Microsoft’s Secure Boot chain of trust has been running on certificates issued in 2011. The KEK CA 2011 expired on 24 June 2026 and the Microsoft UEFI CA 2011 on 27 June. The last, Windows Production PCA 2011, expires on 19 October 2026. The replacements are a set of 2023 certificate authorities that Microsoft has been rolling out through Windows Update.
This isn’t a “PCs stop booting” event, and it’s worth saying plainly because that’s how it has been reported in places. Microsoft’s guidance is that devices without the new certificates keep working, but can no longer receive new protections for the early boot process — Boot Manager updates, Secure Boot database and revocation updates, and fixes for boot-level vulnerabilities. That’s the layer bootkits target, so quietly falling off updates there is a real gap.
Microsoft updates most devices automatically. Some need a firmware (BIOS/UEFI) update from the manufacturer first — typically older models, or machines that have missed firmware updates for a while. Have your fleet checked for certificate status, push outstanding manufacturer firmware, and flag any device that can’t take the update for your next refresh round.
