Web_Logo
Remote Support
Microsoft Windows: Secure Boot Certificate Deadline 24 June
Home » Microsoft Updates  »  Microsoft Windows: Secure Boot Certificate Deadline 24 June

Microsoft Windows: Secure Boot Certificate Deadline 24 June

A critical Windows security deadline is 17 days away. The Secure Boot certificates built into Windows since 2011 are expiring, and Microsoft is replacing them via Windows Update. Devices that do not receive the update in time will progressively lose the ability to receive boot-level security protections.

  • What it is: Secure Boot is a security feature that protects Windows during the boot process from malware and unauthorised software. The underlying certificate (Microsoft Corporation KEK CA 2011) expires on 24 June 2026. Microsoft is issuing new 2023-dated replacement certificates through Windows Update.
  • Who is affected: All Windows 10 and Windows 11 devices. Devices that have not kept up with Windows Updates are most at risk of missing the transition.
  • What the risk is: Devices that do not receive the new certificates will no longer receive future Secure Boot protections, including mitigations for newly discovered boot-level vulnerabilities. BitLocker and third-party bootloader compatibility may also be affected over time.
  • What action is needed: Ensure all Windows devices are running current Windows Updates and have restarted recently. From the April 2026 update onwards, the Windows Security app shows Secure Boot certificate status under Device Security. IT admins should verify this across managed devices before 24 June.

The transition happens automatically via Windows Update for most devices, but unmanaged or rarely-updated machines may miss it. More information is available from Microsoft Support and the Windows IT Pro Blog. If you need help verifying your device fleet before the deadline, contact your IT provider.