Following extensive discussions within the CA/Browser Forum, digital certificate authorities are preparing to significantly shorten certificate lifespans. In the near future, these validity periods will decrease to between 60 and 90 days. Ultimately, the industry intends to restrict these lifespans to a mere 47 days, excluding root certificates. Let’s Encrypt, a leading free certificate authority, plans to go even further, reducing its certificate lifespan to 45 days. Consequently, the entire renewal process must eventually rely entirely upon robust automation mechanisms.
Transitioning to 64-Day Validity in 2027
Let’s Encrypt previously unveiled its comprehensive implementation plan. Beginning February 10, 2027, the default validity period for digital certificates issued under the classic ACME profile will shrink to 64 days. Simultaneously, the authorization reuse period will drop to 10 days. These profound adjustments will apply exclusively to newly issued or renewed digital certificates. Fortunately, the organization will not prematurely revoke any certificates issued before this critical deadline.
Based on this timeline, the final digital certificates boasting a 90-day lifespan will expire precisely on May 11, 2027. After that date, developers continuing to utilize Let’s Encrypt will automatically receive new certificates valid for only 64 days. For organizations that have already deployed comprehensive, automated issuance and deployment workflows, this transition should cause minimal disruption.
Early Testing Available Beginning October 2026
Let’s Encrypt recently published a vital announcement regarding testing procedures. Starting October 14, 2026, the organization will activate the new, shortened cycle within its staging environment. Developers and meticulous website administrators can proactively test and rigorously verify their application renewal processes. Identifying and rectifying potential issues early ensures a seamless transition before the mandatory February 10 deadline for automated application and deployment.
The Final Push Toward 45 Days
Furthermore, by February 16, 2028, every single certificate issued by Let’s Encrypt will feature an abbreviated 45-day lifespan. This aggressive schedule outpaces the broader industry plan formulated by the CA/Browser Forum. According to that broader strategy, the maximum validity for publicly trusted TLS certificates will drop to 100 days beginning in March 2027, before finally settling at 47 days in 2029. Clearly, Let’s Encrypt is adjusting its policies significantly ahead of the established industry standards.
The Critical Need to Review Automated Renewals
For clients utilizing the ACME Renewal Information (ARI) extension, Let’s Encrypt can directly notify the client to schedule the renewal. Generally, this sophisticated process requires absolutely no manual intervention. However, if renewal scripts run strictly on fixed schedules or rely on manual certificate replacements, administrators must urgently review their cron jobs and deployment protocols.
Let’s Encrypt strongly recommends configuring the renewal trigger at the two-thirds mark of the certificate’s lifespan. For example, a system utilizing a 64-day certificate should automatically initiate the renewal check precisely on day 43. Numerous complex network services currently lack the capability to accomplish automated certificate issuance and deployment through ACME or similar mechanisms. These legacy services, which depend entirely on manual application and replacement, will inevitably encounter monumental obstacles in the future. As certificate validity periods plummet, the frequency of necessary manual interventions will skyrocket. Any human error, whether forgetting to renew or botching the deployment, will disastrously render the service completely inaccessible.
Support Our Threat Intelligence
Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!