What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On most supported Windows 11 and Windows 10 home PCs, you do not install the 2023 Secure Boot certificates by hand: Microsoft delivers them through Windows Update. Keep updates enabled, leave Secure Boot on, and check the device’s status. If the update does not complete, use Microsoft’s status indicators and check for firmware support from the PC manufacturer before trying recovery steps.

What expires in 2026—and what the replacement certificates do

Microsoft’s 2011 Secure Boot certificates expire on three different dates in 2026. The dates are not a deadline at which Windows suddenly stops starting: Microsoft says a device without the replacements continues to start normally. However, it may miss future protections for the early boot process, including updates to the Secure Boot databases and mitigations for newly discovered boot-level vulnerabilities. Microsoft’s certificate overview maps the expiring certificates to their replacements:

Expiring certificate Expiration date 2023 replacement and role
Microsoft Corporation KEK CA 2011 June 24, 2026 Microsoft Corporation KEK 2K CA 2023, in the KEK; KEK authorizes updates to DB and DBX.
Microsoft UEFI CA 2011 June 27, 2026 Microsoft UEFI CA 2023 for third-party boot loaders and EFI applications, and Microsoft Option ROM UEFI CA 2023 for third-party Option ROMs; both are in DB.
Microsoft Windows Production PCA 2011 October 19, 2026 Windows UEFI CA 2023, in DB for the Windows boot loader.

DB is the allowed-signature database; DBX is the revoked-signature database; KEK authorizes changes to DB and DBX. Having Windows boot normally does not establish that the replacement certificates are present.

How to receive the certificates through Windows Update

1. Make sure Windows can install updates

Check that updates are not paused, then install available Windows updates through the normal Windows Update settings. Microsoft’s managed rollout is gradual, so an eligible PC may not receive every Secure Boot action at once. Microsoft’s guidance for managed updates says most supported home devices do not need a separate manual certificate installation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Microsoft Windows 11 (USB)
  • Less chaos, more calm. The refreshed design of Windows 11 enables you to do what you want effortlessly.
  • Biometric logins. Encrypted authentication. And, of course, advanced antivirus defenses. Everything you need, plus more, to protect you against the latest cyberthreats.
  • Make the most of your screen space with snap layouts, desktops, and seamless redocking.
  • Widgets makes staying up-to-date with the content you love and the news you care about, simple.
  • Stay in touch with friends and family with Microsoft Teams, which can be seamlessly integrated into your taskbar. (1)

2. Check whether Secure Boot is enabled

  1. Press Windows+R, type msinfo32, and press Enter.
  2. In System Information, find Secure Boot State.
  3. If the value is On, Secure Boot is enabled. This checks the setting, not whether all 2023 certificates have been applied.

Do not turn Secure Boot off to avoid the 2026 expiration. Microsoft’s recommended route is to receive the certificate updates and any required OEM firmware support.

3. Allow the managed process to finish

Keep the PC connected to Windows Update and restart when Windows requests it. There is no universal single restart or generic PowerShell command that manually enrolls all the required certificates across PCs. Windows processes Secure Boot update actions through a scheduled task and can retry failed actions; the exact progress depends on the device and its firmware. See Microsoft’s FAQ on the update process for rollout context.

Rank #2
Microsoft System Builder | Windоws 11 Home | Intended use for new systems | Install on a new PC | Branded by Microsoft
  • STREAMLINED & INTUITIVE UI, DVD FORMAT | Intelligent desktop | Personalize your experience for simpler efficiency | Powerful security built-in and enabled.
  • OEM IS TO BE INSTALLED ON A NEW PC with no prior version of Windows installed and cannot be transferred to another machine.
  • OEM DOES NOT PROVIDE SUPPORT | To acquire product with Microsoft support, obtain the full packaged “Retail” version.
  • PRODUCT SHIPS IN PLAIN ENVELOPE | Activation key is located under scratch-off area on label.
  • GENUINE WINDOWS SOFTWARE IS BRANDED BY MIRCOSOFT ONLY.

How to tell whether an update is incomplete

If Windows updates are current but you are unsure whether Secure Boot remediation has completed, check the indicators Microsoft documents. Event ID 1801 and the registry value UEFICA2023Status not set to Updated can indicate that remediation is incomplete. These signals are useful for troubleshooting; they do not by themselves identify the cause. Microsoft’s Secure Boot certificate update guidance describes the event and registry status.

What to do if Windows Update cannot apply the certificates

Check the exact PC model’s firmware

Windows coordinates the update, but the UEFI firmware must support changes to the Secure Boot databases. Some KEK updates also require a payload signed by the OEM platform key. Check the manufacturer’s support page for the exact PC model and install its current firmware update if Microsoft’s diagnosis indicates a firmware dependency. Older or unsupported devices may not have the required OEM support.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Microsoft Windows 11 PRO (Ingles) FPP 64-BIT ENG INTL USB Flash Drive
  • MICROSOFT WINDOWS 11 PRO (INGLES) FPP 64-BIT ENG INTL USB FLASH DRIVE

Use caution with failed updates

Microsoft’s troubleshooting guidance says Secure Boot actions run through the MicrosoftWindowsPISecure-Boot-Update scheduled task, which records results and retries failed actions. Firmware limitations can prevent progress. The documented risks of Secure Boot database changes include validation errors, BitLocker recovery prompts, startup hangs, and failure to boot. Consult the Secure Boot troubleshooting guide for the failure affecting your device; do not apply recovery instructions for a different scenario.

Use recovery media only for the specific recovery case

Microsoft documents one conditional recovery procedure after a Secure Boot database change: on a second Windows PC with the July 2024 or newer update, copy SecureBootRecovery.efi from C:WindowsBootEFI to a FAT32 USB drive under EFIBOOT, rename the copy to bootx64.efi, then boot the affected PC from that drive to re-add Windows UEFI CA 2023. This is recovery media for that described case, not a routine installation method. Microsoft advises reapplying all required certificates and considering the latest OEM firmware after recovery. If Windows will not boot or BitLocker recovery appears, follow recovery instructions for the actual device and failure.

Rank #4
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Windows 10 users need to know

Windows 10 support ended on October 14, 2025. Continuing to receive security updates, including Secure Boot updates, requires enrollment in Windows 10 Extended Security Updates (ESU). Check the PC’s ESU eligibility and enrollment status as well as Windows Update; having Secure Boot enabled alone does not provide post-support servicing.

For work- or school-managed PCs

If your organization manages the device, ask its IT administrator about the deployment plan rather than attempting manual certificate enrollment. Microsoft’s managed-update guidance covers home, business, and school devices, while the applicable servicing and rollout path may depend on organizational management.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 1
Microsoft Windows 11 (USB)
Microsoft Windows 11 (USB)
Make the most of your screen space with snap layouts, desktops, and seamless redocking.; FPP is boxed product that ships with USB for installation
$128.99
Bestseller No. 2
Bestseller No. 3
Microsoft Windows 11 PRO (Ingles) FPP 64-BIT ENG INTL USB Flash Drive
Microsoft Windows 11 PRO (Ingles) FPP 64-BIT ENG INTL USB Flash Drive
MICROSOFT WINDOWS 11 PRO (INGLES) FPP 64-BIT ENG INTL USB FLASH DRIVE
SaleBestseller No. 4

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.