Let’s Encrypt cuts certificate lifetimes to 64 days starting February 2027
Let’s Encrypt will shorten the lifetime of its free SSL/TLS certificates from 90 days to 64 days on 10 February 2027. The change is intended to limit the impact of compromised or wrongly issued certificates and encourage administrators to automate renewals fully.
Testing begins on 14 October 2026, giving administrators time to check their systems before the deadline. Modern ACME clients that support ARI should handle renewals automatically, while fixed schedules and manual processes may need updating. Let’s Encrypt plans to move to 45-day certificates in 2028; authorisation reuse periods will also shrink from 30 days to 10 days, then seven hours.
- Let’s Encrypt certificates will last 64 days from February 2027.
- Administrators should test renewal automation before the change.
- 45-day certificates are planned for 2028.
New here? Start with this
Let's Encrypt is a free service that issues security certificates to websites, allowing them to use encrypted connections. These certificates prove a website's identity and encrypt data passing between visitors' browsers and the site's servers.
Currently, Let's Encrypt certificates last 90 days before needing renewal. Shortening this period means compromised or incorrectly issued certificates stop working sooner, limiting potential damage. Shorter lifetimes also encourage website administrators to fully automate their renewal processes rather than handling them manually.
Let's Encrypt dominates the free certificate market globally and is crucial to internet infrastructure, so changes to its policies have wide-ranging effects on security. Reducing certificate lifetimes limits how long stolen or wrongly issued certificates can be misused, while encouraging organisations to update their renewal systems rather than maintaining manual processes.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Shorter certificate lifetimes meaningfully reduce the window during which a compromised or misissued certificate can cause harm, and the policy encourages organisations to fully automate renewal processes, which is foundational to security hygiene. Let's Encrypt's four-month notice and testing period before implementation demonstrates responsible change management, providing reasonable opportunity for adaptation.
The case against
Whilst the security rationale is sound, more frequent certificate renewals increase operational complexity and create additional points of failure, potentially disadvantaging smaller organisations without mature automation infrastructure. The more rapid cadence strains administrative resources and Let's Encrypt's infrastructure alike, and the transition timeline may not provide sufficient grace period for all participants to adapt properly, risking unforced outages.