What Let's Encrypt's 64-day notice actually changes
Let's Encrypt says that on February 10, 2027, new certificates last 64 days by default. Staging switches on October 14, 2026. Existing certificates are not revoked.
The short version
On February 10, 2027, the default certificate lasts 64 days unless a subscriber already chose 45 or 6 days. Valid certificates are not revoked. Staging issues 64-day certificates from October 14, 2026.
What happened
On October 7, 2026, Let's Encrypt published a post by Sarah Gran. It says that on February 10, 2027, subscribers move to 64-day certificates by default unless they select a shorter lifetime of 45 or 6 days. Certificates issued or renewed on or after that date have a 64-day validity period. The post expects the last 90-day certificate to expire on May 11, 2027, and says valid certificates will not be revoked for this change. Staging switches to 64-day issuance on October 14, 2026. Ars Technica and LWN reported the same post. The page filing it is Futureweb.
What the default does not cover
The default change is the classic profile. Subscribers already on the opt-in 45-day profile or the 6-day profile are outside the new default, because they already chose a shorter life. A December 2025 post had scheduled this February 2027 step, including a 10-day authorization reuse period, and a further cut to 45 days on February 16, 2028. The October 7 post is the near-term notice. It is not a surprise relative to that schedule. The desk is Networking.
What a subscriber is told to change
The post says a client that supports ACME Renewal Info can take the renewal time from Let's Encrypt, and that a renewal hard-coded as a count of days before expiration should move to about two-thirds of the certificate's life. It says that habit also prepares for the 45-day default in 2028. This page does not list the day-counts people might have hard-coded. The instruction is the fraction, not a search recipe. What a TLS certificate binds, which is a different question from how long it lasts, is what a TLS certificate binds.
Why it matters on this desk
The dependency is the lifetime of a publicly trusted certificate, so the brief sits on the networking desk. The check is a date, a number of days, and a statement that existing certificates are not revoked. Rate limits, ACME endpoints, and issuance chains are unchanged, according to the post. A security brief about a product bulletin is a different document, on Security.
What the reuse change is
The same post says the authorization reuse period drops from 30 days to 10 days, and to seven hours in 2028. The reason it gives is a 2029 cut in the maximum time validation data may be reused, and a wish to stop repeating part of validation when that data is older than seven hours. It says a client that was not built to depend on reuse needs no change for this part. A software note on what a version number has to mean is what a version number has to mean.
What the outlets are checking
Ars Technica and LWN both report the February 10, 2027 date and the 64-day default. They are not a second policy. Where an outlet adds a client name or a migration anecdote, that detail stays with the outlet. The company's sentences are the dates, the three lifetime choices, the no-revocation line, the staging date, and the reuse periods. This page does not add a count of certificates Let's Encrypt issues. A separate public-trust filing, about an authority that says it is not issuing yet, is what Cloudflare's certificate post has not issued.
What to watch next
October 14, 2026 is the staging date. February 10, 2027 is the production date for the 64-day default. May 11, 2027 is the date the post expects the last 90-day certificate to expire. February 16, 2028 is the later 45-day step from the 2025 schedule. A post that moves any of those dates replaces this one. A post that only repeats 64 days does not.
What would change the record
A correction of the February 10 date, a decision to revoke 90-day certificates after all, or a change to the reuse period would replace the sentences above. The December 2025 post remains the schedule this October notice is carrying out. Ars Technica and LWN are the check that the October 7 post was reported more than once. They are not the policy.
What stays a lifetime change
What stays specific is an October 7, 2026 notice: on February 10, 2027, the default Let's Encrypt certificate lasts 64 days, staging moves on October 14, 2026, valid certificates are not revoked, and the last 90-day certificate is expected to expire on May 11, 2027. Shorter profiles remain available. Rate limits and issuance chains stay as they are. It is not a new certificate authority. It is not a revocation event. The post and the two outlets agree on the default date. This page does not invent a client count. Sarah Gran's byline and the October 7 dateline are what make the page a company notice rather than a trade summary. The December 2025 post is the earlier schedule, and it already named February 10, 2027 for the 64-day classic profile and February 16, 2028 for 45 days. The new post adds the staging date, the May 11 expiration estimate, the no-revocation line, and the reuse cut from 30 days to 10 days. A subscriber who only read a headline could miss that existing certificates keep running. That line is the one that keeps this from being a revocation story. Ars Technica reported the cut. LWN reported the same move. Neither is the policy text. The policy text is the post.
Sources
The reports this brief is filing. Futureweb did not republish them.
Questions
When does Let's Encrypt say the default certificate lifetime becomes 64 days?
February 10, 2027, for certificates issued or renewed on or after that date, unless the subscriber has selected a 45-day or 6-day profile. The post is by Sarah Gran, dated October 7, 2026.
Will Let's Encrypt revoke existing 90-day certificates on February 10, 2027?
No. The October 7 post says valid certificates will not be revoked as part of this change. It expects the last 90-day certificate to expire on May 11, 2027.
When does Let's Encrypt say staging will issue 64-day certificates?
October 14, 2026. The post says the staging switch is for testing before the production change.
What happens to the Let's Encrypt authorization reuse period?
The October 7 post says it falls from 30 days to 10 days with the 64-day change, and to seven hours in 2028. Subscribers who did not design a client around reuse are told they need no change for that part.
Does the 64-day change alter Let's Encrypt rate limits or issuance chains?
The October 7 post says no. It says rate limits are unaffected, and that ACME endpoints and issuance chains are unaffected.