Microsoft ends support for old Secure Boot certificates
Microsoft has announced that starting in June 2026, old Secure Boot certificates will no longer be valid. Most devices will require updates through standard Windows updates. For some systems, an OEM firmware update will be necessary to maintain up-to-date boot protection.
Crius
Microsoft has announced the upcoming expiration of Secure Boot certificates issued in 2011: starting in June 2026, these certificates will begin to lose their validity. For most Windows devices, certificate replacement is already being handled through standard system updates, but some computers will require a firmware update from the manufacturer (OEM).
Main Changes and Timeline
The company is warning users and IT administrators that the original Secure Boot certificates, used since the era of Windows 8 and Windows Server 2012, will start to expire in June 2026 and will be fully invalid by October of the same year. Microsoft is already distributing new certificates, issued in 2023, through regular Windows updates for most devices.
Important Notices and Recommendations
Information about these upcoming changes appeared in the release notes for the Patch Tuesday update on January 13, 2026, for Windows 11 (KB5074109), as well as in a separate publication, KB5079373, which explains the implications of certificate expiration. Microsoft emphasizes that most devices will receive the new certificates automatically, but some systems will require a manual OEM firmware update.
Even after the old certificates expire, devices will still be able to boot and receive standard Windows updates. However, without the new certificates, such systems will not be able to receive security updates for the early stages of the boot process, including updates to Windows Boot Manager, Secure Boot databases, revocation lists, and patches for recently discovered boot chain vulnerabilities.
Security Implications
In a more detailed explanation (KB5062710), Microsoft notes that everyday device operation may not change immediately, but over time, systems without the new certificates will become less secure as new threats emerge during the boot process.
Transition to New Certificates
Microsoft is migrating devices to 2023 certificate authorities, including new entries for signing Secure Boot database updates and Windows boot components. In some cases, it may be necessary to add individual 2023 certificates, depending on what the device needs to trust (for example, trust in Option ROM).
For most consumer PCs, the new certificates will be delivered through managed Microsoft updates. However, to properly apply the new certificates on some systems, an OEM firmware update will be required. Microsoft does not recommend disabling Secure Boot as a workaround.
Recommendations for Enterprise Environments
For managed device fleets, Microsoft's guidance and action plan describe methods for inventory, monitoring, and implementing changes (including using Intune, group policies, and the registry) before the final deadline in June 2026.
Context of the Changes
Third-party publications note that Microsoft views this process as a "generational update" to the boot trust chain. Now, certificate updates are delivered through standard Windows servicing for supported devices, ensuring a smoother and more secure transition to new security standards.
