Key Takeaways
- Let's Encrypt will cut SSL/TLS certificate lifetimes to 64 days starting February 10, 2027.
- The change aims to enhance security by reducing the risk of private key thefts.
- Administrators are advised to update their systems by October 14, 2026, to avoid unexpected certificate expirations.
Starting on February 10, 2027, the non-profit certificate authority Let's Encrypt will reduce the validity period of its SSL/TLS certificates from 90 days to 64 days. This move is part of the organization's ongoing efforts to improve security and ensure the widespread adoption of HTTPS.
Administrators are encouraged to prepare for the change by updating their systems. Let's Encrypt will begin testing the new 64-day certificates from October 14, 2026, and users are advised to opt-in to these tests to ensure their systems are compatible with the new standards.
Prior to Let's Encrypt's launch in early 2016, certificates were often issued for periods of 1 to 3 years. The initial 90-day certificates were introduced to encourage the automation of certificate renewal processes, which were previously manual or non-existent.
Shorter certificate validity periods are expected to limit the potential impact of private key thefts, as the risk of exposure is reduced within a shorter timeframe. This change is aimed at accelerating the adoption of HTTPS across the web, enhancing overall security for users and websites.
For administrators already implementing modern ACME clients that support ARI (ACME Renewal Information), the transition should be seamless. However, those relying on hardcoded renewal schedules or manual processes are advised to update their systems by the deadline to avoid certificate expiration issues.
Let's Encrypt's decision to reduce certificate lifetimes is part of a broader strategy to maintain high standards of security and reliability. The organization continues to prioritize the protection of user data and the promotion of secure web practices.
Administrators are encouraged to stay informed and prepared for the upcoming changes. Let's Encrypt will provide detailed guidance and support to ensure a smooth transition for all users.





