If you were holding your breath back in June wondering whether your PC would still boot after the old Secure Boot certificate deadline passed, Microsoft wants you to take a deep breath. The rollout of updated Windows Secure Boot certificates is still in progress, and the company has confirmed that devices which haven’t received the new credentials yet will continue to function normally. While the initial wave of updates targeted the June 24 and June 27 expiration dates, the broader deployment is stretching well into the fall, giving users more time than expected to get their systems aligned.
The Current Status of Updated Windows Secure Boot Certificates
The core issue revolves around the digital signatures that verify the integrity of your PC’s startup process. Secure Boot prevents malicious software from loading before Windows starts by checking the signatures of bootloaders against a trusted list. For years, many systems relied on certificates issued in 2011. Since those credentials had a 15-year lifespan, they were set to expire this year, which would have effectively disabled Secure Boot on affected machines.
Microsoft initially pushed a “just-in-time” update in late June to address the immediate expiration of the Microsoft Corporation KEK CA 2011 and the Microsoft UEFI CA 2011. However, the deployment proved complex across the vast ecosystem of OEM hardware. According to the July 2026 update notes for OS builds 26200.8875 and 26100.8875 (KB5101650), Microsoft clarified that the process is far from over. The company is continuing to push the newer certificates via standard Windows Update channels for the next several months.
Additionally, Microsoft maintains a blacklist of known bootloaders that are considered compromised. The Windows Boot Manager can expand this blacklist via DBX block updates, ensuring your system stays protected against newly discovered boot-level threats as the rollout continues.
The Certificate Expiration Timeline
Understanding the timeline helps clarify why the rollout is staggered. The expiration of the legacy certificates happens in three distinct phases, which explains why some systems are still waiting:
- The Microsoft Corporation KEK CA 2011 expired on June 24, 2026.
- The Microsoft UEFI CA 2011 expired on June 27, 2026.
- The Microsoft Windows Production PCA 2011 remains valid until October 19, 2026.
Even though the first two certificates have passed their expiration dates, Microsoft has stated that devices will continue to start up and receive standard Windows updates. The third certificate provides a hard deadline of October 19, 2026, for the final phase of the migration. The new certificates being deployed were issued in 2023, and while their specific validity period hasn’t been publicly detailed, they are designed to replace the aging 2011 credentials for the long term.
What This Means for Your PC
For the average user, the immediate takeaway is that your PC is safe. The systems that missed the June window will not brick, and you will not lose access to Windows Update. The primary impact is that Secure Boot might not be fully functional in terms of checking against the newest blacklist of compromised bootloaders until the update finally lands.
If you are running Windows 10, there is an additional layer to consider. Microsoft confirmed that Windows 10 devices will only continue to receive these Secure Boot updates if they are enrolled in the Extended Security Updates (ESU) program. A Windows 10 PC that is no longer registered for updates will not receive the new certificates, regardless of the broader rollout timeline.
How to Check Your Secure Boot Status
Microsoft introduced a visual indicator in Windows 11 to help users track the progress of these certificate updates without needing to dig into command-line tools. You can find this status under Settings > Windows Security > Device Security > Secure Boot.
The indicator uses a traffic light system to communicate your status:
- Green: Your certificates are up to date and Secure Boot is fully active.
- Yellow: Windows requires additional firmware information before it can apply the new certificates.
- Red: There is an active issue blocking the update, often indicating that a manufacturer BIOS update is required.
What to Do If You’re Still Waiting
If your status is yellow or red, or if you simply want to ensure your system is ready, the first step is to check for pending updates. Open Settings > Windows Update and click Check for updates. Microsoft is working directly with PC manufacturers to push the necessary firmware and certificate updates through this channel. In some cases, you may need to take the initiative. If the update does not appear, visit your manufacturer’s support website to see if a BIOS or UEFI update is available for your specific model. Applying these firmware updates often unlocks the ability for Windows to install the new Secure Boot credentials.
Manufacturer Support Policies
It is important to note that not all hardware will receive these updates indefinitely. Manufacturers have set boundaries based on their support lifecycles:
- Dell: Does not provide BIOS updates for systems whose support period expired before January 1, 2026.
- HP: Excludes PCs manufactured in 2018 or earlier from receiving these updates.
- Lenovo: Has a similar policy, limiting updates to systems within their active support window.
If your device falls outside these manufacturer guidelines, you may not be able to obtain the updated certificates through official channels. In such cases, the system will continue to boot, but Secure Boot functionality may remain limited.
What This Means for You
The extended timeline gives users a significant buffer. You do not need to rush to a repair shop or panic about your system bricking. However, staying proactive is wise. Regularly checking for Windows updates and manufacturer BIOS patches ensures your system is protected against boot-level threats as the October deadline approaches. The rollout is moving forward, and your PC will get its security credentials eventually.
Source: Windows News, Reviews, Advice & Deals | PCWorld
Build details:
- kb5101650
Over to you: Are you seeing the green light in your Secure Boot settings, or are you still waiting for the update to roll out?



