So it’s because the new intermediate CAs are not signed by the ISRG root, and therefore are unable to issue new certificates with a proper chain?
I hope you will issue a new certificate when the intermediate CA is signed by the root.
If it will take some time to do the key ceremony, it would have been nice to have an explanation on the site, why it has an invalid certificate.