Windows 10 stopped receiving security updates on 14 October 2025. That deadline has been and gone, and the machines still work, which is precisely the problem — nothing visibly broke, so nothing forced a decision.
Almost a year later, the question is no longer whether to move. It is what the bridge costs, and whether paying for it makes sense against simply replacing the machine. Microsoft’s Extended Security Updates programme has a deliberately escalating price, and Year One coverage runs out next month. So this is the point where a business either commits to another year of paying to delay, or stops.
Here is the actual arithmetic, and what Axio Networks does across our own client base in Scottsdale and the Phoenix metro.
What ESU actually costs
Microsoft’s commercial Extended Security Updates pricing for Windows 10 is per device, per year, and it doubles annually:
- Year 1 — $61 per device. Covers November 2025 to October 2026.
- Year 2 — $122 per device.
- Year 3 — $244 per device. The programme ends in October 2028.
Two details matter more than the headline numbers.
The pricing is cumulative. You cannot skip a year and join later at the current rate. A business that did not buy Year 1 and wants coverage for Year 2 pays for Year 1 as well — $183 per device to get current. There is no option to buy in halfway.
The device must be on Windows 10 version 22H2. An older build does not qualify, so any machine not already there needs updating before it can receive updates at all.
Run the whole programme and you spend $427 per device across three years, and in October 2028 you own a machine that is three years older than it is today, still running an operating system that has now genuinely reached the end of the line. ESU is not a strategy. It is a deliberately uncomfortable way to buy time, priced so that buying time stops making sense.
What “end of support” actually means for a business
The machine keeps working. That is what makes this easy to defer, and it is also the trap.
What stops is patching. Every vulnerability discovered in Windows 10 from October 2025 onward stays open on an unpatched machine, permanently. The gap does not hold steady, it widens every month — and because patched systems get the fix publicly, each Patch Tuesday effectively publishes a list of things that still work against the machines that did not get it.
Three consequences land on a small business before any of that becomes an incident:
Your cyber insurance application asks. Unsupported operating systems appear directly on renewal questionnaires, and as we cover in our guide to what cyber insurance covers and what gets denied, an inaccurate answer is not a small problem. Carriers now verify rather than take your word for it.
Modern access controls will start refusing it. This is not theoretical for us — blocking unsupported operating system types is one of the standard Conditional Access policies we deploy. A device running something that no longer receives security updates does not get to authenticate. Increasingly the machine will not be excluded from your environment by an attacker; it will be excluded by your own policy, or by a client’s.
Compliance obligations do not have an exception for “it still works.” If you handle regulated data, an unsupported operating system is a finding.
What we actually do about it
Across our entire client base, under 5% of machines are still running Windows 10 — and every one of those is covered by Extended Security Updates. Nothing is sitting unpatched and unprotected while somebody decides.
The decision rule is simple. If a machine can move to Windows 11 without creating a problem bigger than an employee not liking Windows 11, it gets upgraded. Preference is not a technical blocker, and the upgrade is free where the hardware qualifies.
We buy ESU only where it is genuinely necessary — as a bridge for a specific machine with a specific reason, not as a default position for an estate. Paying $122 a device in ESU Year 1 to avoid a decision, and $244 in Year 2 to avoid it again, is how a deferred cost becomes a larger one.
And where a machine cannot take Windows 11, our answer is usually not ESU either. It has aged out of service and gets replaced. A computer that fails the Windows 11 requirements is typically old enough that its remaining working life is short, and spending $427 over three years to keep it limping is money that would have gone further toward the machine that replaces it.
The hardware blocker is rarer than people expect
Much of the Windows 11 conversation has been about TPM 2.0 and processor generations, and a lot of businesses assume their fleet will fail.
In practice we do not hit that often. The requirements are loose enough that most business-class systems qualify, and when we do find a machine that genuinely cannot be upgraded, the hardware requirement is rarely the real story — the machine is simply old. The Windows 11 check is functioning as an age test, and it is usually telling you something you already knew.
Before assuming a replacement cycle, it is worth actually checking rather than estimating. Most of the fleets we migrate turn out to be in better shape than the owner feared.
The genuine exception, and how to handle it safely
There is a real category where none of the above applies, and pretending otherwise is unhelpful.
Some businesses run equipment whose control software is not compatible with newer versions of Windows. Production machinery, laboratory instruments, diagnostic equipment, specialist manufacturing systems — hardware that cost a great deal, works perfectly, and is tied to a computer that cannot be changed without replacing the whole thing.
Across our client base, fewer than five machines run an operating system older than Windows 10, and every one of them is exactly this case. We do not pretend they are fine, and we do not tell the client to scrap functioning production equipment. We isolate them:
- Severely restricted internet access — only the specific services that machine genuinely requires, and nothing else.
- No access to the rest of the internal network. The machine cannot reach file shares, other workstations, or anything it does not strictly need. If it is compromised, the compromise stops there.
- Treated as untrusted by design, with network segmentation doing the work the operating system can no longer do.
That is the best available answer: the business keeps operating, the equipment keeps earning, and the risk is contained to a single box that cannot reach anything worth reaching. It is a deliberate exception with controls around it — which is a completely different thing from an unsupported machine sitting on the main network because nobody got round to it.
What to do in the next month
- Count them. Not an estimate — an actual list of which machines are still on Windows 10, and which of those are on 22H2. You cannot make the ESU decision without the number.
- Check what is only on those machines. Ageing hardware failing is the single most common cause of data loss we deal with. Before you retire or replace anything, confirm nothing important lives solely on the device.
- Sort each one into upgrade, replace, or isolate. Most will be upgrade. A few will be replace. Isolate should be a very short list with a specific reason attached to each entry.
- Decide about Year 2 deliberately. If ESU is genuinely needed, buy it knowing it costs $122 per device in Year 1 and $244 in Year 2. If it is not, do not renew by default.
- Check what your policies already say. If your Conditional Access blocks unsupported operating systems, the deadline may arrive as a login failure rather than a security incident.
- Answer your insurance renewal accurately. An honest “some devices remain on Windows 10 with ESU, with a replacement plan by date X” is a far better answer than an optimistic one.
Frequently asked questions
Is Windows 10 still safe to use?
Not without Extended Security Updates. Support ended on 14 October 2025, so vulnerabilities found since then are never patched on an unenrolled machine, and the exposure grows every month. With ESU applied it continues to receive security fixes, which is a holding position rather than a solution.
How much does Windows 10 ESU cost for a business?
Commercial pricing is $61 per device for Year 1, $122 for Year 2 and $244 for Year 3, and it is cumulative — buying in at Year 2 means paying for Year 1 as well, so $183 per device. The programme ends in October 2028, and the full three years totals $427 per device.
Can I skip a year of ESU and rejoin later?
No. The programme is cumulative, so you pay for the years you missed in order to buy the current one. There is no discounted entry point later.
Is upgrading to Windows 11 free?
Yes, where the hardware meets the requirements. The cost is not the licence, it is the time to do the upgrade properly and the small number of machines that turn out to need replacing.
What if my machine does not meet the Windows 11 requirements?
In our experience that is less common than people expect, and when it happens the machine is usually simply old. Our default is replacement rather than paying an escalating annual fee to keep an ageing device on an unsupported operating system.
We have a machine that runs production equipment and cannot be upgraded. What do we do?
Isolate it. Restrict its internet access to only the services it genuinely requires, and prevent it from reaching the rest of the internal network. The equipment keeps working and any compromise is contained to that one device. This is a legitimate exception when it is a deliberate, documented decision with controls around it.
Will an unsupported operating system affect our cyber insurance?
It can. Unsupported operating systems appear on renewal questionnaires, and carriers increasingly verify what they are told rather than accepting an attestation. Answer accurately and include the remediation plan.
Sources and further reading
- Microsoft: Windows 10 Extended Security Updates — pricing, eligibility and programme dates.
- Microsoft: Windows 11 system requirements.
- CISA Known Exploited Vulnerabilities Catalog.
Talk to an IT team in Scottsdale
Most Microsoft 365 tenants are running on defaults that were set once and never revisited.
Axio Networks is a managed IT and cybersecurity provider based in Scottsdale, Arizona. Founded in 2019, we support small and mid-sized businesses across the Phoenix metro — Scottsdale, Phoenix, Tempe, Chandler, Mesa, Gilbert and Fountain Hills — with an under-30-minute average response time.
Start with a free IT assessment, call 480-602-2946, or email [email protected].
Related: Managed Microsoft 365 · Cloud services