Your Windows 11 PC has a set of security keys baked into it, and the original ones start expiring this month. Ignore that and your computer keeps working fine, but it quietly stops getting one specific kind of malware protection. Nothing crashes. No blue screen.
The keys are part of Secure Boot, the feature that checks the startup code your PC loads before Windows runs and refuses to load anything not signed by a trusted source. Microsoft issued the original batch back in 2011. Those certificates were never meant to last forever, and now they are hitting their expiration dates on a staggered schedule through 2026.
What actually expires, and when
Microsoft has not bundled this into one deadline, so the "June 2026" headline is only half the story. The Microsoft Corporation KEK CA 2011 expires June 24, 2026. The Microsoft UEFI CA 2011, which covers third-party boot loaders and option ROMs (small startup programs on hardware like graphics cards), expires June 27, 2026. The Windows Production PCA 2011 hangs on until October 19, 2026.
To replace them, a fresh set of 2023 certificates gets written into your motherboard's firmware (the chip-level software that runs before Windows loads), pushed out through Windows updates on most machines, though some rely on a firmware update from the PC maker. Some people spotted a new "Secure Boot" folder in Windows 11 lately. It is not a bug, according to Windows Latest, but part of this very update.
Microsoft Support Windows Secure Boot Certificate Expiration CA
What you lose if you skip it
A PC that never gets the 2023 certificates "will continue to start and operate normally," Microsoft says, "and standard Windows updates will continue to install." Your machine does not turn into a brick, and it keeps getting regular patches. Anyone telling you it stops booting is wrong.
The catch is what quietly stops updating. Microsoft says such a device "will no longer be able to receive new security protections for the early boot process," including updates to the boot manager and the Secure Boot databases and their revocation lists.
The risk is malware like BlackLotus, uncovered in 2023, which could load before Windows and bury itself in the boot chain, where normal cleanup does not reach. Security firm ESET confirmed it was real. It got in by abusing a Secure Boot bypass tracked as CVE-2022-21894, and Microsoft has spent the years since chipping away at that whole class of attack with boot-manager revocations, the effort filed under CVE-2023-24932. Freeze the revocation updates, and tomorrow's boot-level attacks have an easier time.
One more wrinkle. The update only reaches PCs that have Secure Boot switched on. Older machines running Legacy BIOS, or anyone who turned Secure Boot off, get left out entirely, per reporting from Windows Latest. You can see where your machine stands in the Windows Security app, under Device Security, which shows the certificate status and may nudge you if something needs doing.
Microsoft Support Secure Boot Certificate Status Windows Security, Windows Latest
You don't need to panic today
This is not a same-day emergency for most people. Some machines already have the new keys. Others get them over the coming months as updates arrive.
The smart move is simple. Keep Windows updates on. Leave Secure Boot enabled. Glance at Device Security once in a while. Your real risk is not a dead PC, it is a slow drift where your machine stops learning about new boot-level threats and you never think to check, because day to day it runs completely fine.
Microsoft Support Windows Secure Boot Certificate Expiration CA




