Microsoft just quietly widened the net for one of the most behind-the-scenes security fixes in Windows 11, and the clock is ticking on the final Secure Boot deadline.
With the September 2026 Patch Tuesday update, Microsoft expanded which PCs can automatically receive new Secure Boot certificates — and the last major certificate expiry lands October 19, 2026. Here’s exactly what changed and what you need to do before then.
What changed in the September 2026 update
According to the release notes for Windows 11 KB5124008 (Build 26200.9445), Microsoft once again broadened the rollout of Secure Boot certificates. More PCs now fall under the “high confidence” targeting bucket that lets them receive the new certificates automatically.
Microsoft stated in the September 2026 update documentation that “this update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates.”
In practical terms, this means a larger share of supported machines will pick up the certificate updates without any manual intervention from you. The targeting data Microsoft is adding simply refines which hardware configurations it deems safe to receive the new certificates on its own.
If your PC does receive a Secure Boot certificate change, expect it to potentially reboot one or even a few extra times — usually bundled alongside the monthly security update. That’s normal, though it can feel annoying when it happens.

What is actually happening with Secure Boot in 2026
Secure Boot is mandatory on Windows 11. It relies on certificates stored in your PC’s firmware (UEFI) to decide whether boot-level software is trusted, long before Windows 11 even starts loading. If something suspicious — like a compromised or malicious boot loader — tries to run, Secure Boot blocks it before the OS launches.
The concept is solid, but the industry has no better mechanism for managing certificates that control what runs at the boot level. And here’s the core problem: several of these certificates were last issued back in 2011, during the Windows 8 era, and they’re now expiring in 2026.
There’s no single expiration date, which is why Microsoft keeps shipping updates. According to Microsoft’s own documentation, the old certificates expire in stages:
| Old certificate | Expiration | Explanation according to Microsoft |
|---|---|---|
| Microsoft Corporation KEK CA 2011 | June 24, 2026 | Signs updates to Secure Boot’s allowed and revoked databases (DB and DBX) |
| Microsoft UEFI CA 2011 | June 27, 2026 | Signs third-party boot loaders, EFI apps, and some option ROMs |
| Microsoft Windows Production PCA 2011 | October 19, 2026 | Used for signing the Windows boot loader |
The first two dates have already passed. June 24 was the expiry for the Microsoft Corporation KEK CA 2011, which signs updates to Secure Boot’s allowed and revoked databases, while Microsoft UEFI CA 2011 expired on June 27.

The October 19 Secure Boot deadline explained
The next big date is October 19, 2026, when the Microsoft Windows Production PCA 2011 certificate expires. Microsoft says this certificate signs the Windows boot loader, which makes it one of the more important ones in the chain — if it lapses without a replacement, the very act of starting Windows could be affected.
But don’t panic if you haven’t seen the update land yet. Microsoft has repeatedly clarified that the rollout isn’t finished and will continue over the coming months.
During an Ask Microsoft Anything session with Windows experts, the company made clear that updates would keep flowing beyond these deadlines. Microsoft previously confirmed via its support documentation that “we will continue to install the newer certificates via Windows updates in the coming months.”
Even when the June 24 deadline arrived, Microsoft significantly expanded the number of devices eligible to automatically receive the newer certificates — but it never treated that date as a hard stop, and it never set an end date where the update mechanism would suddenly stop working.

What you must do before the deadline
For most Windows 11 users, there isn’t much to do manually. Microsoft is distributing the new Secure Boot certificates through Windows Update, so the main job is simple: stay up to date.
Make sure you’ve installed the latest updates, including the September 2026 Update. You can also verify the status yourself.
Open Windows Security > Device security > Secure Boot. If everything is current, it should tell you that “Secure Boot is on and all required certificate updates have been applied. No further certificate changes are needed.”
If Windows says you’re still running an older boot trust configuration, keep Windows Update enabled and check for any firmware or BIOS updates from your PC manufacturer. OEMs sometimes hold the exact firmware needed to apply the newer certificates cleanly.

Some PCs may need a firmware update before the newer certificates can be applied correctly — and that typically triggers another reboot. In testing, machines have been observed rebooting multiple times for Secure Boot, sometimes because a manufacturer suddenly remembers a firmware update is required for your specific PC. If you see repeated reboots, it’s usually this process working itself out, not a failure.
What this means for you
Microsoft and OEMs have confirmed that compatible devices won’t suddenly lose the ability to move to the 2023 certificates just because an old one has expired. PCs without the newer certificates will continue to start normally and receive standard Windows updates while the rollout continues.
So the practical takeaway is straightforward: keep Windows Update on, install your monthly security patches, and watch for any BIOS or firmware updates from your PC maker. That’s the entire checklist. There’s no manual certificate swap, no registry tweak, nothing to break.
The October 19 deadline is the last of the three staged expirations, but as Microsoft has stressed, certificate deployment will keep rolling out on supported PCs and non-managed business devices in the months ahead. The deadline marks the final certificate in the chain, not the end of Microsoft’s work on the issue.
Source: Windows Latest
Build details:
- kb5124008
Over to you: Have you seen your PC reboot extra times for a Secure Boot update, or is your status already showing all certificates applied?



