Windows 10 left mainstream support on 14 October 2025. Most businesses we speak to did one of three things that month: upgraded what could be upgraded, bought a year of Extended Security Updates for the rest, or quietly did nothing and hoped. All three groups now have a date to deal with, because year one of commercial ESU ends on 13 October 2026, and year two costs twice as much as year one did.
ESU was always meant as a bridge, not a destination. The pricing is designed to make each extra year hurt more than the last, and it works. The question for this October is not whether to renew, but which machines have earned one more year and which ones you are simply avoiding.
Where the numbers stand
Microsoft's commercial ESU pricing is public and deliberately steep:
- Year one (to 13 October 2026): about US$61 per device.
- Year two (to October 2027): about US$122 per device.
- Year three (to October 2028): about US$244 per device, and that is the end of the road.
ESU is cumulative. A business that skipped year one and wants to join now pays for year one as well, because the updates are cumulative too. There is no cheap way in late.
Two exceptions are worth knowing. Windows 10 running in Microsoft's own cloud desktops, Windows 365 and Azure Virtual Desktop, receives ESU without the per-device charge. And the separate consumer ESU programme is aimed at home PCs, not a business fleet, so it is not a loophole for the office.
At the rand exchange rate, a twenty-PC office paying for year two is looking at the price of several new mid-range laptops, spent on keeping old ones alive for twelve months.
The three groups, and what each should do now
You upgraded everything
Check that it is true. The most common surprise in an IT health check this year has been the Windows 10 machine nobody counted: the PC in the workshop that drives a label printer, the reception machine that runs the CCTV viewer, the laptop in a drawer that a sales rep takes on the road twice a month. Pull the operating-system report from whatever manages your devices, and if nothing manages them, walk the building.
You bought year one
This is the group with a real decision to make. Year one was the reasonable choice for many businesses: it bought time to budget, to wait for a line-of-business vendor to certify Windows 11, or to replace hardware on a sensible schedule rather than in a panic. Renewing everything again at double the price is rarely the reasonable choice. Split the list:
- Renew only machines with a specific, written reason and a date by which that reason goes away. "The payroll package is certified on Windows 11 from its March release" is a reason. "We haven't got round to it" is not.
- Upgrade machines that meet the Windows 11 hardware requirements. A surprising number were bought in 2019 or 2020 and qualify; they were left on Windows 10 by habit.
- Replace the rest. The ESU money for year two is a meaningful deposit on the hardware.
You did nothing
Your Windows 10 PCs have had no security fixes for nearly a year. Every vulnerability found in that time is unpatched on them, and attackers do read Microsoft's monthly patch notes to find out what still works against older systems. This is the group we worry about, because the risk does not announce itself. The PC works perfectly right up to the day it is the way in.
An unsupported PC does not slow down or show a warning. It keeps working exactly as before, which is precisely why it gets left on the network.
Why "it still works" is not the test
The case for keeping an old PC is usually that nothing is wrong with it. That is true of the hardware and irrelevant to the risk. An unpatched machine on the same network as your accounting system is not a problem for that machine alone: it is a foothold. Ransomware rarely lands on the server directly. It lands on the least-maintained device that can reach the server, and moves from there.
Two other costs are easy to miss. Your cyber insurance questionnaire almost certainly asks whether every device runs a supported operating system, and a claim after an incident is exactly when an insurer checks the answer. And under POPIA you are expected to take reasonable technical measures to protect personal information. Running an operating system its maker has stopped fixing is a difficult position to call reasonable.
If a machine genuinely cannot move yet
Some PCs exist to run one thing: a CNC controller, a lab instrument, an old access-control console. If it cannot be upgraded and ESU is not justified, isolate it. Take it off the general network, remove email and web browsing, block it from reaching the file server, and let it talk only to the device it controls. A contained old machine is an accepted risk; an old machine on the open office network is an unmanaged one.
Checking which PCs can take Windows 11
Windows 11 needs a TPM 2.0 security chip, Secure Boot, and a processor from roughly 2018 onwards: Intel 8th generation or AMD Ryzen 2000 series and newer, broadly. Microsoft's PC Health Check app gives a yes or no per machine, and most device-management tools report it across the fleet. Two practical notes:
- TPM is often present but switched off in the firmware settings on business desktops. A machine that "fails" may pass after a five-minute change in the BIOS.
- Do not use the workarounds that bypass the hardware check. They install Windows 11 on unsupported hardware, which Microsoft does not guarantee to keep updating. You would be trading one unsupported state for another.
Make the replacement plan boring
The businesses that handled this well did not do anything clever. They had a hardware register, a replacement cycle of four or five years, and a line in the IT roadmap that budgeted for it. The Windows 10 deadline was then just another year's refresh, slightly larger than usual.
If you are replacing a batch now, use the moment to fix what else was drifting: enrol the new machines in proper device management, turn on disk encryption, make sure updates install themselves, and remove local administrator rights from day-to-day accounts. Those are the basics that make the next operating-system deadline a non-event.
Before 13 October
- Count. Every Windows 10 device, including the ones in drawers and workshops.
- Test. Run the hardware check on each one and note which pass.
- Decide per device. Upgrade, replace, isolate, or renew with a written reason and an end date.
- Budget the renewals honestly. Year two at double the price, with year three at double again waiting behind it.
Done properly, the renewal list should be short enough to read aloud. If it is not, the list is telling you something about your hardware cycle, not about Microsoft's pricing.