Let's Encrypt: 64-day certificates by default from 10 February 2027
From 10 February 2027, Let's Encrypt will issue 64-day certificates by default. Staging tests start 14 October 2026; the last 90-day certificate expires on 11 May 2027.
UptimeMag editorial team · 8 October 2026 · 2 min read

Let's Encrypt is changing the default validity period for TLS certificates: from 10 February 2027, all certificates issued or renewed will have a 64-day validity period, unless shorter periods are chosen (45 or 6 days, already announced previously). The news was shared by Sarah Gran on the official Let's Encrypt blog on 7 October 2026. For anyone managing automated renewals on servers and hosting panels, the deadline cannot be pushed back: the logic behind your scripts needs checking before February.
What's changing and when
The authority will not revoke already-issued valid certificates: the transition will be gradual. The last 90-day certificate is expected to expire on 11 May 2027. To allow for testing, Let's Encrypt will start issuing 64-day certificates in the staging environment from 14 October 2026: anyone managing ACME automation should test there before the change rolls out to production.
What to check in your scripts
If renewal is automated and your ACME client supports ARI (ACME Renewal Info), no action is needed: ARI tells the client when to renew, and the source recommends checking your client's documentation to verify whether it's implemented.
If, on the other hand, renewals are hard-coded to a fixed number of days before expiry, they need updating to trigger at roughly two-thirds of the certificate's validity period. Let's Encrypt's practical advice: grep your cron jobs, wrapper scripts and runbooks for typical figures like 83, 80 or 60, which are calibrated around the current 90-day period.
This step also paves the way for the further reduction to a 45-day default planned for 2028.
Shorter authorisation reuse period
In parallel, the domain authorisation reuse period will drop from 30 to 10 days, and down to just 7 hours in 2028. The change allows Let's Encrypt to align with a planned reduction in maximum validation reuse periods due in 2029, and removes the need for "CAA rechecking" (the recheck performed when validation data is more than 7 hours old). Anyone who hasn't built their ACME client relying on validation reuse doesn't need to change anything.
Rate limits are unaffected by this change. Neither the ACME endpoints nor the issuance chains are changing. For further queries, Let's Encrypt points to the community forum and the official documentation.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Let's Encrypt.