Home
Services
Managed ServicesConsulting ServicesCo-Managed ITTechnical AssessmentImplementation ServicesWorkshops
Industries
LegalPrivate EquityFinancial ServicesNon-Profit
Resources
BlogIT BasicsResource LibraryPartners
Company
AboutMission & CultureFoundersPress & NewsHypershift.labs ↗ContactConsultation
← All postsInsights

Secure Boot June 2026 Readiness Checklist

The June 2026 Secure Boot certificate expiration represents a critical readiness milestone for organizations running Microsoft Windows endpoints, servers, and virtual machines. While Microsoft is distributing updated Secure Boot certificates through standard update channels, IT teams must address firmware readiness, reboot coordination, BitLocker recovery planning, and legacy device support to avoid operational disruptions.

11 Steps to Get Ready for Secure Boot Certification Expiration

1. Inventory Your Complete Device Estate

Before remediation begins, establish comprehensive visibility across your entire technology footprint. Standard asset reports often lack the specific details required for this transition.

Your inventory should capture:

  • Secure Boot enabled or disabled status
  • Current Secure Boot certificate state
  • Firmware vendor and version
  • Device model and generation
  • TPM status
  • BitLocker status
  • Windows update compliance
  • BIOS or UEFI mode
  • Device management enrollment type
  • Firmware update delivery method

2. Verify the New 2023 Certificates Are Present

The remediation goal involves ensuring devices obtain the updated Secure Boot trust chain before older 2011 certificates expire. Microsoft identifies expiring certificates as including the Microsoft Corporation KEK CA 2011, Microsoft Corporation UEFI CA 2011, and Microsoft Windows Production PCA 2011.

Validate whether applicable devices have these updated certificates:

  • Microsoft Corporation KEK 2K CA 2023
  • Microsoft UEFI CA 2023
  • Microsoft Option ROM UEFI CA 2023
  • Windows UEFI CA 2023

A critical gap: devices can receive the certificate update without rebooting, leaving them still dependent on the older trust chain while appearing compliant on dashboards.

3. Ensure Windows Updates Are Current and Not Blocked

Microsoft is rolling updated Secure Boot certificates through regular Windows update channels for supported endpoints. However, organizational policies and update deferrals frequently prevent these updates from reaching every device.

Review update controls across:

  • Microsoft Intune update rings
  • Windows Autopatch policies
  • Windows Update for Business settings
  • Group Policy update deferrals
  • SCCM or Microsoft Configuration Manager deployments
  • RMM patching tools
  • WSUS approvals

4. Coordinate OEM Firmware Updates with a Staged Ring Approach

Secure Boot intersects firmware, certificates, hardware drivers, and OEM implementation, requiring a controlled infrastructure change rather than routine patching.

Use this staged rollout model:

  • Ring 0: IT Lab Validation — Test representative devices across major manufacturers and configurations
  • Ring 1: IT Department and Low-Risk Pilot Users — Deploy to technically capable users who can report issues quickly
  • Ring 2: Standard Business Users — Expand to controlled groups across departments
  • Ring 3: High-Volume Production Rollout — Deploy broadly after validation
  • Ring 4: Sensitive and Specialized Systems — Handle executives, clinical systems, and regulated workloads with dedicated planning

5. Manage BitLocker Before It Manages Your Helpdesk

Secure Boot changes can trigger BitLocker recovery events. Organizations must prepare operational discipline and support procedures.

Before deployment, confirm:

  • BitLocker recovery keys are escrowed and accessible
  • Helpdesk has a documented recovery process
  • Users understand BitLocker recovery prompts
  • BitLocker suspension policy is defined and approved
  • Devices resume protection after updates

6. Assess Windows Server and Virtual Machine Exposure

A critical distinction: Windows Server does not automatically receive 2023 Secure Boot certificates through Windows Update like Windows 11 endpoints do. Server certificate updates require manual deployment.

Review:

  • Physical Windows servers
  • Hyper-V hosts and Generation 2 virtual machines
  • VMware-based Windows workloads
  • Azure VMs with Trusted Launch and Confidential configurations
  • Domain controllers and application servers

Note: Generation 1 Hyper-V VMs do not use UEFI firmware and are unaffected.

7. Refresh Golden Images, Autopilot Profiles, Build Processes, and Recovery Media

Outdated provisioning and recovery artifacts can reintroduce risk months after remediation. Recovery media created before 2023 certificate adoption may fail to boot on firmware updated to the new trust chain.

Update and validate:

  • Windows Autopilot deployment profiles
  • Golden images and task sequences
  • VM templates
  • WinPE recovery media
  • Bootable USB recovery sticks
  • Installation media used by helpdesk and field technicians

8. Identify Unsupported or Near-End-of-Life Hardware

This event creates forcing decisions about hardware lifecycle management. Older devices with unreliable firmware support may introduce more risk than value through remediation attempts.

Flag devices that are:

  • Out of warranty or no longer OEM-supported
  • Unable to receive firmware updates
  • Frequently offline or missing TPM
  • Better suited for replacement than remediation

9. Validate Compliance and Audit Requirements

For regulated organizations, this extends beyond IT maintenance into security governance, audit readiness, and cyber insurance posture.

Document:

  • Inventory scope and risk assessment
  • Remediation and exception handling procedures
  • Testing results and deployment rings
  • Change approvals and completion evidence
  • Deferred or unsupported systems
  • Executive sign-off

10. Prepare Communications Before the First Rollout

Technical success depends on coordinated communication with stakeholders, helpdesk teams, security leadership, and end users before deployment begins.

Prepare communications addressing:

  • Executive stakeholders and department leaders
  • Helpdesk escalation procedures
  • Remote employees and VIP users
  • Potential BitLocker recovery prompts
  • Reboot window impacts

11. Hotpatch Devices Need Special Handling

Windows Hotpatch reduces reboot frequency, but the 2023 Secure Boot certificate cannot fully activate without a reboot. Hotpatch devices may show update completion while remaining dependent on the older trust chain for weeks.

Build scheduled reboot orchestration alongside certificate rollout to ensure certificates actually activate across the fleet.


Organizations seeking detailed exposure assessment can request a free Secure Boot risk report identifying at-risk devices, missing certificate indicators, firmware exposure, update policy blockers, and recommended remediation priorities before the June 2026 deadline.