UEFI Secure Boot Certificate Expiration Is Coming in 2026: What IT Teams Need To Do Now
- juanjllamasjr
- May 16
- 3 min read

A major Secure Boot certificate expiration event is approaching in 2026, and organizations should begin preparing now.
Many Windows systems, servers, virtual machines, and even some Linux dual-boot environments still rely on Microsoft Secure Boot certificates originally issued in 2011. Those certificates begin expiring in June 2026, with additional expirations occurring in October 2026. (Microsoft Support)
If organizations fail to update firmware trust stores and Secure Boot certificates before these dates, systems may eventually lose the ability to trust newer bootloaders, receive Secure Boot security updates, or properly validate firmware components.
This is not just a theoretical issue. Microsoft has already begun warning organizations to take action now. (TECHCOMMUNITY.MICROSOFT.COM)
The Key Expiration Dates
The following Microsoft Secure Boot certificates begin expiring in 2026:
Certificate | Expiration Date | Replacement Certificate |
Microsoft Corporation KEK CA 2011 | June 24, 2026 | Microsoft Corporation KEK 2K CA 2023 |
Microsoft Corporation UEFI CA 2011 | June 27, 2026 | Microsoft UEFI CA 2023 |
Microsoft Windows Production PCA 2011 | October 19, 2026 | Windows UEFI CA 2023 |
These certificates are deeply embedded into the Secure Boot trust chain used by Windows devices and many third-party EFI applications. (Dell)
Why This Matters
Secure Boot is designed to prevent malicious code from loading before the operating system starts. It relies on trusted certificates stored inside UEFI firmware to validate boot components.
As these older 2011 certificates expire, systems must transition to the newer 2023 certificates to continue securely validating:
Windows boot managers
Firmware updates
EFI applications
Option ROMs
Third-party bootloaders
Without those updated certificates, organizations could eventually face:
Failed operating system upgrades
Secure Boot validation errors
Inability to apply future boot security fixes
Firmware compatibility issues
Boot failures after future revocation updates
Microsoft has specifically warned that systems not updated before expiration may stop receiving Secure Boot protections entirely. (Microsoft Support)
Systems Most Likely To Be Affected
Organizations should closely review:
Older Windows 10 and Windows 11 systems
Windows Server 2012/2016/2019/2022 environments
Long-lived virtual machines
Devices rarely receiving BIOS updates
Air-gapped systems
Dual-boot Linux systems
Older OEM hardware nearing end-of-life
Many devices deployed over the last decade still contain only the original 2011 Secure Boot trust chain.
What IT Teams Should Do Now
Audit Current Secure Boot Certificates
Identify systems still using the 2011 Secure Boot certificates.
Update BIOS and UEFI Firmware
Install the latest firmware updates from OEM vendors to ensure compatibility with the newer 2023 certificate chain.
Ensure Windows Updates Are Current
Microsoft is distributing portions of the new Secure Boot certificate infrastructure through Windows updates. (TECHCOMMUNITY.MICROSOFT.COM)
Validate Secure Boot Is Enabled
Systems with Secure Boot disabled may not properly receive or enforce updated trust protections.
Test Recovery Procedures
Verify BitLocker recovery workflows and recovery media before making Secure Boot modifications.
Test Boot Media
Older WinPE environments, Linux boot media, and recovery tools may eventually require updated signatures.
Identify Unsupported Hardware
Some aging devices may never receive compatible firmware updates and should be reviewed as part of hardware refresh planning.
Why Organizations Should Not Delay
This transition is happening in stages, but waiting until certificates expire could create operational problems that are far harder to resolve later.
UEFI and Secure Boot operate below the operating system layer. When trust failures happen there, systems may fail before standard recovery tools or endpoint protections can even load.
As attackers increasingly target boot-level persistence and firmware compromise, Microsoft and hardware vendors are tightening Secure Boot enforcement.
Organizations that proactively update now will avoid emergency remediation later.
Firmware security is no longer optional infrastructure maintenance. It has become part of the enterprise security boundary itself.

