Secure Boot is a UEFI firmware feature that checks digital signatures before it lets startup software run. It can stop an untrusted boot loader, firmware driver or EFI application from taking control before Windows starts. It does not scan every file, replace antivirus software or prove that everything inside the operating system is safe.

That distinction matters in 2026 because Microsoft is replacing several Secure Boot certificates issued in 2011. The old certificates have begun expiring, and the Windows boot-loader certificate expires on October 19, 2026. A PC without the newer certificates will normally keep starting, but Microsoft says it may stop receiving new early-boot protections.

What Secure Boot checks

A modern PC starts in Unified Extensible Firmware Interface, or UEFI, firmware. Before passing control to Windows, that firmware checks the signature on each pre-boot component against trust data stored on the device.

Microsoft’s Secure Boot documentation names three important stores:

Store What it does
Platform Key, or PK Controls changes to the Secure Boot configuration
Key Enrollment Key database, or KEK Holds keys that may update the allow and revoke databases
Signature databases, db and dbx db identifies trusted signers or images; dbx blocks revoked ones

If an image hash appears in both db and dbx, the revoked list wins. The computer does not merely check whether a file has any signature. It checks whether the signer or image is trusted by this device and has not been revoked.

The chain continues after the firmware starts Windows Boot Manager. Windows then verifies later stages of the boot process and loads its early antimalware component. Secure Boot protects the handoff into that chain; it is not the whole chain by itself.

What happens when a check fails

The outcome depends on the component and the firmware. If the UEFI firmware does not trust an early component, it should refuse to execute it and use the manufacturer’s recovery path. A problem with Windows Boot Manager can lead to a backup copy or Windows Recovery Environment.

That is why changing a boot drive, installing another operating system or using older hardware can produce a Secure Boot error even when the software is legitimate. The signature may not be in the device’s allow database, or it may rely on a certificate the device no longer trusts.

Turning Secure Boot off can make the software start, but it also removes the signature check. A better first step is to identify the blocked component, update the PC firmware and operating system, and use a boot image signed for the device’s current trust database.

Secure Boot is not TPM

Secure Boot and the Trusted Platform Module work at different points.

Secure Boot is an enforcement rule in firmware: it decides whether pre-boot code may run. A Trusted Platform Module is a protected component that can hold keys and record measurements of the boot state. Windows features such as BitLocker can use those measurements when deciding whether to release an encryption key.

A PC can support one without using the other. Windows 11 requirements brought the two terms together, but enabling TPM does not automatically enable Secure Boot, and Secure Boot does not mean the drive is encrypted.

What Secure Boot does not protect

Secure Boot narrows one attack path. It does not prevent:

  • malware that runs after a trusted operating system has started;
  • stolen passwords, phishing or malicious browser extensions;
  • a signed component that later proves vulnerable, until its signature or hash is revoked;
  • physical changes made by someone who can enter firmware setup and alter the trust configuration;
  • data loss when the disk has no encryption or backups.

The most useful way to think about Secure Boot is as a gate at the beginning of startup. Other controls still have to protect the operating system, accounts, applications and data after that gate opens.

Why the 2011 certificates are changing

Windows devices have carried a common set of Microsoft Secure Boot certificates since Windows 8. Microsoft is replacing them with certificates issued in 2023.

According to Microsoft’s certificate-expiration guidance, the relevant dates are:

2011 certificate Expiration Replacement
Microsoft Corporation KEK CA 2011 June 24, 2026 Microsoft Corporation KEK 2K CA 2023
Microsoft UEFI CA 2011 June 27, 2026 Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023
Microsoft Windows Production PCA 2011 October 19, 2026 Windows UEFI CA 2023

The split between the new UEFI and option-ROM certificates lets an organization trust third-party option ROMs without automatically trusting third-party boot loaders.

Certificate expiry is not a switch that bricks the PC. Microsoft says an affected device continues to start, operate and install standard Windows updates. The problem is narrower and still important: without the new certificates, the device may not receive future updates to Windows Boot Manager, Secure Boot databases, revocation lists or mitigations for new boot-level vulnerabilities.

What a home user should do

Keep Windows Update and the PC manufacturer’s firmware updates current. Microsoft says it manages the certificate update on a significant portion of Windows devices, while some organizations and unusual configurations need their own deployment process.

On supported Windows builds, the Windows Security app can show Secure Boot certificate update status. If the device reports a problem, follow the PC maker’s instructions before changing keys in firmware. Export BitLocker recovery information first if the machine uses device encryption, because firmware changes can trigger a recovery-key prompt.

Do not delete the existing PK, KEK, db or dbx entries as a routine fix. Those stores define what the device trusts. Rebuilding them is an administrative recovery action, not ordinary maintenance.

How to check whether Secure Boot is enabled

In Windows, open System Information and look for Secure Boot State. A value of On means the running system started with Secure Boot enabled. Off means the feature is disabled. Unsupported usually means the machine is using legacy BIOS mode or does not expose the required UEFI support.

This check says whether the feature ran for the current boot. It does not by itself prove that the 2023 certificates are installed, which is why the certificate-specific Windows Security status and vendor guidance matter in 2026.