Skip to content
Under attack?Get emergency help now
All articles
31 August 2026F1 IT Solutions

Still on Windows 10? Your Grace Year Ends This October

Windows 10Windows 11Managed ITPatchingMicrosoft 365

When Windows 10 reached end of support in October 2025, most organisations did one of two things: they finished their move to Windows 11, or they bought themselves a year with Microsoft's Extended Security Updates (ESU) programme.

That year is nearly up. On 13 October 2026 the first ESU period ends, and the ground shifts again. If your business still has Windows 10 machines on the network, the next six weeks are the cheapest and calmest this project will ever be.

What actually changes on 13 October 2026

Three things happen at once, and they affect home-grade and business devices differently.

Consumer ESU ends outright. Microsoft's consumer ESU programme was a one-year bridge only. There is no second year. Any Windows 10 machine enrolled through the consumer route stops receiving security updates entirely, which matters more than many owners realise, because plenty of small businesses run on devices enrolled this way.

Business ESU doubles in price. Organisations can buy ESU Year 2, which runs from October 2026 to October 2027 at a list price of US$122 per device, double Year 1's US$61. Year 3 doubles again to US$244. The licences are also cumulative: if you skipped Year 1 and want Year 2, you pay for both. Rand and pound pricing varies by reseller, but the doubling pattern is the point.

Microsoft 365 Apps carry on, the OS does not. Microsoft will keep issuing security updates for Microsoft 365 Apps on Windows 10 until October 2028. That protects Word, Excel and Outlook, not the operating system underneath them. An up-to-date Outlook on an unpatched OS is still an unpatched machine.

Why this is a business risk, not an IT detail

Every month, Microsoft patches vulnerabilities in Windows 11. Attackers study those patches and look for the same weaknesses in systems that no longer receive them. An unsupported operating system does not get riskier gradually; it accumulates known, documented holes that nobody is closing.

That shows up in places beyond the machines themselves. Cyber insurers increasingly ask whether unsupported software is in use, and regulators on both sides of our client base, POPIA in South Africa and GDPR in the UK and Europe, expect appropriate technical measures to protect personal information. A fleet of out-of-support machines is hard to defend under either framework. In our own vulnerability management work, unsupported operating systems are findings that never close, and they drag the whole risk picture down.

Your three realistic options

1. Upgrade what qualifies

Windows 11 is a free upgrade for eligible hardware, and the requirements (TPM 2.0 and a supported processor, among others) are the usual sticking point. Check eligibility centrally rather than machine by machine: a provider running proper managed IT services can pull this from monitoring and inventory tools across the fleet in one pass.

2. Replace what does not

Machines that fail the hardware check are generally older devices approaching replacement anyway. Treat this as a planned refresh rather than an emergency purchase, and stagger it in waves so budgets and staff disruption stay manageable. Structured hardware and software procurement also avoids the premium that comes with last-minute buying in early October.

3. Buy ESU as a deliberate bridge, not a strategy

ESU Year 2 is the right answer for a small number of machines that genuinely cannot move yet, such as devices tied to legacy line-of-business software or specialised equipment. It is the wrong answer as a fleet strategy: at US$122 per device, doubling each year, it costs more than it saves within a couple of cycles, and it buys time without reducing risk.

A 60-day plan that avoids an October scramble

  1. Inventory first. List every device, its Windows build, its Windows 11 eligibility and its owner. This is a day's work with proper tooling, and it turns an anxious unknown into a short list.
  2. Decide per device. Upgrade, replace, bridge with ESU, or retire. Most fleets split cleanly once the inventory exists.
  3. Pilot with one team. Confirm that the applications, printers and VPN behave on Windows 11 before rolling out widely.
  4. Check your backups before the waves start. A migration is exactly the wrong moment to discover a restore problem, something we have written about in why your backup plan might fail when you need it most.
  5. Handle the stragglers properly. Buy ESU for the short list that needs it before 13 October, and wipe retiring machines so no company or personal data leaves with them.

The takeaway

Deadlines like this reward the organisations that move early. Two months is comfortably enough time to inventory a fleet, upgrade the willing machines and plan around the awkward ones, but only if the work starts now rather than in the second week of October. Whether you run this in-house or with a partner, start with the inventory this week; everything else follows from it.

Want this handled for you?

Talk to the F1 team about cybersecurity, AI and managed IT for your business.