Secure Boot Certificate Updates: How to Verify and Update Your Windows PCs
Secure Boot certificate expiration began in June 2026. Verify the full certificate and boot-manager update, review errors, and deploy safely to a Windows fleet.

Microsoft's 2011 Secure Boot certificates began expiring in June 2026. The Windows boot-loader signing certificate expires on October 19, 2026. Check your fleet's actual deployment status now; the presence of one replacement certificate is not a complete readiness check.
This guide was checked against Microsoft's documentation on October 3, 2026. Certificate servicing depends on the Windows version, installed updates, firmware, and device-specific deployment status.
The Secure Boot Certificate Expiration: What Actually Happens
Secure Boot checks trusted signatures before the operating system loads. The replacement trust entries were issued in 2023. Microsoft's published schedule is:
| Expiring certificate | Expiration date | Replacement |
|---|---|---|
| Microsoft Corporation KEK CA 2011 | June 24, 2026 | Microsoft Corporation KEK 2K CA 2023 |
| Microsoft UEFI CA 2011 | June 27, 2026 | Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023, as applicable |
| Microsoft Windows Production PCA 2011 | October 19, 2026 | Windows UEFI CA 2023 |
Expiry alone normally leaves a PC able to start and install standard Windows updates. Without the replacement trust entries, it cannot receive new early-boot security protections that depend on them. Microsoft explains the schedule and impact.
These are firmware trust certificates, distinct from website TLS certificates. For Windows 10, separately establish a supported servicing path such as eligible ESU coverage; see our Windows 10 end-of-life guide.
How to Check a Single PC
Start with read-only checks. Keep Secure Boot enabled; do not disable it or reset its keys to work around expiry.
Step 1: Confirm Secure Boot is enabled
Open System Information (msinfo32) and check Secure Boot State. If it is Off or Unsupported, record that finding and review the device's supported configuration with its manufacturer. Changing firmware security settings without preparation can affect startup and disk-encryption recovery.
Step 2: Check Windows deployment status
In an administrator PowerShell window, read the servicing values:
Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing" -ErrorAction SilentlyContinue |
Select-Object UEFICA2023Status, UEFICA2023Error, UEFICA2023ErrorEvent
- Updated: Windows reports that its certificate and boot-manager deployment completed. Confirm that no nonzero servicing error or relevant unresolved event contradicts that result.
- InProgress: Deployment is not complete. Review pending restarts, errors, and firmware prerequisites.
- NotStarted or missing values: Completion is not established by this check. Investigate Windows servicing and OEM guidance; missing values alone do not identify which certificates the firmware contains.
Microsoft defines these values in its certificate deployment registry guide.
Step 3: Use certificate presence as a supplemental check
The following command checks only for a particular certificate name in the allowed-signature database:
[System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Windows UEFI CA 2023'
True is not proof of a completed transition. It does not verify the KEK, all other applicable trust entries, or the installed boot manager. False or a command error needs investigation rather than an automatic conclusion about hardware support. Use the status values, System event logs, and OEM guidance together.
The Automatic Path: Verify Completion
Microsoft automatically services some device configurations through its managed rollout and high-confidence targeting. A recent purchase, familiar manufacturer, current Windows updates, or ESU enrollment does not guarantee completion.
Install the supported Windows and OEM updates, complete required restarts, and repeat the status check. If deployment remains incomplete, follow Microsoft's troubleshooting guide. Its checks cover the scheduled task, servicing errors, missing OEM-signed KEKs, and firmware limitations.
The Managed-Fleet Path: Intune, Registry Keys, and Small-Business Reality
Verify recovery keys before firmware or certificate changes
Confirm that the BitLocker recovery key is available to an authorized administrator before changing firmware or Secure Boot settings. Follow the device manufacturer's instructions about suspending protection where required, and confirm protection resumes afterward. Suspending BitLocker is not a substitute for having a recovery key. Do not reset Secure Boot keys to factory defaults unless the OEM's current recovery procedure explicitly requires it and the installed defaults support the updated boot manager.
Use a pilot device for each hardware and firmware combination before expanding a deployment. Record the Windows build, BIOS version, servicing status, errors, and restart results. Plan a maintenance window and access to recovery support.
Where available, use Microsoft's supported Intune or Group Policy deployment method. For administrators choosing the registry method, Microsoft's current guide specifies the following trigger:
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot /v AvailableUpdates /t REG_DWORD /d 0x5944 /f
Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"
These commands initiate servicing; they do not certify success. Follow Microsoft's documented restart sequence and monitor progress before repeating actions or rolling them out to other devices. The task normally runs every 12 hours. A final AvailableUpdates value of 0x4000 can be expected on successful completion because that modifier remains set; do not require zero as the sole completion signal.
Confirm UEFICA2023Status is Updated, review UEFICA2023Error and relevant events, and investigate stalled devices using Microsoft's deployment instructions. KB5025885 is a separate Windows Boot Manager revocation process for CVE-2023-24932, not the universal certificate-renewal procedure.
The Problem Machines: OEM Firmware and Virtual Machines
Some devices need updated firmware or an OEM-signed KEK before Windows can complete the transition. Use the support page for the exact model; do not infer support from a manufacture year alone.
Virtual machines have their own firmware state. Check affected guests separately; an updated host does not establish guest readiness. If a supported remediation is unavailable, document the risk and assess isolation or replacement alongside the workload's other support requirements.
The Verification Checklist
Confirm Secure Boot state, supported Windows servicing, required OEM firmware, completed certificate and boot-manager deployment, and any unresolved errors. A DB certificate match alone is not a pass. Repeat the check after remediation and include it in your periodic security audit.
Related Resources
Frequently Asked Questions
Related Articles
More from Cybersecurity

Windows 10 End of Life: Navigating the 2026 Secure Boot Certificate Expirations
Windows 10 support has ended and Secure Boot certificates need renewal. Check consumer versus commercial ESU eligibility, certificate status, and Windows 11 compatibility.
4 min read

How to Set Up Automatic Updates on Every Device (Windows, Mac, iPhone, Android, Router)
Enable and verify automatic updates on Windows, macOS, iPhone, Android, routers, and NAS devices — a complete cross-platform guide for small businesses.
15 min read

Why Your Business Emails Are Going to Spam (And the 3-Step Fix)
If a client has ever said 'I never got your email,' your domain authentication is probably broken. Here's the 3-step fix for SPF, DKIM, and DMARC — takes about 20 minutes.
10 min read
