October 14, 2025 was the date Windows 10 support officially ended. Most small businesses didn't feel it, because Microsoft offered a bridge: Extended Security Updates, a program that keeps critical and important security patches flowing to Windows 10 for a limited time after that cutoff. A lot of owners enrolled, breathed easy, and moved on to other priorities. That first year of coverage runs out October 13, 2026, which is now about four weeks away. What happens next depends entirely on whether that gets noticed before or after the patches stop.
1. The deadline that already passed wasn't the real deadline
It's easy to assume "Windows 10 end of life" was a one-time event that already happened and got handled. In reality, ESU turned it into a series of smaller deadlines. Consumers could enroll for free with certain conditions, or pay a small one-time fee, for a single year of coverage. Businesses enroll through volume or cloud licensing on a per-device basis, with coverage available for up to three years past the original end-of-support date. Each of those years is its own deadline, and each one costs more than the last. Assuming last year's enrollment carries forward automatically is the mistake that turns a planned transition into a scramble in the second week of October.
2. Paid ESU is a bridge, not a destination
Business ESU pricing roughly doubles with each additional year of coverage, which is by design. Microsoft built the program to buy time for a migration, not to be a permanently affordable alternative to upgrading. A business that leans on ESU year after year without a plan behind it ends up paying an escalating annual fee for an operating system that still won't be supported once the program ends entirely. Treating this deadline as the moment to finalize a migration timeline, rather than the moment to renew and move on again, is what keeps the eventual cost from compounding.
3. The upgrade path isn't the same for every machine
Windows 11 requires a TPM 2.0 security chip and a processor from a supported generation, requirements that rule out a meaningful share of PCs bought before roughly 2019. For those machines, there is no in-place software upgrade to buy time with, replacement is the only real option. That's exactly why the right first step isn't picking an ESU tier, it's a full hardware inventory: which machines can upgrade in place, which need replacing, and which are running software old enough that the hardware refresh needs to happen alongside an application review, not after it. Skipping that inventory is how businesses end up buying another year of ESU for a PC they were going to replace anyway.
Why this is a security question, not just an IT budget line
An unpatched operating system doesn't announce itself. The machine keeps working exactly as it did the day before, which is precisely what makes it easy to deprioritize. But every vulnerability discovered in Windows 10 after ESU coverage lapses stays open on that device indefinitely, with no patch coming. That risk doesn't stay contained to one PC either, a single compromised machine on a network is often the starting point for the kind of lateral movement covered in how ransomware actually gets into a small business. Closing that gap is part of the same discipline behind ongoing patch management generally, treating an end-of-support operating system with the same urgency as a missed critical patch, because functionally that's exactly what it is.
Frequently asked questions
What actually happens to a Windows 10 PC after ESU ends?
Nothing happens instantly. The computer keeps turning on and running the software already installed. What stops is new security patches for Windows 10 itself, which means every vulnerability found after that date stays open on that machine indefinitely unless another year of ESU is purchased or the device moves to a supported operating system.
Is business ESU the same program as the free consumer year?
No. The free or low-cost path was built for individual consumer devices. Business ESU is licensed per device through a volume or cloud program, runs up to three years past the October 2025 end-of-support date, and the price roughly doubles each additional year, so year one costs the least it will ever cost.
Can every Windows 10 PC just be upgraded to Windows 11 instead?
Not always. Windows 11 requires a TPM 2.0 security chip and a supported processor generation, which a meaningful share of five-plus-year-old business PCs don't have. Those machines need replacement hardware, not just a software upgrade, which is exactly why an inventory has to come before a plan.
Why does an unpatched Windows 10 PC matter if it's behind a firewall?
A firewall controls what reaches the device from outside the network. It does nothing once an employee opens an attachment, plugs in a USB drive, or a different infected machine on the same network tries to spread. An unpatched operating system is still the easiest place for that kind of compromise to succeed and stay in place.
Not sure how many machines on your network are still running Windows 10?
30 minutes with an engineer with DoD infrastructure experience. We'll walk through a device inventory and lay out what needs to move before the next ESU deadline hits.
Book your free assessmentPrefer to talk first? Email sales@ghosxt.com or call (831) 204-0501.