Thanks @Osiris for the response. Before I could test your suggestion, I found a workaround / fix.
I suspect Sophos UTM is trying to renew, but the certs were still good so LE "said" pound sand.
In Sophos UTM needed to delete all existing LE certs on both the Certificates tab AND the Certificate Authority tab under Certificate Management.
Note this screws up every config where those certs are used.
Once the above were deleted, I enabled LE support and the "account' was created. Then I could recreate the certs needed and the fun part...
Reconfig of the WebServer protection and filtering proxy.
It's all back up as it should be.
For anyone running by this discussion in the future, delete the certs on both tabs and start over.