By Adam Conway
Publication Date: 2026-03-06 22:31:00
Every Secure Boot-enabled Windows PC you’ve used for the last decade has relied on the same set of cryptographic certificates to keep its boot process secure. Those certificates were issued by Microsoft back in 2011, and they’re the reason your computer can verify that the software loading before Windows starts is legitimate and hasn’t been tampered with. They’re baked into your motherboard’s firmware, and most people have never had a reason to think about them. That’s about to change.
On June 24, 2026, the first of these certificates expires, and if your PC isn’t updated in time, it won’t suddenly stop booting, and it’ll even still receive regular updates, but it will lose the ability to receive future security updates for some of the most sensitive parts of the Windows startup process. Microsoft has started rolling out replacements through Windows Update, but this isn’t a simple patch. It requires coordination between Microsoft, your PC’s manufacturer, and in some cases, you….



