With the recent rollout of the September 2026 Patch Tuesday update, Microsoft has reiterated its commitment to the ongoing distribution of Secure Boot certificate updates. Despite the passing of initial certificate deadlines, the tech giant assures users that it will continue to release these updates, with the next significant deadline looming in October 2026.
In the release notes for Windows 11 KB5124008 (Build 26200.9445), Microsoft highlighted an expansion in the rollout of Secure Boot certificates, now extending eligibility to a broader range of PCs classified as “high confidence.” The update documentation states, “This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates.”
As users download the necessary Secure Boot updates, they may encounter a prompt for an additional reboot, typically coinciding with these monthly security updates. It’s important to note that some Secure Boot certificate updates necessitate a reboot for proper installation. Furthermore, certain PCs might require firmware updates prior to the successful application of the newer certificates, which could lead to yet another reboot.
In our observations, it appears that PCs may reboot multiple times during the Secure Boot process, even after updates have been applied. This behavior often arises from a pending firmware update that manufacturers may suddenly recall is necessary for the device.
Microsoft has clarified that the rollout of Secure Boot updates is far from complete and will persist over the coming months. This aligns with insights shared during an Ask Microsoft Anything session, where Windows experts confirmed that updates would continue beyond the established deadlines. “We will continue to install the newer certificates via Windows updates in the coming months,” Microsoft assured.
What is actually happening with Secure Boot in 2026?
Secure Boot is a critical requirement for Windows 11, utilizing certificates stored within the computer’s firmware (UEFI) to verify the trustworthiness of software involved in the boot process, well before Windows 11 initiates. This mechanism effectively blocks any untrusted boot-level software, such as malicious boot loaders, from executing before the operating system loads.
While the concept is commendable, the challenge lies in the industry’s lack of a robust solution for managing certificates that dictate software trust at the boot level. Certificates issued as far back as 2011, during the era of Windows 8, are now nearing expiration in 2026. However, it’s crucial to understand that there isn’t a singular expiration date for Secure Boot, prompting Microsoft to continue its updates.
For those unfamiliar, Microsoft’s older certificates expire in stages:
| Old certificate | Expiration | Explanation according to Microsoft |
|---|---|---|
| Microsoft Corporation KEK CA 2011 | June 24, 2026 | Signs updates to Secure Boot’s allowed and revoked databases (DB and DBX) |
| Microsoft UEFI CA 2011 | June 27, 2026 | Signs third-party boot loaders, EFI apps, and some option ROMs |
| Microsoft Windows Production PCA 2011 | October 19, 2026 | Used for signing the Windows boot loader |
Although the deadlines for the first two certificates have passed, the transition to Secure Boot is ongoing. The next significant date to watch is October 19, 2026, when the Microsoft Windows Production PCA 2011 certificate expires, a critical component for signing the Windows boot loader.
Here’s what you must do before the October Secure Boot deadline
For the majority of Windows 11 users, manual intervention is minimal. Microsoft is systematically rolling out new Secure Boot certificates through Windows Update, so it’s advisable to ensure the latest updates, including the September 2026 Update, are installed.
To verify if Secure Boot is updated, navigate to Windows Security > Device security > Secure Boot. The status should indicate, “Secure Boot is on and all required certificate updates have been applied. No further certificate changes are needed.”
If Windows indicates that an older boot trust configuration is still in use, it’s essential to keep Windows Update enabled and check for any firmware or BIOS updates from your PC manufacturer.
As we continue to monitor the developments surrounding Secure Boot certificates, it’s noteworthy that Microsoft significantly broadened the pool of devices eligible for automatic updates when the June 24 deadline arrived. Importantly, Microsoft has consistently communicated that June 24 was not a definitive endpoint for the rollout.
In fact, prior to the first deadline, Microsoft had already confirmed that there would be no abrupt cessation of the update mechanism. Both Microsoft and OEMs reiterated in July that compatible devices would retain their ability to transition to the 2023 certificates, irrespective of the expiration of older certificates.
Microsoft has reiterated that PCs lacking the newer certificates will continue to boot normally and receive standard Windows updates while the rollout of certificates persists. The September Windows 11 update further expands the targeting data utilized by Microsoft to determine which PCs can safely receive the certificates, with deployment expected to continue across supported PCs and non-managed business devices in the months ahead.