Windows 11 Secure Boot Certificates Are Expiring — Here's What You Need to Do

0 comments
Windows 11 Secure Boot Certificates Are Expiring — Here's What You Need to Do

If you've noticed a yellow or red warning next to "Secure Boot" in the Windows Security app recently, it's not a false alarm and it's not malware — it's part of a genuine, long-planned certificate changeover that every major PC manufacturer has spent the last few months preparing customers for.

Here's what's actually happening, why it matters, and — because a small number of BIOS updates tied to this rollout have caused real problems — what to check before you let your PC update itself.

⏸️

Update — 12 July 2026: Microsoft has temporarily paused the Secure Boot certificate update on some PCs. If Windows Security now shows a message saying certificate updates are paused because of a known issue, don't try to force the update and don't turn Secure Boot off. In Microsoft's words: "Secure Boot certificate updates are temporarily paused while Microsoft and partners work toward a supported resolution." Affected devices need a firmware update from their manufacturer, which will arrive through the maker's standard update channel. Your PC keeps starting normally and receiving regular Windows updates in the meantime — it just can't apply the newest boot-level protections until the fix lands.

🛡️

What's actually happening

Secure Boot is a UEFI firmware feature that runs before Windows even loads. It checks that your PC is only booting software that hasn't been tampered with. That system has been backed by Microsoft certificates issued back in 2011 — and those certificates are now expiring, in three stages:

  • 🔐 Microsoft Corporation KEK CA 2011 — expired 24 June 2026
  • 🔐 Microsoft UEFI CA 2011 — expired 27 June 2026
  • 🔐 Microsoft Windows Production PCA 2011 — set to expire 19 October 2026

Microsoft has been rolling out replacement 2023 certificates via Windows Update since earlier this year, and pushed the certificates to all remaining eligible devices in June 2026 ahead of the deadline. For most regular users, this has already happened automatically and nothing further is needed. The process also depends on each manufacturer shipping a compatible BIOS/firmware update for older hardware, though — which is where things get more involved for some PCs.

🔍

How to check your PC's status

Open the Windows Security app, go to Device Security, and look for the Secure Boot section:

✅ Green checkmark

You're fully updated, no action needed.

🟡 Yellow warning

Update pending — Windows Update hasn't reached your hardware yet, your manufacturer needs to release a BIOS update first, or (as of July 2026) Microsoft has temporarily paused the update for your device because of a known issue.

🔴 Red icon

A specific firmware incompatibility that needs attention.

⚪ Section missing

Secure Boot may be disabled, or the PC is on unsupported/bypassed hardware.

Windows 10 users aren't left out either — May 2026's KB5087544 update added the same green/yellow/red status reporting to Windows 10's Security app.

💻

What each manufacturer is telling customers

ASUS

Most users update automatically; manual PowerShell/registry steps published for stragglers, plus a model list for commercial PCs shipping with 2023 certificates pre-installed.

Dell

Devices with End of Service Life before 1 Jan 2026 won't get a BIOS update. New platforms since late 2024 ship with both 2011 and 2023 certificates.

HP ⚠️

Consumer PCs update via Windows Update; commercial PCs need a specific minimum BIOS version. HP's own early-2026 BIOS updates caused BitLocker recovery loops on some premium commercial models — corrected versions now available.

Lenovo

Detailed BIOS download guide by product family (ThinkPad, IdeaPad, Legion, Yoga etc.), with direct links per model.

Acer

Automatic via Windows Update for supported models; some older models (circa 2020–2022) are reportedly stuck with no BIOS update currently available.

MSI

Older Intel/AMD platforms update via Windows Update only; newer 12th-gen-and-up platforms need a BIOS flash from MSI.

Samsung / LG / Surface

Each has published dedicated guidance; Surface devices update via the standard Microsoft firmware pipeline.

💡

Worth knowing before you touch anything: HP has publicly acknowledged that some of its own early-2026 BIOS updates for premium commercial laptops triggered BitLocker recovery loops and boot failures. HP has since issued corrected BIOS versions, but if you have an HP business laptop, it's worth confirming you're on the corrected firmware before installing anything further — and backing up your BitLocker recovery key regardless of brand.

🛠️

What to do before you update anything

  1. Check your Secure Boot status first in Windows Security > Device Security, so you know whether you actually need to do anything.
  2. Back up your BitLocker recovery key before installing any manufacturer BIOS update — several OEM guides (Acer and MSI included) now recommend this as step one, precisely because a BIOS update can occasionally trigger a BitLocker recovery prompt on the next restart.
  3. Find your specific model's guide on your manufacturer's support site rather than applying a generic fix — the correct BIOS version and update path differs by model and even by manufacturing year.
  4. If your device shows End of Service Life and isn't getting a BIOS update, it can generally keep running normally — you'll simply stop receiving future boot-level security patches on that specific certificate chain, which is worth factoring into your next upgrade decision.
🤝

When it's worth getting help

Most home users won't need to do anything beyond checking the Windows Security app. It's more likely to be worth a professional look if you're managing several business laptops running BitLocker, an older device has no manufacturer BIOS update available, or a PC lands on a BitLocker recovery screen or boot failure straight after a firmware update.

We're fielding a steady stream of these questions from customers around Carrum Downs, Frankston, Cranbourne, Lyndhurst, Langwarrin, Seaford, Skye and Patterson Lakes this month — mostly small businesses running older HP and Dell fleets. If that's you, we're happy to check it: book a diagnostic or call (03) 8759 1801.

A $50 diagnostic fee applies to hardware-related diagnosis (waived if you proceed with the repair).

Frequently asked questions

Do I need to do anything right now?

Most users don't — Microsoft pushed the 2023 certificates to all eligible devices via Windows Update in June 2026. Check Windows Security > Device Security for a green checkmark to confirm.

What does a yellow or red warning mean?

Yellow means the update hasn't reached your device yet, often because your manufacturer needs to release a BIOS update first. Red indicates a specific firmware incompatibility that needs manual attention.

Will this update wipe my files or break my PC?

No, the certificate update itself doesn't touch your files. The risk is narrower and specific: a small number of manufacturer BIOS updates tied to this rollout (notably some early-2026 HP updates) have triggered BitLocker recovery prompts. Having your recovery key on hand avoids any drama if that happens.

My old PC shows "Secure Boot unavailable" — is that a problem?

It usually means Secure Boot is disabled or the device is on unsupported/bypassed hardware. It's not an emergency, but it does mean the device won't benefit from ongoing boot-level security improvements.

Where can I find my manufacturer's specific guide?

Check your PC brand's official support site directly — ASUS, Dell, HP, Lenovo, Acer, MSI, Samsung and LG have each published a dedicated Secure Boot certificate page with model-specific instructions (see sources below).

📚

Sources

Macrotech Solutions is an independent computer and Apple repair centre. We are not affiliated with, endorsed by, or sponsored by Microsoft, HP, Dell, Lenovo, ASUS, Acer, MSI, Samsung, LG, or any other manufacturer named in this article. All trademarks belong to their respective owners.

Leave a comment

All blog comments are checked prior to publishing
You have successfully subscribed!
This email has been registered