Services, honestly

Let's Encrypt's 45-day option: should client sites switch now?

Let's Encrypt's opt-in tlsserver profile now issues 45-day certificates. Which client sites should switch now, which should wait, and how to check renewals.

By Volant team

A designer looks after twelve small sites: a dentist, two cafés, a yoga studio and a handful of trades. This morning she reads that Let's Encrypt, the free service that supplies the padlock certificate on most of those sites, has started issuing 45-day certificates. Her first thought is the dentist's booking page showing a security warning on a Monday morning. Her second is: do I have to change something today?

Probably not. As of 13 May 2026, Let's Encrypt issues 45-day certificates through an opt-in setting called the tlsserver profile, meant for early adopters and testing. Everyone else stays on the default, which still issues 90-day certificates and will shorten in stages over the next two years. The useful move now is to switch one site you control, confirm your renewals cope, and check every other site's renewal before the default changes.

What changed on 13 May?

A security certificate proves a website is who it says it is, and it's what puts the padlock in the browser. Let's Encrypt certificates have lasted 90 days for years. In December 2025 Let's Encrypt announced they'll be cut to 45 days by 2028, in line with new industry rules that every public certificate provider must follow.

The first step landed this week. Let's Encrypt lets your renewal software ask for a "profile", a named set of certificate settings. On 13 May it switched its tlsserver profile to issue 45-day certificates, and on 14 May it confirmed in its community forum that the change was live. The profile is opt-in. If your software doesn't ask for it, nothing changes for your sites today.

When will every site move to shorter certificates?

Here's the timeline from Let's Encrypt's announcement:

Date What changes Who it affects
13 May 2026 tlsserver profile issues 45-day certificates Only sites that opt in
10 February 2027 Default profile issues 64-day certificates Every site on the default
16 February 2028 Default profile issues 45-day certificates Every site on the default

Let's Encrypt notes that each change applies from a site's next renewal after the date, not on the day itself. So there's time. But nine months is less time than it sounds when you look after a dozen sites across four hosts.

Should client sites switch to 45 days now?

For most client sites, no. Switch one first.

Let's Encrypt's own advice is that most people whose certificates renew automatically won't need to change anything, as long as their automation copes with shorter certificates. The 45-day profile exists so you can find out whether yours does, before February 2027 decides for you.

Switch a test site now if:

  • you host the site yourself and run the renewal software;
  • your renewal software lets you choose a profile (Let's Encrypt's profiles page notes that not every renewal tool supports this);
  • you can watch it through at least one full renewal.

Leave a site on the default for now if:

  • the host manages certificates for you and you can't choose a profile;
  • the site renews by hand, or you're not sure how it renews (fix that first);
  • the site is business-critical and you haven't tested the shorter profile anywhere else.

The tlsserver profile changes more than the length. Let's Encrypt's profiles page lists a shorter window for proving you control the domain and slimmer certificates. Modern software handles these without trouble, but it's another reason to test on one site before changing many.

How do you check that renewals will cope?

Go through each site once, write down the answers, and keep them with the client's details.

  1. Who renews the certificate? Your host, a control panel, or software you run. If nobody knows, that's the first thing to fix.
  2. When does the current certificate expire? Click the padlock or site settings icon in the browser and open the certificate details.
  3. How does renewal decide when to run? Let's Encrypt warns that renewing on a fixed 60-day cycle won't work with 45-day certificates. It recommends renewing at about two thirds of the way through a certificate's life, or using a feature called ACME Renewal Information (ARI), which lets Let's Encrypt tell your software when to renew. Check your software's documentation for ARI.
  4. Would you know if a renewal failed? Let's Encrypt recommends monitoring that alerts you when certificates aren't renewed on time. A simple monitoring service that checks expiry dates is enough for a small agency.

What does this mean for your care plans?

A care plan that says "security certificate included" is quietly promising that renewals work. Shorter certificates mean renewals happen more often, so a broken renewal shows up sooner. That isn't a reason to worry. It's a reason to check.

Add three lines to your monthly routine:

  • confirm each site's certificate expiry date is comfortably in the future;
  • confirm renewal is automatic, and note who does it;
  • note any site that renews by hand and move it to automatic renewal.

If you haven't written up the wider changes for clients, the 45-day SSL certificate changes cover what to tell them and what to put in the plan. And if you bundle hosting, renewal checks belong in the costs and time you price for, as the guide to a website hosting and maintenance package sets out.

Clients rarely need the technical detail. A one-line note in your monthly report is plenty: "Your site's security certificate renewed automatically on 3 May and is valid until July."

What should you tell clients now?

Very little, unless they ask. A client who reads a headline about "shorter certificates" may worry that their site is about to break. A short, calm answer helps:

Website security certificates are moving to shorter periods, so they renew more often. Your site renews its certificate automatically, and I check it every month as part of your plan. You don't need to do anything.

Only send that if it's true. If one of their sites renews by hand, or you're not sure who renews it, fix that first and then tell them it's sorted. Clients remember the designer who told them before there was a problem far better than the one who explained afterwards.

Is this worth selling as a service?

Certificate checks are small work, and they're best as part of a care plan rather than a separate charge. What clients value is that someone is watching. Describe it by what they get: "We check your site's security certificate every month, so visitors don't see a warning."

If you sell to local businesses through a marketing offer rather than web builds, the same check fits there too. The page for marketers selling local services covers how care and marketing work sit together, and a service recipe is a simple way to write the monthly steps down so they happen the same way every time.

The short version: switch one site you control, watch it renew, check the rest, and put the check in your plan. Then February 2027 is just another month. The services you can sell after the website show where certificate checks fit alongside the rest of the care work a one-person AI agency sells.

Questions

Questions people ask

Should I switch my sites to 45-day certificates?
Most client sites don't need to switch now. The 45-day option is opt-in and meant for early adopters and testing. Switch one site you host yourself, where your renewal tool supports choosing a profile, to prove your renewals cope with shorter certificates. Leave the rest on the default until you've seen that work.
When will all Let's Encrypt certificates be 45 days?
Let's Encrypt's timeline moves its default profile to 64-day certificates on 10 February 2027 and to 45-day certificates on 16 February 2028. The changes apply at each site's next renewal after those dates.
Do I need to do anything if my host manages certificates for me?
Usually not, but ask the host whether its renewals are ready for shorter certificates and check each site's expiry date now and then. The certificate is your client's padlock, whoever renews it.
How do I check when a site's certificate expires?
In most browsers, click the padlock or site settings icon next to the address and open the certificate details. The expiry date is listed there. A monitoring service can check it for you and warn you before it lapses.

Start here

Try one ideaon your next client.

Every how-to here works with a simple notes file. Keep the ones that help, and let Volant keep track when you're ready.

For Mac and Windows. Works with Claude Code.

Join the waitlist