# Let's Encrypt — TLS certificate maximum validity by Certificate Authority: what each CA actually issues today For Let's Encrypt, profile or product is classic; maximum validity (days) is 90; still issuing tls certificates is yes; notes is The FAQ states the default lifetime; the profiles documentation names the default profile 'classic'. Let's Encrypt recommends renewing 90 day certificates every 60 days. There is no way to adjust these lifetimes, recorded from its source on 2026-08-18. - **Certificate Authority:** Let's Encrypt _(verified: appears in the quote below)_ - **Profile or Product:** classic _(our reading, not quoted from the source)_ - **Maximum validity (days):** 90 _(verified: appears in the quote below)_ - **Still issuing TLS certificates:** yes _(our reading, not quoted from the source)_ - **Notes:** The FAQ states the default lifetime; the profiles documentation names the default profile 'classic'. Let's Encrypt recommends renewing 90 day certificates every 60 days. There is no way to adjust these lifetimes. _(our reading, not quoted from the source)_ ## What the source says > Our default certificates are valid for 90 days. ## Source - https://letsencrypt.org/docs/faq/ Last verified: 2026-08-18. Review by: 2026-09-17. Part of [TLS certificate maximum validity by Certificate Authority: what each CA actually issues today](https://referencesource.org/ca-issuance-validity/).