Skip to content
Blog/IT Management

Windows 10 in 2026: A Practical Upgrade Plan for London Businesses

Free Windows 10 support ended in October 2025. Here is how to check ESU, decide which PCs to upgrade or replace, and plan the rollout without stopping work.

//Updated //8 min read
IT technician inventorying office laptops to identify an unsupported Windows 10 device

Windows 10 reached end of support on 14 October 2025. If your business is still running it, something needs to change - but the first step is to establish what each machine is actually receiving.

Standard, free Windows 10 support ended on that date. A device correctly enrolled in Microsoft's Extended Security Updates programme can still receive critical and important security updates for a limited period. A device outside ESU cannot. Two identical-looking Windows 10 laptops can therefore carry very different levels of risk.

The machines still work. The software still runs. Nothing visibly broke on 15 October. The risk is quieter: a Windows 10 device outside ESU no longer receives operating-system fixes for newly discovered vulnerabilities. We saw the consequence of unsupported systems with Windows XP in 2017, when WannaCry disrupted organisations including the NHS.

The principle has not changed: know which devices are still protected, then give every remaining Windows 10 machine an exit route.

August 2026 update: check ESU status, not just the Windows version

As of 11 August 2026, a Windows 10 label on its own is not enough to make a decision. For every business device, record five things:

  1. The Windows edition and version installed.
  2. Whether ESU is activated, and when that coverage ends.
  3. Whether the processor, TPM 2.0 and Secure Boot configuration meet Windows 11 requirements.
  4. Which critical applications, printers or specialist devices depend on it.
  5. Whether the backup works and the BitLocker recovery key is available.

Consumer ESU ends on 13 October 2026. Organisations can use Microsoft's commercial ESU programme for longer, through annual subscriptions, but it remains a bridge rather than normal product support. We cover the October 2026 deadline, commercial ESU costs and Secure Boot changes separately.

If your inventory cannot answer those five questions, it is not yet detailed enough to support an upgrade decision or an insurance conversation.


What "end of support" actually means

Let's be specific, because there's confusion around this.

What stopped: Standard security updates, bug fixes, feature updates and free technical support for Windows 10 Home and Pro (version 22H2). Microsoft confirmed the end-of-support date on its Windows 10 lifecycle page.

The temporary exception: Devices enrolled in Extended Security Updates can continue receiving critical and important security updates. ESU does not restore feature updates, general technical support or the normal product lifecycle.

What didn't stop: Your computer still turns on. Your applications still run. Microsoft 365 apps on Windows 10 will continue receiving their own security updates until October 2028 - but only for the apps, not the operating system underneath them (Microsoft Support).

The distinction matters. Running patched applications on an unpatched operating system is like fitting a new lock on a door with rotten hinges. The lock works fine. The door is still the problem.

A note on Enterprise: Windows 10 Enterprise LTSC has separate, longer support timelines. If your IT team has specifically deployed LTSC, this article doesn't apply to those machines. But if you're a small business, you're almost certainly running Home or Pro.


Why this matters beyond the technical

There are four business reasons to care about this, even if cybersecurity isn't your primary concern.

Insurance. Cyber insurance policies may ask whether software is supported and patched. A Windows 10 device outside ESU can weaken that position, but the policy wording and the facts of a claim decide the outcome. Record the device, the temporary control and the dated migration plan rather than assuming antivirus alone solves it.

Client contracts. If you handle client data - and most businesses do - your contracts likely include data protection obligations. Running unsupported software is difficult to defend as meeting a "reasonable standard of care." If a breach occurs and your client discovers you were on Windows 10, that conversation will be uncomfortable.

Compliance. Cyber Essentials requires software in scope to be supported and security updates to be applied. Plain Windows 10 outside ESU does not meet that position. An ESU-enrolled device needs to be assessed against the scheme requirements and the organisation's declared scope. The NCSC urged organisations to plan their Windows 11 upgrade before support ended.

The wider risk. The UK government's 2025/2026 survey found that 43% of businesses identified a cyber breach or attack in the previous 12 months. An unsupported operating system does not guarantee an incident, but it leaves one avoidable route open.


Your four options

1. Upgrade to Windows 11 (free, if your hardware supports it)

This is the straightforward path. If your PC meets Microsoft's Windows 11 system requirements, including TPM 2.0 and Secure Boot, the operating-system upgrade is free. Many recent business laptops qualify, but the processor generation and firmware configuration still need checking.

Check compatibility using Microsoft's PC Health Check app, or simply go to Settings → Update & Security → Windows Update and see if the upgrade is offered.

The installation time varies by hardware and connection speed. Your files, apps, and settings normally carry over. It's not painless - some older peripherals may need driver updates, and a few legacy applications may have compatibility issues - but for most businesses, it's the least disruptive option.

2. Buy Extended Security Updates (ESU)

Microsoft offers a paid commercial programme that continues delivering critical and important security updates beyond the end-of-support date (Microsoft ESU). For organisations, coverage is bought annually for up to three years. It buys defined time while you migrate; it does not turn Windows 10 back into a normally supported operating system.

ESU is most useful when a specific application needs testing on Windows 11, a replacement is already ordered, or a staged hardware refresh needs a few more months. Attach an owner and exit date to every ESU device.

Think of it as renting time, not solving the problem - and the rent goes up. We've laid out how a fifteen-person fleet actually makes the exit - the half-day audit, the repair-or-replace judgement, and evening changeovers with no downtime. We look at what happens when consumer ESU runs out in October 2026 separately, because that second deadline is steeper than the first.

3. Replace the hardware

If your machines are old enough that they can't run Windows 11 - typically pre-2018 devices without TPM 2.0 - upgrading the OS isn't an option. The most practical solution is replacing the hardware.

For a small business, this is often the right move anyway. Hardware old enough to miss the Windows 11 requirements may also be approaching the point where battery, storage and reliability matter more than the operating system alone. Modern business hardware comes with Windows 11 pre-installed.

If you're replacing multiple machines, compare a current hardware quote with the cost of ESU and the time spent supporting the old device. Plan the rollout in batches rather than all at once so one compatibility issue does not affect the whole team.

4. Consider alternatives

This isn't the right path for most businesses, but it's worth mentioning. If your work is primarily browser-based - Google Workspace, web applications, cloud tools - a Chromebook or macOS device might be more appropriate than a Windows machine. Chromebooks in particular offer strong security at a low price point and are worth considering for roles that don't need Windows-specific software.


A migration checklist

If you're ready to move, here's the sequence that keeps things orderly.

Before you start:

  • Audit every device in the business. Record its Windows edition, ESU status, Windows 11 eligibility, critical applications and peripherals.
  • Back up everything. Full backups of all devices, verified by actually restoring a test file. Backups you haven't tested aren't backups - they're assumptions.
  • Confirm that BitLocker recovery keys are accessible before changing firmware, TPM or operating-system settings.
  • Identify critical applications and check their Windows 11 compatibility. Most modern software works fine. Legacy or industry-specific applications sometimes don't.

During migration:

  • Start with one representative pilot machine. Test the applications, printer, VPN and security tooling used by that role before approving the wider batch.
  • Upgrade in batches, not all at once. Move 2-3 machines first, collect user sign-off, then schedule the rest around working hours.
  • Update all drivers after the upgrade - especially display, network, and printer drivers.
  • Test everything: Microsoft 365, your line-of-business applications, printers, VPN connections, video conferencing.

After migration:

  • Verify that Windows Update is working and automatic updates are enabled.
  • Update your asset register with the new OS versions.
  • If you have an IT support provider, make sure they're aware of the migration.
  • Document any configuration changes for future reference.

A practical plan for a 15-device London office

This is the delivery model we would quote for a small office that needs to move without losing a working day:

Day 1 - inventory and decisions. Build the five-point record for every device. Classify each one as upgrade, replace, temporary ESU or genuine exception. The output is a named device list, not a general recommendation.

Day 2 - pilot and recovery test. Back up one representative laptop, confirm the recovery key, upgrade it and test the user's real applications and peripherals. If the pilot fails, the rest of the fleet stays untouched while the cause is resolved.

Days 3-5 - controlled batches. Move the compatible machines in small groups outside their busiest hours. Each device gets an update check, security-tool check and user sign-off before the next group starts.

Final pass - remove the ambiguity. Replacements receive a migration date. Any machine staying on ESU gets an owner and exit date. Unsupported exceptions are isolated or taken out of service rather than disappearing back into the office.

Marcin keeps the client-side plan, decisions and communication in one place. Jaryd Kroesen and LONDONPCFIX lead the engineering checks and rollout, with the wider London engineer network available when the schedule needs parallel on-site work.


What we're seeing in practice

Windows 10 machines are still common in the small offices covered by our business IT support. The difficult part is rarely clicking the upgrade button. It is finding the one finance application, printer driver or recovery key that turns a routine change into lost working time.

The most common reason for delay isn't cost or complexity. It's inertia. The machine works. It looks the same as yesterday. There's no flashing red warning. The risk is invisible - right up until it isn't.

If you've been putting this off, the best time to migrate was October 2025. The second best time is now. Every week a device remains outside ESU is another week without new Windows 10 operating-system security fixes.


Sources

Common questions

Only if the device is enrolled in Extended Security Updates. Free support ended on 14 October 2025, so a machine outside ESU receives no operating-system fixes for newly discovered vulnerabilities. Two identical-looking Windows 10 laptops can carry very different risk - check ESU status, not just the Windows version.

Four. Upgrade to Windows 11 free where the hardware qualifies; buy Extended Security Updates as a bridge, with an owner and exit date attached to every device; replace hardware too old for Windows 11, typically pre-2018 machines without TPM 2.0; or move browser-based roles to Chromebook or macOS.

Five things per device: the Windows edition and version; whether ESU is activated and when that coverage ends; whether the processor, TPM 2.0 and Secure Boot meet Windows 11 requirements; which critical applications, printers or specialist devices depend on it; and whether the backup works and the BitLocker recovery key is available.

It can. Cyber Essentials requires software in scope to be supported and patched, which plain Windows 10 outside ESU does not meet, and an ESU device must be assessed against the scheme and your declared scope. Insurers may ask whether software is supported, so record the device, the control and a dated migration plan.

Marcin Skwiercz

Written by

Marcin Skwiercz

Founder of Evolfe. Fixing London's technology since 2014 - 12 years of hands-on repair and IT support behind every article.

About EvolfeLinkedIn

Need help with this?

We can help your business prepare.

Evolfe provides IT support and management for London businesses. If anything in this article applies to you, get in touch.

Book a Free Consultation

The Evolfe letter

Practical IT insights, straight to your inbox

One email a month, in plain English. No spam, unsubscribe any time.