Needs to work every few years for each domain. Unless all your certificates expire at the same time (or you only have a few), this will be triggered a few times per year.
And moreover, your scenario is essentially "worst case: fall back to previous behavior." That's not too bad...