Windows Secure Boot Certificate Updates Are Still Rolling Out

news
Windows Secure Boot Certificate Updates Are Still Rolling Out

Microsoft says Windows PCs that have not yet received updated Secure Boot certificates can continue working normally while the rollout continues over the coming months.

The company began replacing Secure Boot certificates issued in 2011 because several were scheduled to expire during 2026. A Windows update released on June 24 was expected to bring newer certificates to more devices, but many computers still have not received them.

Microsoft has clarified that missing the initial certificate deadlines will not immediately stop a PC from starting. Windows 10 and Windows 11 devices without the newer certificates should continue to boot and install standard Windows updates.

The replacement process is expected to continue gradually rather than reaching every compatible computer at the same time.

Why Secure Boot Certificates Need Replacing

Secure Boot is a security feature that checks software loaded during the startup process. It compares digital signatures against trusted certificates and blocks components that are unauthorised or known to be unsafe.

This process helps protect a PC from malware that tries to run before Windows has fully started.

Microsoft also maintains a database of compromised bootloaders. Windows can receive updates to this database, known as DBX updates, so Secure Boot can block newly identified threats.

Many current Windows devices still rely on certificates created in 2011 with a 15 year validity period. Those certificates are now expiring and must be replaced with newer versions for Secure Boot protection to continue functioning correctly.

Secure Boot certificateExpiration date
Microsoft Corporation KEK CA 2011June 24, 2026
Microsoft UEFI CA 2011June 27, 2026
Microsoft Windows Production PCA 2011October 19, 2026

The final listed certificate remains valid until October 19, giving Microsoft and hardware manufacturers more time to complete the transition.

The replacement certificates were issued in 2023. Microsoft has not provided clear public information about how long those certificates will remain valid.

PCs Without the Update Will Still Start

Microsoft says devices that have not received the new certificates will continue to start normally.

Standard Windows updates should also continue installing while the rollout remains in progress. The absence of the new certificates does not mean a computer will suddenly stop working because one of the older certificates has expired.

Current situationExpected behaviour
New certificates installedSecure Boot continues with updated trust files
Certificates not installed yetWindows should still boot normally
Waiting for firmware informationUpdate may arrive after compatibility checks
Firmware issue detectedBIOS or UEFI update may be required
Unsupported older PCManufacturer may not provide the required firmware

Microsoft plans to continue delivering the replacement certificates through Windows Update over the next few months.

You therefore do not need to manually change firmware settings or attempt unsupported installation methods simply because your computer has not received them yet.

How to Check the Secure Boot Certificate Status

Windows 11 includes an indicator that shows whether a device is ready for the new certificates.

You can find it by opening Settings, selecting Windows Security, opening Device Security, and checking the Secure Boot section.

The indicator uses three colours:

Indicator colourMeaning
GreenThe system is ready and no action is required
YellowWindows needs more firmware information
RedA problem is blocking the certificate update

A green result means the certificate status is normal.

Yellow generally means Microsoft needs additional information about the device’s firmware before the update can be safely installed. In many cases, no immediate action is required.

A red warning means something is preventing the process from completing. The PC may need a BIOS or UEFI update from its manufacturer.

Some PCs May Require a BIOS Update

Microsoft is working with PC manufacturers to prepare firmware updates for affected systems.

Secure Boot depends partly on the computer’s BIOS or UEFI firmware. If the firmware cannot properly support the new certificates, Windows Update may delay or block their installation.

You should check the support page for your laptop, desktop, or motherboard when Windows displays a red Secure Boot warning.

Before installing a BIOS update, confirm the exact model and follow the manufacturer’s instructions carefully. Interrupting a firmware update can leave a device unable to start.

There is no reason to install an unrelated BIOS version when Windows shows a green status or when the certificate rollout is simply pending.

Older Computers May Not Receive the Certificates

Some manufacturers are limiting firmware support based on the age of the device.

Dell reportedly does not plan to provide the required BIOS updates for systems whose support period ended before January 1, 2026. HP excludes some PCs released in 2018 or earlier, while Lenovo has similar restrictions for older models.

Device situationPossible outcome
Current supported modelFirmware and certificate updates likely
Older supported modelUpdate may arrive later
Device outside support periodManufacturer may not release new BIOS
Unsupported firmwareSecure Boot certificate update may remain unavailable

This does not necessarily mean an older PC will immediately become unusable. It means the system may not receive the firmware changes required for the full Secure Boot certificate transition.

Owners of affected computers should review the manufacturer’s support documents rather than assuming every model will be updated.

Windows 10 Requires Extended Security Updates

Windows 10 devices can receive the Secure Boot certificate updates only while they remain eligible for Windows security updates.

For most consumer systems, that means enrolling in Microsoft’s Extended Security Updates program after normal Windows 10 support has ended.

A Windows 10 computer that is not registered for ESU and no longer receives updates will not receive the new Secure Boot certificates through Windows Update.

Windows versionRequirement
Windows 11Continue installing normal Windows updates
Supported Windows 10 installationContinue installing available updates
Windows 10 after standard supportESU enrolment required
Windows 10 without ESUNew certificates will not arrive through Windows Update

This makes update eligibility particularly important for people who plan to keep using Windows 10.

Most People Do Not Need to Take Immediate Action

The delayed rollout is not an emergency for most Windows owners.

Your PC should continue starting and receiving updates while Microsoft distributes the newer certificates. The best approach is to keep Windows Update enabled, install normal system updates, and check the Secure Boot status indicator occasionally.

A manufacturer BIOS update may be necessary when Windows shows a red warning or the hardware maker specifically lists an update for the certificate transition.

You should avoid disabling Secure Boot unless a trusted support document requires it for troubleshooting. Turning it off reduces protection against malware that attempts to load during startup.

The rollout may take several more months, but Microsoft says computers that are still waiting should remain usable throughout the process.

Discover: News

Discussion (0)

Be the first to comment.