Microsoft is updating its Windows certificate framework, focusing on Secure Boot certificates and the expiration of certain Windows 11 Insider certificates. A new certificate update is crucial to prevent disruptions in applications and IT processes. Microsoft is phasing out outdated certificates and modernizing signing algorithms, with the Windows Production Public Certificate Authority (PCA) 2011 set to expire on October 19, 2026. It will be replaced by a new PCA, and stronger signing algorithms like RSA-3072 and SHA-384 will be adopted later this year. Applications relying on outdated technologies may fail due to these updates. IT administrators and application developers are advised to review software, adopt algorithm-agnostic approaches, test certificate changes, and check private trust stores for issues. The timeline includes the PCA expiration in 2026, a transition to stronger configurations later that year, and a default to post-quantum cryptography (PQC) in 2027, with ongoing updates as security needs evolve.