Your Windows PC has a security deadline in June 2026 (Malwarebytes)
by Stefan Dasic | May 28, 2026
A Secure Boot certificate refresh is rolling out across supported Windows devices through Windows Update. In June 2026, the Secure Boot certificates that have shipped inside Windows since 2011 begin to expire, and Microsoft is replacing them with new 2023-dated certificates.
The good news: If you keep your PC updated, you probably wont need to do anything. The bad news: Some older devices may not transition cleanly. Your PC wont suddenly stop working, but over time it could miss important boot-level security protections without you realizing it.
Heres whats going on, why it matters, and how to check that your machine is on the right side of the deadline.
***
The trusted party part is the crucial bit. Trust is established through cryptographic certificates baked into your motherboard firmware. The current certificates were issued in 2011 and are now reaching expiration. Three specific certificates are involved:
Microsoft Corporation KEK CA 2011: expires June 24, 2026
Microsoft UEFI CA 2011: expires June 27, 2026
Microsoft Windows Production PCA 2011: expires October 19, 2026
Microsoft is replacing them with a 2023-dated set, including Windows UEFI CA 2023 and Microsoft Corporation KEK 2K CA 2023. According to Microsoft engineers speaking during a March 2026 AMA session, the new certificates are valid until 2038, and a separate post-quantum cryptography transition is planned for around 2030 for future hardware.
***
more: https://www.malwarebytes.com/blog/how-to/2026/05/your-windows-pc-has-a-security-deadline-in-june-2026?