Well, 90-day certificate lifetime is actually good. But what would be the difference between 90-day and 93-day?
With 93 days, a certificate issued 1st of month M will be guaranteed to not expire before 1st of month M+3. Renewal automation could just be simplified as a bash script that will run every 1st of month M, M+3, M+6, M+9
Monitoring of certificate expiration would be deadly simple.