Windows 10 reached end of support on October 14, 2025, so Microsoft no longer ships free security patches for it. Paid Extended Security Updates keep critical fixes coming for a while, but for businesses the first year of that program ends in October 2026, and the price doubles every year you stay on it. The practical answer for a small business: inventory your Windows 10 machines now, upgrade the ones that qualify to Windows 11, and replace the handful that cannot make the jump, on your own calendar instead of a scramble this fall.
What end of support actually means
End of support does not mean your computers stop working. It means Microsoft stops fixing newly discovered security holes. A Windows 10 PC will still boot, open Outlook, and print invoices exactly as it did before. What changes is invisible: every vulnerability found after the patches stop stays open on that machine, and attackers go looking for exactly those. Microsoft's Extended Security Updates program is a paid bridge that delivers critical patches while you move to something newer. It was built to reduce risk during a transition, and it expires. Home-edition machines lose access to that bridge in the fall of 2026. Businesses can pay for updates for up to three years, at a price designed to climb.
What it costs to keep Windows 10 on life support
For a business, the first year of Extended Security Updates runs about $61 per device. The price then doubles each year: roughly $122 in year two and $244 in year three, or around $427 per machine to ride it out the full stretch. That money buys no new speed, no new features, and no help desk support. It only keeps an aging computer patched while it gets older.
Two other dates deserve a spot on your calendar. Microsoft's 2011 Secure Boot certificates begin expiring in June 2026, so machines that miss the certificate updates can hit startup and security-validation problems that have nothing to do with the usual patch cycle. Microsoft 365 apps, separately, keep getting security updates on Windows 10 through October 10, 2028, which helps but does nothing for the operating system underneath them. Windows 10 virtual machines running in Azure or Windows 365 get Extended Security Updates at no extra charge, a narrow exception most small offices will never touch.
Your three real options
Most small businesses land on one of three paths, often a mix of all three:
- Upgrade in place to Windows 11. If the hardware qualifies, this keeps your files and applications and costs nothing but time. Windows 11 needs a TPM 2.0 security chip and a reasonably recent processor, so most business PCs bought from around 2019 on are eligible.
- Replace the machines that cannot upgrade. Older desktops and laptops that fail the Windows 11 check are usually due for retirement anyway. A new business-class machine is faster, under warranty, and supported for years, and it earns back some of its price in the time your team stops losing to slow hardware.
- Buy ESU for a short list of stragglers. A PC tied to specialized equipment or a line-of-business app that is not ready yet can sit on Extended Security Updates as a bridge, with a firm retirement date attached. Paying rising subscription fees across a whole fleet only postpones the decision.
Why the deadline is really a security and compliance deadline
One unpatched front-desk PC is rarely just one machine's problem. It shares a network with your file server, your accounting system, and everyone's email, so it becomes the soft entry point an attacker uses to reach the rest. Regulators and insurers have caught up to this. HIPAA and PCI both expect supported, patched software, and running an operating system past end of life is the kind of finding that fails an audit. Cyber insurers now ask what you run, too: our guide to the IT controls underwriters now require explains how an unsupported OS can raise a premium or sink a claim. Keeping the whole fleet current is basic hygiene, the same discipline we lay out in the small-business cybersecurity checklist.
How to plan the move without disrupting work
Start with an inventory. You cannot plan around machines you have not counted, so list every Windows 10 device, its edition, and whether it meets the Windows 11 requirements. Sort them into three buckets: upgrade-ready, replace, and bridge-with-ESU. Handle regulated and front-desk machines first, since those carry the most risk and the tightest scheduling. In a dental or medical office, operatory and reception PCs have to be swapped around patient appointments and imaging software has to be validated on the new systems, which fills a calendar faster than most owners expect. Do the work in phases, after hours where you can, and migrate data and settings before anything gets retired. Once your team is on Windows 11, lock down the accounts too; our walkthrough of the Microsoft 365 settings most small businesses miss is a sensible next step. This is routine work for a managed provider. 37 Forge inventories your fleet, tells you which machines upgrade and which retire, and runs the swaps from McKinney, on-site anywhere in Collin County in under an hour when a machine needs hands-on attention.
Frequently asked questions
- When does support for Windows 10 actually end?
- Free security updates ended on October 14, 2025. Paid Extended Security Updates extend critical patches after that, and for businesses the first year runs through October 2026 before the price doubles. Companies can keep buying ESU for up to three years, but Microsoft designed the rising cost to push migration rather than reward waiting.
- Can we keep using Windows 10 after the updates stop?
- The machines keep working, but they stop being defended. Every security flaw found after the patches end stays open on that computer, and one unpatched PC shares a network with your servers, email, and financial systems. That makes it a likely entry point for an attacker, which is why running an unsupported operating system counts as a serious risk rather than a minor inconvenience.
- How much does the ESU bridge cost a business?
- Extended Security Updates run about $61 per device for the first year, then double each year after: roughly $122 in year two and $244 in year three. That is a reasonable bridge for a few machines that genuinely cannot move yet, such as a PC tied to specialized equipment. It is an expensive way to delay the inevitable across a whole office, since the fees buy no new speed, features, or support.
- Will our computers run Windows 11?
- Windows 11 requires a TPM 2.0 security chip and a fairly recent processor, so most business machines bought from around 2019 on qualify for a free in-place upgrade. Older desktops and laptops often fail the hardware check and are better replaced than patched. An inventory tells you exactly which machines upgrade and which are due for retirement.
- Does running an unsupported OS affect cyber insurance or compliance?
- Yes. HIPAA and PCI both expect supported, patched software, and an operating system past end of life is the kind of finding that fails an audit. Cyber insurers also ask what you run, and an unsupported OS can raise your premium or give an insurer grounds to deny a claim. Keeping systems current is one of the cheapest ways to protect both coverage and compliance.
- How should a small business start the migration?
- Begin with an inventory of every Windows 10 device and whether it meets the Windows 11 requirements, then sort machines into upgrade, replace, and short-term bridge. Handle regulated and front-desk systems first, and run the swaps in phases, after hours where possible, so daily work is not disrupted. 37 Forge handles this from McKinney and can be on-site anywhere in Collin County in under an hour when a machine needs hands-on work.
Want a Windows 11 migration plan for your office?
Book a free 30-minute assessment with a local Collin County engineer. We will inventory your Windows 10 machines and tell you which to upgrade, replace, or bridge, whether or not you hire us.
Book an assessment →