Skip to content
UEFICA2023StatusSecure Boot certificate update statusExplainerRarely reported

UEFICA2023Status: what NotStarted, InProgress and Updated mean for Secure Boot

By Gaurav Rawat · Updated Oct 2, 2026 · Checked against Microsoft documentation · How this page is made

Quick answer

UEFICA2023Status is a registry value that shows how far Windows has got in replacing the Secure Boot certificates that Microsoft issued in 2011, which began expiring in June 2026. "Updated" means you're done. "InProgress" usually just needs a restart or two. If it stays stuck for days, the fix is almost always a firmware (BIOS/UEFI) update from your PC maker.

What it means

Secure Boot is the part of your PC's firmware that checks the boot loader is genuine before Windows starts. It does that with certificates, and the ones Microsoft put on most PCs back in 2011 began expiring in June 2026. Windows is replacing them with a new 2023 set (you'll see names like Windows UEFI CA 2023), and it does this automatically through Windows Update.

Your PC still boots if the old certificates expire. What you lose is the ability to receive future security fixes for the boot process itself, which is exactly the area attackers target with bootkits.

Where the value lives

Windows records progress in the registry under:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing

The UEFICA2023Status value there reads one of three things:

  • NotStarted – Windows hasn't begun the update on this PC yet.
  • InProgress – the update is under way. A scheduled task called Secure-Boot-Update (under \Microsoft\Windows\PI\) runs at startup and every 12 hours, and parts of the change only complete after a restart.
  • Updated – the new certificates are in place. Nothing else to do.

Why some PCs get stuck

Windows writes the new certificates into the firmware, and the firmware has to accept them. On some older or less-maintained models it doesn't, so the status sits at InProgress and the System event log keeps showing Secure Boot events. That's not something Windows can fix on its own; it needs a firmware update from the manufacturer.

Common causes

  • The update simply hasn't finished yet: it runs in stages and needs at least one restart.
  • Windows Update is paused or behind, so the servicing steps haven't been delivered.
  • The PC's firmware rejects or doesn't commit the new certificates, which needs a BIOS/UEFI update from the manufacturer.
  • The manufacturer hasn't supplied the authorisation Microsoft needs to update the key that signs the certificate list on that model.
  • Secure Boot has been turned off in the firmware settings.

How to fix it

Safest and most likely fixes first. Readers' answers to "Did this fix it?" reorder this list over time.

  1. Install every pending update and restart twice

    Start here if the status is NotStarted or InProgress. Most PCs finish on their own this way.

    1. Open Settings > Windows Update and select Check for updates.
    2. Install everything offered, including anything under Advanced options > Optional updates.
    3. Restart the PC, use it normally for a while, then restart it again later the same day.
    4. Check the UEFICA2023Status value again. It can take a day for the 12-hour task to run its next step.
    Did this fix it?
  2. Check the value yourself

    When you want to see the real status rather than guess.

    1. Press Win + R, type regedit and press Enter.
    2. Go to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing.
    3. Read UEFICA2023Status. Don't change it: the value is a report, and editing it doesn't do the update.
    Did this fix it?
  3. Update your PC's firmware (BIOS/UEFI)

    If the status has been stuck at InProgress for several days after restarts.

    1. Find your exact model: press Win + R, type msinfo32 and note System Manufacturer and System Model.
    2. Go to the manufacturer's support page for that model and look for a BIOS or UEFI firmware update that mentions Secure Boot or the 2023 certificates.
    3. Plug a laptop into power, then install the update using the manufacturer's instructions. Don't interrupt it.
    4. Restart, run Windows Update again, and restart once more.
    Did this fix it?
  4. Make sure Secure Boot is on

    If System Information shows Secure Boot State: Off.

    1. Press Win + R, type msinfo32 and check Secure Boot State.
    2. If it's Off, restart into your firmware settings (Settings > System > Recovery > Advanced startup > Restart now > Troubleshoot > Advanced options > UEFI Firmware Settings).
    3. Enable Secure Boot, save and exit. If Windows was installed in legacy BIOS mode, don't change this without help, because the PC may not boot.
    Did this fix it?

Is it just you?

7 Microsoft Q&A threads discuss this, 1 active in the last 30 days. Most recent activity:

Checked Oct 2, 2026. Refreshed automatically every few days.

Sources

Frequently asked questions

Will my PC stop booting when the old Secure Boot certificates expire?

No. It keeps booting. It just can't receive future security updates for the boot process until the new certificates are installed.

Should I edit UEFICA2023Status to say Updated?

No. The value only reports progress. Changing it doesn't install anything and can confuse the update task.

Does Windows 10 get the new Secure Boot certificates?

Fully updated Windows 10 version 22H2 PCs include the same servicing task, so the update reaches them through Windows Update too.

What if my manufacturer never releases a firmware update?

The PC keeps working on the old certificates but stops getting new boot-level protections. Keep Windows updated and check the manufacturer's site from time to time.

Written by

Gaurav Rawat

Gaurav Rawat is a full-stack developer from Jaipur with a B.Tech in Information Technology. At PC Decoder, he writes practical guides on Windows 11 updates, error codes, and fixes for apps that stop working after an update, with an emphasis on clear steps that actually solve the problem.

More from Gaurav Rawat