Let's Encrypt will shorten free SSL/TLS certificate lifetimes from 90 days to 64 days starting February 10, 2027. The organization says the move continues its long-running push toward shorter validity periods, which began with 90-day certificates in 2016. The new schedule is designed to push administrators toward full ACME automation, particularly through the ARI renewal mechanism that lets the certificate authority tell clients when to renew.
Before the change takes effect, Let's Encrypt will open opt-in testing on October 14, 2026, so users can check their setups. The organization recommends that administrators audit renewal scripts for hardcoded values such as 83, 80, or 60 days, and confirm their ACME clients support ARI. It also advises setting expiration notifications and taking advantage of the testing period before the February deadline.
The company also plans to shrink authorization reuse periods from 30 days to 10 days, and eventually to seven hours by 2028. A further reduction to 45-day certificate lifetimes is planned for 2028. Administrators who rely on manual renewals or fixed renewal schedules have about four months to update their systems before the new deadline takes effect.