Microsoft is rolling out new Secure Boot certificates to Windows devices to replace expiring 2011 certificates. The updates arrive via Windows Update starting this week (April) and target Windows 10 and 11 systems, according to Microsoft.
Microsoft said if Secure Boot, which ensures a computer boots using only software trusted by the manufacturer, is not updated users risk rootkit-based attacks or system boot failures, or Blue Screen of Death (BSoD), at system startup.
The 2011 UEFI CA certificates, which validate the bootloader’s integrity before the operating system loads, expire in 2026. If these certificates lapse without replacement, affected hardware will fail to boot or become vulnerable to bootkit malware.
In April 2026, the Windows Security app added a status indicator under “Device security” to track these updates. Users see a green, yellow, or red badge indicating their protection status. A green badge confirms the 2023 certificates are active. Yellow or red badges signal that the hardware requires manual intervention or a firmware update.
In May 2026, Microsoft will escalate these warnings to system-level alerts outside the security app. While managed IT environments have this feature disabled by default, administrators can enable it via group policy to oversee fleet-wide compliance.
This certificate rotation is a critical maintenance event for the global hardware ecosystem. Secure Boot serves as the root of trust for modern computing; failure to update these keys exposes the pre-boot environment to persistent rootkits that bypass traditional antivirus software.
Photo by Clint Patterson on Unsplash