Padlock graphic with the text Let's Encrypt 64-day certificates, changing from 90 days to 64 days

Let’s Encrypt 64-Day Certificates Arrive Feb 10: Is Your Renewal Ready?

Let’s Encrypt 64-day certificates will replace the current 90-day ones as the default on February 10, 2027. If your site renews automatically, you may not need to do anything, but a hardcoded renewal schedule could quietly break. Here’s how to check in about five minutes.

Quick facts, so you can skim:

  • Staging starts issuing 64-day certificates on October 14, 2026.
  • Production switches by default on February 10, 2027.
  • The last 90-day certificate should expire around May 11, 2027.
  • Existing valid certificates will not be revoked.
  • Rate limits, ACME endpoints and issuance chains stay the same.

The short version: renewals just got more frequent, and old assumptions baked into scripts are the real risk.

What Let’s Encrypt 64-day certificates change for your site

As Let’s Encrypt announced, any certificate issued or renewed on or after February 10, 2027 gets a 64-day lifetime instead of 90. That’s a drop of 26 days. Your site keeps working exactly as before as long as renewal keeps working.

You can still ask for a shorter lifetime if your client allows it. The 45-day and 6-day options announced earlier are not affected by the new default.

Think of it as a faster clock. You don’t pay more or do anything different on the web page, but a missed renewal now bites sooner.

The dates to put in your calendar

The rollout is gradual, and the later steps matter too. Here’s the timeline from the official post:

Date What happens
October 14, 2026 Staging starts issuing 64-day certificates so you can test.
February 10, 2027 Production default becomes 64 days.
May 11, 2027 The last 90-day certificate is expected to expire.
2028 Default drops to 45 days; authorization reuse shrinks to seven hours.
2029 Maximum validation reuse periods are reduced.

Notice that 45 days is already planned for 2028. Fixing your setup now saves you from doing it twice.

Will your auto-renewal survive the switch?

It depends on how your client decides when to renew. There are two safe setups and one risky one.

  • Your client supports ACME Renewal Info (ARI). Let’s Encrypt tells it when to renew, so no schedule change is needed.
  • Your client renews at roughly two-thirds of the certificate’s lifetime. That works for any length.
  • Your schedule is hardcoded, such as “renew 30 days before expiry.” This is the one to fix.

Why it matters: a rule that made sense for 90 days can leave almost no buffer on a 64-day certificate. For a 64-day certificate, the two-thirds rule works out to about day 43, or roughly 21 days before expiry. That figure is my own arithmetic, not a number from Let’s Encrypt.

Check your client’s documentation to confirm ARI support, since it varies by tool.

A five-minute checklist before February

Do these in order. Most people finish after step three.

  • Test against staging once it opens on October 14.
  • Search your cron jobs, wrapper scripts and runbooks for numbers like 83, 80 or 60, which often mark old renewal windows.
  • Switch to ARI or a two-thirds rule if your tool allows it.
  • Add automatic reload and deploy steps, plus an alert when renewal fails.
  • Change anything only if your setup relies on authorization reuse, which drops from 30 to 10 days.

The alert is the cheapest insurance here. Browsers are already strict about insecure pages, as we covered in our Chrome 154 HTTP warning guide, so an expired certificate costs you visitors fast.

What this means if you run a small site or blog

Most small sites use a host or control panel that renews certificates in the background. In that case the change is invisible to you. The host’s software will pick up the new default on its own.

The people who need to act are those who run their own server, use custom scripts, or manage certificates for clients. If that’s you, open your renewal config today and note how it decides when to renew. Ten minutes of reading now beats an expired-certificate warning on a Monday morning.

One more tip: set a calendar reminder for October 14 and run one test issuance on staging. A staging certificate is not trusted by browsers, so you can’t break a live site by trying it.

Why certificate lifetimes keep getting shorter

Let’s Encrypt says the goal is to reduce the risk of key compromise and mis-issuance. A stolen key is only useful until its certificate expires, so shorter lifetimes shrink that window.

The trade-off is that automation stops being optional. If you’re also tightening other security basics, our npm malware package check is a good next stop.

Frequently Asked Questions

Do I need to do anything right now?

No. Production doesn’t change until February 10, 2027. Use the time to test on staging from October 14.

Will my current 90-day certificate stop working?

No. Let’s Encrypt won’t revoke valid certificates for this change. Your 90-day certificates run until they expire.

Do I have to pay for shorter certificates?

Let’s Encrypt did not announce any pricing change. Its certificates stay free, and rate limits are not affected.

What if my host manages certificates for me?

Then your host handles it. If you’re unsure, ask them whether they support ARI or renew at two-thirds of lifetime.

My take: don’t panic, but don’t ignore it either. If your renewal is fully automatic and alerts you on failure, you’re fine. If it runs on a number someone typed in years ago, fix that this month, before the 64-day clock makes mistakes expensive.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *