Managing Microsoft Windows Production PCA Certificate Expiration Before the October 2026 Deadline

A guide to the Windows Secure Boot certificate transition: what changes on October 19 and how to prepare your fleet.
Some of us are probably a little tired of hearing about the multiple Secure Boot certificate expirations this year. But if there’s one worth spending extra time on, it’s this last one. For those catching up, Microsoft is in the process of replacing the Secure Boot certificates that Windows devices have relied on for more than a decade. The final deadline for these updates arrives on October 19, 2026, when the Microsoft Windows Production PCA 2011 certificate expires. Devices that haven’t received the replacement certificates by then may not be able to receive future Secure Boot protections, making now a good time to understand where your fleet stands.
The real challenge, though, isn’t applying the update. It’s knowing which devices have already received the new certificates, and which still depend on the 2011 chain. This guide provides an overview of what’s changing, how to assess the readiness level of your estate, and how to prepare before the Windows Production PCA 2011 certificate expires.
What Is Expiring?
Secure Boot works by trusting a short list of certificates within UEFI firmware. Those certificates sign the code that runs before Windows loads, which is how a device confirms its bootloader hasn’t been tampered with. Microsoft issued the current set back in 2011, and they expire this year.
| Current certificate | Deadline | What it does | 2023 replacement |
| Microsoft Corporation KEK CA 2011 | Expired June 24, 2026 | Authorizes updates to the Secure Boot allow list (DB) and revocation list (DBX) | Microsoft Corporation KEK 2K CA 2023 |
| Microsoft UEFI CA 2011 | Expired June 27, 2026 | Signs third-party bootloaders and option ROMs, including the Linux shim | Microsoft UEFI CA 2023 and Option ROM UEFI CA 2023 |
| Microsoft Windows Production PCA 2011 | Expires October 19, 2026 | Signs the Windows bootloader itself | Windows UEFI CA 2023 |
For a device to keep trusting Windows after the cutover, the 2023 certificates need to be in its firmware before October 19th.
What Changes on October 19th?
October 19th is the Windows Production PCA 2011 deadline. This certificate signs the Windows bootloader. Once it lapses, Microsoft will sign boot components with the new Windows UEFI CA 2023 if installed.
A device without the 2023 certificates keeps running and can continue receiving standard Windows updates, but it may not be able to receive future Secure Boot protections that depend on the updated certificate chain. Over time, it can become less protected against newly discovered early-boot threats if future Secure Boot mitigations cannot be applied.
Microsoft has done a great job preparing teams to manage such threats in the past including CVE-2023-24932. By ensuring the Secure Boot certificates are updated across your fleet, your machines will be able to receive similar security updates if required.
Who Does Microsoft Cover Automatically?
Microsoft is rolling the 2023 certificates out to eligible devices through Windows Update, so many consumer and cloud-managed machines move over in the background without direct IT action. The exposure concentrates in fleets that manage their own updates, including:
- Older PC and server generations that are past service and won’t get the OEM firmware update that embeds the 2023 certificates.
- Air-gapped and offline machines that Windows Update can’t reach.
- Virtual machines, since each VM carries its own firmware certificate store and updating the host does nothing for the guests.
- Dual-boot Linux devices, where the shim must be re-signed against the 2023 certificate before the 2011 entry can go.
Why Visibility Is the Real Problem
Most vulnerability scanners and EDR tools don’t read UEFI variables. They can’t tell you which certificates sit in a device’s firmware, or whether its revocation list is current. So the basic question of which machines still hold the 2011 certificates, and which have taken the 2023 set can’t be answered by most tools.
Rather than push firmware and certificate changes blindly, using an endpoint monitoring or digital employee experience (DEX) tool can help you take a more focused approach. By understanding exactly which devices have yet to be updated, you can remove days of manual work and be confident that your entire fleet has been brought into compliance.
How Do You Prepare for October 19th?
Once you can see the fleet, the work is straightforward:
- Inventory certificate state across the fleet and confirm which devices already hold the 2023 set.
- Split the machines with a firmware update available from the end-of-life hardware that has none. EOL hardware then moves into a refresh cycle.
- Back up BitLocker recovery keys before touching Secure Boot on encrypted devices.
- Apply any required OEM firmware updates first, then the Windows certificate update.
- Reboot in a maintenance window and verify the 2023 certificates landed.
- Track the stragglers and keep the inventory current so a future BIOS reset doesn’t strand a machine that never took the certificates.
How SysTrack Helps
SysTrack, Lakeside’s digital employee experience engineering platform, reads Secure Boot certificate status from every endpoint and puts it in one view: which devices are compliant, which are mid-transition, and which are stuck. Our Secure Boot DEX Pack follows each machine through the full sequence, from BitLocker key backup to firmware commit to the final boot-manager update, so you watch progress instead of guessing at it.
A daily check gathers certificate status, and the remediation action backs up the BitLocker key, then triggers Microsoft’s own certificate update, in the supported order. No custom certificate operations are required and when a device stalls, the dashboard says why, whether that’s a missing update, a firmware issue, or an expired OEM certificate, so you act on the one machine instead of re-running a blanket script.
One enterprise IT team used it to clear hundreds of non-compliant machines with no manual, per-device work, then moved to the next batch without the hours hands-on remediation would have taken. The certificate update was always available from Microsoft. Knowing exactly where to apply it, and confirming it worked, is the hard part.
Getting Started
Every Windows device in your estate either has the 2023 certificates or it doesn’t, and right now most teams can’t say which is which. Get the view first. Once the fleet is visible, remediation is the easy part, and the machines that would otherwise fall behind future boot-level protections show up while there’s still time to fix them. Ready to see where your fleet stands before October 19th?
See where every device stands on Secure Boot.
Already a customer? The Secure Boot certificate transition guides walk through the DEX Pack setup step by step.
Subscribe to Lakeside Updates
Receive product updates, DEX news, and more



