
Microsoft Rolls Out Secure Boot 2023 Certificates to Windows 10 and 11 PCs
Microsoft has begun automatically deploying the Secure Boot 2023 certificate update to eligible Windows 10 and Windows 11 devices, ensuring systems remain protected as the original Secure Boot certificates issued in 2011 begin to expire.
The rollout coincides with the expiration of the first-generation Secure Boot certificates, preventing potential security and compatibility issues for supported PCs.
Why the Update Matters
Secure Boot is a firmware-level security feature that verifies the digital signatures of software loaded during the boot process before Windows starts.
By validating trusted components, Secure Boot helps defend against low-level malware such as:
- Rootkits
- Bootkits
- Other boot-time attacks
Without valid certificates, Secure Boot cannot properly verify trusted boot components, weakening this critical layer of protection.
The 2011 Certificates Are Expiring
Microsoft is replacing the original Secure Boot certificates with new Secure Boot 2023 certificates.
The original certificates expire on the following dates:
- Microsoft Corporation KEK CA 2011: June 24, 2026
- Microsoft UEFI CA 2011: June 27, 2026
- Microsoft Windows Production PCA 2011: October 19, 2026
To avoid disruptions, Microsoft has been gradually deploying the new certificates through Windows Update, with the rollout expanding significantly during June 2026.
Automatic Installation Through Windows Update
According to Microsoft, most eligible PCs that received the June 2026 Patch Tuesday update should also receive the new Secure Boot certificates automatically.
The rollout is being performed gradually using Microsoft’s device targeting system, ensuring only compatible systems receive the update before broader deployment.
How to Check if Your PC Is Updated
You can verify whether the new certificates have been installed through Windows Security:
- Open Settings.
- Navigate to Privacy & Security → Windows Security.
- Select Device Security.
- Check the Secure Boot status.
The status indicators mean:
- Green: Secure Boot is functioning normally and the required certificates are installed.
- Yellow warning: Your PC has not yet received the Secure Boot 2023 certificates, possibly due to pending compatibility checks or a required BIOS/UEFI update.
- Red X: A firmware or compatibility issue is preventing the update from being installed. In this case, check your PC manufacturer’s website for a BIOS or UEFI firmware update.
If the Secure Boot section is missing entirely, Secure Boot may be disabled in your system firmware or may have been bypassed during Windows installation.
Alternative Verification Method
You can also verify Secure Boot status using Windows System Information:
- Press Windows + R.
- Type
msinfo32and press Enter. - Under System Summary, locate Secure Boot State.
If Secure Boot is enabled, the entry should display “On.”
What Happens If You Don’t Receive the Update?
A Windows PC without the new Secure Boot certificates will continue to boot and operate normally. However, it will no longer receive future Secure Boot-related security updates after the legacy certificates expire.
This could leave the system more vulnerable to sophisticated threats that target the boot process, including rootkits and bootkits. For that reason, users are encouraged to keep Windows fully updated and install any available BIOS or UEFI firmware updates to ensure compatibility with the Secure Boot 2023 certificate rollout.




