Windows Update is delivering replacement Secure Boot certificates to eligible PCs as Microsoft’s original 2011 certificates expire in stages during 2026. A PC that misses the replacement should not normally stop starting or receiving regular Windows updates, but it can miss future protections for the early boot process. As of October 8, 2026, Microsoft says the rollout is continuing; check Windows and your PC maker’s guidance rather than assuming your device has updated.
Will an expiring Secure Boot certificate stop your PC from starting?
Usually, no. Microsoft says a Windows device without the replacement certificates can continue to start, and ordinary Windows updates can continue to install. Expiration is not described as an immediate shutdown or boot failure.
The consequence is a gradual loss of future protection for the code and trust data used before Windows starts. Without the new certificates, a device may not receive future updates to Windows Boot Manager, Secure Boot databases and revocation lists, or mitigations for newly discovered boot-chain vulnerabilities. The gap matters more as new threats emerge. Some protections involving Secure Boot trust, including certain BitLocker hardening scenarios, may also be affected.
Secure Boot is implemented in UEFI firmware. Its trust chain uses a Platform Key, Key Exchange Keys (KEK), an allowed-signature database (DB), and a disallowed-signature database (DBX). These determine which pre-Windows boot components can run and which are blocked. Microsoft explains the effects of expiration in its Secure Boot certificate expiration guidance.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Which certificates are expiring, and when?
The original certificates issued in 2011 do not all expire on the same day. Microsoft lists these dates and their 2023 replacements:
| 2011 certificate | Expiration | 2023 replacement and purpose |
|---|---|---|
| Microsoft Corporation KEK CA 2011 | June 24, 2026 | Microsoft Corporation KEK 2K CA 2023, stored in KEK and used to sign DB and DBX updates |
| Microsoft UEFI CA 2011 | June 27, 2026 | Microsoft UEFI CA 2023, for third-party boot loaders and EFI applications |
| Microsoft UEFI CA 2011 | June 27, 2026 | Microsoft Option ROM UEFI CA 2023, for third-party option ROMs |
| Microsoft Windows Production PCA 2011 | October 19, 2026 | Windows UEFI CA 2023, used to sign the Windows boot loader |
Microsoft split trust for third-party boot components and option ROMs into separate certificates so systems can control those choices independently. The dates above are certificate expiration dates, not deadlines after which Windows must fail to boot. See Microsoft’s certificate expiration and CA update table for the certificate details.
Rank #2
- 【🔒 Never Worry About Data Theft Again!】 Finally feel safe leaving your computer unattended!" Our military-grade USB metal port lock physically blocks USB ports, stopping hackers from stealing files/photos/trade secrets. Protect your privacy as easily as putting on a phone case.
- 【💻 Extend Your Device’s Lifespan by 30%!】 Lab-proven: Blocking dust reduces USB port failures by 75%! Save hundreds on repair costs – perfect for families with kids or dusty workspaces.
- 【⏱️ 3-Second Security Upgrade】 Easier than tying your shoes! No tools needed – just insert and twist. Bring them when traveling to secure hotel computers in seconds.
- 【🔑One key, full protection】Your one high-security key can fully control the USB port, no need to use multiple keys. Precision cut from durable metal, moderate size, unique hollow design can be hung on a keychain or other items to prevent loss.
- 【🛡️ Childproof & Employee】Proof Security Finally stop worrying about: Kids inserting random USB drives (goodbye corrupted files!) Employees plugging in unauthorized devices (hello productivity!) Cleaning crews accidentally damaging exposed ports
How to check whether your PC gets the replacement certificates
Microsoft is delivering certificates through Windows Update to many eligible devices, but automatic deployment is not guaranteed for every PC. Microsoft says eligible Microsoft-managed devices that share diagnostic data are candidates for automatic updates, while some devices require customer action. Its September 8, 2026 Windows 11 update notice said the rollout had been underway for months and would continue through Windows Update in the coming months.
For a personal PC
- Install available Windows updates through Windows Update.
- Consult Microsoft’s certificate status guidance for ways to determine the state on your device.
- Check your PC maker’s support page for your exact model. Some devices require an OEM firmware update, and availability can depend on whether the model is still supported.
Microsoft’s Secure Boot update FAQ describes the rollout and explains why customer action may be needed on some systems.
Rank #3
- Waterproof and durable: This 32gb flash drive is completely resistant to water, with high-quality metal casing for durability, provides you the reliability as the metal casing provides you protection against dust, water and temprature and shock resistant.
- Small and key chain design: The thumb drive is so small and handy that you can put it in your pocket. With the built in key ring to help you to attach it to your backpack or wallet and no need to worry it will loose, carrying the data wherever you go.
- Plenty of storage for you : You can use the 32gb zip dirve to back up your photos, record good memory videos, listen to music or books in your car, give power point presentations or projects, to make Windows recovery and general files back up......
- Broad compatibility : This 32gb jump drive supports almost all operating systems including Windows Windows 2000/7/8/8.1/10/Vista/XP/2000/ME, Linux and MacOs 10.3 and intel. Compatible with any device with a USB port.
- Default format: FAT32, you can reformat it to exFAT if needed.
For an organization-managed fleet
Follow Microsoft’s administrator inventory and deployment guidance, and verify certificate status with your organization’s management and inventory methods. The required path can depend on Windows version, firmware, and management state. Microsoft’s Windows client deployment guidance covers update planning for managed devices.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What to do if the update is blocked
There is no universal fix that applies to every PC. The appropriate next step depends on the Windows build, UEFI firmware, device model, and how the machine is managed. Microsoft’s troubleshooting guidance for blocked certificate updates describes possible consequences and next steps.
Quick Recap
Best Value
- New and high quality, novelty key design
- Keep your digital world in your pocket in our smallest package
- Transfer and share photos, videos, songs and other files between computers with easy
- Fast data transmission speed
Rank #4
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
- Check whether the PC maker provides a model-specific firmware update or instructions.
- If the device is managed by an organization, contact the administrator rather than applying consumer troubleshooting steps.
- Do not disable Secure Boot or change firmware defaults as a workaround. Microsoft warns that disabling Secure Boot reduces protection and can create security or compliance risks.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

