Windows 10 stopped receiving security updates on 14 October 2025. That was ten months ago, and a surprising number of Greater Boston offices are still running it on at least some machines.

That is understandable. Nothing visibly broke. The machines still boot, Outlook still opens, staff still work. The cost of not migrating has been zero so far, which is exactly what makes it easy to keep postponing.

There is a deadline in October that makes postponing more expensive, and it is worth understanding before it passes.

The paid extension, and why the date matters

Microsoft sells Extended Security Updates — critical and important security patches only, for machines still on Windows 10. For businesses buying through volume licensing the pricing is deliberately uncomfortable:

YearPeriodCost per device
Year 1Oct 2025 – Oct 2026$61
Year 2Oct 2026 – Oct 2027$122
Year 3Oct 2027 – Oct 2028$244

The price doubles every year, and the programme stops after three (Managed Solution, TrustedTech).

The part that catches people is not the doubling. It is this: an organisation that waits and buys in Year 2 cannot buy Year 2 alone — it has to buy Year 1 retroactively as well.

So for a business still on Windows 10 today with no ESU coverage, the arithmetic is:

  • Enrol before October 2026: $61 per device
  • Enrol after: $61 + $122 = $183 per device

For twenty machines that is the difference between roughly $1,200 and $3,700, for the same protection. And ESU buys security patches only — no feature updates, no non-security fixes, and no technical support from Microsoft.

Why this matters more in Massachusetts

201 CMR 17.00 requires any business holding personal information about a Massachusetts resident to maintain a written information security program, and among the safeguards it names is keeping system security software reasonably up to date (Mass.gov).

The regulation does not list operating system versions, and nobody is going to audit you for running Windows 10. The problem is what happens afterwards.

If there is an incident, and the forensic answer is that the affected machines had been running without security updates for a year while the business knew, that is a much worse conversation than the incident itself. It is also the answer that turns up in insurance disputes and in the vendor questionnaires larger clients now send down their supply chain.

Remember too that this applies on the strength of your own payroll records, not just customer data. You do not need Massachusetts customers to be in scope — you need one Massachusetts employee.

What we would actually do, in order

Count the machines and check each one. Not “we have about fifteen laptops” — an actual list with model, age, and whether it meets the Windows 11 requirements. The blocker is usually the TPM 2.0 security chip and the processor generation, and the split is rarely what people guess. A typical result is that two thirds upgrade free and the remainder need replacing.

Split the fleet into three groups. Upgrades in place, which cost nothing but time. Replacements, which need budget. And anything that cannot move for a specific reason — a machine tied to old software, an instrument PC, a device a vendor will not certify. That third group is what ESU is genuinely for.

Decide before October. If any machine will still be on Windows 10 after October 2026, enrolling now costs a third of enrolling later. If the whole fleet can migrate before then, you skip ESU entirely.

Sequence the migration so nobody loses a day. This is the part that gets underestimated. Upgrading in place takes a couple of hours per machine and occasionally goes wrong; replacements need the standard build, the profile, the printers and the line-of-business software. Done one or two at a time around people’s schedules, a twenty-machine office is a few weeks of background work. Done all at once on a Friday, it is a bad Monday.

Write it down. The audit you just did — what you own, what you decided, what you bought — is most of the “identify and assess” work that your WISP needs anyway. Do it once, use it twice.

The honest summary

If every machine can run Windows 11, this is a scheduling problem and ESU is irrelevant to you. Migrate at a sensible pace and be done.

If some machines cannot, you have until October to buy the cheap year rather than two expensive ones, and three years total before the bridge ends. Either way the decision benefits from knowing exactly what you own, and most offices we walk into do not.

If you are not sure which situation you are in, text us with a rough machine count and we can tell you what the audit usually turns up.

Sources

Frequently asked questions

Our Windows 10 machines still work fine. What is the actual risk?
Working and supported are different things. Since October 2025 every vulnerability found in Windows 10 stays open unless you are paying for extended updates. The machine keeps booting and the risk accumulates quietly, which is exactly why this gets postponed — nothing visibly degrades until something goes badly wrong.
Is Windows 11 really going to run on our hardware?
Most business machines from 2019 onward upgrade in place. The blocker is usually a security chip called TPM 2.0 and the processor generation. It is worth checking per machine rather than assuming: we regularly find offices where two thirds upgrade free and the rest need replacing, and knowing the split changes the budget conversation entirely.
Can we just keep paying for extended updates indefinitely?
No. The programme runs a maximum of three years from October 2025, so it ends in October 2028 and cannot be extended further. It is a bridge with a known end, and each year of that bridge costs double the last. Treat it as time to migrate in, not as an alternative to migrating.
Does an unsupported operating system actually breach 201 CMR 17.00?
The regulation does not name operating system versions. What it requires is reasonably up-to-date security patches and a documented assessment of risks to personal information. A fleet knowingly running without security updates is difficult to describe as reasonably up to date, and after an incident that is the question you will be asked.