Windows 10 reached end of support on October 14, 2025. No more security patches, no more fixes, no more help from Microsoft. Six months later, a surprising share of business computers (industry trackers put it around four in ten) are still running it.
If some of yours are in that count, this is what it actually means and what your options are.
What "End of Support" Means in Practice
Every month, security researchers and attackers find new vulnerabilities in Windows. On supported systems, Microsoft patches them on Patch Tuesday. On Windows 10, they now stay open forever unless you're paying for extended updates.
Here's the part people miss: many vulnerabilities affect both Windows 10 and Windows 11. When Microsoft patches Windows 11, attackers can study the patch to find the underlying flaw, then aim it at the operating system that will never receive the fix. Every month that passes, the pile of permanently open holes gets bigger. Six months in, that pile is real.
The Compliance Problem Is Immediate
If your business answers to HIPAA, PCI DSS, CMMC, SOC 2, or your cyber insurance carrier, unsupported operating systems are not a gray area:
Vulnerability scans flag them automatically. Any assessment we run will light up an unsupported OS as a high-severity finding on day one.
Frameworks require supported, patched software. An auditor doesn't have to debate the risk. The OS vendor itself says the product is no longer maintained. That's the finding.
Cyber insurance applications ask. Attesting that your systems are patched and supported while running Windows 10 without extended updates is the kind of inconsistency that gives carriers a reason to fight a claim when you need them most.
Your Three Options
Option 1: Upgrade to Windows 11 (free, if the hardware allows).
The blocker is usually hardware. Windows 11 requires TPM 2.0 and a relatively recent processor, which generally means machines from around 2018 onward. Run the readiness check across your fleet before assuming anything. Many "incompatible" machines just have TPM disabled in firmware, which is a five-minute fix.
Option 2: Pay for Extended Security Updates (ESU).
Microsoft sells continued Windows 10 patches for businesses, but the pricing is designed to push you off the platform: it starts around $61 per device for the first year and doubles each year after, for a maximum of three years. ESU is a bridge for machines you genuinely can't replace yet (a PC that drives a piece of lab or shop equipment, for example), not a strategy.
Option 3: Replace the hardware.
If a machine can't run Windows 11, it's at least seven years old. At that age you're paying for it in slowness and downtime even before the security math. A planned, budgeted replacement cycle beats an emergency one after an incident, every time.
The Sensible Sequence
- Inventory. Know exactly how many Windows 10 machines you have and which ones can take the free upgrade. (If you don't have an accurate inventory, that's its own finding.)
- Upgrade everything eligible. Schedule it in waves, after hours, with a rollback plan.
- Triage the rest. Replace the ones people use daily. ESU only for special cases with a retirement date attached.
- Isolate anything that must stay. A Windows 10 machine that absolutely has to live on (running legacy equipment, usually) should be segmented from the rest of your network and kept off the internet wherever possible.
The Honest Take
This migration was never urgent until suddenly it is. The businesses that handled it in 2025 spent a modest, planned amount. The ones that handle it after an incident, or after a failed audit, spend more and do it under pressure.
If you're not sure where your fleet stands, we can inventory it, check Windows 11 readiness, and give you a prioritized plan in about a week. Reach out and we'll take a look.