Overview
Microsoft's three original Secure Boot certificate authorities (issued in 2011) are scheduled to expire in June 2026. Devices that have not received the replacement 2023 certificates will stop receiving Secure Boot security updates and become vulnerable to bootkits like BlackLotus (CVE-2023-24932).
Three new certificates are being rolled out via Windows Update:
- Windows UEFI CA 2023 — replaces Windows Production PCA 2011
- Microsoft UEFI CA 2023 — replaces UEFI CA 2011 (third-party drivers)
- Microsoft Corporation KEK 2K CA 2023 — replaces KEK CA 2011
This guide shows how to verify certificate status via msinfo32, PowerShell, and UEFI firmware to confirm your PC is protected before the deadline.



