We’re now heading into August and the issue of updated Secure Boot certificates still hasn’t been resolved for all Windows users. The June 24th “Secure Boot” update, which was released just in time for the old-Secure-Boot-certificates-need-to-be-updated deadline, was supposed to roll out new certificates to remaining PCs that needed them. Yet, many computers still haven’t gotten their updated certificates yet.
A few weeks before that, Microsoft had given the all-clear, saying it wouldn’t be the end of the world if you don’t get updated Secure Boot certificates by the deadline, and that it’d still be possible to obtain them even afterwards.
If you haven’t gotten yours yet, Microsoft wants you to keep calm and carry on. According to the July 2026 update notes, Microsoft says the rollout is still ongoing and will be for a while longer:
Windows Secure Boot certificate expiration
Secure Boot certificates used by most Windows devices were set to expire starting in June 2026. Microsoft has been updating these certificates on PCs and non-managed business devices for the past months. Devices that haven’t received the newer certificates will continue to start, and standard Windows updates will continue to install. We will continue to install the newer certificates via Windows updates in the coming months.
In short, Windows 10 and 11 PCs that haven’t gotten their updated Secure Boot certificates will still boot, still get Windows updates, and eventually get their Secure Boot certificates over the next few months.
What’s the big deal?
Why all the fuss about Secure Boot if everything’s still working per usual? Well, Secure Boot is an important security feature that protects your PC from malware attacks that can take hold during system startup. Secure Boot checks the digital signature of every piece of software that’s loaded against a list of trusted signatures, and blocks anything that smells off.
At the same time, Microsoft maintains a blacklist of known bootloaders that are considered compromised, and the Windows Boot Manager can expand the backlist via DBX block updates.
The problem is, on some computers, the certificates needed to run Secure Boot and receive these updates were outdated, first issued in 2011 with an expiry of 15 years. That’s why they must be replaced this year, else Secure Boot will cease to function.
Microsoft says the outdated certificates will expire in three phases:
- The Microsoft Corporation KEK CA 2011 was valid until June 24th, 2026.
- The Microsoft UEFI CA 2011 was valid until June 27th, 2026.
- The Microsoft Windows Production PCA 2011 remains valid until October 19th, 2026.
So, you still have until at least October to obtain the new certificates and continue using Secure Boot. These newer certificates are from 2023, and we don’t know how long they’ll remain valid this time around.
Note: If you’re on Windows 10, you’ll continue to receive updates—including those for Secure Boot—only if you’re enrolled in the Extended Security Updates (ESU) program. A Windows 10 PC that isn’t registered (and therefore no longer receives updates) will not get updated Secure Boot certificates.
How to check your Secure Boot status
Back in April, Microsoft introduced a new indicator in Windows 11 that shows you the status of your PC’s Secure Boot certificates. You can find it under Settings → Windows Security → Device Security → Secure Boot.
Much like a traffic light, the colors on the Secure Boot indicator signal whether action is required: Green means everything is fine, Yellow means Windows needs further information about your firmware before you can receive the certificates, and Red is a warning that an issue is blocking the update and you may need, for example, a manufacturer BIOS update.
Microsoft is working with various PC and laptop manufacturers to provide the necessary BIOS updates. However, in some cases, you will need to take the initiative yourself to ensure your system gets them.
Note: There are some PCs that won’t receive any Secure Boot certificates at all. Dell, for example, doesn’t provide BIOS updates for systems whose support period expired before January 1st, 2026. HP excludes PCs from 2018 and earlier. The situation is similar at Lenovo.
This articles is written by : Nermeen Nabil Khear Abdelmalak
All rights reserved to : USAGOLDMIES . www.usagoldmines.com
You can Enjoy surfing our website categories and read more content in many fields you may like .
Why USAGoldMines ?
USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.
