
Let’s Encrypt is dialing up the pressure on web admins and home lab heroes alike, slashing its default SSL/TLS certificate lifetime from 90 days down to 64 days starting February 10, 2027. The non-profit certificate authority says the move is about tightening security and cementing automated renewals as the norm, not the exception.
The rollout is happening in two stages: first, Let’s Encrypt will flip its staging environment to 64-day certificates on October 14, 2026 so operators can test their setups without risking production outages. Then, on February 10, 2027, the “classic” ACME profile in production will begin issuing 64-day certs by default, with the last legacy 90-day certificate expected to expire on May 11, 2027. This is an interim step on a longer road map that ends with 45-day default lifetimes slated for February 16, 2028 to match upcoming CA/Browser Forum baseline requirements. For environments that want to go even harder on security, Let’s Encrypt already offers short-lived 6-day certificates as an optional profile.
To understand why this matters, it helps to rewind a decade. Before Let’s Encrypt launched in the mid-2010s, commercial SSL certificates routinely lasted one to three years, and manual renewals were just part of the job. When Let’s Encrypt entered the scene it deliberately chose 90-day lifetimes, arguing that shorter validity windows reduce the fallout from stolen private keys and push the ecosystem toward automation. That bet paid off: the project is now a major driver of HTTPS adoption across the web, and its 90-day default became the de facto standard for free certificates. The new 64-day default is the next turn of the screw.
The key technology behind this change is ACME (Automated Certificate Management Environment) and, more specifically, the ACME Renewal Information extension known as ARI. ARI, standardized as RFC 9773, gives a certificate authority a way to tell ACME clients exactly when each certificate should be renewed, replacing crude “renew every X days” cron jobs with per-certificate guidance. Modern ACME clients can query ARI, get a suggested renewal window, and refresh certificates automatically within that window with no human intervention. Let’s Encrypt explicitly frames the 64-day shift as mostly painless for admins already running ARI-aware tooling, but warns that those who still rely on hardcoded schedules or manual renewals are the ones most at risk of surprise expirations.
The decision to pause at 64 days instead of jumping straight to 45 is all about catching laggards before they break things. In community discussions, Let’s Encrypt staff noted that some ACME clients still renew at a hardcoded 60-day interval, a pattern that worked for 90-day certs but would be dangerously close to the edge once lifetimes drop further. By stopping at 64 days first, those sites will start throwing imminent-expiration warnings and attracting attention, giving operators time to fix their automation before the stricter 45-day baseline arrives. Official guidance from Let’s Encrypt is to renew around (frac{2}{3}) of the certificate’s lifetime—roughly day 43 for a 64-day cert and day 30 for a 45-day cert—rather than at some arbitrary fixed offset from issuance.
Practically, here’s what this means for the kind of geeks who spin up game servers, self-hosted wikis, media boxes, or personal blogs on their own hardware. If your current setup uses a simple “renew every 60 days” script or relies on a calendar reminder to rerun certbot, you’ll need to retool before February 2027 or risk waking up to expired HTTPS on your services. The safer path is to upgrade to an ACME client that supports ARI and let it follow Let’s Encrypt’s recommended renewal windows automatically. For environments with tighter security requirements—say, reverse proxies fronting multiple services or zero-trust meshes—shorter profiles like the 6-day option paired with robust automation can significantly narrow the window in which a stolen key is useful to an attacker.
This change isn’t happening in a vacuum. The CA/Browser Forum, which sets industry rules for certificate authorities, is in the process of ratcheting down maximum lifetimes across the board, and Let’s Encrypt’s roadmap to 45 days is explicitly designed to keep it compliant with the upcoming SC-081v3 requirements. Other CAs are also experimenting with ARI and similar mechanisms to make short-lived certs viable at scale, and big players like Google have been updating their public key infrastructure to accommodate these more dynamic renewal flows. Let’s Encrypt emphasizes that rate limits won’t be tightened as part of the shift—renewals don’t count against its issuance limits—so users can safely move to more frequent, automated refreshes without worrying about being throttled.
The bottom line: free certificates aren’t going away, but the days of “set it and forget it” HTTPS are officially over. Let’s Encrypt’s 64-day pivot is a clear signal that automation and ARI-style intelligence are the future of certificate management, even for hobby projects and personal sites. Admins have a generous runway: they can opt in to test the new lifetimes in staging starting October 14, 2026, then ride the wave into production in February 2027 with minimal drama—as long as they modernize their ACME clients and ditch brittle manual renewal habits ahead of time.








