Event ID 1801: Secure Boot CA/keys need to be updated, explained
By Gaurav Rawat · Updated Oct 2, 2026 · Checked against Microsoft documentation · How this page is made
Quick answer
Event ID 1801 from TPM-WMI means Windows has noticed your PC's Secure Boot certificates still need replacing with the 2023 versions. It's a status message, not a fault. If it keeps coming back for days and you never see Event ID 1808 (update completed), install every update, restart, and check for a firmware update from your PC maker.
What it means
Microsoft's original Secure Boot certificates from 2011 began expiring in June 2026, and Windows is replacing them on every PC through Windows Update. Event ID 1801, logged by the TPM-WMI source in the System log, is Windows saying this PC hasn't finished that replacement yet.
On its own, one 1801 event is expected. Most PCs log it, then go through the update steps, then log Event ID 1808 when the new certificates are in place. After 1808 the 1801 messages stop.
When it's a problem
If 1801 keeps appearing for days and 1808 never shows up, the update isn't completing. The registry value UEFICA2023Status (under HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing) will usually be stuck on InProgress or NotStarted. The common reasons are pending Windows updates, a missing restart, or firmware that won't accept the new certificates until the manufacturer releases a BIOS/UEFI update.
Your PC keeps booting normally while this is unresolved. What it can't do is receive future security fixes for the boot process.
Common causes
- The certificate update hasn't run or finished yet, which is normal for a while after the update arrives.
- Windows Update is paused or has pending updates.
- The PC hasn't been restarted since the update steps ran.
- The firmware doesn't accept the new certificates and needs a manufacturer update.
How to fix it
Safest and most likely fixes first. Readers' answers to "Did this fix it?" reorder this list over time.
Update and restart
First step for any recurring 1801.
- Open Settings > Windows Update, select Check for updates and install everything offered.
- Restart the PC. Leave it on and connected for a few hours, then restart again.
- In Event Viewer, under Windows Logs > System, look for a newer Event ID 1808, which means the update completed.
Did this fix it?Check the update status
To see whether you're waiting or stuck.
- Press Win + R, type regedit and press Enter.
- Open HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing.
- Read UEFICA2023Status: Updated means you're done; InProgress for more than a few days means try the firmware fix.
Did this fix it?Install your manufacturer's firmware update
If 1801 keeps repeating and 1808 never appears after several restarts.
- Press Win + R, type msinfo32 and note the System Manufacturer and System Model.
- On the manufacturer's support site, find the latest BIOS/UEFI update for that model.
- Install it with the laptop plugged in, then restart and run Windows Update again.
Did this fix it?
Is it just you?
25+ Microsoft Q&A threads discuss this, 1 active in the last 30 days. Most recent activity:
- Dell Inspiron 5748 hard freezes after Windows 10 Updates - possible Secure-Boot-Update issueAug 30, 2026
- Kernel Security Check Failure Win 11Jul 22, 2026
- how to manually install the new secure boot certificates manuallyJun 8, 2026
- How can I verify that security certificates (Secure Boot / DBX) are fully updated?May 26, 2026
- UEFICA2023Status stuck at InProgress and Secure Boot DB update not applying (TPM-WMI 1796/1801)Apr 30, 2026
Checked Oct 2, 2026. Refreshed automatically every few days.
Sources
Frequently asked questions
Is Event ID 1801 an error I need to fix right away?
Not usually. It's a notice that the Secure Boot certificate update is still pending. It only needs attention if it keeps repeating for days without an Event ID 1808.
What's the difference between Event ID 1801 and 1808?
1801 means the Secure Boot certificates still need updating. 1808 means the update completed.
Should I turn off Secure Boot to stop Event ID 1801?
No. Turning Secure Boot off removes the protection the update is there to keep.

Gaurav Rawat is a full-stack developer from Jaipur with a B.Tech in Information Technology. At PC Decoder, he writes practical guides on Windows 11 updates, error codes, and fixes for apps that stop working after an update, with an emphasis on clear steps that actually solve the problem.
More from Gaurav Rawat