Windows 10 reached end of support on October 14, 2025. Version 22H2 was the final release, and after that date Microsoft stopped providing technical support, feature updates, and quality updates — including security fixes — for the editions that reached end of support.
If your business still has Windows 10 machines running, they did not stop working, and nothing visibly changed. That is precisely why this tends to get deferred. The change is not to the computer in front of you; it is to what happens the next time a serious vulnerability is discovered.
What end of support actually means
There is an important difference between a computer that works and a computer that is supported.
A Windows 10 PC today still boots, still runs your applications, and still connects to the internet. What ended is the maintenance behind it. When a security researcher or an attacker finds a new flaw in Windows 10, Microsoft is no longer producing a fix for unsupported editions. That flaw stays open on that machine for the rest of its life.
This is a gradual divergence rather than a cliff. On day one after end of support, a Windows 10 machine was almost exactly as secure as it was the day before. Each month afterwards, the gap between “flaws that are known” and “flaws that are fixed on this device” widens. That widening is the entire problem.
An honest clarification
Running an unsupported operating system does not mean a machine is compromised, and anyone telling you otherwise is overselling. It means a category of risk that used to be actively managed for you no longer is. That is a real and worsening problem — it is not an emergency on any particular day, which is exactly why it needs a plan rather than an alarm.
The real business risks
- Unpatched vulnerabilities accumulate. This is the central issue, and it only grows.
- Software vendors drop support. Browsers, accounting packages, line-of-business applications, and security tools progressively stop testing against — and then stop supporting — unsupported Windows versions.
- New hardware stops working. Printers, scanners, and peripherals released now are increasingly shipped without drivers for Windows 10.
- Third-party requirements. Cyber insurance questionnaires, customer security reviews, and payment or contractual obligations frequently ask whether systems are vendor-supported. If you handle card payments, note that PCI DSS expects systems in scope to be protected against known vulnerabilities.
- Recovery gets harder. Rebuilding an unsupported machine after a failure means reinstalling an operating system that no longer receives fixes.
Start with an inventory
Almost every business we talk to underestimates this number. The forgotten machines are rarely the obvious desktops — they are the PC running a label printer in a back room, the laptop a part-time employee uses from home, or the machine attached to a piece of equipment that nobody wants to touch because it works.
For each Windows 10 device, record:
- Who uses it, and for what.
- Its Windows edition and version (Settings › System › About).
- Age, processor, memory, and storage.
- Whether it holds business data locally, or only accesses it.
- The applications it must run — especially anything specialized or attached to hardware.
That last point matters more than device age. A five-year-old PC used only for email is a low-stakes replacement. A three-year-old PC running the only copy of a specialized application is a project.
Checking Windows 11 eligibility
Windows 11 has stricter hardware requirements than Windows 10, and this is where upgrade plans usually stall. Per Microsoft’s published system requirements, a device needs a compatible 64-bit processor, 4 GB of memory, 64 GB of storage, UEFI firmware with Secure Boot capability, and TPM version 2.0.
TPM 2.0 and Secure Boot are the usual blockers. Both are hardware and firmware features — they are not something you can add to a machine that lacks them. A perfectly functional PC can be ineligible for Windows 11 and there may be no way to change that.
Two practical notes. First, some machines have a TPM that is disabled in firmware; enabling it can make an apparently ineligible device eligible, so it is worth checking rather than assuming. Second, methods circulate for installing Windows 11 on unsupported hardware. For a business we would advise against relying on them: such installations are not entitled to updates and can stop receiving them, which reintroduces the exact problem you were solving.
Application compatibility
Confirm compatibility before you move anyone, not after. For each business-critical application, check the vendor’s stated support for Windows 11, whether your current licensed version is supported or whether an upgrade is required, and whether attached hardware has Windows 11 drivers.
Give particular attention to older specialized software — industry tools, equipment control software, and anything from a vendor no longer in business. If an application will not run on Windows 11 and cannot be replaced, that is a genuine constraint, and it deserves a deliberate decision: isolate that machine from the wider network and the internet, or replace the application. Leaving it connected and unsupported is the option that quietly carries the most risk.
Upgrade or replace?
For eligible hardware in good condition, the in-place upgrade to Windows 11 is usually straightforward and preserves files and applications. Back up first regardless — see backup planning for small businesses — and upgrade one machine first to confirm your applications behave before doing the rest.
Replacement generally makes more sense when:
- The device is not eligible for Windows 11.
- It is already slow enough that people work around it, or it is near the end of its practical life.
- The upgrade cost approaches replacement cost once you add memory or storage.
- It is out of warranty and used for something important.
Replacing hardware is also the natural moment to reduce how much data sits on individual machines. A device that only accesses centrally stored information is far quicker to replace the next time.
Extended Security Updates
Microsoft offers Extended Security Updates as a paid bridge for devices that cannot move yet. The essentials, from Microsoft’s documentation:
- Devices must be running Windows 10, version 22H2 to be eligible.
- Security updates only. No new features, no non-security fixes, and no general technical support.
- For organizations, ESU is sold through volume licensing, started at $61 USD per device for year one, and the price doubles each consecutive year for a maximum of three years. Coverage is cumulative — buying a later year requires paying for the earlier one.
- For consumers, Microsoft offers a separate, time-limited enrollment path with free and low-cost options. It is aimed at individuals and Home users, and excludes domain-joined and MDM-managed devices, which rules it out for most managed business fleets.
Verify current ESU terms before budgeting
ESU pricing, enrollment windows, and end dates have changed more than once, and the consumer and commercial programs run on different timelines. Confirm the current terms on Microsoft’s ESU documentation before you build a budget around it.
Treat ESU as time bought for a specific, funded plan — not as a way to avoid one. The cost structure is deliberately designed to make indefinite deferral more expensive than migrating.
A prioritized plan
Do this in priority order rather than device by device. The goal is to reduce exposure fastest where it matters most.
Windows 10 migration checklist
- Inventory every Windows device, including back-office machines, home-use laptops, and PCs attached to equipment.
- Confirm which devices still run Windows 10 and which are already on Windows 11.
- Run Windows 11 eligibility checks; where a device fails, confirm whether TPM or Secure Boot is merely disabled in firmware.
- List business-critical applications and confirm each vendor supports Windows 11.
- Prioritize: devices handling customer or financial data first, then internet-facing daily-use machines, then isolated equipment.
- Verify you have a working, tested backup before touching any machine.
- Upgrade one representative device first and confirm applications and peripherals behave.
- Replace ineligible hardware on a scheduled basis rather than all at once, spreading cost across budget periods.
- For anything that cannot move, decide deliberately: purchase ESU, isolate the device from the network and internet, or accept and document the risk.
- Record the plan with dates and owners, and review it quarterly until no unsupported devices remain.
If devices remain on Windows 10 in the meantime, the surrounding controls carry more weight: keeping applications patched, maintaining visibility into device health, and limiting what those machines can reach on your network.
Sources and further reading
- Windows 10 Home and Pro lifecycle(opens in a new tab) — Microsoft Learn
- Extended Security Updates (ESU) program for Windows 10(opens in a new tab) — Microsoft Learn
- Windows 10 Consumer Extended Security Updates(opens in a new tab) — Microsoft
- Windows 11 system requirements(opens in a new tab) — Microsoft Support