Let’s Encrypt, the free and open certificate authority widely used to secure websites with HTTPS, announced it will shorten the default validity period of its TLS certificates from 90 days to 64 days, starting February 10, 2027.
All certificates issued or renewed from that date will have a 64-day lifespan unless users explicitly select one of the shorter options already available: 45 or six days.
Existing certificates will remain valid until their expiration dates. Let’s Encrypt expects the final 90-day certificate to expire on May 11, 2027. The organization also confirmed no valid certificates will be revoked during the transition.
To help administrators prepare, Let’s Encrypt will introduce 64-day certificates in its staging environment on October 14, 2026, allowing users to test their renewal setups before the change reaches production.
The move is part of a broader effort to improve web security by reducing how long compromised or incorrectly issued certificates remain usable. Simply put, shorter certificate lifetimes mean attackers have less time to exploit a stolen private key.
Of course, shorter validity periods also mean certificates must be renewed more frequently. For website administrators already using automated renewal tools, this should require little or no intervention.
In particular, Let’s Encrypt says users whose ACME clients support ACME Renewal Info should be ready for the transition. ARI allows the certificate authority to inform clients when certificates should be renewed, rather than relying on fixed schedules.
However, administrators using cron jobs or scripts with hardcoded renewal intervals should review their configurations. Instead of renewing a certificate a fixed number of days before expiration, Let’s Encrypt recommends scheduling renewals after approximately two-thirds of its validity period has passed.
The organization suggests checking scripts and configuration files for hardcoded values like 83, 80, or 60 days, which may no longer work reliably with shorter-lived certificates.
Another upcoming change concerns domain validation. Let’s Encrypt will reduce the period during which a previously completed domain authorization can be reused from 30 days to 10 days. In 2028, that period will shrink further to just seven hours.
The goal is to align with upcoming industry requirements and simplify how the certificate authority handles previously validated domains. Most users won’t need to make adjustments unless their ACME clients depend on reusing earlier authorizations.
Importantly, the transition won’t change Let’s Encrypt’s existing rate limits, ACME endpoints, or certificate issuance chains.
Looking further ahead, the organization plans to reduce the default certificate lifetime again, this time to 45 days in 2028. That makes the upcoming 64-day limit an intermediate step rather than the final destination.
For more information, see Let’s Encrypt’s official announcement.
