The short version: the first year of Windows 10 Extended Security Updates (ESU) ends on 13 October 2026. Any Windows 10 PC not enrolled in year two stops getting security fixes. Before that date, sort every client PC into three groups: upgrade, replace, or pay for ESU. Anything left over needs a written risk sign-off from the client. Start with the client list this week.
What ends on 13 October 2026?
The first ESU year ends on 13 October 2026. Microsoft ended normal Windows 10 support on 14 October 2025. ESU was the paid way to keep receiving critical and important security updates after that. Microsoft's ESU page says year one starts in November 2025, and consumers get a single year only.
For businesses, the program continues if you buy it. Microsoft says enrolled commercial PCs can receive updates for a maximum of three years after end of support. ESU is not free, and it does not include technical support or new features.
What does it cost?
Microsoft lists $61 USD per device for year one. The price doubles each year, up to three years. That makes year two $122 USD and year three $244 USD.
Two catches:
- ESU is cumulative. If a client skipped year one and wants year two, they pay for both.
- The PC must run Windows 10 version 22H2. Older builds are not eligible, so check this first.
Microsoft also says ESU is included at no extra cost for Windows 10 virtual machines on Azure Virtual Desktop, Windows 365 and Azure VMs. A client with cloud PCs may not need to pay per device at all.
Why this matters for compliance
The Essential 8 maturity model from the Australian Signals Directorate expects operating systems that vendors no longer support to be replaced. For a client working towards Essential 8 Maturity Level 1 or 2, a Windows 10 PC with no security updates is a failed patching control. It can also cost points on cyber insurance forms and government supplier questionnaires, which ask whether all devices run supported software.
ESU is a vendor security update stream, so it may keep a PC patched on paper. It is also a time-limited bridge. Ask the client's assessor how they treat ESU devices, and get the answer in writing. We cover the underlying control in our Essential 8 patch management guide.
If you're a small business
Ask your IT provider for a list of every PC that still runs Windows 10, and the age of each. Many machines from before 2018 fail the Windows 11 hardware check. If the PC is old, replacing it usually costs less over three years than paying ESU at $61, then $122, then $244 USD. Those three years add up to $427 USD per device.
Then decide, PC by PC: upgrade, replace, or pay for one more year.
If you're an MSP
Pull the device list from your RMM or Intune. Group every Windows 10 PC into one of these:
| Group | Test | Action |
|---|---|---|
| Upgrade | Passes the Windows 11 check | Schedule the upgrade through Intune or Windows Update for Business |
| Replace | Fails the check, PC older than about four years | Quote a hardware refresh |
| Bridge | Needs more time, for example a line-of-business app | Buy ESU for that device, with a replacement date |
| Exception | Cannot be replaced or bridged | Isolate it and get a written sign-off |
Bring the bridge and exception lists to the client as a short, priced note. This is a project you can quote now, not an emergency after 13 October.
Worked example
A 20-person accounting firm has 24 PCs. Sixteen already run Windows 11. Five run Windows 10 and pass the hardware check, so you upgrade them in a weekend through Intune. Three fail the check and are seven years old. The firm replaces them. Nothing needs ESU, and the firm's insurer questionnaire can honestly say every device is supported.
If those three PCs could not be replaced until January, you would enrol them in ESU for $61 USD each and note the January replacement date in the risk register.
What to put in writing
For any PC that stays on Windows 10 with no ESU, get the owner to sign a short note that names the device, the risk, the compensating steps (no email, no admin rights, separate network) and an end date. It protects the client and it protects you. Without it, you are the one holding an undocumented risk when an insurer or auditor asks.
Your checklist
- Export every Windows 10 device for every client.
- Check each one for version 22H2 and the Windows 11 hardware requirements.
- Sort devices into upgrade, replace, bridge or exception.
- Send each client a priced plan before 13 October 2026.
- Enrol bridge devices in ESU and diarise the replacement date.
- Get a signed risk note for each exception.
- Record the outcome against the patching control in the client's Essential 8 assessment.
How CYBERWHITE helps
CYBERWHITE runs Essential 8 assessments across a whole MSP client portfolio, so the patch operating systems control and its evidence sit in one place for every client. See MSP solutions, the Essential 8 page, or pricing.
Sources
- Microsoft Learn: Extended Security Updates (ESU) program for Windows 10
- Australian Signals Directorate (ASD): Essential Eight maturity model
Keep reading: Essential 8 Patch Management Guide · The evidence problem: you did the security work, but can you prove it?