A critical security deadline is approaching for all Windows PCs: Microsoft's original Secure Boot certificates — in place since 2011 — begin expiring from 24 June 2026. Businesses that miss this transition will find their Windows computers unable to receive future boot-level security updates, leaving them exposed to a class of attack that Microsoft would otherwise patch.
- What it is: Secure Boot is a Windows feature that verifies your PC's software has not been tampered with before it loads. The certificates underpinning this protection are expiring and being replaced with new 2023-dated certificates. The first certificate (Microsoft Corporation KEK CA 2011) expires on 24 June 2026.
- Who is affected: All businesses running Windows 10 or Windows 11 PCs. Virtually every Windows computer in use today is affected.
- What the risk is: Devices that miss the update will continue to operate normally day-to-day, but they will stop receiving boot-level security updates and malware blacklists. This permanently degrades their defences against boot-level threats — a category of attack that is difficult to detect and remove.
- What action is needed: Ensure Windows Update is enabled and current on all business PCs — Microsoft is delivering the new certificates automatically via Windows Update. On Windows 11, you can verify your status under Windows Security > Device Security > Secure Boot (a green tick means you are protected). Some older PC models may require a firmware update from the manufacturer before the new certificate can be applied. Sources: Microsoft IT Pro Blog, Microsoft Support.
The deadline is less than three weeks away. We recommend confirming update status on all business PCs before 24 June — contact your IT provider if you are uncertain whether your devices are protected.