Image: Ars Technica

UpTrajectory Review

Let's Encrypt is shortening the lifespan of its free SSL/TLS certificates from 90 days to 64 days, with the change taking effect in production on February 10, 2027. An opt-in testing period begins October 14, giving site administrators a runway to validate their automation before the new reality hits. This continues a deliberate trajectory: before 2016, certificates routinely lasted one to three years, and Let's Encrypt's introduction of 90-day certs was itself a radical forcing mechanism for automation. The logic remains consistent — shorter validity windows shrink the attack surface if a private key is compromised, and they compel the kind of renewal infrastructure that manual processes never built.

For small-business operators running their own websites, e-commerce storefronts, or customer portals, this is not an abstract infrastructure story. If your certificate expires unexpectedly, browsers flag your site as insecure, checkout flows break, and trust evaporates in real time. The businesses most at risk are those where SSL renewal is a semi-annual calendar reminder or a task delegated to a contractor who may no longer be on retainer. The 64-day cycle means renewals happen roughly five to six times a year instead of four, and any slack in your process gets compressed.

What is genuinely new here is not the philosophy — Let's Encrypt has been telegraphing shorter lifetimes for years — but the concrete timeline and the explicit dependency on ACME Renewal Information (ARI) support. ARI is the mechanism that lets the certificate authority signal when a renewal should happen, rather than the client guessing on a fixed schedule. If your ACME client supports ARI, the transition should be invisible. If it does not, you are running on borrowed time. We are skeptical of any admin who assumes their current setup will 'probably just work' — that assumption is exactly what this change is designed to punish.

The second-order effect worth noting is fragmentation. Large enterprises with dedicated platform teams will absorb this quietly. Small operators, nonprofits, and community organizations running legacy control panels or shared hosting with opaque renewal logic will feel the pinch disproportionately. Hosting providers that bundle Let's Encrypt certificates will need to update their backends, and some may use the transition as leverage to upsell managed certificates or premium tiers. There is also a subtle cost: more frequent renewals mean more frequent opportunities for automation to fail silently, and monitoring becomes non-negotiable rather than nice-to-have.

What to do now: identify every certificate your business depends on, confirm which ACME client issues and renews it, and verify ARI support before the October 14 test window opens. Opt into the testing phase if your client allows it. If you rely on a hosting provider or IT vendor, ask them directly how they are handling the 64-day transition — and get the answer in writing. Set up expiry monitoring independent of your renewal automation so you get warned before your customers do. February 2027 sounds distant, but infrastructure debt has a way of compounding quietly until it does not.

“For those still relying on hardcoded renewal schedules or manual processes, February will be the deadline to update before certificates start expiring unexpectedly.” — Ars Technica

Takeaway: Audit your SSL renewal automation now and confirm ARI support before Let's Encrypt's 64-day certificates arrive in February 2027.

Excerpt from the original — Ars Technica

Let's Encrypt is continuing a push toward tighter security by reducing free SSL/TLS certificate lifetimes from 90 days to 64 days, starting February 10, 2027. For administrators already implementing modern ACME clients that support ARI (ACME Renewal Information), the change should be seamless. For those still relying on hardcoded renewal schedules or manual processes, February will be the deadline to update before certificates start expiring unexpectedly.
Starting on October 14, Let's Encrypt will begin testing the 64-day certificates, and interested users can opt in to test their setups before production goes live.
Prior to Let's Encrypt's launch in early 2016, certificates were often issued for as long as one to three years. The service started with 90-day certificates to force renewal automation that didn't previously exist. Shorter certificate validity periods limited …