If you have noticed your Windows 11 PC restarting two or three times during a single Patch Tuesday installation, you are not alone. This behavior has become increasingly common since April 2026, often leaving users staring at a black screen or a spinning circle for extended periods. While the experience can feel alarming, Microsoft has confirmed that these repeated restarts are an intentional part of a broader security infrastructure change.
The core driver behind this behavior is the ongoing deployment of new Secure Boot certificates across millions of devices. As Microsoft continues to push these updates alongside standard monthly cumulative patches, the installation process now requires additional steps to write changes directly into your system’s firmware. This article breaks down exactly why this is happening, the technical steps involved, and how you can verify your device’s status.
The Secure Boot Certificate Rollout Continues
Microsoft is currently executing a large-scale update to the Secure Boot certificates used to verify the integrity of the Windows bootloader. This initiative is designed to enhance security by ensuring that only trusted software can load during the startup sequence. The August 2026 Patch Tuesday update, which delivered as many as 400 security fixes and bumped systems to Build 26200.9168, included additional high-confidence device targeting data to expand coverage for this rollout.

The company explicitly noted in the release notes for KB5121003 that certificate deployment via Windows Update continues across supported PCs and non-managed business devices in the coming months. If your device has not yet received the new Secure Boot 2023 certificate, it is likely still pending delivery. This is a one-time process per device, but because Microsoft is targeting a vast array of OEM configurations, the rollout spans several months rather than occurring in a single wave.
The Technical Reason Behind the Reboots
Updating a Secure Boot certificate is fundamentally different from applying standard software patches. The process requires writing new cryptographic keys directly into the motherboard’s firmware. During an Ask Me Anything session, Microsoft engineers clarified that this multi-step procedure is what necessitates multiple restarts.

The workflow typically follows three distinct phases, each requiring a reboot to complete safely. First, the update stages the new certificate data in preparation for the firmware write. Second, the system restarts to allow the firmware to apply the updated certificates. Third, a final reboot is required to boot Windows using the newly signed bootloader. Microsoft stated that most of these restarts occur early in the boot process, which is why they often go unnoticed during automated flows, but they become highly visible when triggered alongside a standard cumulative update.
Other Factors Triggering Reboots
While the Secure Boot certificate is the primary culprit for the recent surge in multiple restarts, it is not the only factor. Windows Update frequently delivers separate firmware and driver updates alongside security patches. If your device has pending firmware changes from the OEM, these will trigger additional restarts as the system applies hardware-level configurations.

This explains why some users may experience multiple reboots across different monthly updates, even after the Secure Boot certificate has been fully applied. A pending driver update or a BIOS/UEFI firmware patch can introduce new restart cycles independent of the certificate deployment. If you notice another reboot later in the same update cycle, it is likely related to these auxiliary components rather than a repeat of the Secure Boot process.
What This Means for You
For everyday users, the immediate takeaway is patience. If your PC is cycling through multiple restarts, it is actively working on critical security infrastructure. Interrupting the process by holding the power button can corrupt the firmware update and may leave the device in an unbootable state. Microsoft advises against delaying updates past three days, as doing so may expose systems to AI-powered security threats that target unpatched vulnerabilities.

Once the Secure Boot certificate is successfully applied to your specific hardware, you should see a return to the standard single-reboot behavior for future updates. If your device remains stuck on a black screen for an unusually long time or fails to progress past the spinning circle, it may indicate a firmware conflict that requires troubleshooting.
How to Verify Your Secure Boot Status
You can check whether your device has received the latest Secure Boot certificate by navigating to Settings > System > Recovery > Advanced startup, or by using the System Information tool. Look for the Secure Boot State entry, which should indicate whether the current certificates are up to date. If you are managing a fleet of devices, administrators should monitor the deployment progress via the Windows Update for Business dashboard to identify devices that may be stuck in the rollout queue.
Source: Windows Latest
Build details:
- kb5121003
Over to you: Have you experienced multiple reboots during this month’s Patch Tuesday, and did your device eventually complete the update successfully?



