Basically if the SVN changes (for September, it jumps to 11.0) in both the DBX and EFI locations, then you're good.
@KevTech has some Macrium X tips posted in this thread. Use the search function (-> "This thread") to find the earlier posts.
This is from my wife's Lenovo M83 desktop after doing the update. Why do I not see SVN 11.0 in the EFI section?
PowerShell 7.6.6
Secure Boot: ON
Virtualization Based Security: OFF
BitLocker on (C:) OFF
UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023
UEFI DB Certs
-------------
MosbyKey [2025.12.22]
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 11.0
EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.
STATUS REPORT
-------------
Registry: "UEFICA2023Status" = Updated
SUCCESS: UPDATES ARE FINISHED.
UEFI CA 2023 certs are present, PCA 2011 cert is revoked.
PS C:\Windows\System32>
*************************************************************************
OOPS! NEVERMIND, I FORGOT TO RUN -VERBOSE. IT LOOKS GOOD NOW.
*************************************************************************
Windows 11 25H2 (26200.9445)
Secure Boot: ON
Virtualization Based Security: OFF
BitLocker on (C:) OFF
BIOS Firmware
-------------
LENOVO 10AL000GUS
Version: FBKTE0AUS
Date: 2021-12-22
Factory Default UEFI PK Cert
----------------------------
(NONE)
UEFI PK Cert
------------
Mosby Generated PK [2025.12.22]
Factory Default UEFI KEK Certs
------------------------------
(NONE)
UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Microsoft Corporation KEK 2K CA 2023
Factory Default UEFI DB Certs
-----------------------------
(NONE)
UEFI DB Certs
-------------
MosbyKey [2025.12.22]
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
Factory Default UEFI DBX Certs
------------------------------
(NONE)
EFI_CERT_SHA256_GUID Signatures: 0
UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 11.0
EFI_CERT_SHA256_GUID Signatures: 455
UEFI Variables
--------------
Credential Guard: ON
SBAT (Linux only): sbat,1,2025051000 / shim,4 / grub,5 / grub.proxmox,2
EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume1\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.367, SVN 11.0
Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.
STATUS REPORT
-------------
Registry: "UEFICA2023Status" = Updated
SUCCESS: UPDATES ARE FINISHED.
UEFI CA 2023 certs are present, PCA 2011 cert is revoked.
PS C:\SecureBoot\SecureBoot-CA-2023-Updates_v2026-09-10>