Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

Windows 10 End of Support: What Your Business Should Do Now

In short

Windows 10 stopped getting security updates on 14 October 2025. Running it now leaves known holes unpatched, which is a real risk and a Cyber Essentials fail. Your options are to upgrade eligible PCs to Windows 11, replace older hardware, or buy short-term Extended Security Updates as breathing room. This guide walks you through a calm, budgeted plan.

The short version

On 14 October 2025, Microsoft ended support for Windows 10. If some or all of your business computers still run it, this guide is for you. There is no need to panic, but there is a need to plan. This is one of those quiet IT problems that costs nothing to ignore today and a great deal to ignore for a year.

Below we explain, in plain English, what “end of support” actually means, why it matters more than most people assume, and the three realistic options in front of you.

What “end of support” really means

When Microsoft supports a version of Windows, it releases updates every month. Most of these quietly fix security holes — weaknesses that criminals and their automated tools look for. It is a bit like a manufacturer issuing recalls: something dangerous is found, and a fix is pushed out to everyone before it can be exploited.

End of support switches that off. From 14 October 2025, no more security updates are made for Windows 10. Any new weakness discovered after that date simply stays open.

End of support does not mean your PCs stop working on the day. It means they stop getting fixed.

That is the trap. The computer boots up, your email opens, your accounts package runs, and everything feels normal. Nothing flashes red. So the deadline slides past, months go by, and the machine becomes steadily more exposed while looking exactly as it did before.

Why this is a genuine risk, not just Microsoft nudging you to spend

It is fair to be sceptical when a supplier tells you to buy new things. But the risk here is real and well understood.

  • The holes are public. When a serious Windows flaw is found, it gets written up and discussed openly. Attack tools are updated to use it within days. On a supported system you get a patch; on Windows 10 you now get nothing, so the door stays open and everyone knows it is there.
  • Attackers specifically target unsupported systems. They know exactly which businesses have not moved on, because unpatched machines are the easiest way in. An unsupported operating system is one of the first things a criminal probes for.
  • It fails Cyber Essentials. The government-backed Cyber Essentials scheme requires all your software, including Windows itself, to be supported and receiving updates. Run Windows 10 now and you cannot pass. If you already hold the certificate, you fail at renewal — which can breach contracts and invalidate the cyber-insurance cover that depends on it.
  • Your other software follows. Over time, browsers, security tools and business applications stop supporting Windows 10 too. The machine slowly becomes an island that nothing new will run on.

None of this means your business is hacked the moment the deadline passes. It means your risk has quietly gone up and will keep rising the longer you wait. This is why we treat it as a core part of managed IT and cyber-security, not an optional upgrade.

Your three realistic options

For almost every business, the answer is one of these three, and usually a mix.

Option 1: Upgrade eligible PCs to Windows 11

Windows 11 is the current supported version, and for machines that qualify, the upgrade is free and reasonably straightforward. It looks and behaves much like Windows 10, so staff adjust quickly.

The snag is eligibility. Windows 11 requires a specific security chip (TPM 2.0) and a fairly modern processor. Computers bought before roughly 2018 often fail this check. Microsoft’s free PC Health Check tool tells you, machine by machine, which ones can upgrade — and that is genuinely the first practical step. You cannot plan until you know how many of your PCs qualify.

Option 2: Replace the hardware

For machines that cannot run Windows 11, replacement is the honest answer. This sounds like the expensive option, and it is the biggest line item, but there are two things worth remembering.

First, if a computer is old enough to be blocked from Windows 11, it is usually old enough to be slowing your staff down anyway. The cost buys back real time. Second, you do not have to do it all at once — replacements can be phased over months to spread the cost, prioritising the oldest and most exposed machines first.

Option 3: Extended Security Updates (ESU) as a bridge

Microsoft sells Extended Security Updates — paid, short-term security patches that keep a Windows 10 machine receiving fixes for a limited time. Think of ESU as a bridge, not a destination. It is useful when:

  • You have a specific machine tied to old software that cannot move yet, or
  • You need a few months of breathing room to budget and roll out replacements in an orderly way rather than a rushed one.

ESU is sensible in small doses. Paying year after year to keep an entire ageing fleet on life support is rarely good value — that money is usually better put toward the machines you were going to need anyway.

How to plan the move without the panic

The difference between an expensive scramble and a calm project is a short, written plan. Here is the sequence we use.

  1. Take an inventory. List every computer, who uses it, and what runs on it. You cannot make good decisions about machines you have not counted.
  2. Run the eligibility check. Use PC Health Check across the fleet. Sort every machine into one of three piles: upgrade to Windows 11, replace, or bridge with ESU for now.
  3. Check your key software. Confirm your important applications — accounts, practice management, industry-specific tools — are supported on Windows 11 before you move. This is almost always fine, but it is a five-minute check that prevents a nasty surprise.
  4. Budget and phase it. Spread replacements across a sensible timeline. Do the oldest and most exposed machines first, and use ESU only to cover the genuine stragglers.
  5. Back up before you touch anything. Any hardware change is a moment where data can go missing. A tested 3-2-1 backup means a failed upgrade is an inconvenience, not a disaster.

The honest bottom line

Windows 10 machines still work, and that is precisely why this problem gets ignored. But every month that passes, an unsupported operating system carries known, unpatched weaknesses, fails your Cyber Essentials position, and drifts further from the software your business relies on.

The fix is not dramatic. It is a list, an eligibility check, and a phased budget. Done calmly over a few months, it costs less and hurts less than a rushed replacement after something goes wrong.

If you would like a hand taking the inventory, checking which machines qualify, and building a costed plan that fits your budget, get in touch. We will tell you plainly what needs doing now and what can wait — and you can see how we price ongoing support on our pricing page.

Frequently asked questions

Will my Windows 10 computers stop working now that support has ended?

No. They will keep switching on and running your software as before. The change is invisible day to day, which is exactly what makes it risky. Microsoft has simply stopped issuing the monthly security updates that fix newly discovered flaws, so any weakness found from now on stays open on your machines. The device keeps working while quietly becoming less safe to use.

Is running Windows 10 after end of support a Cyber Essentials fail?

Yes. Cyber Essentials requires that all software, including the operating system, is supported by the vendor and receiving security updates. An unsupported operating system means you cannot pass certification, and if you already hold Cyber Essentials you would fail at renewal. For many firms that also affects insurance and the contracts that require the certification.

Can I upgrade my existing PCs to Windows 11 for free?

If the hardware meets Microsoft's requirements, yes, the upgrade itself is free. The catch is that many machines bought before roughly 2018 lack the required security chip (TPM 2.0) or a supported processor and cannot upgrade. Microsoft's PC Health Check tool tells you which of your computers qualify, and that check is the first job in any plan.

What are Extended Security Updates and should we pay for them?

Extended Security Updates (ESU) are paid, short-term security patches from Microsoft for machines still on Windows 10. They are a bridge, not a destination, buying you time to budget and roll out replacements in an orderly way. They make sense for a handful of stubborn machines or a phased plan, but paying to keep an ageing fleet on life support is rarely good value.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.