Nothing broke. Nobody noticed.
That is exactly what Microsoft said would happen. A machine that misses these certificates keeps starting, keeps running, and keeps installing every Windows update on schedule. What it quietly stops receiving is new protection for the part of the computer that runs before Windows does, which is the layer that catches malware loading underneath your security software. The third certificate, the one used to sign the Windows startup program itself, expires on October 19.
Microsoft is replacing them automatically through Windows Update, and widened that rollout again in the update it shipped on August 11. It is not sending them everywhere at once. Its own release notes describe adding “high confidence device targeting data,” and Microsoft's guidance ties that confidence to whether a machine has shown a history of successful updates. So two identical PCs, both fully patched, running the same version of Windows, may not have both received it.
Which means up to date does not answer this question. It was never the same question.
Older hardware carries a second problem. The new certificate has to be accepted by the firmware built into the motherboard, and on a machine that has not had a firmware update in years, that acceptance has to be installed first. It comes from whoever built the computer rather than from Microsoft. Dell and HP have both published which of their models are ready.
Two things to ask for, and neither one is a project. First, which of our machines have the 2023 certificates and which do not. Windows keeps a status value on each machine that answers exactly that, so this is a report rather than an audit. Second, for the ones that do not, whether they need a firmware update from their manufacturer, because that is the list with a lead time attached to it.
You have until October 19. That is enough time to handle this and not enough time to discover it.
In October, the machines that are ready and the machines that are not will still look exactly the same.