Google is transitioning the root certificate used in Android hardware key attestation chains. This affects any organisation or service that validates attestation certificates from Android devices.
Timeline:
Who is affected?
Any system that validates Android key attestation certificates needs to update its trust store to include the new root. This includes:
What should I do?
The new root certificate is published in Google's key attestation documentation.
Failure to update before April 10, 2026 will result in attestation verification failures for devices using Remote Key Provisioning, which includes most modern Android devices. Both the old and new root certificates are published at https://android.googleapis.com/attestation/root. Older devices with factory-provisioned keys that do not support key rotation will continue using the previous root indefinitely.