Drooid Logo
Back to story perspectives

Full Breakdown

Secure Boot Certificate Expiration in June 2026 Prompts Action for Windows PCs

5/3/2026, 11:38:43 AM

Secure Boot Certificate Expiration in June 2026

Secure Boot, introduced with Windows 10 in 2011, verifies that only trusted firmware and bootloaders run during system start-up. It relies on a chain of UEFI certificates; the “UEFI CA 2023” certificates were released in 2023. Microsoft now confirms that the original certificates will cease to be valid in June 2026, meaning any PC that does not receive the updated chain will lose a core layer of boot-time protection.

Affected Devices and Scale of Impact

Most modern PCs running Windows 11 will obtain the new certificates automatically through Windows Update. Windows 10 machines enrolled in Microsoft’s Extended Security Update (ESU) program will also receive the updates via the same channel. Devices running unsupported Windows versions—including Windows 10 without ESU—will not receive the new certificates, leaving them without Secure Boot protection. Analysts estimate roughly 400 million PCs are locked out of Windows 11 because they fail the hardware requirements. Mainstream Windows 10 support ended in October 2025, and the ESU enrollment window stays open until 14 October 2026.

Official Guidance and Recommended User Actions

Microsoft states that devices running unsupported Windows versions will not receive the updated certificates and urges customers to use a supported OS. The company confirms that most Windows 11 PCs will receive the certificates through Windows Update. OEMs such as Dell are working with Microsoft to provide firmware updates for older models that require manual intervention. Users can run a PowerShell command that returns “True” if the UEFI CA 2023 certificate is present and “False” otherwise. When the result is “False,” Microsoft advises checking for pending Windows Updates, locating an OEM firmware update, or enrolling in the ESU program before the 14 October 2026 cutoff.

Criticism and Security Concerns

Security analysts warn that PCs lacking the updated certificates will suffer degraded protection and may encounter driver or software failures over time. The situation also raises e-waste concerns, as hundreds of millions of older machines could become insecure without affordable OEM support. Limited firmware updates for hardware older than a decade leave a substantial user base exposed to potential attacks.

Verbatim Quotes

  • “Here's the official statement from Microsoft: It’s important to note that devices running unsupported versions (Windows 10 and older, excluding those who have enrolled in Extended Security Updates) do not receive Windows updates and will not receive the new certificates.” — Microsoft
  • “The company officially says that most modern PCs running Windows 11 will automatically receive the new certificates through Windows Update, just like you'd normally update your system.” — Windows Central
  • “If it reads False, your PC is still using the old Secure Boot certificates set to expire in June.” — Windows Central