There are two deadlines here, not one.
Microsoft ended free security updates for Windows 10 Home, Pro, Enterprise, and Education editions on October 14, 2025. The operating system still runs. Programs still open. The desktop still looks the same. What changed is invisible: Microsoft no longer ships security patches for newly-discovered vulnerabilities. Every new CVE in Windows 10 is permanent on those machines unless they’re enrolled in the paid Extended Security Updates (ESU) program.
That first deadline is old news by now — most owners have heard it. The one that matters as of this update is the second: the single free-consumer year of ESU, and the first paid year most small businesses bought as a stopgap, both run out on October 13, 2026. As of this writing that’s a matter of weeks away. If your plan since last fall was “we’ll deal with it during the ESU year,” this is that year ending.
The practical effect of staying unpatched compounds over months, not days. The first month after EOL, the gap was small. By six months in, the count of unpatched, weaponizable vulnerabilities had already crept up. Now, nearly a year past EOL, any device that’s still on Windows 10 and off ESU is running with a growing, permanent list of known holes — and any device relying on Year 1 ESU is about to lose that coverage too, unless someone actively renews it.
The three paths forward, in order of preference.
Path 1 — In-place upgrade to Windows 11 (cheapest, fastest)
If the hardware meets the Windows 11 requirements, an in-place upgrade preserves files, apps, and settings while moving the OS forward. The minimum spec is: 1 GHz dual-core 64-bit CPU on the supported list, 4 GB RAM, 64 GB storage, UEFI/Secure Boot, and TPM 2.0. Most Intel 8th-gen / AMD Ryzen 2000-series and newer machines qualify; most pre-2018 machines do not. Microsoft’s PC Health Check tool gives a definitive answer per device. Cost: zero in licensing, a couple hours per machine in technician time.
Path 2 — Hardware refresh (Windows 10 → new Windows 11 device)
For machines that fail the Windows 11 hardware check — older CPUs, missing TPM, no UEFI — refresh the hardware. A reasonable mid-tier business laptop runs $900–$1,400, comes preinstalled with Windows 11 Pro, and is the right call for any device older than four years regardless of OS, because the rest of the hardware is aging out too. Plan the refresh as a phased rollout: oldest and most-exposed machines first, the rest on the natural replacement cycle.
Path 3 — Extended Security Updates (ESU) — bridge only, and the bridge is closing
ESU buys time, not a destination. The consumer/Pro Year 1 term — roughly $30 per device, the one most small businesses bought as a stopgap — ends October 13, 2026. Commercial ESU can be renewed for a second and third year, but the price doubles each time, and every renewal is another year of running an operating system with no path forward. If a device is on ESU today with no refresh or upgrade plan behind it, that plan needs to exist now — not after coverage lapses in a few weeks.
The 90-day migration plan for a small business.
Ninety days is the standard, comfortable timeline. If you’re starting this in August 2026 with ESU coverage running out October 13, the honest math is that a full 90-day rollout won’t finish before that date — so compress it: do the inventory and the highest-risk group in the first two to three weeks, and let the rest of the fleet trail behind on the normal cadence below rather than trying to force everything through before the deadline.
Days 1–14: Inventory and assessment
- Pull a full list of every Windows machine, OS version, age, and assigned user. If you don’t have one already, your MSP can run it from the RMM agent in under an hour.
- Run PC Health Check (or the RMM equivalent) on every Windows 10 device. Group results into: upgrade in place, refresh required, and bridge with ESU.
- For each “refresh required” machine, document the user, role, and any role-specific software requirements (CAD, accounting, EHR, POS).
Days 15–30: Procurement and scheduling
- Order the refresh hardware in batches that align with budget cycles. Microsoft Surface, Lenovo ThinkPad, Dell Latitude, and HP EliteBook are all reasonable defaults for a small-business fleet.
- Build a deployment image: company apps preinstalled, Microsoft 365 enrolled, EDR agent baked in, conditional-access policy applied. Image once, deploy many times.
- Schedule the rollout to avoid critical business windows — not the week of an audit, not month-end close.
Days 31–75: Phased rollout
- Start with the highest-risk users: anyone who handles finance, anyone with admin privileges, anyone in a HIPAA / PCI-regulated role.
- Refresh in groups of 5–10 per week so the help desk can support the inevitable “where did my bookmarks go” questions without queueing.
- Decommission the old Windows 10 hardware: wipe the drive (DOD-grade if you handle regulated data), remove from the asset register, and physically dispose or donate through a vendor that issues certificates of destruction.
Days 76–90: Validate and document
- Confirm 100% of production endpoints are Windows 11 (or ESU-enrolled if there’s a documented exception).
- Update the asset register and the cyber-insurance attestation — carriers ask about supported-OS posture explicitly.
- Schedule the next quarterly review to confirm no Windows 10 machines have crept back in via personal-device use or a forgotten kiosk.
Edge cases worth flagging.
- Industry-specific software — some EHRs, ERPs, and CAD packages have lagged on Windows 11 support. Check the vendor compatibility matrix before assuming the migration is a clean in-place upgrade.
- Domain-joined machines — an in-place upgrade preserves the domain join, but it’s the right time to validate the user is in the correct OU and the correct conditional-access policy.
- Loose Windows 10 machines — the receptionist’s spare laptop, the conference-room PC, the lobby kiosk. These are the ones that get forgotten. Inventory them explicitly.
- Windows 11 hardware that just barely qualifies — older 8th-gen i3 machines technically pass the check but perform poorly. Consider replacement on age grounds even if the OS will run.
What this looks like on a Micro-IT managed plan.
Managed Endpoint clients have OS-version inventory baked in — we ran the Windows 10 EOL roster the week of the announcement and have been tracking it since. Migration projects are quoted as fixed-price up front, scheduled around your business calendar, and documented end-to-end. The endpoint hardening (EDR, MFA, DNS filtering, image-level backup) runs on Windows 10 and Windows 11 identically, so security posture stays consistent through the transition.
If you’re not on a managed plan and want a one-shot Windows 10 EOL project — inventory, plan, execute — we’ll quote that too. Get in touch or call 270.816.5726.
Frequently asked questions.
When did Windows 10 reach end-of-life?
Is it dangerous to keep running Windows 10 after EOL?
Can I upgrade my Windows 10 PC to Windows 11 for free?
How much does Windows 10 Extended Security Updates (ESU) cost, and when does it run out?
What happens when Windows 10 ESU coverage ends on October 13, 2026?
How long should a small-business Windows 10 → 11 migration take?
Your next step
Reading is the easy part — the gap closes when someone owns it. Book a free 20-minute call and we’ll walk through how this applies to your environment, in plain English.
