So I wonder when the switch happens, so we can get one last batch of 90 day certs with the old chain to give people more time to move to newer chromes (and firefoxes).
We don't have the exact date set - we're waiting on a cross-sign from IdenTrust, but it will be sometime this fall. I would recommend getting a fresh set of certificates now and again in two weeks.
Also, it would be less risky to pin roots (DST Root X3, ISRG Root X1, and now ISRG Root X2) than intermediates, since we intend to rotate intermediates on a more regular basis in the future.
We don't currently have official guidance on whether or how to use HPKP, but note that it has increasingly been a source of issues in the WebPKI: