Trusence Every claim has a source
Last updated 9 October 2026 Search Türkçe
← All stories
Security

Let’s Encrypt will cut certificate lifetimes to 64 days in 2027

The shorter lifetime is meant to keep automated renewals working, while manual and fixed-schedule setups will need to change before certificates start expiring sooner.

Let’s Encrypt will shorten the default lifetime of its free SSL/TLS certificates from 90 days to 64 days on February 10, 2027, a move meant to push more automated renewal workflows. Administrators using modern ACME clients with ARI support should be able to absorb the change without disruption, but teams that still depend on fixed renewal schedules or manual renewals will need to adapt before certificates begin expiring unexpectedly. The project will open a testing period for the 64-day certificates on October 14, 2026 so users can check their setups ahead of the production switch. The change reflects Lets Encrypt’s long-running effort to make certificate management more automated and less dependent on long-lived credentials.

Why it matters

For sites and services that already use ACME clients with ARI support, the shift should be mostly invisible. Teams that still renew on a fixed timetable or by hand will face a tighter window and need to adjust before the February 2027 switch. A testing period in October 2026 gives them time to confirm their setup before the new default takes effect.

Sources

  • Ars Technica