Secure Boot certificate warning in Windows Security
The Secure Boot certificates Microsoft issued in 2011 started expiring in June 2026 and are being replaced with 2023 ones. If Windows Security shows a yellow or red badge on Secure Boot, your PC has not received the replacements. It will still boot and run normally — what it loses is the ability to receive future boot-level security fixes. Install every Windows update, then your PC maker's firmware update. Do not turn Secure Boot off.
Start here
This warning worries people more than it should, and then not enough. Nothing is about to break: Microsoft is explicit that a device which passes the expiry date without the new certificates still starts and operates normally, and still installs Windows updates. What quietly stops is the delivery of new protections for the part of startup that runs before Windows does — the piece you cannot patch any other way.
Symptoms
- A yellow exclamation or red X badge on Secure Boot under Device security in Windows Security
- The Windows Security tray icon shows a warning that traces back to Secure Boot
- Text pointing you to aka.ms/getsecureboot
- A message that a security update cannot be delivered to your device's current boot configuration
- A message that a hardware or firmware limitation is preventing the update
Why this happens
The 2011 certificate authorities are expiring on fixed dates
Three of them matter to a home PC. Microsoft Corporation KEK CA 2011 expired on 24 June 2026, Microsoft UEFI CA 2011 on 27 June 2026, and Microsoft Windows Production PCA 2011 expires on 19 October 2026. Their replacements are the 2023 set: Microsoft Corporation KEK 2K CA 2023, Microsoft UEFI CA 2023, Windows UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023. This is a scheduled rotation, not a fault on your machine.
Read the badge in Windows Security to find out which state you are in · Install every pending Windows update, then restart
The update is delivered by Windows Update, and your device has not taken it yet
Microsoft delivers the new certificates through its own managed updates. A machine that has been offline, has paused updates, or has been sitting on a metered connection simply has not received them. This is the common case and the easy one.
Firmware on the machine is blocking the update
The certificates live in the UEFI firmware's variable storage, so the firmware has to accept the write. When it will not, Windows Security reports a hardware or firmware limitation, and Microsoft's guidance is to go to the manufacturer. A BIOS or UEFI update from your PC or motherboard maker is what unblocks it.
The boot configuration cannot take the update at all
The red X state is specifically that a security update for the Windows boot experience cannot be delivered to the device's current boot configuration. That is a different message from "not applied yet" and it is the one that warrants following Microsoft's own landing page for your exact hardware rather than guessing.
Read the badge in Windows Security to find out which state you are in · Install the firmware or BIOS update from your PC maker
Fixes
Read the badge in Windows Security to find out which state you are in
about 3 minThe three states mean genuinely different things and lead to different actions. Everything else here depends on knowing which one you have.
Applies to: Windows 11 24H2, Windows 11 25H2, Windows 10 22H2
- Open Windows Security, go to Device security, and look at the Secure Boot section.
- A green check means every required certificate update has already been applied. Nothing to do — close the page.
- A yellow exclamation means the device still has an older certificate, or hardware or firmware is preventing the update. Go to the Windows Update step next.
- A red X means a security update for the Windows boot experience cannot be delivered to your current boot configuration. Read the message text — it will point you at Microsoft's guidance page for your situation.
- Note that the Windows Security tray icon shows the most severe state across all security features, so a warning there is not necessarily about Secure Boot at all.
Confirmed by the vendor.
Source: Microsoft
Install every pending Windows update, then restart
about 30 minThe new certificates are delivered through Microsoft-managed updates. On most machines this is the entire fix.
Applies to: Windows 11 24H2, Windows 11 25H2, Windows 10 22H2
- Open Settings > Windows Update. If updates are paused, resume them.
- Select Check for updates and install everything offered, including optional quality updates.
- Restart when prompted, even if Windows does not insist — the certificate write happens across a reboot.
- Re-check Windows Security > Device security > Secure Boot. Allow a day or two and a couple of restarts before deciding it has not worked; delivery is staged.
Confirmed by the vendor.
Install the firmware or BIOS update from your PC maker
about 45 minWhen the block is in firmware, no Windows update can move it. Microsoft's own advice for that state is to go to the manufacturer.
Applies to: Windows 11 24H2, Windows 11 25H2, Windows 10 22H2
- Find your exact model. On a prebuilt or laptop that is the service tag or model number; on a self-built PC it is the motherboard model, which msinfo32 lists as BaseBoard Product.
- Go to the manufacturer's support page for that model and look for the newest BIOS or UEFI firmware release.
- Follow the manufacturer's own update procedure. Do not interrupt a firmware flash, and on a laptop keep it on mains power throughout.
- After the update, run Windows Update again and restart, then re-check the badge in Windows Security.
- If your BitLocker recovery key is needed after a firmware change, have it to hand before you start — it is in your Microsoft account under Devices.
Confirmed by the vendor.
Leave Secure Boot enabled
about 2 minTurning it off makes the warning go away without fixing anything, and Microsoft says specifically not to do it.
Applies to: Windows 11 24H2, Windows 11 25H2, Windows 10 22H2
- Do not disable Secure Boot to clear this warning. Microsoft states plainly that Secure Boot should not be disabled to work around certificate expiration.
- If you already turned it off for something else, turn it back on — several current games will not launch without it.
- Keep checking the badge after each month's updates. The certificate rollout is ongoing, and a device that cannot take it today may be able to after a firmware release.
Confirmed by the vendor.
Source: Microsoft
Known issues
Devices that do not receive the 2023 certificates keep working and keep installing Windows updates, but can no longer receive updates to Windows Boot Manager, the Secure Boot databases, revocation lists, or fixes for newly discovered boot-level vulnerabilities.
Affects Windows 11, Windows 10 22H2 · Status: workaround only
Some third-party components that depend on Microsoft Secure Boot trust may fail to update on a device left on the 2011 certificates.
Affects Windows 11, Windows 10 22H2 · Status: open
If none of this worked
If Windows Security is warning about Device security but the Secure Boot section itself shows a green check, the warning is about something else on that page — core isolation or the security processor are the usual candidates. If the PC will not boot at all after a firmware update, that is a firmware problem rather than a certificate one: clear CMOS and reapply the manufacturer's recovery procedure. And if you are chasing this because a game says Secure Boot is required, that is a different check entirely — the game is looking at whether Secure Boot is enabled, not at which certificates are in it.
Common questions
- Will my PC stop booting in June 2026?
- No. Microsoft is explicit that a device which reaches the expiration date without the new certificates still starts and operates normally, and still installs Windows updates. Apps, networking and browsing are unaffected. What you lose is future security fixes for the early boot environment.
- Which certificates are actually expiring?
- Microsoft Corporation KEK CA 2011 expired on 24 June 2026, Microsoft UEFI CA 2011 on 27 June 2026, and Microsoft Windows Production PCA 2011 expires on 19 October 2026. They are being replaced by the 2023 set: KEK 2K CA 2023, Microsoft UEFI CA 2023, Windows UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023.
- Can I install the certificates manually?
- For a home PC the answer is to let Windows Update do it and to install the manufacturer's firmware update if the firmware is the blocker. The manual routes exist but they are aimed at IT administrators managing fleets, and a mistake in the Secure Boot variables is the kind of mistake that needs a firmware recovery to undo.
- Windows Security says a hardware limitation is preventing the update. What now?
- That message means the firmware will not accept the new certificates as it stands, and Microsoft's own guidance for it is to contact the device manufacturer. In practice that means checking for a BIOS or UEFI update for your exact model. If the manufacturer has not shipped one, the machine stays on the 2011 certificates until they do.
- Should I just turn Secure Boot off to stop the warning?
- No. Microsoft states that Secure Boot should not be disabled to work around certificate expiration, and disabling it removes protection against boot-level threats entirely rather than restoring anything. It will also stop several current games from launching, since their anti-cheat requires Secure Boot to be on.
Did this fix work?
If a step is wrong, outdated, or did not help, telling us is the fastest way to get it corrected. Reports are reviewed before new articles.
Report a problem with this pageRelated problems
- Do PC games require Secure Boot on Windows 11?
- Windows Update Stuck Downloading or Failing to Install
- Game stutter and Memory integrity on Windows 11
- Smart App Control is blocking a game, launcher or mod
- USB controller, headset or mouse keeps disconnecting on Windows 11
- G-Sync or FreeSync not working in borderless windowed mode
Sources
Microsoft · Support page · checked Aug 22, 2026
- Microsoft Corporation KEK CA 2011 expires on 24 June 2026
- Microsoft UEFI CA 2011 expires on 27 June 2026
- Microsoft Windows Production PCA 2011 expires on 19 October 2026
- The replacements are Microsoft Corporation KEK 2K CA 2023, Microsoft UEFI CA 2023, Windows UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023
- Devices without the 2023 certificates keep starting and operating normally and keep installing standard Windows updates
- Devices without the 2023 certificates can no longer receive updates to Windows Boot Manager, the Secure Boot databases, revocation lists, or fixes for newly found boot-level vulnerabilities
Microsoft · Support page · checked Aug 22, 2026
- Microsoft states a device that reaches the expiration date without the new certificates will still start and operate normally
- Normal startup, Windows updates, apps, networking and browsing continue to work
- New Secure Boot and Boot Manager protections cannot be applied, and vulnerability fixes for the early boot environment will not be available
- Some third-party components that rely on Microsoft Secure Boot trust may fail to update
- Microsoft says the new certificates arrive through Microsoft-managed updates and advises contacting the OEM about firmware updates
- Microsoft states that Secure Boot should not be disabled to work around certificate expiration
Microsoft · Support page · checked Aug 22, 2026
- Windows Security shows the Secure Boot certificate state as a coloured badge on the Secure Boot section of Device security
- A green check means every required certificate update has been applied and no action is needed
- A yellow exclamation means the device still has an older certificate, or hardware or firmware is preventing the automatic update
- A red X means a security update for the Windows boot experience cannot be delivered to the device's current boot configuration
- Microsoft's guidance for the yellow state is to install the latest Windows updates and contact the manufacturer if the limitation is in hardware
- The Windows Security tray icon reflects the most severe state across all security features