Key details

  1. October 7, 2026: Let's Encrypt publishes a concrete 64-day transition and testing notice.
  2. October 14, 2026: 64-day default issuance begins in staging.
  3. February 10, 2027: default classic-profile issuance and renewal drops from 90 to 64 days.
  4. May 11, 2027: Let's Encrypt expects the last pre-cutover 90-day certificate to expire.
  5. Authorization reuse shrinks from 30 days to 10 days, then seven hours in 2028.
  6. ARI-aware clients receive renewal timing; custom scripts should renew at about two-thirds of the certificate lifetime.
  7. No change to ACME endpoints, issuance chains or published rate limits.

What builders should take away

  1. Inventory certificate issuance and renewal paths, including third-party appliances, CI jobs, DNS hooks and hosting panels.
  2. Use the October 14 staging cutover to test the complete issuance, install and service-reload sequence.
  3. Replace fixed 60/80/83-day timers with ARI-aware clients or renewal based on certificate lifetime.
  4. Monitor expiry dates and alert independently of renewal jobs.
  5. If your custom ACME client reuses prior authorizations, test behavior with the 10-day reuse window.

What changed

Let's Encrypt confirmed on October 7, 2026 that certificates issued or renewed under its default classic profile from February 10, 2027 will be valid for 64 days instead of 90. The staging environment will issue 64-day certificates from October 14, 2026 for testing. Existing 90-day certificates remain valid and are not revoked; the last are expected to expire May 11, 2027. The authorization reuse window also falls from 30 days to 10 days. A further move to 45-day default certificates and a seven-hour authorization reuse period is planned for 2028.

Why it matters

The shift is an infrastructure compatibility test disguised as a shorter expiration date. Standard ACME clients that support ACME Renewal Information (ARI) can receive renewal timing guidance from Let's Encrypt, but custom cron jobs, appliance integrations and scripts that renew on a fixed calendar or wait until a certificate is nearly 90 days old can fail silently. The consequence is expired TLS and downtime, not merely more frequent certificate orders. Operators can test in staging in October rather than discovering the issue in February.

Staging changes in October, production in February

The October 14 staging switch allows certificate managers and hosting providers to validate renewal and deployment behavior ahead of the February 10 default change. Production issuance and renewals from that date will have 64-day validity; no mass revocation is planned.

ARI clients should be fine; fixed-day cron jobs are the risk

Let's Encrypt says ACME Renewal Info-compatible clients should handle the change. For custom automation it recommends renewal at approximately two-thirds of the certificate lifetime, not on a fixed date. Check cron, scripts and runbooks for hard-coded 83-, 80- or 60-day assumptions. Renewal must also deploy the certificate and reload the relevant service.

Authorization reuse is shrinking too

The CA will reduce authorization reuse from 30 days to 10 days with the February change, then to seven hours in 2028. This matters mainly to custom ACME integrations that cache prior domain-validation state; routine ACME clients generally should not require a change.

No new issuance chains or rate-limit changes

Let's Encrypt says ACME endpoints and certificate chains are unchanged, and existing rate limits are unaffected. Its February 2026 rate-limit guidance explains that qualifying renewals remain exempt from new-order limits, so increased renewal frequency does not itself imply new rate-limit pressure.

What to watch next

  • Whether common hosting panels and older ACME clients ship fixes before February 10.
  • Whether operators report staging incompatibilities after October 14.
  • Whether Let's Encrypt adjusts the 2028 45-day rollout details.

Still unclear

  • Impact depends on the ACME client and custom automation; modern ARI-compatible setups may need no action.
  • The 2028 shorter-lifetime stage remains a future scheduled transition.

Sources

Direct reading behind this dossier.

3 sources

Discussion

Discussion is reader-contributed. Comments are not part of the BTN dossier or its editorial evidence.

0 visible comments

Join the discussion

Keep comments useful and relevant. Reader contributions may be moderated and are not BTN editorial evidence.

Sign in to comment