There is one little-discussed down side to ever shorter-lived certificates...
If you're using ACME to handle certificate rotation, can't you just configure multiple providers?
Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong.
If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.
Letsencrypt is not the only acme authority. ZeroSSL is the other popular one. There are others.