Still on Windows 10? The Cheap Option Expires in October
Windows 10 lost security updates in October 2025. Paid extensions exist, the price doubles every year, and waiting past October 2026 means paying for two years instead of one.
Windows 10 stopped receiving security updates on 14 October 2025. That was ten months ago, and a surprising number of Greater Boston offices are still running it on at least some machines.
That is understandable. Nothing visibly broke. The machines still boot, Outlook still opens, staff still work. The cost of not migrating has been zero so far, which is exactly what makes it easy to keep postponing.
There is a deadline in October that makes postponing more expensive, and it is worth understanding before it passes.
The paid extension, and why the date matters
Microsoft sells Extended Security Updates — critical and important security patches only, for machines still on Windows 10. For businesses buying through volume licensing the pricing is deliberately uncomfortable:
| Year | Period | Cost per device |
|---|---|---|
| Year 1 | Oct 2025 – Oct 2026 | $61 |
| Year 2 | Oct 2026 – Oct 2027 | $122 |
| Year 3 | Oct 2027 – Oct 2028 | $244 |
The price doubles every year, and the programme stops after three (Managed Solution, TrustedTech).
The part that catches people is not the doubling. It is this: an organisation that waits and buys in Year 2 cannot buy Year 2 alone — it has to buy Year 1 retroactively as well.
So for a business still on Windows 10 today with no ESU coverage, the arithmetic is:
- Enrol before October 2026: $61 per device
- Enrol after: $61 + $122 = $183 per device
For twenty machines that is the difference between roughly $1,200 and $3,700, for the same protection. And ESU buys security patches only — no feature updates, no non-security fixes, and no technical support from Microsoft.
Why this matters more in Massachusetts
201 CMR 17.00 requires any business holding personal information about a Massachusetts resident to maintain a written information security program, and among the safeguards it names is keeping system security software reasonably up to date (Mass.gov).
The regulation does not list operating system versions, and nobody is going to audit you for running Windows 10. The problem is what happens afterwards.
If there is an incident, and the forensic answer is that the affected machines had been running without security updates for a year while the business knew, that is a much worse conversation than the incident itself. It is also the answer that turns up in insurance disputes and in the vendor questionnaires larger clients now send down their supply chain.
Remember too that this applies on the strength of your own payroll records, not just customer data. You do not need Massachusetts customers to be in scope — you need one Massachusetts employee.
What we would actually do, in order
Count the machines and check each one. Not “we have about fifteen laptops” — an actual list with model, age, and whether it meets the Windows 11 requirements. The blocker is usually the TPM 2.0 security chip and the processor generation, and the split is rarely what people guess. A typical result is that two thirds upgrade free and the remainder need replacing.
Split the fleet into three groups. Upgrades in place, which cost nothing but time. Replacements, which need budget. And anything that cannot move for a specific reason — a machine tied to old software, an instrument PC, a device a vendor will not certify. That third group is what ESU is genuinely for.
Decide before October. If any machine will still be on Windows 10 after October 2026, enrolling now costs a third of enrolling later. If the whole fleet can migrate before then, you skip ESU entirely.
Sequence the migration so nobody loses a day. This is the part that gets underestimated. Upgrading in place takes a couple of hours per machine and occasionally goes wrong; replacements need the standard build, the profile, the printers and the line-of-business software. Done one or two at a time around people’s schedules, a twenty-machine office is a few weeks of background work. Done all at once on a Friday, it is a bad Monday.
Write it down. The audit you just did — what you own, what you decided, what you bought — is most of the “identify and assess” work that your WISP needs anyway. Do it once, use it twice.
The honest summary
If every machine can run Windows 11, this is a scheduling problem and ESU is irrelevant to you. Migrate at a sensible pace and be done.
If some machines cannot, you have until October to buy the cheap year rather than two expensive ones, and three years total before the bridge ends. Either way the decision benefits from knowing exactly what you own, and most offices we walk into do not.
If you are not sure which situation you are in, text us with a rough machine count and we can tell you what the audit usually turns up.
Sources
- Microsoft — Windows 10 Extended Security Updates
- Managed Solution — Windows 10 Extended Security Updates: what you need to know before October 2026
- TrustedTech — Windows 10 ESU: 10 things you need to know
- Commonwealth of Massachusetts — 201 CMR 17.00 compliance checklist
Frequently asked questions
- Our Windows 10 machines still work fine. What is the actual risk?
- Working and supported are different things. Since October 2025 every vulnerability found in Windows 10 stays open unless you are paying for extended updates. The machine keeps booting and the risk accumulates quietly, which is exactly why this gets postponed — nothing visibly degrades until something goes badly wrong.
- Is Windows 11 really going to run on our hardware?
- Most business machines from 2019 onward upgrade in place. The blocker is usually a security chip called TPM 2.0 and the processor generation. It is worth checking per machine rather than assuming: we regularly find offices where two thirds upgrade free and the rest need replacing, and knowing the split changes the budget conversation entirely.
- Can we just keep paying for extended updates indefinitely?
- No. The programme runs a maximum of three years from October 2025, so it ends in October 2028 and cannot be extended further. It is a bridge with a known end, and each year of that bridge costs double the last. Treat it as time to migrate in, not as an alternative to migrating.
- Does an unsupported operating system actually breach 201 CMR 17.00?
- The regulation does not name operating system versions. What it requires is reasonably up-to-date security patches and a documented assessment of risks to personal information. A fleet knowingly running without security updates is difficult to describe as reasonably up to date, and after an incident that is the question you will be asked.