Let's Encrypt moves to 64-day certificates in February 2027
Let's Encrypt will cut certificate lifetimes from 90 to 64 days on February 10, 2027; opt-in testing opens October 14. Audit renewal scripts and ARI support.

Let’s Encrypt, the certificate authority that issues more TLS certificates than anyone else, announced on October 7 that newly issued certificates will last 64 days instead of 90 starting February 10, 2027, with opt-in testing open from October 14, 2026. The reuse period for authorizations shrinks alongside it — from 30 days to 10, with a planned seven hours by 2028 — and the official post puts 45-day certificates on the roadmap for 2028, plus a checklist for every certificate holder: audit renewal scripts, confirm the ACME client supports ARI, and wire up expiration alerting.
Key points
- 64 days from February 10, 2027: operators get about four months of lead time, and the opt-in test window opens October 14 for staging environments.
- Two things to actually do: find hardcoded renewal offsets in cron jobs and runbooks (the post names 60-, 80- and 83-day patterns), and confirm the ACME client supports ARI (ACME Renewal Information).
- This is not the end: 45 days is already on the 2028 plan; per the CA/Browser Forum schedule cited by Ars Technica, the industry cap falls to 200 days in March 2026, 100 days in 2027 and 47 days by 2029.
Background
The 90-day lifetime was Let’s Encrypt’s founding design choice in 2016: short-lived certificates forced renewal automation and drove the cost of HTTPS toward zero. Ten years later the CA is cutting its own lifetime for the same reason — a shorter window of exposure after key compromise or misissuance. And the race to shorter certificates belongs to the whole industry: the CA/Browser Forum schedule writes the cap reductions into the calendar, and commercial CAs like DigiCert are following the same table. We previously covered Cloudflare’s public CA service — large platforms building their own issuance paths is the other answer to ever-faster renewal cycles.
The facts
| Change | Now | After | When |
|---|---|---|---|
| Certificate lifetime | 90 days | 64 days | from February 10, 2027 |
| Authorization reuse | 30 days | 10 days | with the 64-day switch |
| Opt-in testing | — | 64-day pipeline, voluntary | from October 14, 2026 |
| Next stop | 64 days | 45 days | 2028 (planned) |
The official checklist has three items in priority order. First, audit every hardcoded offset in renewal automation — anything written on the assumption of “renew 60 days before expiry” can silently never fire or misfire under a 64-day life. Second, confirm ARI support: the ACME extension lets the CA signal exactly which certificate is due for renewal, the coordination mechanism that short cycles depend on. Third, alert on renewal failures. Ars Technica adds an easy-to-miss change: with authorization reuse dropping to 10 days and eventually seven hours, clients that rely on cached validation data will feel the difference first.
What others say
Ars Technica reads the move against the CA/Browser Forum’s industry-wide schedule, pointing out that Let’s Encrypt is executing a browser-vendor-driven consensus — the cited DigiCert calendar has the whole industry at 47 days by 2029. Chinese coverage at IT Home emphasizes the scale: certificates from the world’s largest issuer by volume carry a large share of all HTTPS traffic, so any change to the timetable is a global operations event. The official post keeps an engineer’s tone — lists, dates, a test window — without dramatizing, but it is clear about what happens to those who skip the audit.
Our take
The impact splits sharply by deployment shape: anything on a managed platform (Vercel, Cloudflare, most PaaS) renews dynamically and will not notice; self-managed certbot, internal tooling and older embedded devices are where every hardcoded “60 days” becomes an outage. The one action worth taking now: grep your infrastructure for certificate scripts and replace day-countdown logic with ARI- or expiry-alert-driven renewal. Honest uncertainty: the 2028 45-day target and the 2029 47-day industry schedule are still plans — browser vendors and CAs may renegotiate the pace.
What to watch
- October 14, 2026: opt-in testing of the 64-day pipeline opens; rehearse in staging.
- February 10, 2027: all new certificates at 64 days; authorization reuse drops to 10 days.
- 2028: 45-day lifetimes and seven-hour authorization reuse on the plan.