Services, honestly

SSL certificates are getting shorter: what it means for your care plans

Let's Encrypt is moving to 45-day SSL certificates by 2028. What changes, the dates, and what to check and write into your website care plans now.

By Volant team

A physiotherapy clinic's website goes down on a Monday morning. Not down exactly: the page loads, but the browser shows a full-screen warning that the connection isn't private. Patients trying to book see it and phone instead, or don't. The cause is a security certificate that expired over the weekend, on a site the clinic pays you to look after.

That kind of failure is about to get more chances to happen. Earlier this month Let's Encrypt, a free, non-profit certificate provider, announced it will cut its certificates from 90 days to 45 days by 2028. The rest of the industry is shortening too.

For most sites that renew automatically, nothing breaks. For the ones that don't, the gap between "fine" and "warning page" gets much shorter. Here's what's changing, when, and what to check and write into your care plans.

What does an SSL certificate actually do?

An SSL certificate (strictly, a TLS certificate these days, but everyone still says SSL) is what gives a website the padlock in the browser and the "https" at the start of its address. It proves to the visitor's browser that the site really belongs to that domain, and it lets the two talk privately.

Every certificate has an end date. When it passes, browsers warn visitors away. The fix is a new certificate, and on most modern hosting that happens automatically in the background: a small program called an ACME client asks the certificate provider for a fresh one before the old one runs out.

Your client never sees any of this. They only see it when it fails.

What exactly is changing, and when?

Two things are happening at once.

The industry rules. Certificate providers follow rules set by the CA/Browser Forum, a group of certificate providers and browser makers. In April 2025 it passed a ballot that cuts the longest a public certificate may last from 398 days to 47 days, in stages starting in March 2026 and ending in March 2029. That covers paid certificates too, including one-year certificates.

Let's Encrypt's own timeline. Let's Encrypt currently issues 90-day certificates. Its announcement on 2 December 2025 sets out three dates:

Date What Let's Encrypt changes Who it affects
13 May 2026 45-day certificates on an opt-in profile Only people who choose it, mostly for testing
10 February 2027 Default certificates drop to 64 days Everyone on the default settings
16 February 2028 Default certificates drop to 45 days Everyone on the default settings

Each change applies at a site's next renewal after that date, not to certificates already issued.

Let's Encrypt is also shortening how long a proof of domain control can be reused, from 30 days today to 7 hours by 2028. In plain terms: the renewal program will have to prove it controls the domain almost every time it renews, so any setup where that proof needs a person, or a manual change to DNS records, will feel the change first.

Why is this happening?

Let's Encrypt says shorter lifetimes limit the damage when a certificate is compromised and make cancelling bad certificates work better. The CA/Browser Forum ballot gives similar reasons: checking information more often and keeping certificates shorter reduces the chance and the reach of mistakes.

You don't need to agree with the reasoning to plan for it. It's happening across the industry, and your clients' sites will be on the new rules whatever host they use.

Will your clients' sites be affected?

Sort each site you look after into one of three groups.

Renews automatically on managed hosting. Most hosting companies and site builders handle certificates for you. These sites should keep working with no change. It's still worth confirming, because "the host does it" is an assumption until you've seen it renew.

Renews automatically on a server you or the client set up. Here the renewal program is yours to watch. Let's Encrypt warns that a client renewing on a fixed 60-day schedule will not be enough once certificates last 45 days. It recommends renewal information from the provider (a feature called ARI) or, failing that, renewing about two thirds of the way through a certificate's life.

Renewed by hand, or by a process nobody remembers. This is the group to fix now. Let's Encrypt says plainly that manual renewal isn't recommended, because it has to be done more and more often as lifetimes shrink. A certificate that needs a person every six weeks will eventually meet a holiday, a sick day or a busy month.

What should you check on each site?

Make this part of your January care plan routine. For each site:

  1. Find out who issues the certificate. Click the padlock in the browser and look at the issuer and the expiry date.
  2. Find out what renews it. The host, a plugin, a program on the server, or a person. Write it down in the client's notes.
  3. Check the renewal schedule. If you control it, make sure it isn't a fixed long interval. Let's Encrypt's example of what will break is a hard-coded 60 days.
  4. Check domain validation. If renewals rely on a DNS change, make sure that step is automatic too.
  5. Set up an expiry alert. Let's Encrypt recommends monitoring so you're told when a certificate isn't renewed as expected, and lists monitoring services on its site.
  6. Note sites that can't be automated. An old server, a client-managed setup, a proxy you don't control. These need a conversation with the client, not a reminder in your calendar.

Keep the answers with each client's other details, so next year's check starts from what you found this year.

What should your care plan say about certificates?

Promise the checking, not the clicking. "We renew your SSL certificate" invites a manual job that gets riskier every year. "We check your certificate renews automatically, and we're alerted if it doesn't" describes the work that actually protects the client.

A few lines worth adding to a care plan:

  • What's covered. "We confirm your security certificate renews automatically and watch for failures."
  • What happens on failure. "If renewal fails, we fix it on the same working day and tell you what happened."
  • What's not covered. "Sites that can't renew automatically need a one-off fix, quoted separately."

That last line matters. A care plan that quietly absorbs a manual certificate every six weeks is a care plan losing money. When you write each service down as a service recipe, with its steps and its limits, this sort of change becomes a one-line edit instead of a surprise.

Is this a reason to sell care plans?

It's a fair reason to explain one. Most small business owners don't know their site has a certificate until it expires. A short, honest note that says what's changing, that their site is set up to renew on its own, and that you check it each month, is exactly the kind of work a care plan pays for. Don't dress it up as an emergency; it isn't one for a well set-up site.

If you're adding services to sell after the website, certificate checks belong in the plain monthly routine alongside updates, backups and form tests. The same goes if you're one of the marketers selling local services who look after a client's site as part of a wider package: the site is yours to watch even if the building was someone else's.

For a one-person AI agency, this is also a good job to hand to your agent: have it list every site you look after, the certificate issuer, the expiry date and what renews it. You read the list and decide what to fix. The check takes an hour in January and saves the clinic from a Monday morning warning page.

Questions

Questions people ask

Are SSL certificates changing to 45 days?
Yes, in stages. Let's Encrypt announced on 2 December 2025 that its certificates will go from 90 days to 45 days by February 2028. Separately, the industry's rules cut the longest allowed certificate from 398 days to 47 days in steps between March 2026 and March 2029.
Do I need to do anything if my host renews certificates automatically?
Usually not, but check it. Make sure renewal really is automatic, that it doesn't rely on a fixed schedule such as every 60 days, and that you'd hear about a failed renewal before a visitor does.
Will paid SSL certificates change too?
Yes. The shorter limits come from the CA/Browser Forum's rules, which every publicly trusted certificate provider follows, not just Let's Encrypt. A certificate bought for a year will stop being possible as the limits step down.
What should a website care plan say about SSL certificates?
Say that you check the certificate renews automatically and that you are told if it fails, rather than promising to renew it by hand. Name what happens if a client's setup can't renew automatically.

Start here

Try one ideaon your next client.

Every how-to here works with a simple notes file. Keep the ones that help, and let Volant keep track when you're ready.

For Mac and Windows. Works with Claude Code.

Join the waitlist