The Windows 10 Deadline That Actually Costs You Money

by Sep 18, 2026Business, Microsoft, security, Technology, Windows0 comments

Windows 10 Extended Security Updates Year 1 ends October 13, 2026

The short version

  • Commercial Windows 10 Extended Security Updates Year 1 ends October 13, 2026.
  • Year 2 costs $122 per device, double Year 1. Year 3 doubles again to $244.
  • Coverage is cumulative. Enroll late and you pay for the year you skipped as well.
  • The $30 consumer plan is not available for business PCs, whatever you have read about it.

October 13, 2026 is the date that matters for any business still running Windows 10. That is when Year 1 of the commercial Extended Security Updates program closes and the cheapest version of this problem stops being available. Everything after it costs more, and the increases are not small.

What ESU actually buys you

Windows 10 reached end of support on October 14, 2025. The machines kept working, which is exactly why so many businesses did nothing about it. Extended Security Updates is Microsoft’s paid bridge: enroll a device and it keeps receiving security patches for up to three more years. No new features, no technical support, just the security fixes that stop a PC becoming a liability sitting on your network.

Year 1 runs from November 2025 to October 13, 2026 at $61 per device, or closer to $45 if the machines are managed through Intune or Windows Autopatch. Year 2 is $122. Year 3 is $244. The price doubles on purpose, because ESU was built as a ramp toward migration rather than a place to park indefinitely.

The part that catches people out

Coverage is cumulative, and this is where budgets get wrecked. Microsoft’s own documentation is blunt about it: if you decide to purchase the program in Year Two, you have to pay for Year One too. Skipping this year does not save you $61 per machine. It defers a bill that arrives later at $183 per machine, and it leaves those machines unpatched in the meantime.

There is a second trap worth naming, because it comes up constantly. The widely reported $30 consumer ESU option, along with the free routes through Windows settings sync or Microsoft Rewards points, cannot be used on business PCs. Domain-joined machines and anything enrolled in mobile device management are explicitly excluded. If someone on your team has been budgeting around that $30 figure, the real number is at least double it.

ESU is a bridge with a toll that doubles every year. It buys time to migrate properly. It is not a substitute for migrating.

The options that actually exist

For a business with Windows 10 machines still in service, there are four honest paths and one that only looks like a path:

  • Upgrade in place. Hardware that meets the Windows 11 requirements can move now at no licensing cost. Verify TPM 2.0 and the supported processor list before you promise anyone a date.
  • Replace the hardware. Machines that fail those requirements were usually due for replacement anyway. Weigh the replacement cost against three years of escalating per-device fees.
  • Buy Year 2 and commit to a date. Reasonable when a line-of-business application genuinely is not certified for Windows 11 yet. Put the migration date in writing when you buy.
  • Move the workload to the cloud. ESU is included with Windows 365 and Azure Virtual Desktop, which changes the arithmetic for some roles entirely.
  • Do nothing. The PCs keep booting, which is what makes this tempting and what makes it dangerous.

Why doing nothing is the expensive option

An unpatched Windows 10 machine does not announce itself. It boots, runs Office, reaches your file shares and looks identical to every other PC in the building. What changes is that every vulnerability published after its coverage ends stays open permanently, on a device sitting inside your network with a staff member’s credentials saved on it.

The compliance problem tends to arrive before the breach does. Cyber insurance renewals increasingly ask whether your systems still receive vendor security updates, and a growing number of policies treat unsupported operating systems as grounds for exclusion. Any business with contractual security obligations, regulated data or card payment processing will find that unsupported endpoints surface as an audit finding long before an attacker finds them.

What to do between now and October 13

Start with an inventory, because most businesses are wrong about how many Windows 10 machines they still have. Count them, check each one against the Windows 11 hardware requirements, then split the list into upgrade, replace and blocked. The blocked pile is almost always smaller than people fear, and it is usually tied to one specific application rather than the hardware.

Then price the two columns honestly. Three years of ESU across twenty devices is $8,540 before anyone touches a keyboard, and at the end of it you still own twenty machines running an operating system Microsoft has stopped supporting altogether. The same money often covers replacement hardware that is faster, under warranty, and supported into the next decade.

The deadline itself is arbitrary. Microsoft picked the date. What it forces is not arbitrary at all, because every business still running Windows 10 in 2026 has already made a decision by default, and October 13 is simply the moment that decision starts generating invoices.

Not sure how many Windows 10 machines you still have?

Most businesses underestimate it. PTSI will inventory your fleet, tell you which machines can upgrade and which need replacing, and give you the real cost of each path before the October 13 deadline.

Book a Windows 10 audit

PTSI Editorial Team

Support Line: Phone: +1 646-535-HELP (4357) Email: helpdesk@progressny.com Support web: helpdesk.progressny.com