If you have been watching your Windows Security dashboard for the Secure Boot 2023 update and it has not appeared yet, Microsoft has issued a clear message: do not worry. The company confirmed via the July 14 Patch Tuesday release notes that devices which have not yet received the new certificates will continue to start normally and will keep receiving the update through standard Windows updates in the coming months.
This reassurance comes after the first major deadline passed on June 24, 2026, when the Microsoft Corporation KEK CA 2011 certificate officially expired. While the vast majority of supported PCs have already transitioned to the new cryptographic standards, a significant number of devices remained on the older 2011 certificates when the deadline arrived. Microsoft’s confirmation ensures that these systems will not be left behind, though the path to full compliance may take some time for some users.
The update was formally included in KB5101650, which moved Windows 11 to OS builds 26200.8875 and 26100.8875 for version 25H2 and 24H2 respectively. Under the “Announcements and messages” section of the release notes, Microsoft stated explicitly that devices without the newer certificates will continue to start and receive standard updates, with the new certificates being pushed via Windows Update in the coming months.
What the Secure Boot 2023 Rollout Actually Means
Secure Boot is a UEFI firmware feature designed to prevent malicious software from loading before the operating system starts. It works by checking the digital signature of every piece of software attempting to boot. If a bootloader’s signature does not match what Secure Boot trusts, the firmware refuses to run it. This mechanism is critical for blocking rootkits and bootkits, which are stealthy malware that hide from antivirus tools by loading earlier in the startup process.
The trust system relies on cryptographic certificates. For years, the certificates backing Secure Boot since Windows 8 were issued in 2011. However, cryptographic keys have expiration dates to prevent attackers from finding workarounds, and 15 years is an exceptionally long time for any key to remain in service. As such, Microsoft has been retiring the 2011 certificates in three separate stages to ensure a smooth transition to modern cryptographic standards.
The 2023 certificates replace all three legacy keys. Once a device has them, its boot manager switches over automatically, allowing Microsoft to continue pushing DBX revocation updates. The DBX is a blacklist of compromised bootloaders, and losing the ability to update it leaves systems vulnerable to new threats. The expiration timeline for the old certificates was as follows:
- Microsoft Corporation KEK CA 2011: Expired June 24, 2026.
- Microsoft UEFI CA 2011: Expired June 27, 2026.
- Microsoft Windows Production PCA 2011: Expires October 19, 2026.
While the first two have already passed, the PCA expiration in October gives Microsoft a final window to ensure all eligible devices are compliant. Devices stuck on the 2011 KEK can only receive DBX updates signed with that key, and the ability to sign on it ended on June 24.
Why the Deadline Was Critical for Security
The urgency behind the Secure Boot 2023 transition is not just about cryptographic hygiene; it is a direct response to real-world threats. The most prominent example is BlackLotus, a UEFI bootkit discovered in 2023 that exploited older bootloader vulnerabilities to bypass Secure Boot on fully patched Windows 11 systems.
BlackLotus was able to bypass these protections before Microsoft revoked the vulnerable signatures. Once the 2011 KEK expires, Microsoft can no longer sign new revocation updates with that key. This means that devices still running the old certificates would be unable to receive the latest protections against bootkits like BlackLotus, leaving them exposed to attacks that modern Secure Boot is designed to prevent.
Microsoft has spent close to two years rolling out the 2023 certificates. The June 2026 update pushed most supported PCs into what the company calls the “high confidence category,” where the certificate applies automatically. However, a meaningful number of devices were still on a yellow or red status when the June deadline passed, necessitating the continued rollout confirmation.
How to Check Your Secure Boot Status
If you want to verify whether your PC has received the Secure Boot 2023 certificates, you can check directly through the Windows Security app. This interface provides a clear visual indicator of your device’s compliance status.
To check your status, open Windows Security > Device Security and scroll to the Secure Boot section. The status is indicated by a colored icon:
- Green Checkmark: The certificates are already applied, and your device is fully updated.
- Yellow Warning: Windows needs more compatibility data about your firmware before it can proceed with the update.
- Red Alert: A firmware incompatibility is blocking the update, and you need a BIOS update from your manufacturer.
If the Secure Boot section is missing entirely from the Device Security page, your PC likely has Secure Boot disabled in firmware, is running in Legacy BIOS mode, or was set up using the registry bypass on unsupported hardware. In these cases, the Secure Boot 2023 update cannot be applied because the firmware is not running proper UEFI Secure Boot.
Rollout Challenges and OEM Cooperation
The transition to Secure Boot 2023 has not been without friction. Microsoft and original equipment manufacturers (OEMs) have faced significant challenges in ensuring all devices can receive the update. By the end of June, every major PC manufacturer, including ASUS, Dell, HP, Lenovo, MSI, Acer, Samsung, and LG, published OEM Secure Boot transition guides listing which models are covered.
However, firmware handling has been inconsistent across the industry. In March, investigations found that Secure Boot 2023 updates failed across a meaningful number of PCs due to these inconsistencies. HP later admitted that a batch of its BIOS updates from April 2026 were bricking Windows 11 PCs, trapping commercial laptops and workstations in BitLocker recovery loops.
Microsoft has responded by identifying specific device and firmware combinations where the update causes problems and pausing the rollout on those combinations intentionally. To address these issues, Microsoft held an OEM Secure Boot Office Hours event on July 15, a live Tech Community session where engineers from Microsoft and OEMs including Dell, HP, Lenovo, and Surface answered questions from IT admins regarding confidence ratings, the AvailableUpdates registry key, and BitLocker recovery.
Not every issue has been resolved. Follow-up coverage found that HP’s BitLocker recovery loop is still triggering even on the latest BIOS for some devices, and at least two admins’ questions went unanswered by Dell and HP. These ongoing issues highlight the complexity of managing firmware updates across a diverse hardware ecosystem.
Windows 10 and Extended Security Updates
The Secure Boot 2023 transition also affects Windows 10, which is past its support lifecycle. Microsoft is still shipping Secure Boot certificate updates to Windows 10 using identical code to Windows 11. The May 2026 update, KB5087544, brought the same green, yellow, and red status indicators to the Windows Security app on Windows 10.
However, there is a critical catch for Windows 10 users. Only PCs enrolled in Extended Security Updates (ESU) will continue to receive monthly updates, including the Secure Boot certificates. A Windows 10 PC that is not enrolled and has stopped getting updates will not receive the 2023 certificates, regardless of hardware age.
This makes Microsoft’s recent decision to extend Windows 10 ESU into October 2027 particularly relevant. For organizations and users still relying on Windows 10, enrolling in ESU is now essential not just for security patches, but for maintaining the Secure Boot certificate chain that protects against boot-level attacks.
What You Should Do Now
For most users, the immediate action required is minimal. Unless you are an IT admin managing a large fleet of devices that has not yet received Secure Boot updates, there is no urgent problem that needs to be fixed.
If you are a home user, the best course of action is to ensure Windows Update is running normally. Microsoft will continue to push the certificates to eligible devices over the coming months. You can check your status once to see where you stand, but if you see a green checkmark, you are already compliant.
If you see a yellow warning, you may need to wait for Windows to gather more compatibility data, or you can manually check for driver and firmware updates from your manufacturer’s support site. If you see a red alert, you should visit your manufacturer’s website to download the latest BIOS update for your specific model.
For IT administrators, the situation is more complex. You should review the OEM Secure Boot transition guides for your specific hardware and monitor the Windows Insider Blog for updates on paused rollouts. The Ask Microsoft Anything sessions and the OEM Office Hours event provide valuable resources for troubleshooting firmware compatibility issues.
Devices that are too old to receive BIOS updates, or those running Legacy BIOS mode, will not be able to receive the Secure Boot 2023 certificates. These systems will continue to boot and receive standard updates, but they will lose the ability to receive future DBX revocation updates. For these devices, the long-term recommendation is to plan for hardware replacement to maintain full security compliance.
Summary of Key Dates and Updates
To help you track the rollout, here is a summary of the key dates and updates mentioned in the source material:
- June 24, 2026: Microsoft Corporation KEK CA 2011 expired.
- June 27, 2026: Microsoft UEFI CA 2011 expired.
- July 14, 2026: KB5101650 released, confirming continued rollout.
- October 19, 2026: Microsoft Windows Production PCA 2011 expires.
- October 2027: Windows 10 ESU support extension ends.
Microsoft’s confirmation provides clarity for users who were concerned about missing the deadline. The rollout is ongoing, and while some devices may take longer to receive the update, the path to compliance remains open for all eligible hardware.
Source: Windows Latest
Build details:
- KB5094126
- kb5087544
- kb5101650
Over to you: Have you checked your Secure Boot status yet, or are you waiting for the update to arrive automatically?



