Microsoft has been updating Secure Boot certificates that were originally issued in 2011, since those older certificates begin expiring in June 2026. The "Microsoft Corporation KEK CA 2011" certificate expired on June 24, 2026, "Microsoft UEFI CA 2011" expired on June 27th, and "Microsoft Windows Production PCA 2011" is the last to go, expiring October 19, 2026. Most devices are meant to get the newer 2023 certificates automatically, and many OEMs provide firmware updates when needed — but on some machines (especially 2020-era laptops with older firmware), that update either didn't land properly or the firmware couldn't accept it, which is very likely what caused your boot failure.
Ref:
Windows Secure Boot certificate expiration and CA updates
- Check Windows Security → Device Security → Secure Boot for a green/yellow/red badge.
- Visit Microsoft's Surface Secure Boot Certificates support page to see if your exact model is eligible for updates.
- Only Surface devices from 2024+ have the new certificates built in — older models get them via Windows Update, if still supported.
- Manual update (if your model qualifies):
- Hold Volume-Up + Power → boot into UEFI
- Go to Security → Secure Boot → Change Configuration