Still running Windows 10? Waiting another year costs more than acting now

Most businesses that stayed on Windows 10 did the sensible thing. The machines worked, the deadline came and went, and nothing broke. That was the correct read for about ten months.

About this piece

  • Article
  • Managed IT
  • Written by Nicholas Backwell · Founder, Redsilicon
  • Updated 2026-08-24

The maths changes on 13 October 2026. Microsoft’s Extended Security Updates programme is cumulative, which means the cost of doing nothing goes up whether or not you were ever enrolled.

The short version

  • Windows 10 stopped getting security updates on 14 October 2025. The machines kept running, which is why nobody panicked.
  • Commercial ESU year one covers 15 October 2025 to 13 October 2026. Year two starts the next day.
  • ESU pricing doubles annually: roughly US$61, then US$122, then US$244 per device.
  • You cannot buy year two on its own. Enrolling late means paying for the years you skipped as well.
  • Consumer ESU is free or cheap but excludes any machine joined to a domain or managed by MDM, which rules out most business fleets.

Nothing broke, and that is the problem

Windows 10 did not stop working on 14 October 2025. Microsoft was clear about that: the PCs keep running. Three things stopped, per Microsoft’s ESU documentation (last updated 17 November 2025): technical support, feature updates, and quality updates including security fixes.

That is a slow leak, not a burst pipe. Every Patch Tuesday since has fixed flaws in Windows 11 that also exist in Windows 10, and unpatched Windows 10 machines have quietly accumulated them.

The measured effect is not subtle. Lansweeper, which inventories millions of managed business endpoints, published data on 14 July 2026 showing Windows 10 devices carrying an average of 1,903 active CVEs each, against 652 on Windows 11. Roughly two thirds of those Windows 10 flaws are rated high or critical. About one in forty is known to be actively exploited by attackers right now.

Same dataset, the part that should concern a Durham business owner more: 21.4% of Windows devices at small and mid-sized businesses were still on Windows 10, against 16.6% at large organisations. Smaller companies are further behind, and they are behind on the machines that sit on the same network as the accounting software.

For context on the wider picture, Statcounter put Canada at 78.21% Windows 11 and 20.18% Windows 10 in July 2026, ahead of the worldwide split. The two figures measure different populations, so do not read them as contradicting each other. Statcounter counts web traffic including home PCs. Lansweeper counts managed corporate endpoints.

The pricing trap nobody reads until October

Extended Security Updates is the paid programme that keeps critical and important patches flowing to a Windows 10 machine. Microsoft prices it per device, per year, and doubles it annually. Year one is about US$61. Year two is US$122. Year three is US$244. Three full years comes to US$427 a machine.

Here is the line that catches people, quoted directly from Microsoft’s own documentation:

“Customers can’t buy partial periods... If you decide to purchase the program in Year Two, you have to pay for Year One too, as ESUs are cumulative.”

Read that again with a date attached. A business that skipped year one entirely and decides in November 2026 to buy protection is not paying US$122 per device. It is paying US$61 plus US$122, so US$183, for coverage that only runs to October 2027.

Twenty machines at US$183 is about US$3,660 to rent one more year on hardware you were already unhappy with. That is a meaningful slice of what replacing some of those machines would have cost.

The coverage windows, from Microsoft’s CSP purchasing documentation:

ESU yearCoverage startsCoverage ends
Year 115 October 202513 October 2026
Year 214 October 202612 October 2027
Year 313 October 202710 October 2028

One note on a source discrepancy, because it matters if you are planning around it. Microsoft’s ESU FAQ says year one starts in November 2025, while the purchasing documentation and the lifecycle FAQ both say 15 October 2025. The October date appears in two places and lines up with the lifecycle table, so that is the one to plan against. The November wording is most likely about billing rather than coverage, but Microsoft has not said so directly.

ESU buys you patches, not help

This is the part that surprises owners who assume they are buying support.

Microsoft’s documentation states that ESU support covers “license activation, installation, and possible regressions of the ESU itself.” Nothing else. To raise even those, an organisation needs an active Microsoft Unified support plan, which is not something a 40-person business in Whitby is going to have.

Microsoft 365 support is blunter still. Its guidance on Microsoft 365 Apps and Windows 10, last updated 28 July 2026, sets out what happens when you call with a problem, with or without ESU:

  1. If the issue does not occur on Windows 11, support will ask you to move to Windows 11.
  2. If you cannot move, you get troubleshooting assistance only, and workarounds “might be limited or unavailable.”
  3. You cannot log a bug or request a product fix.

So ESU keeps the security patches coming. It does not get you a person who will fix your problem.

What is quietly expiring on your desktops right now

Windows itself is only half of it. Several things people rely on daily are on their own clocks, and one of them ran out this month.

Microsoft 365 Apps on Windows 10 keeps getting security updates until 10 October 2028, but feature updates freeze at Version 2608. Microsoft names the version rather than a date. Microsoft 365 versions use year-month numbering, so 2608 is the August 2026 release. That is now. Copilot features and anything new stop arriving on those machines from here.

The OneDrive desktop app on Windows 10 version 21H2 and older stopped updating around 15 August 2026, per Microsoft’s Office lifecycle page. On 22H2 it runs to October 2028.

Microsoft Edge and the WebView2 Runtime keep getting updates on Windows 10 22H2 until at least October 2028, and ESU enrolment is not required for that. Microsoft Defender security intelligence updates are also reported to continue to October 2028, though I could only confirm that second-hand rather than from the Microsoft post itself, so treat the Defender date as likely rather than guaranteed.

Office 2016 and Office 2019 ended support on the same day as Windows 10 and are not covered by anything. If you have those installed, they are already unpatched.

Why the consumer option probably does not apply to you

Microsoft extended consumer ESU by a year, to 12 October 2027, in June 2026. It did so with no announcement, just a documentation change and a note appended to a blog post. Enrolment is free if you sync PC settings to OneDrive, or costs 1,000 Microsoft Rewards points, or US$30 once for up to ten devices.

That sounds like an easy answer. For most business fleets it is not available. Microsoft’s consumer ESU page excludes any device joined to an Active Directory domain or enrolled in an MDM solution. If your machines are managed, they do not qualify.

There is a genuine grey area for a small business running workgroup machines with no domain and no MDM. Those appear to meet the technical eligibility criteria, while Microsoft’s commercial lifecycle FAQ says “Pro in Commercial use” belongs in the commercial programme. I could not find a Microsoft statement resolving whether commercial use of consumer ESU is licence-compliant. That is a question for a licensing partner, not a plan.

The wider lesson is worth keeping: Microsoft moved a deadline quietly, with no notice, in a direction that happened to be convenient. It could move one the other way just as quietly. Do not build a three-year hardware plan on the assumption that an extension will show up.

"Our machines are too old" is usually not the reason

The Windows 11 hardware requirements that actually stop older machines are TPM 2.0, UEFI firmware with Secure Boot capability, and a processor on Microsoft’s supported list. For Windows 11 24H2 and 25H2 the oldest mainstream Intel family on that list is 8th generation Core.

Before assuming a machine fails, check whether TPM is present but switched off. On a lot of business-class hardware from roughly 2016 onward, the firmware TPM exists and is disabled by default in BIOS. Turning it on is a reboot and a menu, not a purchase. Microsoft’s PC Health Check app is the documented way to test.

The Lansweeper data is useful here too: only 2.8% of Windows 10 devices in their dataset genuinely could not upgrade on hardware grounds. For most fleets the blocker is project time and disruption, not silicon.

If a machine truly fails the check, installing Windows 11 on it anyway is possible and comes with Microsoft’s written position, on a support page updated 26 January 2026: the PC “will no longer be supported and won’t be entitled to receive updates,” and compatibility damage is not covered under the manufacturer warranty. You would be trading a known unpatched state for a different unpatched state, with the warranty gone.

The Canadian government's position, in one sentence

The Canadian Centre for Cyber Security updated its guidance on obsolete products on 7 July 2026. The closing line is about as direct as federal guidance gets:

“Continuing to use obsolete products will always carry risk. The only way to fully protect your organization is to retire unsupported technology and transition to modern, secure alternatives.”

The same page, ITSAP.00.095, lists compliance violations and degraded incident recovery among the risks, alongside the obvious missing patches. Worth reading before your next insurance renewal.

On insurance specifically, be careful what you believe. Plenty of IT companies will tell you your policy is void the moment you run an unsupported operating system. I could not find a Canadian source that establishes this. What I would do instead is ask your broker directly, in writing, whether your policy has any condition tied to supported software, and keep the answer. That is a five-minute email that settles it for your actual policy rather than for an average one.

What this means for your building

An eight-person office in Bowmanville with six aging desktops is a different problem from a 60-person operation across two buildings in Pickering with a mix of laptops, a couple of shop-floor PCs running a machine controller, and a server nobody wants to touch.

The shop-floor machines are usually the real story. A Windows 10 PC bolted to a CNC machine or a label printer, running vendor software that was never certified past Windows 10, is not a refresh. It is a negotiation with the equipment vendor, and those take months. Find those machines first, because they set your timeline.

Also worth knowing: Microsoft includes ESU at no extra cost for Windows 10 running in Windows 365, Azure Virtual Desktop, Azure VMs and Azure Local. A Windows 10 endpoint connecting to a Windows 365 Cloud PC gets up to three years of ESU entitlement with an active licence. For the one stubborn application that cannot move, that can be cheaper than it sounds.

What to do about it

You can do the first four of these yourself this week.

  1. Count the machines. Not a guess. An actual list of every Windows PC, its Windows version, its age, and who uses it. If you have no inventory tool, walk around with a notepad. Fifty machines takes an afternoon.
  2. Run PC Health Check on a sample. Pick the oldest few of each model. You are trying to learn whether your fleet fails on CPU generation, which is fatal, or on a disabled TPM, which is not.
  3. Check BIOS for a disabled TPM on anything that fails. Intel calls it PTT, AMD calls it fTPM. On a lot of machines this is the whole problem.
  4. Find the machines that cannot move for software reasons. Anything running vendor software tied to a physical device. Email those vendors now and ask for their Windows 11 support position in writing.
  5. Decide by category, not machine by machine. Replace, upgrade in place, buy ESU, or move to a Cloud PC. Most fleets end up with a mix.
  6. If ESU is part of the answer, sort it before 13 October 2026. After that date the cumulative rule applies and the same coverage costs three times as much per machine.

If you would rather not do the inventory yourself, that is the first thing our IT consulting work produces anyway: an asset list with ages and a replacement year against each line. It is also the input to a three-year roadmap so this stops being a surprise every few years.

Want this scoped for your site?

Tell us the building and what you’re trying to achieve. We’ll tell you what it takes, and whether you actually need it.

Before you call

Can we just keep running Windows 10 and be careful?

You can, and plenty of businesses will. Understand what you are accepting: a machine accumulating roughly three times the known vulnerabilities of a patched one, on the same network as everything else you own. If those machines are isolated, offline, and not touching email or files, the risk is much lower. If they are on the main network with a mail client open, it is not.

Is buying ESU ever the right answer?

Yes. When you have a real constraint, such as vendor software that will not run on Windows 11 until next year, or a capital cycle that makes replacement genuinely impossible right now. ESU is a bridge with a price on it. It stops being sensible when it becomes the plan.

Do we need to replace everything at once?

No, and you should not. Replace in batches tied to which machines are worst, which people are most affected by downtime, and what your cash flow allows. What matters is that the batches are scheduled rather than triggered by a failure.

What if we only have a handful of machines and no IT provider?

Then most of this is a Saturday. Check compatibility, upgrade the machines that qualify, replace the two or three that do not, and skip ESU entirely. You do not need to hire anyone for that.

\n
\n \n