Windows Secure Boot Certificates Face June 24 Expiration Deadline

Windows Secure Boot Certificate Expiration: What PC Owners Need to Know Before June 24

A major Secure Boot certificate change is approaching for Windows PCs, and while it will not suddenly stop your computer from turning on, it could affect your device’s ability to stay protected against future firmware-level threats.

Microsoft’s 2011-era Secure Boot certificates, which have helped protect Windows PCs during the startup process for more than a decade, begin expiring on June 24. These certificates are part of the security chain that verifies trusted software before Windows loads, helping block malicious bootkits and other low-level attacks.

For most modern Windows 11 users on supported systems, the transition should happen automatically through Windows Update. However, older PCs, unsupported Windows 10 devices, and machines without updated firmware may face a more complicated situation.

What is expiring?

Three major Secure Boot certificates from 2011 are reaching the end of their validity period:

Microsoft Corporation KEK CA 2011 expires on June 24

Microsoft UEFI CA 2011 expires on June 27

Microsoft Windows Production PCA 2011 expires on October 19

The October expiration is especially important because the Microsoft Windows Production PCA 2011 certificate is used to sign the Windows bootloader. That makes it a key part of long-term boot security and system integrity.

Microsoft began distributing replacement Secure Boot certificates from 2023 through Windows Update earlier this year. The rollout has continued with monthly updates, including the latest cumulative update package identified as KB5089549.

Will your PC stop working after June 24?

No, your Windows PC will not suddenly stop booting when the certificates expire.

Microsoft says affected devices should continue to start normally and will still receive regular Windows updates. Everyday tasks such as browsing, gaming, productivity work, and general system use should not be interrupted simply because the old certificates have expired.

The real concern is security.

If a device does not receive the newer 2023 Secure Boot certificates, it may no longer be able to receive future Secure Boot database updates, certificate revocation lists, or patches for newly discovered boot-level vulnerabilities. That means the PC could become more exposed to advanced attacks that target the startup process before Windows fully loads.

Boot-level malware is particularly dangerous because it can operate beneath the operating system, making it harder to detect and remove. Threats such as BlackLotus have already shown why keeping Secure Boot protections current is important.

How to check Secure Boot status on your Windows PC

You can check whether Secure Boot is enabled by opening Windows Security and going to Device Security. From there, look for the Secure Boot section.

Microsoft also provides guidance through support article KB5062710, which explains the certificate expiration and what users should do if the new certificates have not been applied.

For the best chance of receiving the updated certificates, make sure your system is fully updated:

Open Settings

Go to Windows Update

Check for updates

Install all available updates

Restart your PC if required

Check Windows Security again afterward

If your PC is fully updated but still does not show the expected Secure Boot certificate status, the issue may involve your device firmware rather than Windows itself.

Why some older PCs may not receive the update

Some devices need more than a Windows Update package. In certain cases, the replacement certificate chain must also be supported directly by the PC’s UEFI firmware. That means the device manufacturer may need to release a firmware or BIOS update.

This could be a problem for older desktops, laptops, and motherboards that are no longer supported by their manufacturers. If the hardware maker has stopped providing firmware updates, the system may remain tied to the old 2011 certificates even after Windows installs the latest updates.

Unsupported Windows 10 systems may also be affected. Devices running Windows 10 outside the Extended Security Updates program are not expected to receive the new certificates, leaving them without a supported path for future Secure Boot certificate updates.

What users should do now

If you are using a supported Windows 11 PC, the most important step is to keep Windows Update enabled and install the latest updates as they arrive.

If you are using an older Windows 10 machine or unsupported hardware, you should check whether your device manufacturer has issued a recent BIOS or UEFI firmware update. If no update is available, your PC may continue working but could lose access to future boot-level security protections.

The key takeaway is simple: June 24 is not a shutdown date, but it is an important security deadline. PCs without the newer Secure Boot certificates will still run, but they may become increasingly vulnerable to future firmware and bootloader attacks.

Keeping Windows updated, checking Secure Boot status, and installing the latest firmware from your device manufacturer are the best steps users can take before the certificate transition begins.