Calculator: how many extra issuances with Let's Encrypt's 10-day DCV reuse
From 10 February 2027, domain control validation reuse on Let's Encrypt drops from 30 to 10 days. Here's how many extra issuances this means for 10, 50 and 200 domains.
UptimeMag editorial team · 8 October 2026 · 3 min read

From 10 February 2027, anyone using Let's Encrypt with the classic profile (the default one, used by most hosting providers) will see domain control validation (DCV) reuse drop from 30 to 10 days. This isn't a distant forecast: it's Phase 2 of an already published schedule. For those managing a handful of domains, the change will go unnoticed. For those managing dozens or hundreds, it translates into a precise number of extra ACME calls per year—and therefore more room for error if automation isn't solid.
What's changing, with dates
The source is the phase table published by dotcom-monitor.com on its technical blog. On 13 May 2026 (Phase 1), the opt-in tlsserver profile issues 45-day certificates with authorisation reuse unchanged at 30 days, for early adopters. On 10 February 2027 (Phase 2), the default classic profile moves to 64-day certificates with reuse cut to 10 days, for all users not on tlsserver or shortlived. On 16 February 2028 (Phase 3), the default classic profile reaches 45-day certificates with reuse cut to 7 hours.
The point that matters for planning purposes is this: the authorisation reuse period will go from 30 days to just 7 hours by 2028, making reliable ACME automation mandatory, not optional. The February 2027 Phase 2, with reuse at 10 days, is the intermediate step that most hosting providers will encounter first on the default profile.
The maths: extra issuances per year
With 30-day reuse, a domain doesn't normally repeat DCV at every renewal: the ACME client reuses the authorisation as long as it remains within the window. In practice, with renewal cycles organised around the 30-day authorisation validity, a domain reaches around 12 issuance/renewal cycles a year (365 / 30 ≈ 12.2). With reuse cut to 10 days, the useful window for reusing the same validation shrinks to a third: the same domain reaches around 36 cycles a year (365 / 10 ≈ 36.5).
| Domains managed | Issuances/year with 30-day reuse | Issuances/year with 10-day reuse | Difference |
|---|---|---|---|
| 10 | ~122 | ~365 | +243 |
| 50 | ~610 | ~1,825 | +1,215 |
| 200 | ~2,440 | ~7,300 | +4,860 |
The count is an estimate based solely on the reuse window described by dotcom-monitor and the CA/Browser Forum: the actual number of calls depends on how the ACME client is configured (cron, systemd timer, fixed interval or based on ACME Renewal Information) and how many SANs share the same validation process.
What to check before February 2027
- Check that the ACME client in use (certbot, acme.sh, lego, or the module built into the hosting panel) supports the updated classic profile and doesn't work on fixed renewal intervals such as "every 60 days", because with a 64-day cycle and 10-day reuse, that interval breaks down.
- Verify the rate limits of Let's Encrypt's ACME API for the account in use: more annual issuances per domain mean more calls adding up to the account's monthly total.
- Schedule external monitoring of certificate expiry, because with tighter cycles, a silently failed renewal turns into visible downtime much more quickly.
The phase table, updated as of 15 July 2026, is available on the dotcom-monitor.com blog; the industry-wide schedule for reducing certificate validity and DCV reuse is set out in the CA/Browser Forum's Ballot SC-081v3.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50).