| title | August 2026 Deployment Notice - Microsoft Trusted Root Program |
|---|---|
| description | This document provides details about the changes made in August 2026 to the root store. |
| ms.date | 8/25/2026 |
| ms.service | security |
| author | tahmad2 |
| ms.author | tahminaahmad |
| ms.topic | conceptual |
On Tuesday, August 25, 2026, Microsoft released an update to the Microsoft Trusted Root Certificate Program. The NotBefore date is set to September 15, 2026. This means only certificates issued after this date will be distrusted.
Please note that this release includes PQC Pilot roots; more information can be found under the announcements section: https://github.com/TrustedRootProgram/Program-Requirements/blob/main/Announcements.md
This release will add the following roots (CA \ Root Certificate \ SHA-256 Thumbprint):
- ComSign \ ComSign Dev Root PQ CA \ 01AD5BE684509B24E9AAA5F20B67CA9534C7BD6E442F21DC68FAF91A201719D3
- DigiCert \ DigiCert PQC TLS PILOT MLDSA87 Root CA \ 28999F984E12FE25EDFF2472ACB17CA195A1C5DCD64BEE6F14D5DFC82DFFEBE6
- HARICA \ HARICA TLS ML Root CA 2026 - Pilot \ 14872608F2B05FA79583F19057CBE95DA8153D6DF201DBF3E449FA5E9414AFC6
- IdenTrust Services, LLC \ IdenTrust Pilot Root TLS ML-DSA CA 1 \ F6041FB4B500F2927B98BBAD9C60DF84960ECD2DF88DCF967E7F1D2C80FD56CC
- Sectigo \ Sectigo Pilot Server Authentication Root M27 \ D8156E234404B1424568B89A353F33080A33850F7AD270B8D6842F48074BD2AF
- Shanghai Electronic Certification Authority Co., Ltd. \ UniTrust Global TLS MLDSA Root R1 TEST \ DC742564D508EDF06FCBE7F681A3324C54D13DF4E5C5A9C00681DC3643F763D8
- SSL.com \ SSL.com TLS ML Root CA 2026 - Pilot \ 9474F424AB3D8E892C1EAEDED7BAD828DB13C11A4377604ADF79967E2B27962D
- Visa \ Visa TLS Root CA \ E6432FCE6B48F4E889B2FE183F8B480F72ECF80F57389B0E9C6E89CF04AD69D1
This release will fully NotBefore the following roots (CA \ Root Certificate \ SHA-1 Thumbprint):
- Carillon Information Security Inc. \ Carillon PKI Services G2 Root CA 1 \ EB9237B72076F8CC8BC13E7046F2FCABC18199D3
- certSIGN \ certSIGN_root \ FAB7EE36972662FB2DB02AF6BF03FDE87C4B2F9B
- DigiCert \ Hotspot 2.0 Trust Root CA - 03 \ 51501FBFCE69189D609CFAF140C576755DCC1FDF
- Entrust \ AffirmTrust Premium ECC \ B8236B002F1D16865301556C11A437CAEBFFC3BB
- Entrust \ AffirmTrust Commercial \ F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7
- Entrust \ Entrust 4K TLS Root CA - 2022 \ 193C2A76F8CADD84F35BF52EE7AA506657917A38
- Entrust \ AffirmTrust Premium \ D8A6332CE0036FB185F6634F7D6A066526322827
- Entrust \ Entrust P384 EV TLS Root CA - 2022 \ 1E6C44DC6473D4819BE89FB237AF4883FC376987
- Entrust \ AffirmTrust 4K TLS Root CA - 2022 \ 2E03931CD19C3FF5985FB87AADC153EB5DBDF1E3
- Entrust \ AffirmTrust Networking \ 293621028B20ED02F566C532D1D6ED909F45002F
- Entrust \ Entrust P384 TLS Root CA - 2022 \ 424AAE6D0C8C7624817CDB9CCB510DED6232191D
- Entrust \ Entrust 4K EV TLS Root CA - 2022 \ EADB0AB9DC7938021435FED13E488406A1AA292A
- SecureTrust \ XRamp Global Certification Authority \ B80186D1EB9C86A54104CF3054F34C52B7E558C6
- SecureTrust \ SecureTrust CA \ 8782C6C304353BCFD29692D2593E7D44D934FF11
- SecureTrust \ Secure Global CA \ 3A44735AE581901F248661461E3B9CC45FF53A1B
- SecureTrust \ Trustwave Global Certification Authority \ 2F8F364FE1589744215987A52A9AD06995267FB5
- SecureTrust \ Trustwave Global ECC P256 Certification Authority \ B49082DD450CBE8B5BB166D3E2A40826CDED42CF
- SecureTrust \ Trustwave Global ECC P384 Certification Authority \ E7F3A3C8CF6FC3042E6D0E6732C59E68950D5ED2
- Visa \ Visa Public RSA Root CA \ 82EF4C64F057CA0038F0DB5B76C24B654D7CDA78
This release will NotBefore Code Signing on the following roots (CA \ Root Certificate \ SHA-1 Thumbprint):
- AC Camerfirma, S.A. \ Chambers of Commerce Root - 2008 \ 786A74AC76AB147F9C6A3050BA9EA87EFE9ACE3C
- SECOM Trust Systems CO., LTD. \ SECOM_SCRoot2 \ 5F3B8CF2F810B37D78B4CEEC1919C37334B9C774
- SECOM Trust Systems CO., LTD. \ Security Communication RootCA3 \ C303C8227492E561A29C5F79912B1E441391303A
This release will NotBefore SMIME for the following roots (CA \ Root Certificate \ SHA-1 Thumbprint):
- AC Camerfirma, S.A. \ Chambers of Commerce Root - 2008 \ 786A74AC76AB147F9C6A3050BA9EA87EFE9ACE3C
- Chunghwa Telecom \ ePKI Root Certification Authority - G4 \ 85A6693ED12C4AAD8DB69C8860B580134EBF2C77
- Chunghwa Telecom \ CHT_eCA \ 67650DF17E8E7E5B8240A4F4564BCFE23D69C6F0
- Chunghwa Telecom \ ePKI Root Certification Authority - G2 \ D99B104298594763F0B9A927B79269CB47DD158B
- Government of Saudi Arabia, NCDC \ GovSaudiArabia_NCDCsnrcasha256 \ 8351509B7DF8CFE87BAE62AEB9B03A52F4E62C79
- Government of Sweden (Försäkringskassan) \ Swedish Government Root Authority v3 \ 746F88F9AC163C53009EEF920C4067756A15717E
- Notarius \ Notarius Root Certificate Authority \ 1F3F1486B531882802E87B624D420295A0FC721A
- Notarius \ Notarius Root Certificate Authority \ B1C3AC0977AAF147E5821A87F8DA32226A210693
- OISTE \ OISTE WISeKey Global Root GC CA \ E011845E34DEBE8881B99CF61626D1961FC3B931
- Thailand National Root Certificate Authority \ Thailand National Root Certification Authority - G1 \ 66F2DCFB3F814DDEE9B3206F11DEFE1BFBDFE132
This release will NotBefore TimeStamping for the following roots (CA \ Root Certificate \ SHA-1 Thumbprint):
- Chunghwa Telecom \ ePKI Root Certification Authority - G4 \ 85A6693ED12C4AAD8DB69C8860B580134EBF2C77
- Chunghwa Telecom \ CHT_eCA \ 67650DF17E8E7E5B8240A4F4564BCFE23D69C6F0
- Chunghwa Telecom \ ePKI Root Certification Authority - G2 \ D99B104298594763F0B9A927B79269CB47DD158B
- OISTE \ OISTE WISeKey Global Root GC CA \ E011845E34DEBE8881B99CF61626D1961FC3B931
This release will NotBefore Server Authentication for the following roots (CA \ Root Certificate \ SHA-1 Thumbprint):
- Chunghwa Telecom \ CHT_eCA \ 67650DF17E8E7E5B8240A4F4564BCFE23D69C6F0
- Chunghwa Telecom \ ePKI Root Certification Authority - G2 \ D99B104298594763F0B9A927B79269CB47DD158B
- Government of Sweden (Försäkringskassan) \ Swedish Government Root Authority v3 \ 746F88F9AC163C53009EEF920C4067756A15717E
This release will NotBefore Client Authentication for the following roots (CA \ Root Certificate \ SHA-1 Thumbprint):
- Chunghwa Telecom \ CHT_eCA \ 67650DF17E8E7E5B8240A4F4564BCFE23D69C6F0
- Chunghwa Telecom \ ePKI Root Certification Authority - G2 \ D99B104298594763F0B9A927B79269CB47DD158B
This release will NotBefore Document Signing for the following roots (CA \ Root Certificate \ SHA-1 Thumbprint):
- OISTE \ OISTE WISeKey Global Root GC CA \ E011845E34DEBE8881B99CF61626D1961FC3B931
This release will Disable the following roots (CA \ Root Certificate \ SHA-1 Thumbprint):
- DigiCert \ Baltimore CyberTrust Root \ D4DE20D05E66FC53FE1A50882C78DB2852CAE474
- DigiCert \ GeoTrust Universal CA \ E621F3354379059A4B68309D8A2F74221587EC79
This release will Remove the following roots (CA \ Root Certificate \ SHA-256 Thumbprint):
- Visa \ Visa Information Delivery Root CA \ C57A3ACBE8C06BA1988A83485BF326F2448775379849DE01CA43571AF357E74B
Certificate Transparency Log Monitor (CTLM) policy
The Certificate Transparency Log Monitor (CTLM) policy is now included in the monthly Windows CTL. It's a list of publicly trusted logging servers that is for validating certificate transparency on Windows. The list of logging servers is expected to change over time as they're retired or replaced, and this list reflects the CT logging servers that Microsoft trusts. In the upcoming Windows release, users are able to opt in to certificate transparency validation, which will check for the presence of two Signed Certificate Timestamps (SCTs) from different logging servers in the CTLM. This functionality is currently being tested with event logging only to ensure it's reliable before individual applications can opt in to enforcement.
Note
As part of this release, Microsoft also updated the Untrusted CTL time stamp and sequence number. No changes were made to the contents of the Untrusted CTL but this will cause your system to download/refresh the Untrusted CTL. This is a normal update that is sometimes done when the Trusted Root CTL is updated.
- The update package is available for download and testing at: https://aka.ms/CTLDownload
- Signatures on the Certificate Trust Lists (CTLs) for the Microsoft Trusted Root Program changed from dual-signed (SHA-1/SHA-2) to SHA-2 only. No customer action required. For more information, please visit: https://support.microsoft.com/help/4472027/2019-sha-2-code-signing-support-requirement-for-windows-and-wsus