Let's Encrypt said on October 7, 2026 that from February 10, 2027 its HTTPS certificates will last 64 days by default instead of 90. The change reaches every website that relies on its free certificates. If renewal is automated, most site owners will have nothing to change, but it is worth checking before the date.
What we know
- What changes and when: from February 10, 2027, every certificate Let's Encrypt issues or renews will be valid for 64 days by default, according to the post signed by Sarah Gran on October 7, 2026. Subscribers can choose an even shorter lifetime of 45 or 6 days.
- Existing certificates: none will be revoked. Let's Encrypt expects the last 90-day certificate to expire on May 11, 2027.
- Staging: the staging environment switches to 64-day certificates on October 14, 2026. The post recommends testing there first.
- Who has nothing to do: anyone whose renewals are automated with a client that supports ARI (ACME Renewal Info), the mechanism that lets Let's Encrypt tell the client when to renew, according to the post.
- Who does: anyone whose renewal is tied to a fixed number of days. The post asks them to renew at roughly two thirds of the certificate's lifetime and to search cron jobs, wrapper scripts and runbooks for numbers such as 83, 80 or 60.
- Domain validation: the period during which a completed validation can be reused drops from 30 days to 10, and to seven hours in 2028. Only clients specifically built to rely on that reuse are affected, the post says.
- What comes next: on February 16, 2028 the default drops again, to 45 days, according to the timeline Let's Encrypt published on December 2, 2025.
- Why: the post says shorter lifetimes reduce the risk of key compromise and mis-issuance. The CA/Browser Forum's rules also require it of every publicly trusted certificate authority, according to the 2025 post. Let's Encrypt's documentation says the maximum allowed lifetime falls to 100 days on March 15, 2027 and to 47 days on March 15, 2029.
What changes and what doesn't
The pace changes. With 90 days, renewal comes around day 60, according to Let's Encrypt. With 64 days, two thirds is about day 43: that sum is this article's. The window to fix a failed renewal shrinks from about 30 days to about 21. At 45 days, renewal comes around day 30 and 15 days are left.
Rate limits do not change, because renewals are exempt, according to Let's Encrypt's post of February 24, 2026. The ACME endpoints and the issuance chains stay the same too, the October 7 post says. The certificate is still free and visitors will not notice anything.
One detail matters more as lifetimes get shorter: Let's Encrypt stopped sending expiration notification emails on June 4, 2025, as it announced in January of that year. If a renewal fails, Let's Encrypt will not tell you.
How to tell if it affects you
- Check who issues your certificate. Open your site, click the icon next to the address and view the certificate details. If the issuer is Let's Encrypt, this concerns you. The start and expiry dates are there as well.
- On shared hosting, your provider's control panel handles renewal. Ask them: "Is your automatic Let's Encrypt renewal ready for 64-day certificates from February 10, 2027 and 45-day certificates in 2028?"
- On a VPS or your own server with Certbot, run three checks. "certbot --version" shows the version: since 4.0.0 it renews when less than a third of the certificate's lifetime remains, and before that it used a fixed 30 days, according to its documentation. "systemctl list-timers" or the crontab shows whether the automatic task exists. And "certbot renew --dry-run" performs a test renewal against Let's Encrypt's staging environment, according to the same documentation.
- Hunt for fixed numbers. If a script of your own renews "every 60 days" after issuance, a 64-day certificate leaves a 4-day margin: one failed run and the site has no valid certificate. At 80 or 83 days, the certificate expires before it is renewed. Both sums are this article's.
- If you renew by hand, you will have to do it at least every two months instead of every three. Let's Encrypt does not recommend manual renewal: this is the moment to automate it.
- Set an expiry alert. Let's Encrypt keeps a list of monitoring services and endorses none of them. An expired certificate makes the browser show a security warning instead of your site.
Dates for the calendar: October 14, 2026 (staging), February 10, 2027 (64 days), May 11, 2027 (last 90-day certificate expires) and February 16, 2028 (45 days).
Related: ccTLD Hijacks Led to Rogue Google Certificates: What to Check
Sources
- Let's Encrypt, "64-Day Certificate Lifetimes Coming Feb 2027", October 7, 2026
- Let's Encrypt, "Decreasing Certificate Lifetimes to 45 Days", December 2, 2025
- Let's Encrypt, "Shorter Certificate Lifetimes and Rate Limits", February 24, 2026
- Let's Encrypt, "Profiles" documentation
- Let's Encrypt, "Ending Support for Expiration Notification Emails", January 22, 2025
- Let's Encrypt, "Monitoring Service Options"
- Certbot, User Guide
Updates: this note will be extended if Let's Encrypt changes any date or publishes new instructions before February 10, 2027.