
Windows 10 Extended Security Updates: Year 1 Ends October 13, 2026, and Waiting Costs Double
If your business still runs Windows 10, you have until October 13, 2026 to make a decision that gets more expensive after that date.
That is the end of Year 1 of the Windows 10 Extended Security Updates program for commercial customers. The important part is not the date itself. It is how the pricing works: organizations entering the program in a later year must purchase the earlier years as well before receiving current coverage. Waiting does not defer the cost. It adds to it.
Roughly six weeks remain. Here is what to decide and how.
Where the deadlines actually sit
Windows 10 reached end of support on October 14, 2025. Since then, unenrolled devices have received no security updates at all.
For commercial and educational organizations, ESU runs in three annual terms:
- Year 1: October 15, 2025 to October 13, 2026
- Year 2: October 14, 2026 to October 12, 2027
- Year 3: ends October 10, 2028
Three years is the maximum. There is nothing after that.
The cumulative pricing rule is the whole story
This is the part worth understanding properly, because it is the reason six weeks matters.
ESU is purchased year by year, and each year costs more than the last — the published commercial price roughly doubles annually. Starting in a later year requires purchasing all previous years first.
So an organization that skipped Year 1 and enrolls in Year 2 does not simply pay the Year 2 price. It pays Year 1 plus Year 2, for coverage it did not have during Year 1. Delaying enrolment to save money produces the opposite result.
There is a second-order effect worth noting: devices enrolled retroactively receive the security patches already released during the covered period. So the money is not entirely wasted — but you spent the intervening months unprotected and then paid for the privilege.
If ESU is part of your plan, enrol before October 13. If it is not, that is a legitimate decision, but make it deliberately rather than by missing a date.
Verify current pricing and enrolment mechanics in Microsoft’s Extended Security Updates documentation before you commit. Figures move.
Do not read the consumer headlines as applying to you
In mid-2026 Microsoft extended the consumer ESU program, pushing coverage for personal devices to October 2027. That change was widely reported and it is genuinely useful — for consumers.
It does not change the commercial program. If you are running Windows 10 Pro or Enterprise devices in a business, you are on the commercial track with the annual terms and cumulative pricing described above. Several businesses we have spoken to read the consumer announcement and concluded the deadline had moved. It did not move for them.
Check which program your devices fall under before making a decision based on a headline.
What ESU actually gives you
Less than people assume:
- Critical and Important security updates only. No feature updates, no bug fixes, no performance improvements.
- Security-related technical support only. Not general support for Windows 10.
- No new functionality, ever. The operating system is frozen.
ESU is a bridge, not a destination. It buys planning time for organizations that genuinely cannot replace hardware inside the window. It is not a strategy.
The certificate expirations nobody budgeted for
A separate issue lands in the same period and is easy to miss.
Several Secure Boot certificates that ship in Windows devices reach expiry during 2026. Devices with expired certificates can lose the ability to validate boot components properly, and remediating this across a fleet requires firmware updates from hardware manufacturers, not just Windows patches.
This affects Windows 10 and Windows 11 devices alike, so it is not solved by upgrading. But it does mean 2026 is a year when older hardware needs attention regardless of your ESU decision — and if you are replacing devices anyway, it is one more reason to do it sooner rather than at the same time everyone else does.
The real reason businesses are stuck
Very few organizations chose to stay on Windows 10. They are stuck because Windows 11 has hardware requirements — TPM 2.0 and a supported processor generation among them — that a meaningful share of working, perfectly serviceable machines do not meet.
That turns an operating system upgrade into a hardware purchase, which turns it into a budget conversation, which is why it gets deferred.
Your options per device, honestly:
Upgrade in place. Free, fast, and available only where the hardware qualifies. Run a compatibility assessment across the fleet before assuming anything — the answer is usually better than people expect for machines bought in the last four or five years.
Replace the device. The right answer for hardware already near the end of its service life. If a machine is five years old and needs replacing within eighteen months anyway, buying ESU for it is spending money twice.
ESU for a defined period. Appropriate where a specific application or device genuinely blocks the move and the constraint has a known resolution date.
Retire or repurpose. Some machines run one application that could move elsewhere, or serve a function that no longer needs a full Windows PC.
Most fleets end up with a mix. What matters is that every device falls into a category deliberately.
What to do in the next six weeks
- Inventory the fleet. Every Windows device, its version, its age, and its Windows 11 compatibility status. Include the machines nobody thinks about — the one running the label printer, the one in the warehouse, the laptop in a drawer that someone still logs into.
- Sort into the four categories above. Upgrade, replace, ESU, retire.
- Get a current ESU quote for whatever lands in the ESU bucket. You need a real number to make the comparison against replacement cost.
- Decide before October 13. Enrolling after that date costs more for the same coverage.
- Check your cyber insurance policy. Many contain language allowing a claim to be denied where a breach occurred on unsupported software. Confirm in writing whether your insurer treats an ESU-covered device as supported.
This is not the only deadline in your environment
If you are running Windows 10 on the desktop, there is a reasonable chance the servers behind it are also approaching a date. Windows Server 2016 end of support arrives on January 12, 2027, and SQL Server 2016 end of support has already passed.
Businesses that handle these as three separate emergencies spend considerably more than businesses that inventory once and plan them together. The inventory work is nearly identical; doing it three times is the expensive part.
Where ITsoft fits
We manage endpoint fleets and the infrastructure behind them for businesses across the United States, including environments where downtime is measured in work that does not get done rather than in tickets. Our managed service provider and help desk and remote IT support engagements cover fleet inventory, compatibility assessment, and staged rollouts — and our IT infrastructure installation services cover the replacement side when hardware has to change.
If you cannot say today how many Windows 10 devices you have and how many can take Windows 11, that is the first thing to fix, and it takes days rather than weeks.
Talk to Mike Treat about a Windows 10 fleet assessment — we will inventory your devices, report which can upgrade and which cannot, and give you the ESU-versus-replace comparison with real numbers. The report is yours regardless.
Related reading: Windows Server 2016 end of support · SQL Server 2016 end of support · managed service provider services · data backup and recovery




