{"id":53689,"date":"2026-05-26T05:18:17","date_gmt":"2026-05-26T09:18:17","guid":{"rendered":"https:\/\/overcentral.com\/en\/what-happens-when-secure-boot-expires-on-a-pc\/"},"modified":"2026-05-26T05:19:15","modified_gmt":"2026-05-26T09:19:15","slug":"secure-boot-certificate-expiration-pc","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/secure-boot-certificate-expiration-pc\/","title":{"rendered":"What Happens When Secure Boot Expires on a PC"},"content":{"rendered":"<p>As <a href=\"https:\/\/overcentral.com\/en\/berserk-chapter-384-june-2026-return\/\" title=\"Berserk Returns With New Chapter 384 in June 2026\" data-iacss-internal=\"1\">June 2026<\/a> approaches, a significant security milestone is quietly passing for millions of Windows PCs worldwide. The Secure Boot certificates issued in 2011, designed to protect the boot process for 15 years, are beginning to expire. The first to lapse is the KEK CA 2011 certificate on June 24, followed by the UEFI CA 2011 on June 27, and finally the Windows Production PCA 2011 on October 19. While your PC will still turn on and Windows will still load, the reality is more nuanced than a simple yes or no. This article explains exactly what happens when these certificates expire, what still works, what breaks, and the critical steps you need to take to keep your system secure and updateable.<\/p>\n<h2>What Is Secure Boot and Why Do Certificates Expire?<\/h2>\n<p>Secure Boot is a security standard built into the UEFI firmware of modern PCs. When you press the power button, the UEFI firmware checks the digital signature of every piece of boot software \u2014 from the bootloader to the operating system kernel \u2014 against a database of trusted certificates stored in the firmware. If a signature is valid and trusted, the boot process continues. If not, the system halts to prevent malicious code from loading. This mechanism is your first line of defense against bootkits and rootkits that try to inject malware before Windows even starts.<\/p>\n<p>The certificates used for Secure Boot have a finite lifespan. The ones expiring <a href=\"https:\/\/overcentral.com\/en\/kanojo-no-tomodachi-anime-2026-premiere\/\" title=\"Kanojo no Tomodachi Anime Adaptation Premieres in 2026\" data-iacss-internal=\"1\">in 2026<\/a> were issued in 2011, during the Windows 8 era, and were designed for a 15-year validity period. <a href=\"https:\/\/www.microsoft.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Microsoft<\/a> has known this day would come and has spent years preparing a transition to newer certificates. The 2023 editions of these certificates have already been distributed through Windows Update and are being phased in gradually. But not every PC has received them, and the clock is ticking.<\/p>\n<h2>Three Certificates, Three Expiration Dates<\/h2>\n<p>The expiration is not a single event. Three distinct certificates lapse over a span of about four months, each with different consequences.<\/p>\n<h3>KEK CA 2011 \u2014 June 24, 2026<\/h3>\n<p>The Key Exchange Key (KEK) CA 2011 is the certificate used to sign updates to the Secure Boot databases, including the allowed signature database (DB) and the forbidden signature database (DBX). When this certificate expires, the ability to push new updates to the Secure Boot databases becomes severely restricted. Without a valid KEK, future database updates cannot be authenticated, meaning your PC will be stuck with the current list of trusted and untrusted signatures indefinitely.<\/p>\n<h3>UEFI CA 2011 \u2014 June 27, 2026<\/h3>\n<p>This certificate signs the UEFI drivers and boot loaders produced by third-party hardware vendors. After it expires, new UEFI drivers and boot loaders from third parties will not be recognized as trusted by Secure Boot, potentially causing compatibility issues with future hardware additions or firmware updates.<\/p>\n<h3>Windows Production PCA 2011 \u2014 October 19, 2026<\/h3>\n<p>This is the certificate that signs the Windows bootloader itself. While your existing Windows installation will continue to boot because the bootloader is already trusted, the expiration means that any new version of the Windows bootloader \u2014 such as those delivered with major feature updates \u2014 will not be trusted unless signed with a newer certificate.<\/p>\n<h2>Your PC Will Still Boot \u2014 But at What Cost?<\/h2>\n<p>The most common question users ask is whether their PC will stop working after June 24. The answer from Microsoft is clear: <strong>your PC will still boot normally<\/strong>. Regular Windows Update will continue to install conventional patches and security fixes. You will not be locked out of your machine. However, the security posture of your boot process will be frozen in time.<\/p>\n<p>Once the certificates expire, the Secure Boot databases \u2014 both the allowed list (DB) and the forbidden list (DBX) \u2014 will no longer receive updates. This has a profound implication: any newly discovered bootkit or rootkit that targets a vulnerability in a previously trusted bootloader cannot be added to the forbidden list on your system. Your PC will remain vulnerable to threats that are discovered after the expiration date, with no way to block them through Secure Boot updates.<\/p>\n<h2>What Stops Working When Secure Boot Certificates Expire<\/h2>\n<p>The consequences are not immediate, but they are cumulative and permanent. Here is what changes:<\/p>\n<h3>Boot Manager Updates Permanently Cease<\/h3>\n<p>Microsoft distributes updates to the UEFI boot manager through Windows Update. These updates are signed with the certificates that are expiring. After expiration, your PC will no longer accept new boot manager updates. This means any security fixes or improvements to the boot manager itself will never reach your system.<\/p>\n<h3>Secure Boot Database Updates (DB\/DBX) Stop<\/h3>\n<p>The DBX (forbidden signature database) is the mechanism used to revoke trust in compromised bootloaders. When a new bootkit is discovered, Microsoft adds its signature to the DBX and distributes the update via Windows Update. After certificate expiration, these updates will not install on your PC. Your system will remain unprotected against bootkits discovered after the expiration date.<\/p>\n<h3>Future OS Feature Upgrades Are Blocked<\/h3>\n<p>This is the most restrictive consequence. While Microsoft has stated that <a href=\"https:\/\/overcentral.com\/en\/windows-11-gaming-ram-baseline-16gb-32gb\/\" title=\"Microsoft revises Windows 11 gaming RAM baseline to 16GB, 32GB.\" data-iacss-internal=\"1\">Windows 11<\/a> updates will still install on systems with the 2011 certificates for now, future major version upgrades \u2014 such as the next major release of Windows \u2014 will require bootloader components signed with the 2023 certificates. If your PC does not have the new certificates, the installer will intentionally fail to prevent a bricked system. The installation process checks the UEFI signature database before applying the upgrade and aborts if the required certificates are absent.<\/p>\n<h2>Why Some PCs Cannot Update Even If They Want To<\/h2>\n<p>The update process for Secure Boot certificates is not as simple as a typical Windows update. It involves writing directly to the UEFI firmware, which requires careful coordination between the operating system and the motherboard firmware. Microsoft has been using a controlled feature rollout (CFR) approach, deploying the update in waves based on hardware telemetry. PCs from different manufacturers have different UEFI implementations, and Microsoft has explicitly stated that it cannot test every possible combination of motherboard and firmware.<\/p>\n<p>If your PC has Secure Boot disabled in the BIOS, the certificate update will not be offered at all. Microsoft deliberately blocks the update on systems where Secure Boot is turned off because writing new certificates to the firmware while Secure Boot is disabled can, on some motherboards, corrupt the boot chain when Secure Boot is re-enabled. For PCs that have Secure Boot enabled but still show a status of &#8220;update needed,&#8221; the recommended course of action is to check Windows Update manually or apply the latest firmware update from your PC manufacturer.<\/p>\n<p>Legacy systems that use BIOS instead of UEFI, or that have disks formatted with MBR instead of GPT, are not eligible for Secure Boot updates at all. These systems are effectively excluded from the update process and will remain with the expired certificates indefinitely.<\/p>\n<h2>The Enterprise Challenge: Testing Before Deployment<\/h2>\n<p>For IT administrators managing fleets of corporate PCs, the situation demands careful planning. Microsoft strongly advises against deploying the Secure Boot certificate update via group policy across all devices at once. The reason is that some motherboard models have already shown compatibility issues with the new certificates. Instead, the recommended approach is to select representative hardware models from your inventory, test the update on each, verify successful boot and BitLocker recovery, and then gradually expand the rollout.<\/p>\n<p>Microsoft has provided PowerShell scripts and Event Viewer guidance via the TPM-WMI event source to monitor update status across the enterprise. These tools allow administrators to check which devices have received the update and which still require attention. For Windows Server, the situation is even more manual \u2014 Server editions do not participate in the CFR program, and administrators must apply the certificates using PowerShell commands directly.<\/p>\n<h2>BitLocker and the Reboot Cycle: What to Expect<\/h2>\n<p>During the certificate update process, users may observe multiple reboots. Microsoft has confirmed that this is by design. The update requires at least three reboots: one to write the certificates to firmware, one for the firmware to apply the certificates, and one to load the newly signed bootloader. Some users have reported seeing additional reboots as the system re-seals BitLocker encryption keys after each firmware change.<\/p>\n<p>BitLocker recovery key prompts are unlikely during normal operation because the update process is designed to preserve the encryption state. However, if your system has a particularly sensitive firmware configuration or if the update is interrupted, you may be prompted for the recovery key. It is always wise to have your BitLocker recovery key backed up before applying any firmware-level update. Microsoft has stated that the update process is fully aware of BitLocker and automatically re-seals the encryption keys after each reboot.<\/p>\n<h2>How to Check If Your PC Has the 2023 Certificates<\/h2>\n<p>Verifying your update status is straightforward. Open the Windows Security app, navigate to <strong>Device Security<\/strong>, and then select <strong>Security Processor<\/strong>. Under the <strong>Security features<\/strong> section, look for <strong>Secure Boot<\/strong>. The status will display one of three messages. &#8220;Update completed&#8221; or &#8220;Your system is up to date&#8221; means the 2023 certificates are installed. &#8220;Update needed&#8221; or &#8220;Not yet updated&#8221; means your PC still has the 2011 certificates and action is required. &#8220;Not supported&#8221; means your hardware is not eligible for the update, typically because Secure Boot is disabled or the system is legacy BIOS.<\/p>\n<p>If your status shows &#8220;Update needed,&#8221; the first step is to run Windows Update manually and check for optional updates. If no update is offered, visit your PC manufacturer&#8217;s support site and check for a UEFI firmware update. Installing the latest firmware often resolves the issue because motherboard vendors have been releasing updates that prepare the UEFI environment for the new certificates.<\/p>\n<h2>What About PCs That Cannot Be Updated?<\/h2>\n<p>For PCs that genuinely cannot receive the 2023 certificates \u2014 either because the hardware is too old, the firmware is not compatible, or Secure Boot cannot be enabled \u2014 the practical advice is to continue using the system with the understanding that its boot security is permanently frozen at the June 2026 state. Regular Windows updates and antivirus protection will still function, but the system will be increasingly vulnerable to boot-level threats discovered after the expiration date.<\/p>\n<p>Microsoft has indicated that future Windows feature upgrades may require the new certificates, so these PCs may eventually be unable to upgrade to the next major version of Windows. For critical systems, planning for hardware replacement within the next few years is the most prudent course of action.<\/p>\n<h2>The Road Ahead: Post-Quantum Cryptography and the Next Transition<\/h2>\n<p>The 2023 certificates have a root certificate that expires in 2038, providing ample runway for the current hardware generation. However, Microsoft has already signaled that the next major certificate transition will be driven by post-quantum cryptography. National roadmaps around the world target the early 2030s for migration to cryptographic algorithms that can resist quantum computer attacks. This means that hardware manufactured in the 2030s will likely ship with post-quantum Secure Boot certificates, not the 2023 edition. The current 2023 certificates will serve their purpose for the lifetime of the hardware they protect, and the next transition will come with the next generation of motherboards and firmware.<\/p>\n<p>The expiration of the 2011 Secure Boot certificates marks the end of an era for PC security, but it is not a cause for alarm. Your PC will continue to work. The real cost is the gradual erosion of boot-time security \u2014 a slow fade rather than a sudden shutdown. The update is available, the process is documented, and the tools to check your status are already in your hands. Taking a few minutes to verify that your system has the 2023 certificates is a small investment in the long-term integrity of your boot process. In the world of security, the systems that appear to work fine are often the ones that need the most attention. Your PC will boot, but the question is whether it will remain safe.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As June 2026 approaches, a significant security milestone is quietly passing for millions of Windows PCs worldwide. The Secure Boot certificates issued in 2011, designed to protect the boot process for 15 years, are beginning to expire. The first to lapse is the KEK CA 2011 certificate on June 24, followed by the UEFI CA [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":73238,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/iili.io\/CdGCCTQ.jpg","fifu_image_alt":"What Happens When Secure Boot Expires on a PC","footnotes":""},"categories":[349],"tags":[],"class_list":["post-53689","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/iili.io\/CdGCCTQ.jpg","fifu_image_alt":"What Happens When Secure Boot Expires on a PC","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/53689","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=53689"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/53689\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/73238"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=53689"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=53689"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=53689"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}