SSL certificates are what put the padlock in your browser and keep connections to your website, remote access and email secure. Every certificate has an expiry date, and those dates are getting shorter.
Let's Encrypt, one of the largest certificate providers, has announced that from 10 February 2027 its certificates will last 64 days instead of 90, with a further reduction to around 45 days expected in 2028. More renewals means more chances for one to be missed, and an expired certificate means browser warnings, failed connections and, in some cases, an outage.
The good news is that preparing is straightforward. Here is a simple three-step plan.
Step 1: Review Your SSL Environment
When: now, and by the end of October 2026
Find out what you have before anything changes.
- List the websites, portals, email services and internal systems that use certificates.
- Note who provides each certificate and how it is renewed.
- Flag anything renewed by hand, or that you are unsure about.
Anything that relies on someone remembering to renew it is where problems are most likely to appear.
Step 2: Test Automating Your Next Renewal
When: November to December 2026
Test with a real renewal before the change takes effect. A test environment for the shorter certificates opens on 14 October 2026.
- Switch to automatic renewal wherever your systems support it.
- Check that the renewed certificate is installed and working without anyone stepping in.
- Fix any systems that renew on a fixed schedule that will no longer suit the shorter lifetime.
Finding a problem in a test is far cheaper than finding it on a live system.
Step 3: Automate and Monitor Continuously
When: January 2027 onwards, with the change taking effect on 10 February 2027
Automatic renewal is only reliable if you know when it stops working.
- Set up alerts for failed or upcoming renewals, so you hear about problems before your customers do.
- Agree who is responsible for each certificate.
- Review renewals regularly through spring 2027. The last 90-day certificates are expected to expire by 11 May 2027.
Shorter lifetimes are likely to continue, so setting this up properly now means you will not have to repeat the exercise in 2028.
Key Dates
| Date | What happens |
|---|---|
| 14 October 2026 | Test environment for 64-day certificates opens |
| 10 February 2027 | 64-day certificates become the default |
| 11 May 2027 | Last 90-day certificates expected to expire |
| 2028 | Lifetimes expected to fall to around 45 days |
Need a Hand?
If you would rather not manage this yourself, or you are not sure which certificates your business relies on, we can help. We can review your environment, set up automatic renewal and monitoring, and keep an eye on it going forward, whether you have an internal IT team or not.
Get in touch and we will tell you what applies to your business and what to do first. There is no obligation and no sales pitch, just a straight conversation about where you stand.