Skip to content
Back to blog

Blog

SSL Certificate Lifetimes Are Getting Shorter: What to Do and When

8 October 2026

SSL certificates are what put the padlock in your browser and keep connections to your website, remote access and email secure. Every certificate has an expiry date, and those dates are getting shorter.

Let's Encrypt, one of the largest certificate providers, has announced that from 10 February 2027 its certificates will last 64 days instead of 90, with a further reduction to around 45 days expected in 2028. More renewals means more chances for one to be missed, and an expired certificate means browser warnings, failed connections and, in some cases, an outage.

The good news is that preparing is straightforward. Here is a simple three-step plan.

Step 1: Review Your SSL Environment

When: now, and by the end of October 2026

Find out what you have before anything changes.

  • List the websites, portals, email services and internal systems that use certificates.
  • Note who provides each certificate and how it is renewed.
  • Flag anything renewed by hand, or that you are unsure about.

Anything that relies on someone remembering to renew it is where problems are most likely to appear.

Step 2: Test Automating Your Next Renewal

When: November to December 2026

Test with a real renewal before the change takes effect. A test environment for the shorter certificates opens on 14 October 2026.

  • Switch to automatic renewal wherever your systems support it.
  • Check that the renewed certificate is installed and working without anyone stepping in.
  • Fix any systems that renew on a fixed schedule that will no longer suit the shorter lifetime.

Finding a problem in a test is far cheaper than finding it on a live system.

Step 3: Automate and Monitor Continuously

When: January 2027 onwards, with the change taking effect on 10 February 2027

Automatic renewal is only reliable if you know when it stops working.

  • Set up alerts for failed or upcoming renewals, so you hear about problems before your customers do.
  • Agree who is responsible for each certificate.
  • Review renewals regularly through spring 2027. The last 90-day certificates are expected to expire by 11 May 2027.

Shorter lifetimes are likely to continue, so setting this up properly now means you will not have to repeat the exercise in 2028.

Key Dates

DateWhat happens
14 October 2026Test environment for 64-day certificates opens
10 February 202764-day certificates become the default
11 May 2027Last 90-day certificates expected to expire
2028Lifetimes expected to fall to around 45 days

Need a Hand?

If you would rather not manage this yourself, or you are not sure which certificates your business relies on, we can help. We can review your environment, set up automatic renewal and monitoring, and keep an eye on it going forward, whether you have an internal IT team or not.

Get in touch and we will tell you what applies to your business and what to do first. There is no obligation and no sales pitch, just a straight conversation about where you stand.

Want to talk through your IT security?

We offer a free, no-obligation assessment for businesses across the UK.

Get in touch