
Microsoft Says Secure Boot Certificate Rollout Will Continue for Months
Microsoft has confirmed that the rollout of updated Secure Boot certificates is still underway, reassuring users that PCs which have not yet received the new certificates will continue to function normally. The company says Windows devices will keep booting and receiving regular updates while the certificates are gradually deployed over the coming months.
The announcement follows concerns that the expiration of older Secure Boot certificates could leave some systems without this important security feature.
Rollout Still in Progress
Microsoft had planned to distribute new Secure Boot certificates through the June 24 Windows update, ahead of the expiration of the original certificates issued in 2011.
However, many Windows 10 and Windows 11 PCs have yet to receive the update.
In its latest Windows update documentation, Microsoft states that:
- PCs without the new certificates will continue to boot normally.
- Standard Windows updates will continue to install.
- Updated Secure Boot certificates will be delivered through Windows Update over the next several months.
The company previously confirmed that missing the original deadline would not prevent eligible systems from receiving the certificates later.
Why Secure Boot Matters
Secure Boot is a security feature built into modern PCs that helps protect systems from malware capable of loading during the startup process.
It works by verifying the digital signatures of boot components before Windows starts, allowing only trusted software to load.
Microsoft also maintains a DBX (Forbidden Signature Database) containing compromised bootloaders, which can be updated over time to block newly discovered threats.
The problem is that many devices still rely on Secure Boot certificates created in 2011, which were designed with a 15-year validity period and are now reaching expiration.
Certificate Expiration Timeline
Microsoft says the legacy certificates expire in three stages:
- Microsoft Corporation KEK CA 2011 — expired June 24, 2026
- Microsoft UEFI CA 2011 — expired June 27, 2026
- Microsoft Windows Production PCA 2011 — remains valid until October 19, 2026
The replacement certificates were issued in 2023 and will replace the older trust chain as the rollout continues.
Windows 10 Users Need ESU
For Windows 10 users, receiving the updated certificates depends on continued access to Windows Update.
Microsoft notes that only PCs enrolled in the Extended Security Updates (ESU) program will continue receiving:
- Security patches
- Secure Boot certificate updates
Systems no longer eligible for Windows updates will not automatically receive the new certificates.
How to Check Certificate Status
Windows 11 includes a built-in Secure Boot status indicator that allows users to verify whether their device is ready for the updated certificates.
To view it:
Settings → Windows Security → Device Security → Secure Boot
The indicator uses three colors:
- Green: Secure Boot certificates are up to date.
- Yellow: Additional firmware information is required before the update can be installed.
- Red: A problem is preventing the update, often requiring a BIOS or firmware update.
Some Older PCs May Never Receive the Update
Microsoft is working with PC manufacturers to release firmware updates where necessary, but support varies by vendor.
Some older systems are no longer eligible for BIOS updates, including:
- Certain Dell PCs whose support ended before January 1, 2026
- Many HP systems released in 2018 or earlier
- Older Lenovo devices with expired firmware support
Owners of these systems may be unable to receive the updated Secure Boot certificates if the required firmware updates are no longer available.
No Immediate Action Required for Most Users
Although the rollout has taken longer than expected, Microsoft says there is no need for most users to worry.
Windows devices that have not yet received the updated Secure Boot certificates will continue operating normally, and Microsoft plans to deliver the new certificates automatically through Windows Update over the coming months for supported systems.

