Skip to main content
Dig IT Solutions logo

Managed IT Support

Windows 10 is out of support: what businesses still on Windows 10 must do

Windows 10 support ended 14 October 2025. What UK businesses must do: Extended Security Updates, Windows 11 hardware requirements, Cyber Essentials and refresh.

By Dig IT SolutionsUpdated 8 September 20266 min read

Short answer

Windows 10 reached end of support on 14 October 2025 and no longer receives security updates unless a business pays for Extended Security Updates, available for up to three years. Unsupported Windows 10 fails Cyber Essentials. Upgrade eligible PCs to Windows 11, replace those lacking TPM 2.0 or a supported processor, and use ESU only to bridge the refresh.

Windows 10 reached end of support on 14 October 2025. Microsoft's product lifecycle page is unambiguous: no more security updates, no more fixes, no more support for Home and Pro editions. Nearly a year on, many businesses still have Windows 10 machines in daily use, sometimes because they were not aware, more often because replacing them was deferred. This guide sets out what the end of support means, what Extended Security Updates do and do not cover, which PCs can move to Windows 11, what it means for Cyber Essentials and how to plan the refresh without disruption.

What end of support means in practice

Windows 10 PCs did not stop working in October 2025, and that is the problem. They look the same, run the same applications and give no sign that anything has changed. What has changed is that every security vulnerability found in Windows since then stays open on those machines. Microsoft publishes fixes for Windows 11 every month, attackers read those fixes to see what was vulnerable, and Windows 10 machines without ESU are left with the holes.

Over time the practical consequences widen. Browsers, security agents, Microsoft 365 apps and line-of-business software drop Windows 10 support. Cyber insurers ask about unsupported systems on renewal. Client security questionnaires ask the same. A machine that was fine last year gradually becomes both a security exposure and a compliance problem.

Extended Security Updates: a bridge, not a destination

Microsoft offers Extended Security Updates for Windows 10, described at learn.microsoft.com. For businesses, ESU provides security-only updates for up to three years after end of support, purchased per device, per year, with the price roughly doubling each year. It includes no new features, no non-security fixes and no general support.

ESU is worth using in two situations: to keep specific machines supported while replacements are ordered and deployed, and to cover a device that runs a legacy application that cannot yet move to Windows 11. It is not a sensible way to keep an estate on Windows 10 for three years. By the third year the ESU cost per device approaches a meaningful share of a replacement laptop, and the machine is by then seven or eight years old.

If you use ESU, enrol every Windows 10 device immediately rather than leaving some uncovered, and set a date by which the last one is gone.

Windows 11 hardware requirements

The full list is on Microsoft Learn. The requirements that matter for business PCs:

  • TPM 2.0. A Trusted Platform Module chip, used for disk encryption keys and hardware-backed security. Most business PCs from around 2016 onwards have one, but it is often disabled in the firmware and needs switching on.
  • UEFI firmware with Secure Boot enabled.
  • A supported processor. Broadly Intel 8th generation (2017 and later) or newer, and AMD Ryzen 2000 series or newer. This is the requirement that rules out most older machines, regardless of how well they run.
  • 4GB memory and 64GB storage as minimums. In practice 8GB and an SSD are needed for a usable business machine, and 16GB is the sensible standard for new purchases.

A PC that passes these can be upgraded in place with its applications and data intact. A PC that fails on the processor cannot, and firmware tweaks will not change that.

Cyber Essentials and unsupported software

The NCSC's Cyber Essentials scheme requires that all software within scope is licensed, supported and receiving security updates, and that unsupported software is removed or isolated. A Windows 10 device without ESU is unsupported software. The self-assessment asks directly, and a Cyber Essentials Plus assessor will check devices.

This matters beyond the certificate. Many clients, particularly in professional services and the public sector supply chain, require Cyber Essentials from their suppliers. An unsupported operating system anywhere on the network can cost a contract. If you hold or are working towards certification, the Windows 10 estate is a blocking issue. Dig IT's Cyber Essentials support starts with exactly this kind of gap.

Plan the refresh

A structured approach for a business of up to 250 people:

1. Inventory. List every Windows device, its age, processor, TPM status and whether it passes the Windows 11 check. Your provider's monitoring platform can produce this in minutes. Without one, the PC Health Check app does it per machine.

2. Sort into three groups.

GroupAction
Passes Windows 11, under about four years old, SSDUpgrade in place, scheduled outside working hours
Passes Windows 11 but old, slow or mechanical driveReplace, or upgrade only if a memory and SSD upgrade is cheap and the machine has two years left
Fails Windows 11 (processor or no TPM)Replace, with ESU only until the replacement arrives

3. Standardise the replacements. One laptop family from a business range (Dig IT supplies HP and Dell), 16GB memory, SSD, TPM 2.0, on a rolling refresh so the estate does not all age out together. The hardware lifecycle strategy explains the cycle.

4. Check applications first. Test any line-of-business software, printer drivers, scanners and specialist hardware on Windows 11 before rolling out. Most works. The exceptions are usually old accounting or industry packages, and those are the ESU candidates while the vendor catches up or a replacement is found.

5. Deploy with a standard build. New machines imaged with the business's security baseline: BitLocker enabled, EDR installed, Intune or RMM enrolled, MFA enforced, local admin removed. This is the moment to fix inconsistencies that have accumulated for years. See IT procurement.

6. Schedule and communicate. In-place upgrades take an hour or two per machine and can run overnight. Replacements are a desk swap with data migrated from OneDrive. Tell staff what is happening and when, and keep a spare machine or two for the inevitable exception.

7. Keep Windows 11 current. Each annual Windows 11 version has its own support window, so feature updates need managing through Intune or the RMM platform rather than left to chance. A machine upgraded once and then ignored will be unsupported again within a couple of years.

8. Dispose properly. Wipe or destroy drives with a record kept, remove devices from Microsoft 365 and the asset register, and recycle through a WEEE-compliant partner.

Budget and timing

For a business with 30 PCs of which half fail the Windows 11 check, the refresh is 15 new machines plus a day or two of engineering time for the upgrades and deployment. Spread across two budget quarters with ESU bridging the gap, it is a manageable project. Left until an incident or a failed client audit forces it, the same work happens in a hurry at higher cost.

Businesses on managed IT support should already have had this conversation, with the inventory and a dated plan. If your provider has not raised Windows 10 end of support with you, that is a signal about how proactively your IT is being managed.

What to do next

If you are not certain how many Windows 10 machines you still have, or which of them can be upgraded, start there. Dig IT's IT health check includes a Windows 11 readiness inventory for every device, a sorted upgrade-or-replace list and a costed plan, for businesses across Hertfordshire, west Essex and London.

Frequently asked questions

When did Windows 10 support end?
Windows 10 Home and Pro reached end of support on 14 October 2025, according to Microsoft's product lifecycle page. After that date Microsoft no longer issues security updates, feature updates or technical support for Windows 10 unless the device is enrolled in the Extended Security Updates programme. The PCs keep working, but every new vulnerability found stays unpatched.
What are Windows 10 Extended Security Updates?
ESU is a paid programme that delivers security-only updates for Windows 10 after end of support. For businesses it is available for up to three years, with the price per device roughly doubling each year. It provides no new features or non-security fixes. It is intended as a bridge while a business finishes upgrading or replacing devices, not as a way to keep Windows 10 indefinitely.
Which PCs can be upgraded to Windows 11?
Windows 11 needs a TPM 2.0 chip, UEFI firmware with Secure Boot, at least 4GB of memory and 64GB of storage, and a processor on Microsoft's supported list, which broadly means Intel 8th generation or newer and AMD Ryzen 2000 or newer. Many business PCs bought from around 2018 onwards qualify, sometimes after enabling TPM in the firmware. Older machines generally cannot be upgraded and need replacing.
Does running Windows 10 fail Cyber Essentials?
Yes, unless the device is enrolled in ESU. Cyber Essentials requires all software in scope to be supported and receiving security updates, and unsupported operating systems must be removed from scope or replaced. A business with Windows 10 devices on its network without ESU will not pass the self-assessment, and an assessor will check during Cyber Essentials Plus.
Should we upgrade in place or buy new PCs?
Upgrade in place where the PC meets the Windows 11 requirements and is under about four years old with an SSD. Replace anything that fails the requirements, is older, or would need a memory and storage upgrade to be usable. Replacing brings the estate onto one standard build with modern security hardware, which pays back in support time and makes the next refresh predictable.
What is the risk of just carrying on with Windows 10?
Every vulnerability discovered after October 2025 remains open on those machines permanently. Attackers know this and target unsupported systems. Beyond the breach risk, the business cannot honestly pass Cyber Essentials, may breach cyber insurance conditions, and will find that new software, browsers and security tools drop Windows 10 support over time.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us