Let's Encrypt moving to 64-day certificate lifetimes in 2027
What happened
This is the second stage of Let's Encrypt's plan, announced in 2025 , to move to 45-day certificate lifetimes as required by the the CA/Browser Forum Baseline Requirements . In 2028, Let's Encrypt will switch to 45-day certificates.
Free SSL (the encryption that secures a connection to a website)/TLS certificate lifetimes reduce to 64 days in February. Let's Encrypt is continuing a push toward tighter security by reducing free SSL/TLS certificate lifetimes from 90 days to 64 days, starting February 10, 2027.
For administrators already implementing modern ACME clients that support ARI (ACME Renewal Information), the change should be seamless. For those still relying on hardcoded renewal schedules or manual processes, February will be the deadline to update before certificates start expiring unexpectedly.
Key facts
- This is the second stage of Let's Encrypt's plan, — announced: in 2025 , to move to 45-day certificate lifetimes as required by the the CA/Browser Forum Baseline Requirements
Sources & evidence
- Ars Technica Reporting source
Let's Encrypt cuts certificate lifetimes to 64 days starting February 2027 ↗
https://arstechnica.com/gadgets/2026/10/lets-encrypt-cuts-certificate-lifetimes-to-64-days-starting-february-2027/ - LWN.net Reporting source
Let's Encrypt moving to 64-day certificate lifetimes in 2027 ↗
https://lwn.net/Articles/1099588/