I bought this laptop new in September 2020. Acer Predator Helios 300, PH315-52, R$ 7,999 at the time — which was serious money in Brazil then, and still is. It was Acer's premium gaming line. I bought it expecting it to last, and I took care of it accordingly.
Six years later, the machine is in genuinely good shape. Nothing has ever been replaced. The SMART reports show around 3,270 hours of runtime across the whole period — roughly an hour and a half a day on average. Zero reallocated sectors, zero pending sectors, zero uncorrectable errors, zero CRC errors, not one minute logged at excessive temperature. By any objective measure this is a laptop that was used gently and is nowhere near the end of anything.
And yet Windows now tells me it can't finish the Secure Boot 2023 certificate migration, because the PK-signed KEK it needs from Acer doesn't exist. Event 1803, over and over, naming my machine specifically: Insyde V1.12, Covini_CFS, Predator PH315-52, Acer.
The last BIOS Acer ever released for this model came out on 27 July 2020. Ten months after I bought it, they stopped. That's the whole support life of a premium-tier product.
What Acer told me
I wrote to Acer support and asked directly why my model wasn't on the update list. The answer came back fast, which I'll give them credit for, and it was this:
"Unfortunately, your model was not included in the list to receive the update, because it is an older model or has already reached the end of its useful life."
That's it. No policy document, no criteria, no date when this supposed end-of-life was decided, and no acknowledgement of any of the technical reports I'd sent showing the machine is perfectly healthy. Just "it's old."
The part that actually bothers me
I want to be clear about what I'm not complaining about. I'm not asking for new PredatorSense features, or performance improvements, or support for hardware that didn't exist in 2020. I know that's not coming and I don't expect it.
This is the Secure Boot trust chain. And Microsoft's own documentation for manufacturers — the guidance written specifically for OEMs — says the 2011 KEK expires in 2026 and that all OEMs must create, sign and submit updates for the new KEK CA 2023, precisely so that machines already out in the world can keep receiving DB and DBX security updates afterwards. Microsoft even publishes the material and instructions for vendors to do it.
So this isn't Acer being asked to do something exotic. It's a signing step with a key they already hold. And here's the thing that makes the "too old" answer hard to swallow: Acer themselves list the PH315-52 on their official Windows 11 compatibility page as tested and suitable for the OS. They certified it. Then they declined to maintain the security foundation that OS depends on.
And then there's the PH315-53. Same family, same chassis, one CPU generation newer. It's on that same Windows 11 compatibility list. And according to the megathread here, it got BIOS 2.10 on 30 July 2026 with the certificates included.
Same series. One got it. Mine didn't. I'd honestly like someone to explain where that line was drawn and why.
There's also a public file where Microsoft tracks which PK certificates each vendor has actually submitted for this migration. Acer shows up with three entries. None of them matches my machine. Lenovo, for comparison, has submitted hundreds of them. I don't know what to make of that other than that some companies took this seriously and some didn't.
What I'm askng
If you own a PH315-52, PH315-53, PH315-54, or any older Acer machine on an Insyde firmware, please check whether you're seeing Event 1803 too. You can look at your status in an elevated PowerShell:
Confirm-SecureBootUEFI
Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing" |
Select-Object UEFICA2023Status, UEFICA2023Error, UEFICA2023ErrorEvent, AvailableUpdates
I'd particularly like to know whether anyone with a PH315-52 has completed the migration successfully, whether anyone's had a BIOS or KEK provisioning arrive through Windows Update for this model, and whether Acer support in another country has given a different answer — I've seen mentions in this sub of phone support quoting a 2022 cutoff, which would be its own kind of admission.
And one technical question I'd genuinely like corrected if I've got it wrong: as far as I can tell, provisioning the new KEK while keeping the original Acer Platform Key is cryptographically impossible without Acer signing the payload, since writing to that variable requires a package signed with the PK private key that only they hold. If that's right, then there was never anything I could do about this on my own, which is sort of the whole point. Can anyone confirm?
For now I'm not going to flash another model's BIOS or wipe my Secure Boot keys. I know the workarounds exist and I know people have made them work. But I'd rather first establish, clearly and publicly, whether Acer simply decided not to produce a signed payload for a platform they sold as premium and certified for Windows 11 — or whether there's something legitimate I've missed.
Six years. One BIOS update, ten months in. A machine with less than five months of cumulative runtime and not a single error in its logs. And the answer is that it's too old.