Free Windows 10 support ended on 14 October 2025. If that date has already passed you by, you're not alone, most businesses we talk to are still running at least a handful of Windows 10 devices. The risk isn't dramatic or immediate. It's quieter than that, and it compounds the longer it's left.
In short: Free Windows 10 support ended on 14 October 2025. Your PCs still boot and run, but they no longer receive security patches, so every vulnerability found from that date onward stays open. Your realistic options are to migrate eligible devices to Windows 11, buy Microsoft's Extended Security Updates as a temporary bridge (from around $61 per device in Year One, doubling each year to October 2028), or refresh hardware that can't run Windows 11.
Here's what actually changed, what your options are, and the plan we'd run if this were our own estate.
What does "end of life" actually mean?
From 14 October 2025, Windows 10 stopped receiving free security updates, feature updates and general technical support from Microsoft. The operating system didn't switch off. Your devices still boot, your applications still run, and nothing broke overnight. What changed is that every vulnerability discovered from that date onward goes unpatched on any device still running standard Windows 10.
That's the part that's easy to underestimate. Unsupported software doesn't fail loudly. It just sits there, quietly more exposed with every month that passes, until something exploits a gap that would have been closed on a supported version.
Does ESU fix the problem, or just buy time?
Microsoft's Extended Security Updates programme is the official bridge. For businesses, ESU is purchased through the Volume Licensing Program at $61 USD per device for Year One, and, per Microsoft's published pricing, the price doubles each consecutive year, for a maximum of three years. Run the maths and ESU can, in principle, extend protection all the way to October 2028, but at escalating annual cost that's designed to push you toward migrating rather than renewing indefinitely.
It's also worth being precise about what ESU covers, because it's easy to assume it's a like-for-like extension of normal support. It isn't.
- ESU delivers critical and important security patches only
- It does not restore feature updates or general improvements
- It does not include standard Microsoft technical support
- It does nothing to address hardware or driver support as vendors move on
In other words, ESU keeps the door locked. It doesn't fix anything else about running an operating system Microsoft has otherwise stopped developing.

What's the risk most businesses miss? Insurance and compliance
Security exposure is the obvious risk. The one that catches businesses out is less obvious: cyber insurance. Policies are increasingly written to require that covered systems run supported, patched software. If you file a claim after a breach, and the affected systems had already fallen out of support or ESU coverage, insurers have grounds to deny the claim outright on that basis alone.
"The device that fails you isn't the one that gets breached. It's the one that gets breached and voids your cover at the same time."
That's a materially different conversation to have with your board than "our patching is a bit behind." It turns an IT housekeeping item into a line of business risk that finance and leadership need to know about, not just IT.
Which route suits which device?
The right answer is a property of the device, not of the business, so most estates end up using two or three of these rather than picking one for everything:
| What it involves | Best for | Watch out for | |
|---|---|---|---|
| Upgrade in place | Move the existing device to Windows 11, keeping the hardware | Devices that already meet the Windows 11 hardware bar | Eligibility has to come from the inventory rather than assumption, and applications still need compatibility testing |
| Replace the hardware | New device on Windows 11 from the start, data and settings migrated across | Machines that cannot take Windows 11 and are due a refresh anyway | Capital cost and lead time, and lead time is one of the few genuinely good reasons to buy ESU alongside |
| Extended Security Updates | Keep the device on Windows 10 and pay for continued security patches | Devices that need more runway: an application still being tested, hardware on order, retraining in progress | $61 per device in Year One, doubling each consecutive year to a maximum of three years. Critical and important security patches only, with no feature updates, no standard technical support and no help as hardware vendors move on |
| Cloud desktop | The user works on a Windows 11 desktop hosted in Microsoft's cloud, reached from the device they already have | Users whose local hardware fails the Windows 11 bar but is otherwise serviceable, and roles where a fixed monthly per-user cost suits better than capital spend | The local device is still running Windows 10, so it stays inside the ESU and refresh decision rather than being lifted out of it |
Two rules cut through most of that table. The first is that ESU is a row you buy alongside another one, never instead of one: it is the bridge you cross while the upgrade, the hardware refresh or the cloud desktop rollout is actually happening, and the escalating price is deliberately designed to make standing still expensive. Our breakdown of the ESU year two maths sets out what the full runway costs if you do stand still, and our side-by-side guide to Windows 10 ESU vs Windows 11 vs a Cloud PC compares all three routes on cost shape, hardware implications and how long each one actually buys you.
The second is that no device can be allocated to a row without the inventory behind it. Hardware eligibility is the single biggest determinant of which column a machine belongs in, and it is the one thing businesses most often estimate rather than measure, which is why the audit sits first in the plan below rather than somewhere in the middle of it.
What's the practical plan, not a panic?
None of this means an emergency rip-and-replace this month. It means treating this as a managed, phased project with a clear end date. This is the order we work through with clients:
- Audit first. Get an accurate device inventory: what's still on Windows 10, what hardware it's running on, and whether that hardware even supports Windows 11. You can't prioritise what you haven't counted.
- Prioritise by exposure. Internet-facing devices, machines handling customer data, and anything covered by your cyber insurance policy or compliance obligations move to the front of the queue. A back-office machine with no network exposure is a lower priority than a laptop that travels and connects to client sites.
- Plan the Windows 11 migration in phases. Group devices by hardware eligibility and business function. Devices that can take Windows 11 today should move first; devices that can't need a hardware refresh built into the plan, not discovered halfway through.
- Use ESU only where it earns its keep. For devices that genuinely need more runway, whether that's an ageing line-of-business application still being tested for compatibility, hardware on order, or staff retraining in progress, ESU is a legitimate bridge. It's a poor long-term strategy applied to an entire estate.
- Set a hard date and work back from it. Every day ESU runs without migration progress behind it is a day of escalating cost for no forward motion. Treat the ESU window as a countdown, not a comfort blanket.
This is exactly the gap our Legacy Modernisation & OS Migration service is built to close: a proper audit, a phased migration plan that matches your hardware and application reality, and ESU used deliberately where it makes sense rather than as a default. Where the answer for some of the estate turns out to be a cloud desktop rather than a replacement laptop, our Windows 365 consultancy covers Cloud PC sizing and rollout, and our Azure Virtual Desktop consultancy covers the cases that need pooled hosts, autoscaling or GPU.
Windows 10 isn't going to fail you overnight, and that's precisely the problem. Nothing forces the decision, so it's easy to leave for later. Later gets more expensive every year ESU renews, and the exposure sits there the entire time. The businesses that come through this cleanly are the ones treating it as a project with a plan now, not the ones waiting for a reason to act.
Frequently asked
When did Windows 10 support end?
Free Windows 10 support ended on 14 October 2025. From that date Windows 10 stopped receiving free security updates, feature updates and general technical support from Microsoft. Nothing switched off and nothing broke overnight: devices still boot and applications still run, which is exactly what makes it easy to leave alone. What changed is that every vulnerability discovered from that date onward goes unpatched on any device still running standard Windows 10, so the exposure compounds quietly month by month rather than announcing itself. The only ways to stay patched are to move eligible devices to Windows 11, refresh hardware that cannot run Windows 11, or buy Extended Security Updates as a deliberate, time-limited bridge while one of those two happens.
How much do Windows 10 Extended Security Updates cost?
For businesses, ESU is purchased through the Volume Licensing Program at $61 USD per device for Year One, and per Microsoft's published pricing the price doubles each consecutive year, for a maximum of three years. That means ESU can in principle extend protection to October 2028, but at an escalating annual cost designed to push you toward migrating rather than renewing indefinitely. Budget it against the whole runway rather than the current year: if you intend to be off Windows 10 in two more years, price two years of escalating cost, not one. Treat the ESU window as a countdown rather than a comfort blanket, because every year it renews without migration progress behind it is cost for no forward motion.
Does ESU give you the same support as before?
No, and it is easy to assume it is a like-for-like extension of normal support. ESU delivers critical and important security patches only. It does not restore feature updates or general improvements, it does not include standard Microsoft technical support, and it does nothing to address hardware or driver support as vendors move on. In other words, ESU keeps the door locked. It does not fix anything else about running an operating system Microsoft has otherwise stopped developing. That makes it a legitimate bridge for devices that genuinely need more runway, an ageing line-of-business application still being tested for compatibility, hardware on order, staff retraining in progress, and a poor long-term strategy when it is applied across an entire estate by default.
Does running Windows 10 affect our cyber insurance?
It can, and this is the risk most businesses miss. Cyber insurance policies are increasingly written to require that covered systems run supported, patched software. If you file a claim after a breach and the affected systems had already fallen out of support, or out of ESU coverage, insurers have grounds to deny the claim outright on that basis alone. That is a materially different conversation to have with your board than saying the patching is a bit behind. It turns an IT housekeeping item into a line of business risk that finance and leadership need to know about, not just IT, so it is worth reading the wording of your own policy rather than assuming where you stand.
What should we do first if we still have Windows 10 devices?
Audit before anything else. Get an accurate device inventory: what is still on Windows 10, what hardware it runs on, and whether that hardware even supports Windows 11. You cannot prioritise what you have not counted, and you cannot choose between upgrading, replacing and buying ESU per device without it. Then prioritise by exposure, so internet-facing devices, machines handling customer data and anything covered by your cyber insurance policy or compliance obligations move to the front of the queue ahead of a back-office machine with no network exposure. After that, plan the Windows 11 migration in phases grouped by hardware eligibility and business function, use ESU only where it genuinely earns its keep, and set a hard end date to work back from.



