Six-day and IP certificates become generally available

Let's Encrypt short-lived certificates last 160 hours. Verify ACME client support and renewal monitoring before adoption.

Contents of this article

What happened

On January 15, 2026, Let's Encrypt announced general availability of short-lived and IP address certificates. Short-lived certificates last 160 hours, just over six days, using the shortlived profile. IP certificates must also be short-lived. The announcement describes an opt-in option, not the default at that time.

Implications for website operations

A shorter lifetime also shortens the recovery window after renewal failure. Successful issuance is only the start: deployment, reloads and standby endpoints must update too. Seeing a new certificate in a dashboard does not prove that clients receive it.

Operational next steps

Pilot on a non-critical endpoint, check client profile support, and test alerts and retries when renewal fails. External monitoring should inspect the served certificate's expiry, with a documented emergency reissuance and deployment path.

Official source

Read the official publication

Back to industry insights Contact technical support