- Key Takeaways
- What Does "End of Support" Actually Mean for Windows 10?
- What Is the Real Timeline for Windows 10 End of Life and ESU?
- What's Affected: Which Devices and Products Reached End of Life Alongside Windows 10?
- What's the Impact of Continuing to Run Windows 10 After End of Support?
- How Do You Detect Which Devices in Your Environment Still Run Windows 10?
- What Is the Remediation and Migration Checklist?
- Upgrade, ESU, or an Alternative OS: Which Option Is Right for You?
- Limitations
- What Would Encryption Consulting Recommend?
- Frequently Asked Questions
- Conclusion
Quick answer: Windows 10 reached end of support on October 14, 2025: Microsoft no longer issues security patches or technical support for it. Devices still run but grow more vulnerable each month. If you’re still on Windows 10, audit your fleet, enroll in Extended Security Updates (ESU) as a bridge, and migrate to Windows 11 or new hardware before ESU coverage ends.
Key Takeaways
- Windows 10 support officially ended on October 14, 2025. Microsoft no longer ships security patches, feature updates, or free technical support for it.
- Consumer Extended Security Updates (ESU) extend critical security patches through October 12, 2027, via three enrollment paths: free (with Windows Backup sync), 1,000 Microsoft Rewards points, or a one-time $30 purchase.
- Enterprise ESU is sold through Volume Licensing, per device, for up to three years, with pricing that doubles annually: $61 (Year 1), $122 (Year 2), and $244 (Year 3).
- Many Windows 10 PCs cannot upgrade to Windows 11 because they lack a TPM 2.0 chip, a supported processor, or UEFI Secure Boot.
- Running an unsupported OS creates unpatched CVE exposure, compliance gaps under frameworks like PCI DSS, HIPAA, and ISO/IEC 27001, and potential cyber insurance complications.
Published: September 2025. Updated: August 2026. Reviewed by Encryption Consulting’s security team.
What Does “End of Support” Actually Mean for Windows 10?
“End of support,” also called end of life (EOL), means Microsoft has stopped maintaining Windows 10. A Windows 10 PC still boots, still runs installed software, and still connects to networks. What it no longer gets is the ongoing maintenance that kept it safe: no monthly security patches, no bug fixes, no new features, and no free technical support from Microsoft. Every newly discovered vulnerability, or CVE (Common Vulnerabilities and Exposures record), that affects Windows 10 after this date stays unpatched on that operating system unless the device is enrolled in Extended Security Updates.
This distinguishes end of support from a product being discontinued or removed. Windows 10 keeps working exactly as before; the risk is invisible until an attacker exploits a flaw that Windows 11 and actively supported systems already have a fix for.
What Is the Real Timeline for Windows 10 End of Life and ESU?
Windows 10 Home, Pro, Enterprise, Education, and several specialty editions all reached end of support on October 14, 2025 (6:59:59 a.m. Pacific Time on October 15, per Microsoft’s Modern Lifecycle Policy). That date has already passed. Here is where things stand now and what comes next:
- October 14, 2025: Windows 10 mainstream support ended. Last supported feature version: 22H2.
- Now through October 12, 2027: Consumer ESU coverage window, for devices individually enrolled.
- Now through October 2028: Enterprise and commercial ESU window, capped at three purchasable years past end of support.
- After ESU expires: no further security patches for Windows 10 from Microsoft under any program.
The Extended Security Updates (ESU) program is a paid (or, for consumers, sometimes no-cost) bridge that delivers critical and important security fixes only. It does not include new features, non-security bug fixes, or standard technical support, and it is not a substitute for migrating off Windows 10.
How Do Individual Consumers Enroll in ESU?
Consumers can enroll an eligible Windows 10 (version 22H2) device in ESU through one of three paths, all giving identical coverage through October 12, 2027:
- No additional cost: enable Windows Backup to sync PC settings to a Microsoft account.
- Microsoft Rewards: redeem 1,000 Microsoft Rewards points.
- One-time purchase: pay $30 USD (or local currency equivalent, plus tax); one license can cover up to 10 devices tied to the same Microsoft account.
What Does Enterprise or Business ESU Cost?
Organizations enroll through Microsoft Volume Licensing, per device, on an annual basis, and cannot buy partial years. Pricing doubles each year and is capped at three years total:
- Year 1 (through roughly October 2026): $61 per device.
- Year 2 (through roughly October 2027): $122 per device.
- Year 3 (through roughly October 2028): $244 per device.
For a fleet of any real size, the math argues for migration, not renewal. A 5,000-device fleet still on Windows 10 into Year 3 of ESU is paying $244 per device that same year alone, on top of Years 1 and 2, for security patches only, with no new features and no path beyond the three-year ceiling.
What’s Affected: Which Devices and Products Reached End of Life Alongside Windows 10?
The October 14, 2025 cutoff was not limited to the Windows 10 operating system. Microsoft aligned several other widely deployed products to the same date. Audit your environment for all of the following, not just endpoints:
- Windows 10 editions: Home, Pro, Enterprise, Education, IoT Enterprise, Enterprise LTSB 2015, and Team (Surface Hub).
- Office 2016 and Office 2019: perpetual license versions, no longer receiving security updates.
- Exchange Server 2016 and Exchange Server 2019: on-premises mail servers requiring migration to a supported version or Microsoft 365.
- Visio 2016/2019, Project 2016/2019, Skype for Business Server 2015/2019, and Visual Studio 2015: also reached end of support the same day.
Within Windows 10 itself, the devices most exposed are ones that cannot meet Windows 11’s hardware requirements: a compatible 64-bit processor, 4 GB of RAM, 64 GB of storage, UEFI with Secure Boot, and, most often the blocker, a TPM (Trusted Platform Module) 2.0 chip. PCs built before roughly 2018, and many built through 2020, frequently fail on TPM or processor compatibility even when every other spec is sufficient.
What’s the Impact of Continuing to Run Windows 10 After End of Support?
The operating system does not stop working, so the risk is easy to underestimate. Three consequences compound the longer a fleet stays on unsupported Windows 10:
- Unpatched CVE accumulation: every vulnerability Microsoft’s security teams find in Windows 10 after October 14, 2025 goes unpatched outside of ESU. Attackers actively target newly disclosed flaws in end-of-life software because the exploit window never closes. This is the same underlying exposure that drives malware and ransomware campaigns against outdated endpoints.
- Compliance failures: frameworks such as PCI DSS, HIPAA, SOC 2, and ISO/IEC 27001 generally require systems that process regulated data to run on vendor-supported software. An unsupported OS in scope for an audit is a documented finding, not a gray area, and it can jeopardize certification renewal.
- Cyber insurance implications: insurers increasingly ask about supported-software posture during underwriting and claims review. A breach traced to an unpatched, end-of-life OS can affect a claim outcome or renewal terms, independent of how the breach actually occurred.
There is a certificate and cryptography dimension too. Older Windows 10 builds carry older, unpatched TLS stacks and certificate-handling libraries. As unsupported endpoints age past their last update, they become harder to keep current on trusted root stores, cipher suite policy, and certificate validation logic, adding a quiet layer of crypto-agility risk on top of the OS itself.
How Do You Detect Which Devices in Your Environment Still Run Windows 10?
You cannot remediate what you have not inventoried. Before building a migration plan, confirm the actual scope:
- Pull an OS-version compliance report from Microsoft Intune, Configuration Manager (SCCM), or your existing endpoint management platform, filtered to Windows 10, any build.
- Run a fleet-wide query (for example, PowerShell’s
Get-CimInstance Win32_OperatingSystem) against your CMDB or asset inventory to catch devices outside your management tooling. - Cross-check each Windows 10 device against Windows 11 hardware requirements to segment “eligible for a free upgrade” from “needs new hardware.”
- Include devices your IT team may not directly manage: kiosks, lab and shop-floor PCs, remote and BYOD endpoints, and legacy servers running Windows 10 IoT.
- Where you already run cryptographic asset discovery or certificate lifecycle tooling, cross-reference the OS inventory against certificate and key material tied to those hosts. Unsupported operating systems are a common blind spot in otherwise mature crypto inventories.
What Is the Remediation and Migration Checklist?
Work through these steps in order. This is the practical sequence for moving a fleet off unsupported Windows 10, not a theoretical framework:
- Inventory every endpoint still running Windows 10, including build number, hardware specs, and business owner.
- Check each device against Windows 11 minimum requirements (TPM 2.0, supported CPU, UEFI Secure Boot, 4 GB RAM, 64 GB storage).
- Sort devices into three tracks: free upgrade eligible, hardware refresh required, or ESU bridge required for a defined period.
- Enroll any device that must stay on Windows 10 past today in consumer or enterprise ESU immediately; do not let coverage lapse between end of support and enrollment.
- Prioritize migration for internet-facing systems, privileged-access workstations, and anything in scope for a compliance framework or cyber insurance policy.
- Update vulnerability scanning, patch management, and asset management tools to explicitly flag Windows 10 and other end-of-life software as high-priority findings.
- Re-run compliance questionnaires and cyber insurance disclosures with the current, accurate supported-software status of your fleet.
- Set a hard internal deadline well ahead of your ESU expiration date (October 12, 2027 for consumer ESU; up to October 2028 for enterprise ESU) to have every device fully migrated.
Upgrade, ESU, or an Alternative OS: Which Option Is Right for You?
There is no single correct answer for every device. Use the comparison below against your actual inventory and risk tolerance:
| Option | Cost | Coverage Window | Best For | Main Tradeoff |
|---|---|---|---|---|
| Upgrade to Windows 11 (existing PC) | Free, if hardware is eligible | Ongoing, current mainstream support | Devices that already meet TPM 2.0 and CPU requirements | Requires app and driver revalidation |
| New Windows 11 or Copilot+ PC | Hardware purchase cost | Ongoing, current mainstream support | Devices that fail Windows 11 requirements | Capital cost and deployment effort |
| Consumer ESU | Free (Windows Backup), 1,000 Rewards points, or $30 one time | Through October 12, 2027 | Individuals needing a short bridge | Security-only, no features or standard support |
| Enterprise ESU | $61 to $244 per device per year, doubling annually | Up to 3 years (through October 2028) | Organizations phasing a larger migration | Cost multiplies yearly; still time-limited |
| Migrate to an alternative OS (Linux, ChromeOS Flex) | Low to no licensing cost | Ongoing, vendor-dependent | Legacy or low-requirement hardware, non-Windows-dependent workloads | Application compatibility and retraining |
Limitations
This guidance is general and does not replace Microsoft’s own lifecycle documentation for your specific product edition. A few caveats worth flagging:
- ESU pricing, enrollment mechanics, and regional availability are set by Microsoft and can change; confirm current terms before budgeting or purchasing.
- Windows 10 IoT Enterprise LTSC and other Long-Term Servicing Channel editions follow separate lifecycles from mainstream Home, Pro, and Enterprise editions and may have different end dates.
- Consumer ESU enrollment is tied to a Microsoft account; organizations should use the enterprise ESU path through Volume Licensing rather than the consumer program.
- This article focuses on Windows 10 and directly related Microsoft products; it does not cover every third-party application that may separately lose vendor support on its own schedule.
What Would Encryption Consulting Recommend?
Treat the Windows 10 migration deadline as a forcing function, not just an IT ticket. Every unsupported endpoint you leave running is also an endpoint whose certificates, cipher suites, and cryptographic libraries you can no longer patch. That is exactly the kind of blind spot that shows up in a compliance audit or a post-incident review months later.
Encryption Consulting’s Encryption Advisory Services and Compliance Advisory Services help organizations turn an OS migration into a broader security upgrade rather than a one-time scramble:
- Build a prioritized migration and ESU-bridge plan aligned to compliance deadlines and business risk, not just IT convenience.
- Identify certificates, keys, and crypto libraries tied to end-of-life devices through cryptographic asset discovery, so nothing gets orphaned mid-migration.
- Modernize PKI infrastructure with PKI-as-a-Service, reducing dependency on aging, unsupported on-premises systems as endpoints refresh.
- Automate certificate discovery and lifecycle management with CertSecure Manager so certificate visibility does not depend on any single unsupported host.
- Map the migration against active compliance frameworks (PCI DSS, HIPAA, ISO/IEC 27001, SOC 2) so the audit trail shows deliberate remediation, not a gap discovered by an auditor.
Encryption Consulting is ISO/IEC 27001:2022 and SOC 2 certified and has delivered 500+ encryption and cybersecurity projects across 25+ countries, guiding enterprises through assessment, roadmap development, implementation, and ongoing optimization. Whether you are still deciding between ESU and a hardware refresh, or you have already started migrating, our team can help make sure the encryption and PKI layer moves with you, not after you.
Frequently Asked Questions
Is Windows 10 still safe to use after end of support? It is not actively unsafe on day one, but it becomes progressively riskier. Without security updates, every newly discovered Windows 10 vulnerability stays exploitable indefinitely unless the device is enrolled in Extended Security Updates (ESU). For personal, low-risk use, short-term exposure is manageable; for business, regulated, or internet-facing systems, it is a real and growing liability.
What is ESU (Extended Security Updates)? ESU is Microsoft’s paid, and for some consumers no-cost, program that continues delivering critical and important security patches for Windows 10 after its October 14, 2025 end-of-support date. It does not include new features, non-security bug fixes, or standard technical support, and it is explicitly a temporary bridge, not a long-term substitute for upgrading.
Is consumer ESU really free? It can be, for individual users. Enrolling with Windows Backup enabled (syncing PC settings to a Microsoft account) costs nothing. Alternatively, users can redeem 1,000 Microsoft Rewards points or pay a one-time $30 fee, which can then cover up to 10 devices linked to the same account. All three paths provide identical coverage through October 12, 2027.
Can I still reinstall or reactivate Windows 10 after end of support? Yes. End of support does not disable existing installations or block reinstallation using a valid license. What ends is Microsoft’s ongoing maintenance: no further security patches, feature updates, or free technical support outside of ESU enrollment.
What happens when ESU coverage itself runs out? Consumer ESU ends October 12, 2027. Enterprise ESU can run up to three years past end of support, through roughly October 2028, after which Microsoft issues no further security updates for Windows 10 under any program. Devices still running Windows 10 at that point have no vendor-supported path to remain patched and should already be migrated.
Conclusion
Windows 10 end of support is no longer a future deadline to plan around; it is a fact you are already operating under. The ESU program buys real, verifiable time, up to two years for consumers and up to three for organizations, but it is priced and designed to make renewal progressively less attractive than migration. The organizations that come out ahead are the ones that used ESU as a deliberate, time-boxed bridge to Windows 11 or new hardware, not as a way to defer the decision indefinitely. Start with an honest inventory of what is still running Windows 10, and work the checklist above until that number is zero.
References
- Microsoft Support: Windows 10 support has ended on October 14, 2025
- Microsoft: Windows 10 Consumer Extended Security Updates (ESU)
- Microsoft Learn: Extended Security Updates for Windows 10
- Microsoft Lifecycle: Products reaching end of support on October 14, 2025
- Microsoft Lifecycle: Windows 10 Home and Pro
- Microsoft Learn: Windows 11 requirements
- Key Takeaways
- What Does "End of Support" Actually Mean for Windows 10?
- What Is the Real Timeline for Windows 10 End of Life and ESU?
- What's Affected: Which Devices and Products Reached End of Life Alongside Windows 10?
- What's the Impact of Continuing to Run Windows 10 After End of Support?
- How Do You Detect Which Devices in Your Environment Still Run Windows 10?
- What Is the Remediation and Migration Checklist?
- Upgrade, ESU, or an Alternative OS: Which Option Is Right for You?
- Limitations
- What Would Encryption Consulting Recommend?
- Frequently Asked Questions
- Conclusion
