Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Starting February 10, 2027, Let’s Encrypt plans to issue certificates with 64-day lifetimes by default under its classic ACME profile, down from the 90-day lifetime used today. Certificates issued or renewed before that date are not changed, and Let’s Encrypt says it will not revoke valid certificates because of the switch. The real risk is not the shorter validity itself. It is renewal automation built around a 90-day schedule that keeps running on that old timing after certificates start expiring sooner.

What changes on February 10, 2027

  • Effective date: February 10, 2027, for certificates issued or renewed under the default classic ACME profile, according to Let’s Encrypt’s October 7, 2026 announcement.
  • Default lifetime: 64 days. Subscribers who have already chosen a shorter-lived profile, such as the opt-in tlsserver or shortlived profiles, keep that selection. The 64-day default applies to the classic profile.
  • Scope: The change applies to certificates issued or renewed on or after the date. It is not retroactive, so a certificate issued in January 2027 keeps the lifetime it was issued with.
  • Authorization reuse: The reuse period for domain validation drops to 10 days at the same February 2027 milestone. It drops to seven hours in February 2028, according to the October 2026 announcement and the December 2, 2025 timeline post.

Timeline

The dates below are the ones Let’s Encrypt had published as of October 9, 2026. Check the official blog for later operational changes before you schedule work.

Date Planned change Source
May 13, 2026 Opt-in tlsserver profile moves to 45-day certificates December 2, 2025 timeline post
October 14, 2026 Staging switches to 64-day issuance so operators can test October 7, 2026 announcement
February 10, 2027 Default classic profile moves to 64-day certificates and 10-day authorization reuse October 7, 2026 announcement; December 2, 2025 timeline post
May 11, 2027 Expected expiration of the last 90-day certificate October 7, 2026 announcement
February 16, 2028 Default classic profile moves to 45-day certificates and seven-hour authorization reuse December 2, 2025 timeline post

What does not change

  • Existing valid certificates: Let’s Encrypt says it will not revoke valid certificates as part of this transition.
  • ACME endpoints and issuance chains: Let’s Encrypt says these will not change.
  • Rate limits: Let’s Encrypt says rate limits are not affected by the 64-day change.

The May 11, 2027 date is the point at which the last 90-day certificate is expected to expire. After that, every certificate from the default classic profile is on the shorter schedule, and the 90-day renewal habits that still work today will stop being safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why Let’s Encrypt is shortening lifetimes

Let’s Encrypt says shorter lifetimes reduce how long a mis-issued certificate, or one whose private key has been compromised, stays valid. It also says shorter lifetimes encourage operators to automate certificate management. Its certificate lifetime rationale page, last updated July 22, 2026, ties the 45-day target to changes in the CA/Browser Forum Baseline Requirements.

Sarah Gran, author of the October 7, 2026 announcement, puts the operational point directly: “If your renewals are hard-coded to a date from expiration you should update them to renew at approximately ⅔ of the lifetime instead.”

Let’s Encrypt has not published an independent measurement of how much shorter lifetimes reduce risk. The figures in this article are the scheduled values for lifetimes and reuse periods, not study results.

How to prepare your renewal automation

  1. Test in staging first. Let’s Encrypt’s staging environment switches to 64-day certificates on October 14, 2026. Run your renewal flow against it and confirm that the certificate it returns has a 64-day lifetime before production changes.
  2. Confirm ARI support in your ACME client. ACME Renewal Information (ARI) lets the certificate authority tell the client when to renew. Check your client’s documentation for ARI support. Let’s Encrypt says compatible automated clients should be ready for the change because ARI tells them when to renew.
  3. Search for hard-coded renewal intervals. Look in cron jobs, wrapper scripts, configuration management, and runbooks for fixed renewal timing. Let’s Encrypt specifically suggests checking for values such as 83, 80, or 60. Those numbers are typical of a 90-day lifecycle, where renewing 83 days after issuance means renewing seven days before expiry. On a 64-day certificate, a fixed value of 83 can never trigger before the certificate expires.
  4. Move fixed timing to about two-thirds of the lifetime. For a 64-day certificate, that is roughly day 43 after issuance. For the planned 45-day default in 2028, it is roughly day 30. Let’s Encrypt says this prepares systems for the 64-day stage and sets up the 45-day default.
  5. Alert on failed or missed renewals. A renewal that fails silently is now a real outage risk because the margin before expiry is smaller.
  6. Automate deployment and service reload. Renewing a certificate on disk does not help if the web server or service keeps using the old one. Where deployment or reload is still a manual step, automate it.

Warning signs after the switch

  • Renewal logs show no activity for long stretches of a 64-day certificate’s life, while the monitoring dashboard still reports a healthy certificate.
  • A server keeps presenting a certificate whose remaining validity is shrinking, even though a newer certificate exists on disk.
  • Scripts that assume a 90-day expiry date stop matching the expiry date reported by the certificate itself.

If you see any of these, compare the certificate’s actual issue and expiry dates with the schedule your automation expects. Then check the client’s ARI behavior and whether the deployment step ran after the renewal.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Scope of this article

This is a policy transition for Let’s Encrypt certificates, not a choice between products. The sources used here are Let’s Encrypt’s own posts and its lifetime rationale page. They do not cover how other certificate authorities or hosting providers handle lifetimes. Teams that buy certificates elsewhere should check that provider’s own schedule.

For reference, the dates and values in this article come from the October 7, 2026 announcement and the December 2, 2025 timeline post.

Rank #4
Sale
Adams Gift Certificate Book, Carbonless, Single Paper, 3.4 x 8 Inches, White/Canary, 2-Part, 25 Numbered Certificates Plus Store Sign (GFTC1)
  • 2-part carbonless unit set
  • Consecutive numbering
  • Includes Gift Certificates Available sign
  • 25 certificates with envelopes per package
  • White/canary form sequence

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.