Windows Secure Boot Certificate Expiration: 2026 Guide

Windows Secure Boot certificates issued in 2011 began expiring in June 2026, but an affected PC does not suddenly stop booting when a certificate expires. The bigger risk is that a device still using the old trust chain may stop receiving future protections for the Windows boot process. Most supported consumer PCs are being updated automatically, while managed business fleets may need inventory, firmware updates, testing, and targeted deployment.

For US businesses, this is a security-maintenance issue worth checking now rather than a reason to panic. Microsoft says the original Microsoft Corporation KEK CA 2011 expired on June 24, 2026, and Microsoft UEFI CA 2011 expired on June 27, 2026. The Microsoft Windows Production PCA 2011 is scheduled to expire on October 19, 2026.

This guide explains what the expiration means, how to check a Windows PC, what IT teams should verify across a fleet, and when firmware or manual remediation may be required.

What is expiring in Windows Secure Boot?

Secure Boot is a UEFI firmware feature that checks whether software involved in starting the computer is trusted before Windows loads. That trust is built around certificates stored in firmware and the Secure Boot databases.

The certificate rollover is happening because several Microsoft certificates introduced in 2011 are reaching the end of their planned lifetime. Microsoft has created replacement certificates dated 2023 and is distributing them through Windows servicing and OEM firmware updates.

2011 certificateExpiration dateReplacement
Microsoft Corporation KEK CA 2011June 24, 2026Microsoft Corporation KEK 2K CA 2023
Microsoft UEFI CA 2011June 27, 2026Microsoft UEFI CA 2023 / Microsoft Option ROM UEFI CA 2023
Microsoft Windows Production PCA 2011October 19, 2026Windows UEFI CA 2023

The dates matter, but the more important question is whether your device has already received the newer 2023 certificates.

Will a Windows PC stop booting after the certificate expires?

Usually, no. Microsoft says devices that have not received the new certificates can continue to start and can continue receiving standard Windows updates.

The problem is narrower and more serious over time: the device may no longer be able to receive new Secure Boot and Windows Boot Manager protections that depend on the updated trust chain. That can include new revocations, early-boot mitigations, and fixes for vulnerabilities discovered after the old certificate has expired.

In other words, expiration is not a built-in shutdown date. It is a point after which an unremediated device can fall behind on boot-level security.

How can you check Secure Boot certificate status in Windows?

On supported Windows 10 and Windows 11 systems, Microsoft added Secure Boot certificate status information to the Windows Security app during 2026.

  1. Open Windows Security.
  2. Select Device security.
  3. Open the Secure Boot section.
  4. Review the certificate-update message and status indicator.

A green status indicating that all required certificate updates have been applied means no further certificate action is needed. A yellow warning can indicate that a hardware or firmware limitation is preventing the automated update. A red status can appear when a boot-security fix cannot be delivered on the device’s current configuration.

If you are already shopping for newer Windows hardware, BrandLigo’s AI PC and NPU guide explains the modern Windows laptop platform without treating every new specification as an automatic reason to upgrade.

What should a small business do?

A small business using ordinary Windows Update should start with three checks: make sure Windows is fully patched, confirm Secure Boot is enabled, and look at the Secure Boot status inside Windows Security.

For many supported PCs, Microsoft manages the certificate update automatically. If the status shows that the device is updated, there is no reason to change firmware settings manually.

If the status says action is required, check the PC manufacturer’s support page for current BIOS or UEFI firmware. Microsoft specifically notes that some hardware needs an OEM firmware update before the certificate transition can complete correctly.

Do not disable Secure Boot as a workaround. Microsoft warns that doing so reduces protection against boot-level malware and can create additional security or compliance problems.

What should enterprise IT teams check across a Windows fleet?

Managed environments need more than a spot check on one laptop. Microsoft recommends inventorying devices that still use the old certificates and validating readiness before broad deployment.

Useful signals include the Secure Boot certificate state, Windows event logs, and the UEFICA2023Status registry value. Microsoft’s troubleshooting guidance calls out Event IDs 1795 and 1801 as indicators administrators may encounter while diagnosing certificate-update problems.

A practical rollout looks like this:

  1. Inventory the fleet. Identify devices that still rely on 2011 Secure Boot certificates.
  2. Update OEM firmware first where needed. Older or unusual firmware is a common source of transition problems.
  3. Create a representative pilot group. Include different manufacturers, models, firmware versions, and BitLocker-enabled devices.
  4. Confirm recovery readiness. Make sure BitLocker recovery information and normal endpoint-recovery procedures are available before firmware changes.
  5. Deploy through supported management methods. Microsoft documents options including Intune, Group Policy, configuration service providers, and registry-based controls.
  6. Monitor status after rollout. Verify that devices report the updated certificate state and watch for boot or BitLocker issues.

This is one reason newer business PCs can be easier to manage than aging mixed fleets. BrandLigo’s overview of HP’s 2026 PC lineup explains how its consumer and business laptop families differ, including the business-focused EliteBook range.

Why firmware matters in this transition

Secure Boot trust lives partly in UEFI firmware, so Windows Update is not the only piece involved. Microsoft can service many systems automatically, but it cannot make unsupported or incompatible firmware behave like a current platform.

Microsoft Learn advises administrators to update firmware before certificate remediation when necessary and to test across multiple hardware and firmware combinations. Dell has also published its own Secure Boot transition guidance, which is a useful reminder that businesses should check OEM-specific instructions rather than assume every Windows PC behaves identically.

Does BitLocker stop working if Secure Boot is outdated?

Not automatically. Microsoft does not say that ordinary BitLocker encryption simply shuts off when a Secure Boot certificate expires. The concern is that Secure Boot trust participates in the broader early-boot security chain, and Microsoft notes that scenarios such as BitLocker hardening or mitigations for boot-level vulnerabilities can be affected if a device cannot receive new Secure Boot protections.

Firmware and Secure Boot changes can also cause BitLocker recovery prompts on some systems, which is why enterprise teams should pilot changes and confirm recovery keys are available before broad deployment.

Do you need to replace older PCs?

Not simply because a 2011 certificate reached its expiration date. If a supported PC can receive the 2023 certificates and any required firmware update, replacement is unnecessary for this issue alone.

Replacement becomes more reasonable when a device is no longer supported by its OEM, cannot accept the required firmware changes, is already outside normal Windows support, or presents a larger maintenance burden than its remaining value justifies.

When replacement is appropriate, compare the full device lifecycle rather than buying for one security label. BrandLigo’s technology company directory can also help buyers research manufacturers and software providers alongside product-focused guidance.

What not to do

  • Do not disable Secure Boot just to remove a warning.
  • Do not assume the PC is safe because it still boots. Normal startup does not prove the new certificates are installed.
  • Do not push firmware changes fleet-wide without a pilot.
  • Do not ignore BitLocker recovery readiness.
  • Do not treat every device as identical. OEM and firmware differences matter.

The practical takeaway for August 2026

Two of the main 2011 Secure Boot certificates have already reached their June 2026 expiration dates, while the Windows Production PCA 2011 reaches its expiration date on October 19, 2026. The useful action is not to panic about the dates; it is to confirm that each supported Windows device has moved to the newer 2023 trust chain.

For an individual PC, keep Windows and firmware current and check Windows Security. For a business fleet, inventory first, update firmware where required, pilot the transition, and then deploy through supported management tools. A machine that still starts normally can still be behind on boot-level protections, so verification matters more than visible symptoms.

Frequently asked questions

What happens when a Secure Boot certificate expires?

An affected Windows PC can usually continue to boot and receive standard updates, but it may no longer receive new protections for Windows Boot Manager and other early-boot security components until the trust chain is updated.

Are the 2026 Secure Boot certificates already expired?

Some are. Microsoft Corporation KEK CA 2011 expired June 24, 2026, and Microsoft UEFI CA 2011 expired June 27, 2026. Microsoft Windows Production PCA 2011 is scheduled to expire October 19, 2026.

How do I know whether my PC has the new certificates?

On supported Windows versions, open Windows Security, go to Device security, and review Secure Boot status. Managed environments can also use inventory, registry, and event-log signals documented by Microsoft.

Should I turn Secure Boot off?

No. Microsoft specifically advises against disabling Secure Boot as a workaround because it reduces protection against boot-level threats.

Do all businesses need to update certificates manually?

No. Many supported systems receive the new certificates through Microsoft-managed servicing. Manual work is more likely when devices are centrally managed, have older firmware, or hit an OEM compatibility limitation.

Can the update cause BitLocker recovery prompts?

Microsoft’s troubleshooting guidance lists unexpected BitLocker recovery prompts among possible higher-risk scenarios when firmware or certificate updates do not apply cleanly. Businesses should confirm recovery information before broad firmware changes.

About this article. Written and fact-checked by the BrandLigo editorial desk. Secure Boot dates and remediation guidance were verified against current Microsoft and OEM documentation on August 21, 2026.

Sources: Microsoft: Windows Secure Boot certificate expiration and CA updates; Microsoft: Secure Boot update status in Windows Security; Microsoft Learn: Update Secure Boot certificates; Microsoft Windows Server Blog: Prepare servers for Secure Boot updates; Dell: Secure Boot transition FAQ.