But if my server is already active / licensed, would we be fine when the SSL renews after Sept, since it renews about every 3 months?
So I can't say for sure, but that's because I almost never use 3CX FQDNs (and their SSLs) in my installs.
However, once active, a 3CX PBX can stay active for a long time - I've seen years, but also a bunch of things can trigger it to re-activate (and no, I don't have a comprehensive list). If it's a VM, reactivation seems to get triggered more often then bare metal installs. But it's a bad day when you come in and the system is down because reactivation was triggered and it failed.
In the past, for 3CX FQDNs, when talking about the old 3CX free offering, 3CX had "monitoring" of the PBX being online / in use. If it wasn't in use, 3CX would shutdown the machine and after a few months of it being shutdown they would delete it and then the FQDN would be freed up. I don't think this monitoring applies to paid licenses, but the license would have to continue to be paid obviously.
For the LE certs to work, at a minimum, the FQDN has to be active. So really, the question is, once activation server certs change, will that somehow cause the FQDN to be released (because if so, you have lots of issues, including the SSL)? And if not, does the PBX require activation server communication for the LE cert? Certbot doesn't, but I don't know if 3CX customized it.
Lots of text and you still don't have a 100% guarantee that it will or will not work post September. If I were a betting man though, I would say you would be fine, provided you upgrade within a few months of September - really that reactivation request will likely bite you before anything else will.