Windows Security Is Warning You About Secure Boot Certificates. In Most Cases There Is Nothing to Fix.
October 4, 2026
The web is full of guides to "fix" this message. Microsoft's own support page says most people have nothing to fix — and the two things people try first are the two things that can leave you with a computer that will not boot.
If you have opened Windows Security lately and clicked into Device security, you may have found a coloured badge sitting on Secure Boot and a sentence you have never seen before — something about your PC "using an older boot trust configuration that should be updated." Nothing you did caused it. No program broke. Your computer is almost certainly fine. It is a notice about a set of security certificates stored in your PC's firmware, and Microsoft only started showing it in the Windows Security app in April 2026, which is why it looks new and alarming.
Search the wording and you will find a wall of pages offering to help you "fix" it, which is where people go wrong. Microsoft's own support page for this message is unusually blunt about the common case: "In the majority of cases, no action is needed. The Secure Boot certificate update is delivered automatically through Windows Update to consumer PCs and some business devices. Make sure your device is connected to the internet and has the latest updates installed." That same page notes it "is intended primarily for Windows Pro and Home users" — so this is a home-computer notice, not an enterprise one you wandered into by mistake.
We are writing it up now because of a date, and because of two bits of folk wisdom that have quietly stopped being safe. The old certificates do not all expire together: there are four of them, on three different days, and the last one falls on October 19, 2026. The two moves people reach for to make the warning go away — switching Secure Boot off, and loading the firmware's defaults — are the two that can turn a working computer into one that will not start. One of them is advice we have given ourselves elsewhere on this site, and it now needs a caveat it did not need a year ago.
Where the message lives, and the exact words you might see
The path is Windows Security, then Device security, then Secure Boot. In Microsoft's words: "When you go to Windows Security > Device security > Secure Boot, a green, yellow, or red badge attached to the Secure Boot icon indicates your current Secure Boot status." The badge also bubbles up to the Device security tile on the "Security at a glance" home page, which is how most people meet it — they open the app for an unrelated reason and find something no longer green.
Microsoft describes three certificate states. "Fully updated" means "Your device has received all required Secure Boot certificate updates, and the updated Boot Manager has been installed. No action is needed." "Not yet updated" means "Your device is running with an older Secure Boot certificate. The Secure Boot certificate update is expected to be applied automatically through Windows Update. Make sure your device is connected to the internet and has the latest Windows updates installed." The third, "Requires action," is the red one, and it is narrower than it sounds — more on that below.
Underneath, the app shows one specific sentence, and knowing which one you have is the whole job. If it reads "Secure Boot is on and all required certificate updates have been applied. No further certificate changes are needed." you are done. If it reads "Secure Boot is on, but your device is using an older boot trust configuration that should be updated." Microsoft's instruction is simply "Make sure your device has the latest Windows updates installed. Restart if prompted." That is the message the vast majority of people are searching for, and the correct response to it is to install updates and get on with your day.
Three rarer variants are worth recognising. "Secure Boot is on, but your device is affected by a known issue. To reduce risk, Secure Boot certificate updates are temporarily paused while Microsoft and partners work toward a supported resolution." means Microsoft has deliberately held your machine back, and "No action is needed. The certificates update will resume automatically once the issue is resolved." A version ending "There is not yet enough data to classify your device for automatic update." means your PC "might need additional validation before the update can proceed automatically." And "Secure Boot is on, but your device does not support the automated Secure Boot certificate update due to hardware or firmware limitations." is the one that genuinely puts the ball in your court.
What is actually expiring: four certificates, and three of them already have
Secure Boot works on trust. As Microsoft puts it, these certificates "allow the firmware to verify that critical components—such as boot managers, option ROMs (firmware drivers), and other firmware-based software—are trusted and have not been tampered with," and "When older certificates expire, they can no longer be used to sign new components or updates." The scope is universal: "Since Windows introduced Secure Boot support, all Windows-based devices have carried the same set of Microsoft certificates in the KEK and DB." Those originals were issued in 2011, and they are now timing out and being replaced with 2023 versions.
The four dates, from Microsoft's own certificate table, are worth seeing laid out, because the headlines have tended to pick whichever one was closest. "Microsoft Corporation KEK CA 2011" expired on June 24, 2026. "Microsoft UEFI CA 2011" expired on June 27, 2026, and is being replaced by two separate certificates rather than one, so that, in Microsoft's example, a PC that needs to trust "option ROMs (firmware drivers)" can do so "without adding trust for third-party boot loaders." And "Microsoft Windows Production PCA 2011" expires on October 19, 2026 — that is the one Microsoft lists as "Used for signing the Windows boot loader," which is why it is the date that gets written about.
So if you are reading this in October 2026, three of the four have already gone, and the fourth is the important one. The reason the June dates passed without a wave of dead computers is the one Microsoft states directly: devices that miss the new certificates "will continue to start and operate normally, and standard Windows updates will continue to install." That is the correct expectation for October 19 as well, and it is worth saying plainly, because the shape of this story invites the opposite.
The green check is not proof — read the line underneath it
This is the detail we would most like people to take away, and it comes with a warning label on Microsoft's own page: "A green checkmark alone does not confirm your certificates are updated. Look also for the text: 'Secure Boot is on and all required certificate updates have been applied. No further certificate changes are needed.'" In other words, a green tick on Secure Boot can mean "Secure Boot is switched on and working" while the certificate changeover has not happened yet.
The system tray icon is even less specific. Microsoft explains that the little shield's badge "reflects the overall security status of your device" and that "It's calculated as the most severe state across all security features." A clean shield therefore tells you that nothing anywhere is shouting — not that your certificates are current. If you want to know where you stand, read the sentence, not the colour.
The red badge is narrower than it sounds
It would be reasonable to assume a red badge means "your certificate expired." It does not. Microsoft reserves the "Requires action" state for a specific situation: "A security update exists for the Windows boot experience that cannot be delivered to your device's current boot configuration. This state appears only after a security vulnerability that affects the boot process is discovered and cannot be serviced on devices that have not yet received the updated certificates."
Read that carefully and the red badge is a statement about the outside world, not about your hardware: somebody found a hole in the boot process, Microsoft wrote the fix, and your PC is in no state to be handed it. Microsoft adds that this "could occur as early as June 2026, when some of the current Secure Boot certificates begin to expire," and that when it happens "the Secure Boot badge changes to a red stop icon." The published guidance for that state is "Your device is still using an old certificate after the expiration dates. Visit aka.ms/getsecureboot for guidance."
What you actually lose if your PC never gets the new certificates
Here Microsoft is clearer than most of the coverage, and the honest answer is "less than you fear, but it gets worse slowly." On the plus side: "If your device reaches the expiration date without the new certificates, it will still start and operate normally. Standard Windows updates will continue to install." And explicitly, "Everyday app use, networking, browsing, and most OS features remain unchanged."
What stops is the deepest layer of patching. Such devices "will no longer be able to receive new security protections for the early boot process, including updates to Windows Boot Manager, Secure Boot databases, revocation lists, or mitigations for newly discovered boot level vulnerabilities." Microsoft frames the drift this way: "As new threats emerge, a device in this expired state becomes progressively less protected."
There is a second, more practical cost further down the road. Microsoft warns that falling behind "may also lead to compatibility issues, as newer operating systems, firmware, hardware or Secure Boot-dependent software may fail to load." Translated: this is the kind of thing that, two years from now, makes a Windows upgrade or a new graphics card refuse to cooperate for reasons nobody connects back to a certificate. It is not an emergency today. It is a good reason not to leave it indefinitely.
The two reflexes that make it worse
When a security screen turns yellow, people want the yellow gone. Both popular ways of achieving that are worse than the warning.
The first is switching Secure Boot off in the firmware, which does make the message disappear. Microsoft addresses it head on: "Secure Boot should not be disabled to work around certificate expiration. Disabling Secure Boot significantly reduces device protection, removes safeguards against boot-level malware, and can create new security and compliance risks." It also guarantees you never get fixed, because "Devices with Secure Boot disabled will not receive the new Secure Boot certificates in firmware. As a result, they will remain vulnerable to boot-level malware, such as bootkits, because Secure Boot protections are not enforced." You would be trading a notice about future protection for the immediate loss of present protection.
The second is the one we want to flag hardest, because it is standard troubleshooting advice that has quietly become conditional. Going into the BIOS/UEFI and choosing "Load Optimized Defaults" or "Load Setup Defaults" has been a safe, almost reflexive first move for fifteen years — we recommend it ourselves in our guide to a PC that cannot find its boot device. It is no longer unconditionally safe on a machine that has already moved to the new certificates. In Microsoft's words: "If Windows is already using the 2023-signed boot manager but the firmware is reset to defaults that don't include the Windows UEFI CA 2023 certificate, Secure Boot will block the boot process."
That is Secure Boot doing precisely its job — refusing to start a boot loader it no longer has a reason to trust — and it is not a five-second fix. Microsoft's own repair instruction is "you need to reapply the 2023 certificate to the firmware's DB using the recovery application. This is done by creating a recovery USB, then booting the affected device from that USB to restore the missing certificate." You need a second working computer and a USB stick to get back in. The sting is who this lands on: the people most likely to be poking around in firmware defaults are people already troubleshooting something, so the reset gets blamed on the original fault and the real cause goes unnoticed.
The practical rule for 2026 and beyond: do not load firmware defaults on a PC that boots fine, and if you are in there to change one setting, change that one setting. Microsoft also cautions against pre-emptive firmware fiddling generally — "The guidance is to not change or update the Secure Boot configuration unless the OEM has released an update to change the Firmware defaults to the new certificates."
When there really is something to do
One state is genuinely actionable, and it is the yellow one. "A yellow badge on Secure Boot means your device has an actionable issue, such as a hardware or firmware limitation that prevents the automated certificate update. Contact your device manufacturer for assistance." That is not a brush-off; it is the literal fix. Your PC's maker — Dell, HP, Lenovo, Asus, Acer, a motherboard brand on a desktop — has to publish a firmware/BIOS update before Windows can finish the job.
The catch is one Microsoft states but most coverage skips, and it matters for the older machines we see most: contact your maker about firmware "keeping in mind that such updates may only be available for devices that are still within their support period." A ten-year-old laptop may simply never get one. That is a real answer, and it is better to know it than to keep hunting.
If you have already sailed past an expiry date, you have not missed the boat. Microsoft is explicit: "The cumulative updates that contain the new Secure Boot certificates can still be applied even if the existing certificates have expired. If the device can boot Windows and install updates, the updated certificates can be written to firmware by following the published deployment guidance." Catching up late works.
Dismissing the warning, and why we would not
The app lets you silence it. There is a Dismiss button under the Secure Boot status message and, behind it, an "I accept the risks, don't remind me" option that requires administrator rights. Dismissing is cosmetic: "The Secure Boot icon badge reverts to the default state," "The status text in the app remains visible," and "App notifications are paused for this device until the status changes."
Microsoft's own recommendation on it is one line: "If your device has not yet received the updated certificates, dismissing the warnings is not recommended." The reason is the one from earlier in this article — "Devices with outdated Secure Boot certificates and boot loaders might be unable to receive future security updates that protect the Windows startup process." If you are waiting on a firmware update from a manufacturer, silencing the badge is reasonable. Silencing it instead of installing your Windows updates is not.
One more reason not to panic-click
A scary, official-looking security warning about certificates, attached to a looming deadline, is ideal raw material for a scam. Expect "your Secure Boot certificate has expired" pop-ups, search ads for paid "certificate repair" tools, and cold calls. None of it is necessary: the real update arrives through Windows Update at no cost, and the only legitimate place you need to visit is Microsoft's own aka.ms/getsecureboot page. Microsoft does not telephone people about their certificates, and nobody needs remote access to your machine to install a Windows update.
Bottom line
For almost everyone reading this, the entire job is: install your Windows updates, restart when asked, stay connected to the internet, and leave Secure Boot switched on. Then check Windows Security, Device security, Secure Boot — and read the sentence rather than the colour, because a green tick on its own does not mean the certificates landed.
If it says hardware or firmware limitations, go looking for a BIOS update from whoever made the machine, and accept that a very old PC may not get one. If it is red, start at aka.ms/getsecureboot. And whatever the colour, do not switch Secure Boot off to quiet it, and do not load firmware defaults on a computer that is currently booting perfectly well.
We service desktop and laptop computers across Southern California, and this is exactly the sort of thing we can settle in a few minutes — reading the real certificate state, finding out whether your model has a firmware update available, getting stalled Windows updates moving again, or recovering a machine that stopped booting after a firmware reset. If your PC is showing one of these messages and you would rather someone just looked at it, get in touch.
Keep reading
- This PC Can't Run Windows 11? How to Fix the TPM and Secure Boot Errors
- No Boot Device Found? "Reboot and Select Proper Boot Device" — What It Means and How to Fix It
- Windows Is Switching Memory Integrity On By Itself This Month. If an Old Driver Is in the Way, Here's What You'll See.
- Windows Update Stuck Downloading or Won't Install? How to Unstick It
- That "Microsoft Security Alert" Pop-Up With a Phone Number Is a Scam
Free calculators
Service areas we cover
We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.
Call (626) 655-0020