Friday, 9 October 2026

Let’s Encrypt forces faster renewals, pushing sites to automate

A new plan reduces SSL/TLS certificate lifetimes from 90 days to 64 days, with early testing starting Oct. 14, 2026 and production in February 2027.

Rows of server racks in a data center

The short version

  • Let’s Encrypt will reduce certificate lifetimes from 90 days to 64 days, effective Feb 10, 2027.
  • Testing of the new 64-day lifetimes starts Oct 14, 2026 for administrators to opt in.
  • The change pushes sites toward greater automation to shorten renewal windows and improve security.
  • ARIs (ACME Renewal Information) will streamline renewal timing for modern ACME clients.
Quick read · 1 min

Let’s Encrypt will shorten SSL/TLS certificate lifetimes from 90 days to 64 days starting Feb 10, 2027. Testing begins Oct 14, 2026 with opt-in available.

Why it matters: shorter lifetimes reduce exposure from compromised keys and push sites toward full automation of renewals.

What you can do now: ensure your ACME client supports ARI, test renewals in a staging environment, and plan for updating renewal workflows.

Let’s Encrypt is tightening the reins on how often websites need to refresh their SSL/TLS credentials. Beginning February 10, 2027, the free certificate authority will shrink the valid window of its certificates from 90 days to 64 days. The move is designed to accelerate renewal automation and reduce the risk that a compromised key or a misissued certificate can stay active too long.

For site operators and developers who already rely on modern automation, the transition should be largely painless. The change targets processes that renew certificates on a schedule, encouraging people to move toward live, automated renewal checks rather than fixed, manually updated calendars.

To help teams get ready, Let’s Encrypt will start testing the 64-day model on October 14, 2026. Admins can opt in to the testing program to see how their tooling handles shorter lifetimes before the production rollout. This early work helps providers verify compatibility with their renewal logic and monitoring alerts.

The organization also hints at a longer path: shorter defaults may come in 2028, with a plan to reach 45-day lifetimes. The trend clearly aims to push the ecosystem toward full automation, making routine renewals happen without human intervention while keeping security current with rapid key and algorithm updates.

What this means for everyday users is mostly about reliability and trust. Shorter certificate lifetimes shrink the window where a bad actor could exploit a stolen private key, and they push websites to adopt the latest cryptographic standards sooner. If you run a website, you’ll want to test ARI support in your ACME client. ARI stands for ACME Renewal Information, and it helps clients know precisely when to renew, without guessing from a fixed schedule.

What you can do now: check that your hosting or deployment pipeline uses an ACME client that supports ARI, start a staging renewal test, and update your monitoring so you’re alerted well before a 64-day expiry hits production. You’ll also want a plan for automated rollout of certificate updates across any load balancers or edge servers you manage.

In short, Let’s Encrypt is nudging the web toward faster, more automated security refreshes. If your system already automates certificate renewal, you’re ahead. If not, October 2026 is a good window to start testing and adjusting your processes for a tighter renewal cadence.

Padlock
Server room

You're reading the quick version.