Old Secure Boot certificates will expire in 2026
Microsoft warns that starting in June 2026, old Secure Boot certificates will no longer be valid. Users are advised to check their PC’s compatibility in advance and update their firmware to ensure they continue receiving future security updates.
Crius
Microsoft warns that the Secure Boot certificates issued in 2011 will soon expire—this will happen in June 2026. Users are advised to check in advance whether their PCs are ready to switch to the new certificate chain and to update their firmware if necessary.
What Will Change After 2026
Microsoft has already begun rolling out a new Secure Boot certificate chain, which will become mandatory for Windows once the original 2011 certificates expire. However, the next stage of the transition depends not only on Windows itself but also on whether your device’s firmware (UEFI) is ready for the change.
If your UEFI firmware does not support the new 2023 certificates, Windows Update may attempt to make the switch, but your device could end up in a “reduced security” state. In this case, future security-related boot updates may not be applied correctly.
Certificate Expiration Timeline
The trusted Secure Boot root certificates from Microsoft, issued in 2011, will start expiring at the end of June 2026. According to Dell:
- June 24, 2026: Microsoft Corporation KEK CA 2011 expires,
- June 27, 2026: Microsoft Corporation UEFI CA 2011 expires,
- October 19, 2026: Microsoft Windows Production PCA 2011 expires.
Impact on Users
Manufacturers agree that systems will continue to boot, but devices that do not switch to the new 2023 certificate chain may lose the ability to receive future bootloader and Secure Boot updates. This is referred to as “reduced security.”
The key technical mechanism is already implemented in supported Windows versions. Since updates released on February 13, 2024, it has been possible to add the Windows UEFI CA 2023 certificate to the Secure Boot allowed signatures database (db). This update is required to receive future bootloader updates through monthly patches.
Manufacturer Recommendations
- Microsoft notes that most devices will receive the new certificates automatically via updates, but some will require an OEM firmware update to properly apply the new certificates.
- Dell distinguishes between the active Secure Boot database (updated via Windows Update) and the default database (updated via BIOS). Certain firmware actions, such as switching to “Expert Key Mode,” may erase active variables if the default database is not updated.
- Lenovo recommends updating the BIOS to add the 2023 certificates to the default Secure Boot variables. Sometimes, additional steps are needed to activate the new variables, and it is also recommended to back up BitLocker recovery keys in advance.
- HP states it is working with Microsoft to prepare devices for the new certificates and warns that certificate expiration may prevent security updates related to Secure Boot and Windows Boot Manager from being received.
- ASUS provides detailed instructions for the transition, including checking for new certificates in the firmware and steps to take if they are missing. The FAQ describes how to restore default keys or reset to factory settings after a BIOS update.
Considerations for Custom-Built PCs
Users who assemble their own PCs may need to manually activate the new keys, even if Windows has already delivered the necessary updates.
For Enterprise Users
Microsoft provides specific indicators of successful implementation:
- An event with ID 1808 in the Windows event log confirms successful application,
- An event with ID 1801 indicates a failure,
- The UEFICA2023Status registry key should be set to “Updated,” and the absence of the UEFICA2023Error key means there are no errors.
Important Recommendations
If issues are detected or the manufacturer recommends a BIOS update, you should first apply the OEM firmware updates and then install the related Secure Boot updates for Windows. This highlights that Windows updates are only part of the process.
Connection to Windows 10 Support
The certificate update is another reason for Windows 10 users to consider their options. Support for this version ended on October 14, 2025, and to receive security updates after this date, the Extended Security Updates (ESU) program is required.
Microsoft emphasizes that devices running unsupported Windows versions do not receive updates, so switching to the new certificates is directly tied to using supported OS versions (or ESU for Windows 10, if applicable).
