Let's Encrypt to shorten certificate lifetimes to 64 days from February 2027
Let's Encrypt will cut the default lifespan of its free SSL/TLS certificates from 90 to 64 days starting February 10, 2027, with a testing phase opening October 14, 2026 for admins to trial the change. The certificate authority also plans a further reduction to 45-day defaults in 2028.
GoKawiil's interpretation of the reporting above, not reported fact.
Shorter lifespans limit the damage a compromised or mis-issued certificate can do, and push the industry further toward automated renewal via ACME and ARI rather than manual or hardcoded update schedules. Administrators relying on fixed renewal scripts rather than automated tooling risk unexpected certificate expirations once the shorter window takes effect.
- Default certificate lifetime drops from 90 to 64 days on February 10, 2027
- Opt-in testing for the shorter lifetime begins October 14, 2026
- A further cut to 45-day default certificates is planned for 2028
Source: arstechnica.com, 2026-10-08
Published there as: “Let's Encrypt cuts certificate lifetimes to 64 days starting February 2027”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.