Microsoft is refreshing Secure Boot certificates to plug security holes before they happen — if you bought a PC last year, you should be set

2 days ago 5
Windows 11
(Image credit: Microsoft)

Microsoft is issuing new Secure Boot certificates to Windows PC users, as the initial certificates are reaching the end of a planned lifespan after 15 years and are set to expire in June 2026.

The company has been issuing new certificates as part of Windows updates for personal users, businesses, and schools that let Microsoft manage their updates.

Secure Boot is a process that runs at startup, prior to Windows loading, and uses cryptographic keys to verify that only trusted software can run. In

a blog post

, Nuno Costa, the partner director for Windows servicing and delivery, writes that "Retiring old certificates and introducing new ones is a standard industry practice that helps prevent aging credentials from becoming a weak point and keeps platforms aligned with modern security expectations."

But if you bought a PC in 2025, you're probably already set. Costa writes that Microsoft has been working with OEM partners, which have been obtaining new certificates since 2024. Machines from OEMs starting from 2024 and "almost all" systems shipped in 2025 already have new Secure Boot certificates. So if you bought one of the

best ultrabooks

or

best gaming laptops

, you should be in the clear.

If your certificate expires, your PC should function as expected, though its security will be compromised.

"As new boot‑level vulnerabilities are discovered, affected systems become increasingly exposed because they can no longer install new mitigations," Costa writes. “Over time, this may also lead to compatibility issues, as newer operating systems, firmware, hardware, or Secure Boot–dependent software may fail to load."

Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.

Google Preferred Source

Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.

Andrew E. Freedman is a senior editor at Tom's Hardware focusing on laptops, desktops and gaming. He also keeps up with the latest news. A lover of all things gaming and tech, his previous work has shown up in Tom's Guide, Laptop Mag, Kotaku, PCMag and Complex, among others. Follow him on Threads @FreedmanAE and BlueSky @andrewfreedman.net. You can send him tips on Signal: andrewfreedman.01

Read Entire Article