Let's Encrypt Shortens Free Certificate Lifetimes to 64 Days
Security·October 9, 2026

Let's Encrypt, the nonprofit certificate authority that issues free SSL/TLS certificates, will shorten the lifetime of those certificates to 64 days beginning in February 2027. The current validity period is 90 days, so the change cuts roughly a month from each certificate.
The practical effect falls on anyone who runs a website or service that depends on Let's Encrypt. Shorter certificates renew more often, which means manual renewal becomes harder to keep up with. Sites that still rely on someone remembering to copy a new certificate onto a server are the most exposed to outages when a renewal slips. Operators who already use an automated client, such as certbot or another ACME-compatible tool, should see little change beyond a higher number of renewal events.
The reasoning behind the move is security. A certificate that is valid for a shorter window limits how long a stolen or mis-issued certificate can be abused. Shorter lifetimes also reduce the reliance on certificate revocation, which has long been unreliable in practice. The shift is part of a wider movement across the web public key infrastructure ecosystem toward shorter-lived certificates, and it is designed to make automated issuance the default rather than the exception.
For now, the February 2027 date gives administrators several months to check their renewal tooling, confirm that cron jobs or renewal timers are running, and test their setups against a shorter cycle. Teams that manage large fleets of certificates may want to audit where certificates are installed, since any system that cannot renew automatically will need attention before the deadline.
Reporting based on an external source.