Want to see more content like this? Add us as a Preferred Source on Google to see more of our articles when you search.
Last updated September 24, 2026
Windows 10 officially lost support on October 14, 2025. That date came and went quietly for most businesses. No dramatic shutdown, no red warning screen, nothing that forced anyone's hand. Computers running Windows 10 booted up the next morning exactly like they had the day before.
That's exactly the problem.
We've been doing managed IT for 15 years. If there's one pattern we've seen play out again and again, it's this: the risks that feel least urgent are usually the ones that end up costing the most. End-of-life software doesn't fail loudly. It quietly stops getting protected, and most businesses don't find out how exposed they were until something goes wrong.
And the quiet period is ending. Two deadlines land within a week of each other next month:
- October 13, 2026: The first year of business Extended Security Updates (ESU) closes. Businesses that enroll after this date pay for Year 1 and Year 2 to get current. See the pricing breakdown.
- October 19, 2026: The Microsoft Windows Production PCA 2011 Secure Boot certificate expires. This one affects Windows 11 and Windows Server too. Jump to the Secure Boot section.
Here's what's going on, what it means for your business, and what to do about it.
In this article
- Quick Answers
- Windows 10 Isn't Gone. It's Just Unprotected.
- The Extended Security Updates (ESU) Program
- Why the "Free" Consumer ESU Doesn't Help Your Business
- The Deadline Nobody's Talking About: Secure Boot Certificates
- Why This Matters More Than a Typical "Upgrade Eventually" Situation
- What to Actually Do About It
- Frequently Asked Questions
Quick Answers
- Is Windows 10 still safe to use for business? Not without ESU. Microsoft no longer patches newly discovered security flaws on standard installs. Read why.
- What does business ESU cost? $61 per device for Year 1, $122 for Year 2, and $244 for Year 3. It's cumulative, so enrolling now means paying $183 per device. See the full table.
- Can my business use the free consumer ESU? No. Domain-joined, Entra-joined, and MDM-managed PCs are excluded. Here's why.
- What else is expiring? Secure Boot certificates from 2011. The last major one expires October 19, 2026. Learn what to check.
Windows 10 Isn't Gone. It's Just Unprotected.
"End of support" doesn't mean Windows 10 stopped working. It means Microsoft stopped fixing the security holes discovered in it. Feature updates, bug fixes, and, most importantly, security patches for newly found vulnerabilities are no longer delivered to standard Windows 10 installs.
That distinction matters more than most people realize. Attackers don't need to find a brand-new flaw to exploit an unsupported system. They just need to find any flaw discovered after the cutoff date, because they know it will never be patched on that machine. Unsupported operating systems become permanently soft targets. The gap between "vulnerability discovered" and "vulnerability weaponized" is often measured in days, not months.
Adoption data shows how much of the business world is still exposed. Windows 11 has overtaken Windows 10 in overall market share, but a substantial portion of Windows devices, commonly cited somewhere from the mid-20s to around a third depending on the month and the data source, are still running Windows 10. On the business side that number tends to run higher, since organizations with legacy line-of-business software, specialized hardware, or large PC fleets move slower than individual consumers do.
The Extended Security Updates (ESU) Program: What It Buys You, and What It Doesn't
Microsoft built an off-ramp for organizations that can't migrate immediately: the Extended Security Updates (ESU) program. It's worth understanding exactly what it does and doesn't cover. We've seen more than one business assume ESU is a full support extension. It isn't.
What ESU includes:
- Critical and important security patches only
- No new features, no bug fixes, no performance improvements
- No general technical support from Microsoft
- Devices must be on Windows 10 version 22H2 to receive ESU patches at all
What it costs (commercial/business pricing):
| Coverage Period | Price per Device | Cumulative Total |
|---|---|---|
| Year 1 (Oct 2025 – Oct 13, 2026) | $61 | $61 |
| Year 2 (Oct 14, 2026 – Oct 2027) | $122 | $183 |
| Year 3 (Oct 2027 – Oct 2028) | $244 | $427 |
The price doubles every year, and you can't buy Year 2 or Year 3 without also having paid for the years before it. Businesses that wait don't get a discount for delaying. They get hit with retroactive charges instead. A business that skips Year 1 and enrolls after October 13 pays $183 per device before receiving a single Year 2 patch. Organizations managing devices through Microsoft Intune or Windows Autopatch can get a reduced Year 1 rate, but the doubling structure still applies going forward.
For a business running 50 Windows 10 devices, that's roughly $3,050 for Year 1, $6,100 for Year 2, and $12,200 for Year 3. That's $21,350 across the full three years, spent to keep the lights on with no new capability to show for it. Run the math across your fleet and it becomes clear pretty quickly why ESU is meant as a bridge, not a destination.
Why the "Free" Consumer ESU Doesn't Help Your Business
You may have seen headlines saying Microsoft extended free Windows 10 security updates through October 12, 2027. That's true, but it applies to personal devices only. Consumers can enroll for free by syncing PC settings, by redeeming Microsoft Rewards points, or with a one-time $30 purchase. Microsoft's own terms exclude devices joined to an Active Directory domain or Microsoft Entra, devices managed through MDM, and any commercial use. You can read the details directly on Microsoft's Consumer ESU page.
If your business PCs are managed in any of those ways, the consumer path is closed to you, and using it anyway can cause compliance problems. Commercial ESU is your only route.
One partial bright spot: Microsoft 365 Apps on Windows 10 continue receiving security updates through October 2028. The operating system underneath them is still the exposed layer.
The Deadline Nobody's Talking About: Secure Boot Certificates
Here's the part of this story most small businesses haven't heard yet, and it isn't limited to Windows 10. It affects Windows 11 and Windows Server too.
The cryptographic certificates that power Secure Boot, the feature that verifies your computer is only loading trusted, unmodified boot software, were issued back in 2011. They're reaching the end of their 15-year lifespan. The first two, the Microsoft KEK CA 2011 and Microsoft UEFI CA 2011, expired in June 2026. The third, Microsoft Windows Production PCA 2011, which signs the Windows Boot Manager itself, expires on October 19, 2026.
Devices that don't get updated to the newer 2023 certificates by then will keep booting normally. There's no dramatic failure moment. What they lose is the ability to receive future security protections for the earliest stage of the startup process: new bootloader signatures, revocation updates for compromised boot components, and defenses against bootkit-style malware that loads before your antivirus even wakes up. BlackLotus, the first UEFI bootkit known to bypass Secure Boot on a fully patched Windows 11 machine, is the exact class of threat this protects against. Microsoft explains the transition on its Secure Boot certificate expiration support page.
Most current-generation, actively managed hardware receives the certificate update automatically through Windows Update, and PCs shipped since early 2024 generally include the 2023 certificates already. The devices at risk are the ones sitting in a closet as a spare, running older or unsupported firmware, offline for extended periods, or unsupported because they're on Windows 10 without ESU. A Windows 10 PC that isn't enrolled in ESU won't receive the updated certificates at all. For businesses carrying Windows 10 machines past their support date, this is a second, compounding layer of exposure landing in the same month.
Some older hardware also needs a BIOS/firmware update from the manufacturer before the new certificates can be installed, which is why checking device by device matters more than assuming Windows Update has handled it.
Why This Matters More Than a Typical "Upgrade Eventually" Situation
We get it. IT refresh cycles compete with a hundred other budget priorities, and a computer that still boots and runs Excel doesn't feel broken. A few things make this particular end-of-life event higher stakes than most.
Attackers actively target the transition window. Threat actors watch end-of-support timelines closely because they know a predictable, large population of devices will go unpatched. Unsupported systems become disproportionately attractive targets precisely because any vulnerability they find will stay open indefinitely.
Compliance and insurance exposure. If your business handles regulated data or carries cyber insurance, running unsupported operating systems can put you in violation of policy language or compliance requirements without you realizing it, at least until a claim gets denied or an audit flags it. We've written before about why businesses are losing cyber insurance coverage in 2026. Outdated, unsupported infrastructure is exactly the kind of finding underwriters look for.
The cost curve only goes one direction. ESU pricing doubles annually by design, specifically to push migration rather than reward delay. The longer a business waits, the more expensive "buying more time" becomes. At a certain point, the three-year ESU total approaches or exceeds what a hardware refresh would have cost in the first place.
Hardware age compounds the problem. A meaningful number of Windows 10 holdouts are on that version because the hardware doesn't meet Windows 11's requirements. That means the fix isn't just a software upgrade, it's a device replacement, and that takes longer to budget and execute than most businesses assume.
What to Actually Do About It
If you're not sure where your business stands, here's the practical sequence we walk clients through:
- Inventory first. Get a real count of which devices are still on Windows 10, which are eligible for a free upgrade to Windows 11, and which will need new hardware. You can't budget or prioritize what you haven't measured.
- Separate "needs new hardware" from "just needs upgrading." These are two very different timelines and cost centers, and it's worth not letting them blur together in planning. We've made a guide to help with this decision: How Long Should Business PCs Last?
- Decide if ESU makes sense as a bridge, and for which devices. ESU can be the right call for a small number of legacy or specialized systems that genuinely can't move yet. It's usually the wrong call as a blanket strategy for an entire fleet. If you need it, enroll before October 13 to avoid paying the catch-up price for skipped years.
- Check Secure Boot certificate status separately from your Windows 10/11 migration. This applies even to devices already on Windows 11, especially older hardware, devices with custom firmware, or anything that's been offline or dormant for a while. Aim to have every device confirmed before October 19, and make sure BitLocker recovery keys are backed up before any firmware or certificate changes.
- Build the migration into a real timeline with a budget owner, not a "someday" line item. Every month of delay moves you closer to Year 3 pricing and leaves more devices exposed to boot-level threats.
Frequently Asked Questions
Does Windows 10 stop working after October 2025?
No. It keeps functioning normally. What stops is the flow of new security patches, unless the device is enrolled in ESU.
How much does Windows 10 ESU cost for a business?
$61 per device for Year 1, $122 for Year 2, and $244 for Year 3, or $427 per device for the full three years. Pricing is cumulative, so a business enrolling for the first time after October 13, 2026 pays $183 per device. See the full pricing table.
Is ESU available to small businesses, or just large enterprises?
It's available to organizations of any size through Microsoft's Volume Licensing Program or a Cloud Solution Provider, but it has to be purchased that way. Domain-joined and MDM-managed business devices can't use the simplified consumer enrollment path.
Microsoft extended free ESU to 2027. Doesn't that cover my business?
No. That extension applies to personal devices only. Business PCs joined to a domain, joined to Entra, or managed through MDM must use paid commercial ESU. Read the full explanation.
Can I just disable Secure Boot instead of updating the certificates?
Technically yes, but it's not a real fix. Disabling Secure Boot removes a foundational layer of boot-level protection, can affect Windows 11 supportability, and may run afoul of cyber insurance or compliance requirements that assume it's active.
What happens if my business does nothing?
Devices keep running, which is exactly what makes this easy to ignore. But every month without patches or updated boot certificates widens the window attackers have to exploit known, permanently unfixed vulnerabilities on your network.
Windows migrations and end-of-life transitions are rarely the most exciting item on an IT roadmap, but they're consistently one of the highest-leverage ones: a fixed-cost project today versus an open-ended risk tomorrow. If your business is still sorting out where its devices stand, that inventory step is the place to start, and with two deadlines in the next few weeks, sooner is cheaper.
Recent Comments