Let's Encrypt, the nonprofit certificate authority that secures a large share of the web, is shortening its default TLS certificate lifetime from 90 days to 64 days. The change takes effect on 10 February 2027, the organisation said in a blog post on 7 October.

From that date, every certificate Let's Encrypt issues or renews will be valid for 64 days unless a subscriber opts into an even shorter lifetime of 45 or 6 days. The last 90-day certificate is expected to expire on 11 May 2027. Let's Encrypt says it will not revoke valid certificates as part of the transition.

To let administrators prepare, the new lifetime will appear first in Let's Encrypt's staging environment on 14 October 2026, and the CA recommends testing there before production switches.

The practical risk is automation that renews on a hard-coded schedule. Let's Encrypt advises clients that use ACME Renewal Info (ARI), which lets the CA tell the client when to renew, that they need to do nothing. Everyone else should move to renewing at roughly two-thirds of the certificate lifetime — and, as a starting point, to grep cron jobs, wrapper scripts and runbooks for hard-coded values such as 83, 80 or 60 days.

A second change tightens validation: the authorisation reuse period falls from 30 days to 10 days, and to seven hours in 2028, to comply with a 2029 cap on maximum validation reuse periods and to remove the need for 'CAA rechecking'.

Rate limits, ACME endpoints and issuance chains are unaffected. The 64-day default is a stepping stone: Let's Encrypt has already announced a 45-day default for 16 February 2028. The organisation says shorter lifetimes reduce the risk of key compromise and mis-issuance.