top of page

UEFI Secure Boot Certificate Expiration Is Coming in 2026: What IT Teams Need To Do Now

  • juanjllamasjr
  • May 16
  • 3 min read
UEFI Secure Boot certificates expiring in 2026
UEFI Secure Boot certificates will expire in 2026, with key dates on June 24, June 27, and October 19. Update firmware and verify secure boot now for continued protection.

A major Secure Boot certificate expiration event is approaching in 2026, and organizations should begin preparing now.


Many Windows systems, servers, virtual machines, and even some Linux dual-boot environments still rely on Microsoft Secure Boot certificates originally issued in 2011. Those certificates begin expiring in June 2026, with additional expirations occurring in October 2026. (Microsoft Support)


If organizations fail to update firmware trust stores and Secure Boot certificates before these dates, systems may eventually lose the ability to trust newer bootloaders, receive Secure Boot security updates, or properly validate firmware components.


This is not just a theoretical issue. Microsoft has already begun warning organizations to take action now. (TECHCOMMUNITY.MICROSOFT.COM)


The Key Expiration Dates


The following Microsoft Secure Boot certificates begin expiring in 2026:


Certificate

Expiration Date

Replacement Certificate

Microsoft Corporation KEK CA 2011

June 24, 2026

Microsoft Corporation KEK 2K CA 2023

Microsoft Corporation UEFI CA 2011

June 27, 2026

Microsoft UEFI CA 2023

Microsoft Windows Production PCA 2011

October 19, 2026

Windows UEFI CA 2023


These certificates are deeply embedded into the Secure Boot trust chain used by Windows devices and many third-party EFI applications. (Dell)


Why This Matters


Secure Boot is designed to prevent malicious code from loading before the operating system starts. It relies on trusted certificates stored inside UEFI firmware to validate boot components.


As these older 2011 certificates expire, systems must transition to the newer 2023 certificates to continue securely validating:


  • Windows boot managers

  • Firmware updates

  • EFI applications

  • Option ROMs

  • Third-party bootloaders


Without those updated certificates, organizations could eventually face:


  • Failed operating system upgrades

  • Secure Boot validation errors

  • Inability to apply future boot security fixes

  • Firmware compatibility issues

  • Boot failures after future revocation updates


Microsoft has specifically warned that systems not updated before expiration may stop receiving Secure Boot protections entirely. (Microsoft Support)


Systems Most Likely To Be Affected


Organizations should closely review:


  • Older Windows 10 and Windows 11 systems

  • Windows Server 2012/2016/2019/2022 environments

  • Long-lived virtual machines

  • Devices rarely receiving BIOS updates

  • Air-gapped systems

  • Dual-boot Linux systems

  • Older OEM hardware nearing end-of-life


Many devices deployed over the last decade still contain only the original 2011 Secure Boot trust chain.


What IT Teams Should Do Now


Audit Current Secure Boot Certificates


Identify systems still using the 2011 Secure Boot certificates.


Update BIOS and UEFI Firmware


Install the latest firmware updates from OEM vendors to ensure compatibility with the newer 2023 certificate chain.


Ensure Windows Updates Are Current


Microsoft is distributing portions of the new Secure Boot certificate infrastructure through Windows updates. (TECHCOMMUNITY.MICROSOFT.COM)


Validate Secure Boot Is Enabled


Systems with Secure Boot disabled may not properly receive or enforce updated trust protections.


Test Recovery Procedures


Verify BitLocker recovery workflows and recovery media before making Secure Boot modifications.


Test Boot Media


Older WinPE environments, Linux boot media, and recovery tools may eventually require updated signatures.


Identify Unsupported Hardware


Some aging devices may never receive compatible firmware updates and should be reviewed as part of hardware refresh planning.


Why Organizations Should Not Delay


This transition is happening in stages, but waiting until certificates expire could create operational problems that are far harder to resolve later.


UEFI and Secure Boot operate below the operating system layer. When trust failures happen there, systems may fail before standard recovery tools or endpoint protections can even load.


As attackers increasingly target boot-level persistence and firmware compromise, Microsoft and hardware vendors are tightening Secure Boot enforcement.


Organizations that proactively update now will avoid emergency remediation later.

Firmware security is no longer optional infrastructure maintenance. It has become part of the enterprise security boundary itself.


 
 

Recent Posts

See All
bottom of page