Windows PCs and servers have a security deadline this month. The Secure Boot certificates built into Windows since 2011 expire on 24 June 2026, and businesses that miss the update window will be left with a permanent gap in their boot-level security.
- What it is: Microsoft is replacing 15-year-old Secure Boot certificates with updated 2023-dated certificates. After 24 June, systems that have not received the update cannot receive new boot-level security protections — including malware blacklist (DBX) updates and future boot manager security fixes.
- Who is affected: All businesses running Windows PCs and servers. Most PCs with automatic Windows Updates enabled are likely already covered. Windows Server environments and systems with updates disabled require manual action by an IT administrator.
- What the risk is: Affected systems will continue to boot normally but will permanently lose the ability to receive boot-critical security updates, leaving them increasingly exposed to firmware-level threats and bootkits over time. This gap does not fix itself after the deadline passes.
- What action is needed: Confirm that Windows Update is current on all PCs and laptops before 24 June. Windows Server environments must be updated manually. Some systems may also require a BIOS/UEFI firmware update from the manufacturer before the new certificates can be applied.
With less than three weeks to the deadline, we recommend verifying patch status now. Microsoft's official guidance and readiness tools are available at aka.ms/GetSecureBoot. Contact your IT provider if you need assistance confirming your environment is ready.