all systems operational +48 697 610 212
Technical · [2026-07-17]

Windows 10 End of Support — What Your Company Must Do Now

Windows 10 support ended on 14 October 2025. What it means for your company, your options (Windows 11, hardware replacement, ESU) and where to start.

WINDOWS-10 · WINDOWS-11 · MIGRATION · INTUNE · SECURITY · IT-FOR-BUSINESS · GUIDE

On 14 October 2025 Microsoft ended support for Windows 10. If computers in your company still run “the ten,” from that day they no longer receive any security updates. The systems keep working, but every new vulnerability stays permanently unpatched.

This isn’t a problem that goes away on its own. The longer your fleet sits on an unsupported system, the higher the risk: to security, to compliance (including NIS2) and often to the accounting or industry software that stops being certified for the old system. This post is a practical guide: exactly what changed, what your options are and how to run the migration so it doesn’t turn into a panicked replacement of everything under time pressure.

Before you decide, nail down three numbers:

  1. How many computers in your company still run Windows 10.
  2. How many of them qualify for Windows 11 without a hardware swap (TPM 2.0, Secure Boot, supported processor).
  3. How many will need replacing — and on what budget and timeline.

Without these three numbers, every conversation about cost and deadline is guesswork. Every sensible plan starts with them.


Table of contents

  1. What “end of support” really means — and what it doesn’t
  2. Why it’s a real risk for your business, not just a formality
  3. Four options — and when each makes sense
  4. How to check which computers can run Windows 11
  5. How to run the migration without chaos
  6. The most common mistakes
  7. Checklist

1. What “end of support” really means — and what it doesn’t

Let’s start with two extreme reactions, because both are wrong: panic and dismissal.

What did NOT happen: Windows 10 computers didn’t stop working. They won’t lock up, won’t wipe your data, won’t show a screen forcing a purchase. They boot and keep running like yesterday.

What did happen: since 14 October 2025 Microsoft no longer releases free security updates for Windows 10. No more monthly patches. Every new vulnerability found after that date — and they’re found constantly — stays open in the system forever. There’s no vendor technical support either.

The difference is subtle but crucial. The problem isn’t that the system stops working, but that every month it grows more full of holes, with nothing to signal it. The risk builds slowly instead of hitting all at once, and that’s exactly why it’s so easy to put off.

2. Why it’s a real risk for your business, not just a formality

At home you can ignore this for longer. In a company you can’t, for a few concrete reasons:

  • Security. Unpatched holes are the easiest way in for ransomware. Attackers aim precisely at systems everyone knows are no longer patched, because published vulnerabilities keep working on them indefinitely.
  • Compliance. NIS2 and most security policies explicitly require current, supported software. A fleet on an unsupported system is a ready-made finding in any audit.
  • Cyber insurance. More and more cyber-risk policies include a condition to keep software supported. Running Windows 10 can make a payout harder after an incident.
  • Industry and accounting software. Vendors of accounting, ERP and medical systems are gradually dropping support for Windows 10. At some point an update to your key program simply won’t install on the old system.
  • GDPR compliance. Processing personal data on an unsupported, unpatched system is hard to defend as “adequate technical measures.”

None of these blows up on day one. They all build up, and they usually surface at the worst possible moment: after an incident.

3. Four options — and when each makes sense

There’s no single right answer for the whole fleet. The best route is usually a combination of the following, chosen computer by computer.

Option A: Upgrade to Windows 11 on current hardware

For computers that meet the Windows 11 requirements (see section 4), this is the cheapest and simplest route. The upgrade keeps your files, settings and installed programs. When: hardware from the last ~5–6 years that passes the compatibility check.

Option B: Replace computers that don’t qualify

Some older machines won’t run Windows 11: no TPM 2.0, a processor that’s too old. For these the only sensible move is replacement with new hardware (shipping with Windows 11 already). When: computers older than ~6 years, or ones that are slowing down and are replacement candidates anyway. This is often a good chance to refresh the oldest part of the fleet instead of patching it.

Option C: ESU — buying time, not a solution

The ESU (Extended Security Updates) program lets a company pay to extend security updates for Windows 10 alone — for up to three years, until October 2028. It’s a fee per device, and the price rises every year (the second year more than the first, the third more still — Microsoft deliberately nudges you toward migrating this way). When: when you physically can’t migrate the whole fleet in time, or when a specific computer has to stay on Windows 10 because of an old application you can’t move right away. Treat ESU as a bridge for a few months, not a plan for years. Every year you pay more for an ever older system.

Option D: Rethinking the workstation model

While you’re migrating, it’s worth asking whether every workstation has to be a classic Windows PC. For some roles a cloud desktop, a thin client or — for purely browser-based work — a lighter system fits better. When: with larger fleets, hardware rotation and remote work. It’s a strategic decision, not an emergency one. But the end of Windows 10 support is a good moment to consider it.

OptionCostRiskFor whom
A. Windows 11 on current hardwareLowLowHardware meeting the requirements
B. Hardware replacementHigher (new hardware)LowOld, non-qualifying machines
C. ESURises each yearMedium (still an old system)Bridge, exceptions, old apps
D. Cloud / VDI / lighter systemDepends on modelDepends on scopeSelected roles, long-term plan

4. How to check which computers can run Windows 11

Windows 11 has hard hardware requirements — the main reason part of the fleet won’t upgrade “in place”:

  • TPM 2.0 — a security module (often disabled in the BIOS though physically present; sometimes you just need to switch it on).
  • UEFI with Secure Boot — the boot mode; older Legacy/BIOS configurations have to be switched over.
  • A supported processor — roughly Intel 8th generation and newer or AMD Ryzen 2000 and newer.
  • 4 GB RAM and a 64 GB drive — in practice you’ll want more for comfortable work.

You can check a single computer with Microsoft’s PC Health Check app. But in a company with a dozen or several dozen workstations, walking desk to desk is a waste of time. It makes more sense to run a fleet audit — a single pass shows which machines qualify right away, which just need TPM enabled or the boot mode switched, and which have to be replaced. The result is a ready list split into three buckets plus a cost estimate — a starting point for a plan rather than another unknown.

5. How to run the migration without chaos

The difference between a calm migration and an emergency scramble is planning and order. Here’s how we do it in practice:

  1. Fleet audit. What you have, what qualifies for Windows 11, what needs a settings change, what has to be replaced. Without this, you’re planning blind.
  2. Pilot. A rollout on a small test group and finalizing policies before we move the rest. This is where all the surprises show up — on a controlled sample, not across the whole company.
  3. Staged rollout. Mass deployment in batches, remotely, through Microsoft Intune and Windows Autopilot — a new laptop configures itself after the first sign-in, and existing ones we migrate without visiting every desk. The company works normally while workstations switch over in groups.
  4. Keeping data and access. Files, profiles and email access stay put — the employee turns the computer on and keeps working. A tested backup before you start is the foundation.
  5. Post-rollout care. Policies set once in Intune apply automatically to every new computer, and the helpdesk catches minor issues in the first days.

The biggest advantage of doing this right once: the next rollout is just taking the hardware out of the box. For the details — how we pick the method and how zero-touch through Autopilot works — see the service page: Windows 11 deployment for business.

6. The most common mistakes

  • “It still works, so we’ll wait.” It works, but without patches. The risk grows unnoticed, and the longer you delay, the bigger the chance the migration lands in a rush, after a breach.
  • Replacing everything at once. Expensive and unnecessary. A large part of the fleet will upgrade in place; you only need to replace what doesn’t qualify.
  • Migrating without a backup. A system upgrade rarely ends in data loss, but “rarely” isn’t “never.” A tested backup before you start is a requirement, not an option.
  • Forgotten workstations. The computer in the warehouse, on the production floor, the Windows-based POS terminal — these are easy to miss in the inventory, and they’re often the most critical machines.
  • Treating ESU as a solution. ESU pushes the problem down the road and costs more every year. Without a migration plan behind it, it’s just deferring the trouble for a surcharge.

7. Checklist

  • Fleet inventory — how many computers, on which system, how old
  • Compatibility check against Windows 11 — three buckets: qualifies / needs settings / to replace
  • Verified industry software — does it run and is it supported on Windows 11
  • Backup before migration — done and tested
  • Phase plan — pilot, group order, deadlines
  • ESU decision — for exceptions only, aware of rising costs
  • Post-rollout care — who catches issues in the first days

Summary

  • Windows 10 has been unpatched since 14 October 2025 — computers work, but without security updates.
  • It’s a real business risk — security, compliance (NIS2, GDPR), cyber insurance, industry software.
  • There’s no single option for the whole fleet — usually it’s a mix: in-place upgrade, replacing the oldest machines, ESU for exceptions only.
  • Start with an audit — until you know how many computers qualify, you can only estimate cost and deadline in the dark.

Got computers on Windows 10 and don’t know how many will run Windows 11? See how we deploy Windows 11 in businesses or book a free consultation — we’ll audit your fleet and show you what to upgrade, what to replace and what it costs.

Want the same results in your infrastructure?

Get in touch — the first consultation is free.

Free consultation