In a fresh development, this doesn't affect our editorial independence. When you purchase through links in our articles, we may earn a small commission.
Industry observers note that the June 24th “Secure Boot” patch, which was dropped just in time for the old-Secure-Boot-certificates-need-to-be-revised deadline, was supposed to roll out fresh certificates to remaining PCs that needed them. Yet, many computers still haven’t gotten their revised certificates yet. We’re now heading into August and the issue of revised Secure Boot certificates still hasn’t been resolved for all Windows users.
In a fresh development, a few weeks before that, Microsoft had given the all-clear, saying it wouldn’t be the end of the global stage if you don’t get revised Secure Boot certificates by the deadline, and that it’d still be possible to obtain them even afterwards.
As part of the ongoing story, according to the July 2026 patch notes, Microsoft says the rollout is still ongoing and will be for a while longer:. If you haven’t gotten yours yet, Microsoft wants you to keep calm and carry on.
Industry observers note that windows Secure Boot certificate expiration.
Industry observers note that microsoft has been updating these certificates on PCs and non-managed business devices for the past months. Devices that haven’t received the newer certificates will continue to start, and standard Windows updates will continue to install. We will continue to install the newer certificates via Windows updates in the coming months. Secure Boot certificates used by most Windows devices were set to expire starting in June 2026.
As part of the ongoing story, in short, Windows 10 and 11 PCs that haven’t gotten their revised Secure Boot certificates will still boot, still get Windows updates, and eventually get their Secure Boot certificates over the next few months.
According to the latest update, well, Secure Boot is an important security capability that protects your PC from malware attacks that can take hold during system startup. Secure Boot checks the digital signature of every piece of programs that’s loaded against a list of trusted signatures, and blocks anything that smells off. Why all the fuss about Secure Boot if everything’s still working per usual?
Industry observers note that at the same time, Microsoft maintains a blacklist of known bootloaders that are considered compromised, and the Windows Boot Manager can expand the backlist via DBX block updates.
In a fresh development, that’s why they must be replaced this year, else Secure Boot will cease to function. The problem is, on some computers, the certificates needed to run Secure Boot and receive these updates were outdated, first issued in 2011 with an expiry of 15 years.
As part of the ongoing story, microsoft says the outdated certificates will expire in three phases:.
In a fresh development, these newer certificates are from 2023, and we don’t know how long they’ll remain valid this time around. So, you still have until at least October to obtain the fresh certificates and continue using Secure Boot.
According to the latest update, a Windows 10 PC that isn’t registered (and therefore no longer receives updates) will not get revised Secure Boot certificates. Note: If you’re on Windows 10, you’ll continue to receive updates—including those for Secure Boot—only if you’re enrolled in the Extended Security Updates (ESU) program.
In a fresh development, you can find it under Settings → Windows Security → Device Security → Secure Boot. Back in April, Microsoft introduced a fresh indicator in Windows 11 that shows you the status of your PC’s Secure Boot certificates.
According to the latest update, much like a traffic light, the colors on the Secure Boot indicator signal whether action is required: Green means everything is fine, Yellow means Windows needs further information about your firmware before you can receive the certificates, and Red is a warning that an issue is blocking the patch and you may need, for example, a manufacturer BIOS patch.
In a fresh development, however, in some cases, you will need to take the initiative yourself to ensure your system gets them. Microsoft is working with various PC and laptop manufacturers to provide the necessary BIOS updates.
According to the latest update, dell, for example, doesn’t provide BIOS updates for systems whose support period expired before January 1st, 2026. HP excludes PCs from 2018 and earlier. The situation is similar at Lenovo. Note: There are some PCs that won’t receive any Secure Boot certificates at all.
In a fresh development, this article originally appeared on our sister publication PC-WELT and was translated and localized from German.
The report highlights that after studying communication science, she went straight into a job at PCMagazin and Connect Living. Since then, she has been writing about everything to do with PCs and technology topics, and has been a permanent editor at our German sister site PC-WELT since May 2024. Laura is an enthusiastic gamer as well as a movie and TV fan.