Today, 26 June 2026, marks the expiry of the Secure Boot certificates that have shipped inside Windows devices since 2011. Microsoft has been rolling out replacement certificates via Windows Update — if your devices are kept up to date, no action is needed. If not, today is the day to check.
- What it is: The Microsoft Corporation KEK CA 2011 Secure Boot certificate expires today. Microsoft has been replacing it with updated 2023-dated certificates delivered through automatic Windows Update, starting from the April 2026 update.
- Who is affected: All Windows PCs and servers that have not applied updates from April 2026 onwards. Devices with automatic updates enabled should already be covered.
- What the risk is: Devices that miss the update will continue to boot and operate normally, but will no longer receive security updates for the boot process — including protection against newly discovered boot-level threats, BitLocker hardening updates, and Secure Boot revocation list changes. Over time this limits protection against emerging firmware-level attacks.
- How to check: Open the Windows Security app on each device and look under Device security for Secure Boot status. If the new certificates have been applied, you will see a confirmed status there. This check has been available since the April 2026 Windows update.
- What to do: Ensure all Windows devices have applied updates from April 2026 onwards. Devices running Windows 11 with automatic updates enabled should already be covered.
If you manage a fleet of Windows devices and are unsure about patch compliance across your environment, contact us and we can run a status check. This is a time-sensitive item — the certificate window closes today.
Sources: Microsoft Support — Secure Boot Certificate Expiration | Microsoft Tech Community