Not a threat and not an opinion: it is the calendar the industry has already agreed. In 184 days the maximum drops to 100, and in 2029 to 47. What you renew once a year today becomes four times, then eight.
At that rate manual renewal stops being an inconvenience and becomes an outage waiting to happen. ACME settles it: your server asks for and renews the certificate by itself, with nobody writing down a date.
The maximum in force since March 2026.
Four renewals a year for every certificate.
Eight a year. By hand, this no longer holds.
What ACME is
ACME — Automatic Certificate Management Environment — is an IETF standard, RFC 8555. It is the same protocol Let's Encrypt uses, and the one certbot, acme.sh, Caddy, Traefik, cert-manager and nearly everything else speaks. Your server proves it controls the domain, asks for the certificate and renews it when the time comes. No emails, no CSRs pasted by hand, no dates.
The difference from Let's Encrypt is not the protocol: it is what stands behind the certificate — a warranty, organisation validation if you need it, support with a name attached, and issuance that does not depend on a free tier's rate limit.
Plus cPanel, Plesk, IIS, HAProxy, Synology, pfSense and anything else that speaks ACME: it is a standard, not an integration of ours.
The comparison
| By hand | ACME | |
|---|---|---|
| Issuing the first one | 5steps: CSR, validate, download, install, restart | 1command, and minutes |
| Renewals a year in 2029 | 8for every certificate | 0of them yours |
| With ten domains | 80a year | 0— the same work as with one |
| Hours a year on that | 26hours of somebody's time | 0after setting it up once |
| If nobody remembers | The site goes down | Does not apply |
| Who does it | A person, with a reminder | The server |
The certificates
They come in two shapes. The difference is not the quality of the certificate — the same authority issues both — but how you ask for it.
ACME Certificate-as-a-Service
We hand you EAB credentials and your ACME client asks the authority for certificates all year, without coming back to the shop.
Plan + Automate
The same RapidSSL or GeoTrust as always, with the automation included in the price. You buy one and it keeps renewing itself.
One domain, renewing itself
Unlimited issuance · 1 name included
Unlimited issuance · 1 name included
One domain, renewing itself
Covers *.yourdomain.com and every subdomain
Covers *.yourdomain.com and every subdomain
| Certificate | Shape | Covers | Additional names | Warranty | Price per year |
|---|---|---|---|---|---|
| Plan + Automate | 1 domain | — | USD$10K |
$44.90
|
|
| ACME CaaS | 1 domain | up to 100, priced per name | USD$50K |
$49.90
|
|
| ACME CaaS | 1 domain | up to 100, priced per name | USD$500K |
$69.90
|
|
| Plan + Automate | 1 domain | — | USD$500K |
$79.90
|
|
| Plan + Automate | *.yourdomain.com | — | USD$10K |
$199
|
|
| Plan + Automate | *.yourdomain.com | — | USD$500K |
$299
|
How it works
certbot, acme.sh, or whichever your panel or proxy already ships. Many servers already have one.
With the EAB credentials we hand you. Once, and it is done.
The client validates, issues, installs and renews before expiry. Whether that is 200 days or 47.
Questions
Same protocol, and it works. What it does not carry is a warranty, organisation validation, or anybody to call. For a personal site it is enough; for a company answering for its mail or its payments, usually not.
No. The ACME client does it for you at each issuance, with a fresh key.
Yes, validating over DNS. On the CaaS products a wildcard is quoted separately; the wildcard Plan + Automate ones already include it.
A key pair that binds your ACME client to your account with the authority. We hand them over at purchase and they are configured once.
Issuance yes; the organisation validation happens once and lasts, so the renewals after it are automatic. Write to us and we will look at your case.
They can be migrated without waiting for expiry. We do it with you and without an interruption.
Tell us which server you run and how many domains you have, and we will tell you which ACME client suits you and which of these certificates. If you would rather not touch it, we install it for you.