A BIOS update replaces the firmware stored on the motherboard, the code that runs before any operating system exists. It arrives as a file from the manufacturer, and applying it rewrites the flash chip on the board.
The advice everybody repeats is that you should not do it unless something is broken, and that was written when the only reasons were bug fixes and the only outcome of a bad flash was a dead board.
Both halves have changed: firmware updates now carry fixes for vulnerabilities below the operating system, and the certificates Secure Boot depends on started expiring in June 2026.
- Rewrites the firmware on the motherboard flash chip
- The reasons used to be bugs and hardware support; now they include security
- Microsoft's 2011 Secure Boot certificates began expiring on 24 June 2026
- A failed flash can still kill a motherboard, and recovery paths are uneven
- On a managed fleet it is the layer patched least
On this page
The mechanismWhat a BIOS update actually is
The BIOS sits in a flash chip on the motherboard, and ROM in a modern computer is writable, which is the entire reason updates are possible. A BIOS update is a signed image the manufacturer publishes, and the update process erases and rewrites that chip.
Two things follow, and both matter more than they sound.
The first is that the BIOS image is specific to one motherboard or one system model. Not a chipset, not a family, not a close relative.
The manufacturer page for your exact model, matched to the exact revision printed on the motherboard, is the only correct source, and identifying the motherboard precisely is the first step of the process rather than a detail.
The second is that the write has to finish. Everything else about the risk follows from that single fact, which is why the whole procedure is built around not being interrupted.
Modern firmware is UEFI rather than the original BIOS, and everybody still says BIOS update rather than UEFI firmware update. The name lost its accuracy along with the name of the chip.
What changedWhy the old advice expired
The advice was: leave it alone unless you have a specific problem it fixes.
It was good advice for its era, for two reasons that no longer hold together. A BIOS update was nearly always a bug fix or support for a newer processor, so a working system gained nothing. And the flash process was fragile, done from a boot disk, with a real chance of ending the day with a dead motherboard.
Here is what changed.
The BIOS became a security surface. Code in the flash chip runs before the operating system, before any security software, and it survives reinstalling the operating system and replacing the drive.
A vulnerability there is worth more to an attacker than one almost anywhere else, and vendors now ship a BIOS update specifically to close them. Declining those is not neutral.
The update process got safer. Signed images are checked before they are accepted. Many desktop motherboards carry a second copy of the BIOS, or a flashback feature that writes from a USB stick with no processor or memory installed.
Updates arrive through Windows Update or through the fwupd utility on Linux rather than from a boot disk somebody made by hand.
And there is now a dated reason. Microsoft's Secure Boot certificates from 2011 have expiration dates. Per Microsoft's own documentation:
| Certificate | Expires | Replaced by |
|---|---|---|
| Microsoft Corporation KEK CA 2011 | 24 June 2026 | Microsoft Corporation KEK 2K CA 2023 |
| Microsoft UEFI CA 2011 | 27 June 2026 | Microsoft UEFI CA 2023 |
| Microsoft UEFI CA 2011 | 27 June 2026 | Microsoft Option ROM UEFI CA 2023 |
| Microsoft Windows Production PCA 2011 | 19 October 2026 | Windows UEFI CA 2023 |
Be precise about what that means, because the internet is not. A device that does not get the new certificates keeps working. Microsoft states that such machines continue to start and operate normally and that standard Windows updates continue to install.
What they lose is future protection: no more updates to the Windows Boot Manager, the Secure Boot databases or the revocation lists, and no mitigations for boot level vulnerabilities discovered from now on.
That is not a brick. It is a machine quietly leaving the group that gets fixed, at the layer where a compromise is hardest to detect and hardest to remove.
Most devices receive the new certificates automatically, and many manufacturers ship a firmware update to make that go smoothly, which is the concrete reason a BIOS update sitting on a vendor page in 2026 is worth reading rather than ignoring.
The decisionWhen to do one, and when not to
| Situation | Update | Why |
|---|---|---|
| The release notes name a security fix | Yes | It runs below everything that would catch it |
| Your vendor recommends it for Secure Boot | Yes | It is the dated case above |
| Installing a newer CPU on an older motherboard | Yes, first | The system may not post at all otherwise |
| Memory instability the notes mention | Yes | Memory training lives in firmware |
| Everything works and the notes list nothing | No | The old advice still holds here |
| The notes say performance improvements | Rarely | Firmware is not where speed comes from |
| You cannot identify the exact motherboard | No | The wrong image is how motherboards actually die |
| Mid incident, to fix something unexplained | No | Adding a risky change to an open problem |
The fifth row is the one that survives from the old advice, and it is still correct. Nothing here says apply a BIOS update on a schedule for its own sake. It says read the release notes for the version on offer, which is a different instruction from the one everybody learned.
The procedureDoing it without killing the board
Get the file from the manufacturer, for the exact model. Not a driver site, not a forum mirror. Match the model and the motherboard revision.
Read the release notes, all of them. Vendors often say a BIOS update cannot be rolled back, or that one version must be applied before a later one, or that settings will reset.
Note your settings first. Boot order, virtualization, Secure Boot state, memory profile, fan curves. A BIOS update commonly returns them to defaults, and a system that will not boot afterward is usually a boot order that moved rather than a failed flash.
Use mains power. A laptop on battery is the classic interrupted flash, and a power cut mid write is the other one. Neither is recoverable on most hardware.
Prefer the built in updater. The utility inside the BIOS itself, or the vendor software for your operating system, or Windows Update where the manufacturer publishes there. All three are safer than a hand made boot disk.
Know your recovery path before you start. Many desktop motherboards have a second BIOS copy or a flashback port that writes from USB with no processor installed. Most laptops have neither, and recovery means a service center.
Do not interrupt the process. Not for a screen that appears to have frozen, not for a system that reboots twice by itself. A BIOS update looks alarming while it works.
PitfallsWhere people go wrong
Applying the wrong image. The single most common way a motherboard actually dies. The model number is not enough on boards with revisions.
Updating during an outage. Firmware is the last thing to change while something is already broken, because a failure adds a dead machine to an open incident.
Assuming a laptop has a recovery path. Desktop motherboard flashback features created a general belief in a safety net that most laptop hardware does not have.
Chasing performance. A BIOS update occasionally improves memory compatibility. It does not make a computer faster in any way a user notices.
Treating the 2026 certificate dates as a deadline to panic about. Nothing stops working. What stops is receiving new boot level protection, which is a slow problem rather than a loud one.
Leaving it out of the patch process entirely. The reason the old advice persisted is that it gave everybody permission to skip a whole layer. That layer is now where the interesting attacks are.
ComparisonMotherboard, drive and controller firmware, side by side
| Criterion | Motherboard firmware | Drive firmware | Network and management |
|---|---|---|---|
| Runs before the OS | Yes | No | Yes, on a management controller |
| Fixes security flaws | Yes | Sometimes | Yes, and often critically |
| Risk of a bad update | Board unbootable | Data loss | Card or controller offline |
| Recovery path | Dual BIOS or service | Rarely any | Vendor tooling |
| Usually patched | Almost never | Almost never | Almost never |
| Delivered by | Vendor tool, Windows Update, fwupd | Vendor utility | Vendor tool or the controller |
The fifth row is the finding. Estates that patch the operating system every month typically have never updated any of these three, on any machine, and the middle and right columns are as invisible as the left one.
FAQFrequently asked questions
What is a BIOS update?
A replacement for the firmware stored on the motherboard, published by the manufacturer of the motherboard or the computer. The update process rewrites the flash chip that holds the code running before the operating system starts.
Should I update my BIOS?
Read the release notes and decide from them. If they name a security fix, a Secure Boot change your vendor recommends, or support for hardware you are installing, yes. If they list nothing you need and the machine is fine, no.
Is a BIOS update dangerous?
Less than it was, and not zero. The failure that matters is an interrupted write, which can leave a system unable to start. Many desktop motherboards have a second copy of the BIOS or a flashback feature; most laptops do not.
Will a BIOS update make my computer faster?
Almost never. A BIOS update fixes bugs, closes vulnerabilities and adds hardware support. Performance improvements, where they appear at all, are usually memory compatibility rather than speed.
How do I update the BIOS on Windows 11?
Through the manufacturer software, through the update utility built into the BIOS itself, or through Windows Update where the manufacturer publishes firmware that way. Get the file from the vendor page for your exact system model.
How do I know which BIOS version I have?
System Information on Windows reports the BIOS version and its date, and the firmware setup screen shows the same version during boot. Compare it against the vendor page for your exact motherboard.
What is Secure Boot certificate expiration?
Microsoft's Secure Boot certificates issued in 2011 have expiry dates in 2026: the KEK CA on 24 June, the UEFI CA on 27 June and the Windows Production PCA on 19 October, each replaced by a 2023 certificate.
What happens if my device does not get the new certificates?
It keeps working. Microsoft says such devices continue to start and operate normally and keep receiving Windows updates. What they stop receiving is new boot level protection, including revocation list updates and mitigations for newly found vulnerabilities.
Do I need a firmware update for the Secure Boot change?
Most devices get the new certificates automatically. Many manufacturers publish a firmware update to avoid compatibility problems, and where a vendor recommends one it should be applied before the related Windows updates.
Can a BIOS update fix a computer that will not boot?
Occasionally, when the release notes describe exactly that fault with exactly that hardware. As a general remedy for an unexplained problem, a BIOS update adds risk instead of removing it.
What is BIOS Flashback?
A feature on many desktop motherboards that writes the BIOS from a USB stick with no processor, memory or drive installed. It is both the recovery path from a failed update and the way to update a motherboard too old to post with a new processor.
Does a BIOS update erase my data?
No. It rewrites the firmware chip, not the drive. It commonly resets BIOS settings to defaults, which is why the boot order is worth writing down first.
How often should firmware be updated on a managed fleet?
Often enough to track security releases, which in practice means reading vendor advisories rather than following a calendar. The realistic failure is not updating too often, it is that most estates have never done it at all.
Is a BIOS update the same as a UEFI firmware update?
Yes, in every practical sense. Modern firmware is UEFI and the habit of calling it the BIOS survived, so the two phrases describe the same file and the same update process.
How do I update the BIOS on Windows 10?
To update BIOS on Windows 10, identify the exact board or system model, download the firmware from the manufacturer, and run its updater or flash it from a USB stick in the firmware menu. A motherboard BIOS update should be done on mains power, and never interrupted. Many vendors also deliver firmware through Windows Update.
How do I update the BIOS on an ASUS motherboard?
Find the exact model on the board or in System Information, download the BIOS file for that model from the ASUS support site, copy it to a FAT32 USB stick, restart into the firmware menu and run the EZ Flash utility from there. To upgrade the BIOS safely, stay on mains power and do not interrupt it.
Keep readingRelated concepts
Read next · Firmware and boot What Is a BIOS? What the firmware being replaced actually does between the power button and the operating system, and where its settings live. Open this next12 min- Firmware and boot · 15 min How to Enable Secure Boot, and What to Check Before You Do The feature the expiring certificates belong to, and what to check before turning it on so the machine still starts.
- Firmware and boot · 9 min What Is ROM, and Why Read Only Is No Longer Accurate Why firmware is writable at all, which is the reason updates exist and the reason firmware integrity is a security question.
- Identification · 9 min What a Motherboard Chipset Is, and What It Decides About Your PC The silicon that sets port counts, PCIe lanes and which processors a board will accept.
- Cryptography · 10 min The BitLocker Recovery Key, and Why the Screen Appeared What set this off.
- Windows administration · 10 min How to Update Drivers in Windows 11 and 10, and When to Leave Them Alone Which driver updates are worth installing, and the four routes a driver can reach a Windows PC by.
- Firmware and boot · 10 min What Is Firmware, and Which Firmware a Business Has to Keep Updated What firmware is, which devices in an office run it, and how to update any of them safely.