Microsoft Is Updating Secure Boot Requirements: 
What Windows IoT Device Manufacturers Need to Do
Microsoft has begun transitioning to a new generation of Secure Boot certificates. This change affects manufacturers of devices based on Windows IoT and requires an assessment of existing hardware platforms, firmware, and deployed device fleets.

The transition does not mean that existing devices will suddenly stop working. However, devices that continue to rely on the older 2011 Secure Boot certificates may eventually lose access to new boot-chain security protections, including updates to Windows Boot Manager and the Secure Boot DB and DBX databases used to block vulnerable or compromised components.

For new devices, Microsoft recommends using the 2023 Secure Boot certificates.

Recommended steps for device manufacturers

1. Inventory affected products
Identify all product models running Windows IoT. Record the Windows version, hardware platform, UEFI or BIOS version, Secure Boot configuration, and the certificates currently used.

2. Confirm support for the new certificates
Contact your hardware, motherboard, BIOS, or UEFI supplier to confirm support for the 2023 Secure Boot certificates and determine whether a firmware update is required.

3. Test the update process
Validate the new certificates, firmware, bootloader, recovery procedures, and application software on representative devices before deploying changes to production systems.
Testing should cover both new equipment and devices already installed at customer sites.

4. Prepare a deployment plan
Determine how UEFI firmware, Secure Boot components, and related Windows updates will be delivered to deployed devices.
For isolated systems, devices without centralized management, and equipment operating in protected customer networks, remote updates may be difficult or impossible. In these cases, an on-site service procedure may be required.

5. Check hardware-support timelines
Older device platforms may no longer receive BIOS or UEFI updates from their suppliers. Manufacturers should identify such products separately and assess whether continued support is technically and economically viable.

6. Evaluate the full lifecycle cost
For legacy devices, the cost of developing, testing, certifying, and deploying firmware updates may be significant. Manufacturers should compare this cost with alternative scenarios:
  • upgrading to a newer Windows IoT platform;
  • redesigning the next generation of the device;
  • migrating the product to another operating system.

A good time to review the platform strategy
The Secure Boot certificate transition is not an emergency shutdown event. However, it highlights the long-term dependencies associated with the Windows IoT platform, including firmware vendors, certificate infrastructure, hardware-support periods, and Microsoft lifecycle policies.

When planning new device generations, manufacturers should compare:
  • total platform cost over the device lifecycle;
  • availability of long-term security updates;
  • control over the boot and update infrastructure;
  • dependence on foreign licensing and certification systems;
  • information-security and localization requirements in target markets.

We recommend beginning the assessment before firmware or certificate updates become an urgent requirement. Early planning reduces technical risks, service costs, and disruption for customers.