expiry dates with the schedule your automation expects. Then check the client’s ARI behavior and whether the deployment step ran after the renewal.
Scope of this article
This is a policy transition for Let’s Encrypt certificates, not a choice between products. The sources used here are Let’s Encrypt’s own posts and its lifetime rationale page. They do not cover how other certificate authorities or hosting providers handle lifetimes. Teams that buy certificates elsewhere should check that provider’s own schedule.
Rank #3
For reference, the dates and values in this article come from the October 7, 2026 announcement and the December 2, 2025 timeline post.
Quick Recap
Best Value
Rank #4
- 2-part carbonless unit set
- Consecutive numbering
- Includes Gift Certificates Available sign
- 25 certificates with envelopes per package
- White/canary form sequence
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

