Let's Encrypt's 45-day option: should client sites switch now?
Let's Encrypt's opt-in tlsserver profile now issues 45-day certificates. Which client sites should switch now, which should wait, and how to check renewals.
A designer looks after twelve small sites: a dentist, two cafés, a yoga studio and a handful of trades. This morning she reads that Let's Encrypt, the free service that supplies the padlock certificate on most of those sites, has started issuing 45-day certificates. Her first thought is the dentist's booking page showing a security warning on a Monday morning. Her second is: do I have to change something today?
Probably not. As of 13 May 2026, Let's Encrypt issues 45-day certificates through an opt-in setting called the tlsserver profile, meant for early adopters and testing. Everyone else stays on the default, which still issues 90-day certificates and will shorten in stages over the next two years. The useful move now is to switch one site you control, confirm your renewals cope, and check every other site's renewal before the default changes.
What changed on 13 May?
A security certificate proves a website is who it says it is, and it's what puts the padlock in the browser. Let's Encrypt certificates have lasted 90 days for years. In December 2025 Let's Encrypt announced they'll be cut to 45 days by 2028, in line with new industry rules that every public certificate provider must follow.
The first step landed this week. Let's Encrypt lets your renewal software ask for a "profile", a named set of certificate settings. On 13 May it switched its tlsserver profile to issue 45-day certificates, and on 14 May it confirmed in its community forum that the change was live. The profile is opt-in. If your software doesn't ask for it, nothing changes for your sites today.
When will every site move to shorter certificates?
Here's the timeline from Let's Encrypt's announcement:
| Date | What changes | Who it affects |
|---|---|---|
| 13 May 2026 | tlsserver profile issues 45-day certificates | Only sites that opt in |
| 10 February 2027 | Default profile issues 64-day certificates | Every site on the default |
| 16 February 2028 | Default profile issues 45-day certificates | Every site on the default |
Let's Encrypt notes that each change applies from a site's next renewal after the date, not on the day itself. So there's time. But nine months is less time than it sounds when you look after a dozen sites across four hosts.
Should client sites switch to 45 days now?
For most client sites, no. Switch one first.
Let's Encrypt's own advice is that most people whose certificates renew automatically won't need to change anything, as long as their automation copes with shorter certificates. The 45-day profile exists so you can find out whether yours does, before February 2027 decides for you.
Switch a test site now if:
- you host the site yourself and run the renewal software;
- your renewal software lets you choose a profile (Let's Encrypt's profiles page notes that not every renewal tool supports this);
- you can watch it through at least one full renewal.
Leave a site on the default for now if:
- the host manages certificates for you and you can't choose a profile;
- the site renews by hand, or you're not sure how it renews (fix that first);
- the site is business-critical and you haven't tested the shorter profile anywhere else.
The tlsserver profile changes more than the length. Let's Encrypt's profiles page lists a shorter window for proving you control the domain and slimmer certificates. Modern software handles these without trouble, but it's another reason to test on one site before changing many.
How do you check that renewals will cope?
Go through each site once, write down the answers, and keep them with the client's details.
- Who renews the certificate? Your host, a control panel, or software you run. If nobody knows, that's the first thing to fix.
- When does the current certificate expire? Click the padlock or site settings icon in the browser and open the certificate details.
- How does renewal decide when to run? Let's Encrypt warns that renewing on a fixed 60-day cycle won't work with 45-day certificates. It recommends renewing at about two thirds of the way through a certificate's life, or using a feature called ACME Renewal Information (ARI), which lets Let's Encrypt tell your software when to renew. Check your software's documentation for ARI.
- Would you know if a renewal failed? Let's Encrypt recommends monitoring that alerts you when certificates aren't renewed on time. A simple monitoring service that checks expiry dates is enough for a small agency.
What does this mean for your care plans?
A care plan that says "security certificate included" is quietly promising that renewals work. Shorter certificates mean renewals happen more often, so a broken renewal shows up sooner. That isn't a reason to worry. It's a reason to check.
Add three lines to your monthly routine:
- confirm each site's certificate expiry date is comfortably in the future;
- confirm renewal is automatic, and note who does it;
- note any site that renews by hand and move it to automatic renewal.
If you haven't written up the wider changes for clients, the 45-day SSL certificate changes cover what to tell them and what to put in the plan. And if you bundle hosting, renewal checks belong in the costs and time you price for, as the guide to a website hosting and maintenance package sets out.
Clients rarely need the technical detail. A one-line note in your monthly report is plenty: "Your site's security certificate renewed automatically on 3 May and is valid until July."
What should you tell clients now?
Very little, unless they ask. A client who reads a headline about "shorter certificates" may worry that their site is about to break. A short, calm answer helps:
Website security certificates are moving to shorter periods, so they renew more often. Your site renews its certificate automatically, and I check it every month as part of your plan. You don't need to do anything.
Only send that if it's true. If one of their sites renews by hand, or you're not sure who renews it, fix that first and then tell them it's sorted. Clients remember the designer who told them before there was a problem far better than the one who explained afterwards.
Is this worth selling as a service?
Certificate checks are small work, and they're best as part of a care plan rather than a separate charge. What clients value is that someone is watching. Describe it by what they get: "We check your site's security certificate every month, so visitors don't see a warning."
If you sell to local businesses through a marketing offer rather than web builds, the same check fits there too. The page for marketers selling local services covers how care and marketing work sit together, and a service recipe is a simple way to write the monthly steps down so they happen the same way every time.
The short version: switch one site you control, watch it renew, check the rest, and put the check in your plan. Then February 2027 is just another month. The services you can sell after the website show where certificate checks fit alongside the rest of the care work a one-person AI agency sells.