Secure Boot Update: Is Your PC Protected by New Windows 11 Certificates?
A critical security update to Secure Boot certificates is rolling out for Windows PCs, impacting how your system verifies its integrity during startup. The update, designed to fortify the foundation of trust for modern computing, is already integrated into many newer machines and is becoming available via updates for older systems.
Microsoft is proactively renewing these essential certificates to ensure the continued security of the Windows ecosystem and to enable future innovations in hardware and software. This update is particularly important as the industry moves toward more robust security measures.
Checking Your Secure Boot Status
The first step in determining your PC’s status is to verify whether the new certificates are already embedded in your system’s firmware. According to Microsoft, even if you reset your Secure Boot settings to factory defaults, systems with the updated certificates will still boot operating systems that rely on them.
To check, users can open PowerShell or Terminal and execute the following command: ([System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI dbdefault).bytes) -match 'Windows UEFI CA 2023'). A return value of “true” indicates that your system’s BIOS is running with the updated certificates. Conversely, a “false” result suggests an older BIOS version that requires updating.
Timeline and Manufacturer Support
A senior official stated that “many newer PCs built since 2024, and almost all the devices shipped in 2025, already include the certificates.” This means a significant portion of the market will not require any action. However, PCs several years older may be eligible for the update through a BIOS update.
Major manufacturers are actively providing resources to help users determine compatibility and install the necessary updates. In the United States, Dell, HP, Lenovo, and Microsoft have published lists of supported systems and firmware versions. Asus is offering guidance on obtaining the new certificates through Windows Update, the MyAsus app, or its website. The oldest PCs currently listed as supported generally date back to 2019 or 2020.
It’s worth noting that even if your PC meets the requirements for upgrading to Windows 11, a BIOS update with the new certificates isn’t guaranteed.
Support and Resources
Microsoft encourages home users who encounter difficulties installing the new certificates to utilize its customer support services for assistance. Detailed documentation is also available for IT professionals and organizations managing large-scale updates.
“The Secure Boot certificate update marks a generational refresh of the trust foundation that modern PCs rely on at startup,” one analyst noted. “By renewing these certificates, the Windows ecosystem is ensuring that future innovations in hardware, firmware, and operating systems can continue to build on a secure, industry-aligned boot process.”
This proactive approach to security underscores Microsoft’s commitment to maintaining a robust and trustworthy computing environment for its users.
Related reading
