What changed
Let's Encrypt confirmed on October 7, 2026 that certificates issued or renewed under its default classic profile from February 10, 2027 will be valid for 64 days instead of 90. The staging environment will issue 64-day certificates from October 14, 2026 for testing. Existing 90-day certificates remain valid and are not revoked; the last are expected to expire May 11, 2027. The authorization reuse window also falls from 30 days to 10 days. A further move to 45-day default certificates and a seven-hour authorization reuse period is planned for 2028.
Why it matters
The shift is an infrastructure compatibility test disguised as a shorter expiration date. Standard ACME clients that support ACME Renewal Information (ARI) can receive renewal timing guidance from Let's Encrypt, but custom cron jobs, appliance integrations and scripts that renew on a fixed calendar or wait until a certificate is nearly 90 days old can fail silently. The consequence is expired TLS and downtime, not merely more frequent certificate orders. Operators can test in staging in October rather than discovering the issue in February.
Staging changes in October, production in February
The October 14 staging switch allows certificate managers and hosting providers to validate renewal and deployment behavior ahead of the February 10 default change. Production issuance and renewals from that date will have 64-day validity; no mass revocation is planned.
ARI clients should be fine; fixed-day cron jobs are the risk
Let's Encrypt says ACME Renewal Info-compatible clients should handle the change. For custom automation it recommends renewal at approximately two-thirds of the certificate lifetime, not on a fixed date. Check cron, scripts and runbooks for hard-coded 83-, 80- or 60-day assumptions. Renewal must also deploy the certificate and reload the relevant service.
Authorization reuse is shrinking too
The CA will reduce authorization reuse from 30 days to 10 days with the February change, then to seven hours in 2028. This matters mainly to custom ACME integrations that cache prior domain-validation state; routine ACME clients generally should not require a change.
No new issuance chains or rate-limit changes
Let's Encrypt says ACME endpoints and certificate chains are unchanged, and existing rate limits are unaffected. Its February 2026 rate-limit guidance explains that qualifying renewals remain exempt from new-order limits, so increased renewal frequency does not itself imply new rate-limit pressure.