Microsoft has alerted users about the impending expiration of Secure Boot certificates>, originally issued in 2011, which are crucial for verifying bootloaders on Windows PCs. This mechanism, introduced with Windows 8, ensures that only verified software is loaded during the startup process. While Secure Boot was optional for Windows 8 and 10, it became a mandatory requirement for Windows 11 starting in 2021.</p>
The expiration dates for these certificates are set for June and October 2026. Although this situation has been discussed by Microsoft and major PC manufacturers for some time, the company emphasizes that users need to be proactive to avoid potential issues.
Impact of Certificate Expiration
Once the certificates expire, PCs that do not receive the necessary updates may continue to operate but will enter a degraded security state. This state limits the ability of these systems to receive patches for newly discovered vulnerabilities, which could expose them to security risks. Furthermore, these devices may face compatibility issues with newer operating systems and software that rely on updated Secure Boot certificates.
Updating Secure Boot Certificates
For most systems, including older models, Microsoft intends to use Windows Update to distribute the new certificates. Users with fully patched systems running supported versions of Windows should experience a seamless transition. The update process utilizes a small amount of NVRAM in UEFI-based systems to store the new certificates.
To check if your system has the new certificates, users can run a specific PowerShell command. If the command indicates that the new certificates are in use, the system is prepared for the upcoming changes. If not, users may need to ensure that Secure Boot is enabled and check for any available firmware updates.
Manufacturer Support and Recommendations
Microsoft has noted that many PCs manufactured since 2024, and nearly all devices shipped in 2025, already include the updated certificates. For older systems, manufacturers like Dell, HP, and Lenovo provide lists of compatible devices and firmware versions. Users are encouraged to consult customer support if they encounter difficulties in obtaining the new certificates.
In summary, the renewal of Secure Boot certificates is essential for maintaining the security and compatibility of Windows PCs. Users are advised to stay informed and ensure their systems are updated before the expiration dates.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








