Yes, Windows 10 still runs. Your machines boot, Excel opens, the printer works, nobody is locked out. That part hasn’t changed since Microsoft ended support on October 14, 2025. What changed is that Windows 10 stopped receiving security patches on that date, and every month since then the gap between “patched” and “your PC” has widened.

We’re most of the way through 2026 now. That’s roughly twenty Patch Tuesdays that Windows 11 got and Windows 10 didn’t. Vulnerabilities disclosed in that window — and there have been plenty — are permanent on an unpatched Windows 10 box. Attackers know exactly which population of machines is still sitting there.

So the honest answer to “can I still use Windows 10” is: it works, it’s not safe, and for a business there’s a third problem nobody warns you about — your insurer and your compliance obligations may already consider you non-compliant. That’s the part that turns a technical annoyance into a financial one.

What “end of support” actually means

It’s a narrower thing than most people assume, and also worse. Microsoft didn’t flip a kill switch. Nothing expired. Here’s the concrete list of what stopped:

What kept working: everything else. Microsoft 365 apps on Windows 10 continued getting security updates on a separate, longer runway — Microsoft committed to that through October 2028, though feature updates stopped earlier. Defender definition updates also continued. Chrome and Edge kept shipping. That combination is why nothing appeared to break on October 15, 2025, and why a lot of small businesses concluded the warnings were overblown.

The erosion is slower than that. It shows up as third-party vendors quietly dropping Windows 10 from their supported platform list. A line-of-business app updates and now requires Windows 11. A new printer or scanner ships with no Windows 10 driver. Your accounting software’s next major version won’t install. Each of those is survivable alone; together, over eighteen months, they add up to a machine you can’t do your job on.

The ESU program, and what it costs now

Microsoft offered Extended Security Updates as a paid bridge — critical and important security patches only, no new features, no general support. It came in two flavors.

The consumer program covered a single year, from October 2025 to October 2026, at $30 per device. Microsoft also opened free routes into it: enroll with a Microsoft account and Windows Backup syncing your settings to OneDrive, or redeem 1,000 Microsoft Rewards points. That enrollment prompt appeared in Settings under Update & Security > Windows Update for eligible machines running 22H2.

The commercial program runs up to three years, priced per device per year, and it escalates deliberately — roughly $61 for year one, doubling to about $122 for year two, and doubling again to around $244 for year three. That pricing curve isn’t accidental. It’s designed to make staying on Windows 10 progressively more expensive than replacing the hardware.

Timing note: the consumer ESU year expires in October 2026. If you enrolled last autumn as a stopgap, your bridge runs out in a matter of months. Businesses on the commercial track are heading into the year-two price doubling. Either way, this is the quarter to decide, not next spring.

One thing ESU does not do: it doesn’t fix the compliance problem in every case. Some auditors and insurers treat “vendor-supported” and “receiving security patches” as the same box. Others specifically ask whether the OS is in mainstream support. Read the actual question on your form before assuming ESU satisfies it.

Why half your machines can’t take Windows 11

This is the genuinely frustrating part, and it’s the reason so many small offices are stuck. Windows 11 has a hardware floor that has nothing to do with whether the machine is fast enough.

The requirements: TPM 2.0, UEFI firmware with Secure Boot capability, 64-bit processor with at least 2 cores at 1 GHz or better, 4 GB RAM, 64 GB storage — and, critically, a CPU on Microsoft’s approved list. That list starts at Intel 8th generation (Coffee Lake, 2017-2018) and AMD Ryzen 2000 series. Anything older is off the list regardless of specs.

So a well-specced 2017 workstation with an i7-7700K, 32 GB of RAM, and an NVMe drive — a machine that will comfortably outrun a budget 2024 laptop — is not supported. Meanwhile a slow 2018 Celeron with 4 GB is fine. That’s the CPU list talking, not performance.

Before you write a machine off, check whether TPM is simply disabled in firmware. It’s shipped disabled on a lot of business desktops. Press Win + R, type tpm.msc, press Enter. If you see “Compatible TPM cannot be found,” reboot into UEFI setup (usually F2, F10, or Del at boot) and look for a setting called PTT (Intel Platform Trust Technology), fTPM (AMD firmware TPM), or plainly Security Device Support. Enable it, save, reboot, recheck. On Intel machines from 2016 onward this alone fixes a surprising number of “unsupported” verdicts.

Also confirm the disk is GPT and boot mode is UEFI rather than legacy BIOS. Run msinfo32 and look at “BIOS Mode.” If it says Legacy, you’ll need to convert the disk with mbr2gpt /validate /allowFullOS then mbr2gpt /convert /allowFullOS from an elevated command prompt, and switch the firmware to UEFI. Back up first — this touches the partition table.

The compliance angle small businesses keep missing

Here’s where “it still works fine” gets expensive.

Cyber liability insurance applications have gotten dramatically more specific over the past few years. Most now ask directly whether all operating systems in your environment are vendor-supported and receiving security updates. You answer that question in writing. If you check yes while running unpatched Windows 10, you’ve made a misrepresentation on an insurance application — and the time you find out that matters is when you file a claim after a breach.

Carriers have denied claims on exactly this basis. It isn’t hypothetical.

On the regulatory side: HIPAA’s Security Rule doesn’t name Windows versions, but §164.308(a)(1)(ii)(A) requires risk analysis and §164.308(a)(5)(ii)(B) requires protection from malicious software. An OS that can’t receive patches is a documented, unmitigated risk. Auditors treat it that way. PCI DSS is blunter — Requirement 6.3.3 requires critical security patches installed within one month of release, and 12.3.4 requires review of hardware and software technologies at least annually to confirm they’re still vendor-supported. There’s no path to compliance on an unpatched OS handling card data.

If you do any work under a government contract or subcontract, CMMC and NIST 800-171 have equivalent flow-control requirements. Same conclusion.

The practical version for a ten-person shop: your OS choice is now visible to your insurer, your auditor, and increasingly to enterprise clients who send you vendor security questionnaires before they’ll sign. It stopped being purely an internal decision.

Your options, ranked by what actually makes sense

1. Upgrade in place, where the hardware allows it

Cheapest good outcome. Free license, keeps your files and most applications, takes 30-60 minutes per machine. Run the PC Health Check tool or just open Settings > Windows Update and see whether Windows 11 is offered.

Before you pull the trigger on a business machine: verify your line-of-business software is supported on Windows 11, verify your printer and scanner drivers exist, and take a full image backup. Windows keeps a rollback window of 10 days by default, and that’s genuinely useful — but an image is better.

2. Replace the hardware

For machines already five to eight years old, this is usually the right call even setting Windows aside. A business-class laptop in the $700-1,100 range or a small-form-factor desktop around $600-900 will outlast the next OS cycle too. Refurbished off-lease business machines with 8th-gen or newer Intel chips run $250-450 and are a legitimate option for light users — front desk, shared workstations, kiosk roles.

Do it in waves, not all at once. Replace the oldest third now, the next third next fiscal year. Spreads the cost and the disruption.

3. ESU as a deliberate bridge

Fine as a bridge with a date on it. Not fine as a strategy. If you’re using ESU, you should be able to say which quarter each covered machine gets replaced. “We’ll deal with it later” plus ESU is just paying for the privilege of procrastinating, and the year-two and year-three pricing makes that expensive fast.

4. Move the workload off Windows entirely

Underrated for the right roles. If someone’s whole job is a browser, email, and a web-based CRM, a ChromeOS Flex install on the existing hardware or a Chromebook gives you a supported, patched, hard-to-infect device with almost no retraining. Linux Mint or Ubuntu on old hardware works too, but only if you have someone in-house comfortable supporting it — otherwise you’ve traded a security problem for a support problem.

The honest limit: if the person runs QuickBooks Desktop, a Windows-only practice management app, or anything with a hardware dongle, this doesn’t apply.

Decision table by machine profile

Machine profileWin 11 eligible?Recommended moveRough cost/device
2021+ business laptop or desktopYesUpgrade in place now; it’s overdue$0 + ~1 hr labor
2018–2020, 8th-gen Intel / Ryzen 2000+, 8 GB+Usually — check TPM in firmware firstEnable TPM/PTT, add RAM or SSD if needed, upgrade$0–120
2016–2018, 6th/7th-gen Intel, decent specsNo — CPU not on the listReplace this fiscal year; ESU only as a dated bridge$250–900
Pre-2016, spinning hard drive, 4 GB RAMNoRetire. Not worth ESU dollars.$450–900 replacement
Browser-only user on ineligible hardwareNoChromeOS Flex on existing box, or a Chromebook$0–350
Machine tied to legacy hardware or an old appN/AIsolate on its own VLAN, no internet, ESU, plan replacement of the appESU + config time

If you’re staying on Windows 10 for now, do these things

Sometimes the budget genuinely isn’t there this quarter. Fine — reduce the blast radius instead of pretending the risk isn’t real.

None of that makes Windows 10 supported. It makes an unsupported machine a smaller problem while you fix the real one.

Common questions

Will Windows 10 stop working at some point?

Not from Microsoft’s side. There’s no expiration date in the OS and no plan to disable it. Windows 7 machines still boot today. What ends it in practice is the software around it — a browser that stops updating, an app that requires a newer OS, a driver that never gets written. Expect that squeeze to tighten noticeably through 2027.

Is the free Windows 11 upgrade still available in 2026?

Yes. Microsoft never set a hard cutoff for the free upgrade path from a licensed Windows 10 install, and eligible machines are still being offered it through Windows Update. They’ve reserved the right to end it, so there’s no reason to wait — but if your machine qualifies, you’re not paying for a license.

Can I force Windows 11 onto an unsupported PC?

Technically yes — registry bypasses and modified installers exist. For a business, don’t. Microsoft states these machines aren’t entitled to updates, some bypassed installs have failed on later feature updates, and you’d be relying on an unsupported configuration for a system your revenue depends on. Also worth noting: an auditor or insurer asking “is your OS supported by the vendor” gets an awkward answer either way. If the hardware doesn’t qualify, replace the hardware.

Does ESU cover Office and my other software too?

No. ESU is operating system security patches only — critical and important severity, nothing else. Microsoft 365 apps had their own separate support timeline on Windows 10. Third-party software follows whatever each vendor decides. ESU keeps the floor from rotting; it doesn’t cover what’s sitting on it.

How much downtime should we plan for an office-wide upgrade?

For an in-place upgrade on a healthy machine with an SSD, budget 45-90 minutes of unavailable time per PC, plus 15-20 minutes of settling afterward — reconnecting printers, re-signing into apps, letting search reindex. For fresh hardware with data migration, plan half a day per person. Most small offices we work with run these in batches of three or four after hours across a couple of weeks. Doing the whole office in one night is how you end up with a Monday morning nobody enjoys.

Leave a Reply

Your email address will not be published. Required fields are marked *