Windows 10 ESU Year 2: The October 2026 Decision
The Windows 10 end-of-life project reaches its next commercial deadline when ESU Year 1 ends October 13, 2026. Organizations keeping eligible Windows 10 22H2 devices after that date need Year 2 coverage or an approved alternative. Microsoft says ESU pricing doubles each consecutive year and that an organization entering in Year 2 must also acquire Year 1, so delay does not erase the earlier-year cost.
By Uniqcli Team · · 10 min read · Updated

Key takeaways
- Windows 10 reached end of support on October 14, 2025; ESU supplies critical and important security updates, not normal feature development or general support.
- Microsoft lists Windows 10 ESU Year 1 ending October 13, 2026 and Year 2 ending October 12, 2027.
- Commercial Year 1 is listed at $61 per device. Microsoft says the price doubles each consecutive year, but buyers must verify current program, education, cloud, and reseller terms before budgeting.
- ESU years are cumulative. An organization that first enrolls in Year 2 must also pay for Year 1.
- The right decision is device-specific: refresh, remediate and upgrade, isolate temporarily with ESU, deliver Windows 11 through a Cloud PC, or retire the workload.
- Start with inventory and application evidence. A global device count hides incompatible CPUs, peripherals, line-of-business software, and ownership gaps.
On this page
Procurement Guidance
What changes on October 13, 2026
Microsoft’s lifecycle FAQ identifies October 13, 2026 as the end of Windows 10 ESU Year 1. The next annual coverage period runs through October 12, 2027. For commercial and education devices, up to three years of ESU are available after the operating system’s end of support.
ESU is deliberately narrow. Enrolled Windows 10 PCs receive critical and important security updates as classified by Microsoft. The program does not restore new features, customer-requested nonsecurity updates, design changes, or general support for Windows 10. Support for activation, installation, and possible ESU regressions is limited; organizations needing broader technical support require an appropriate support arrangement.
Windows 10 computers do not stop booting when a coverage period ends. The issue is that newly discovered operating-system vulnerabilities may no longer receive the program’s updates on an unenrolled device. That creates a growing operational and compliance exception, especially for internet-connected endpoints, privileged workstations, and machines handling regulated or sensitive information.
The decision by October is therefore not “does the PC still work?” It is “which devices still justify running an operating system outside normal support, and what funded control covers that decision?”
Confirmed pricing mechanics—and what still needs a quote
Microsoft’s Windows 10 ESU page lists commercial Year 1 at $61 USD per device through Volume Licensing and says the price doubles every consecutive year. That implies a Year 2 list amount of $122 per device. Microsoft also states that ESU must be purchased by year and that customers entering in Year 2 must acquire Year 1 because coverage is cumulative.
The cumulative rule changes the economics. A device newly enrolled for Year 2 does not simply cost the Year 2 amount. The organization must cover the prerequisite year as well, even though it cannot recover the earlier coverage period. That makes postponement an operational delay, not a way to avoid Year 1 licensing.
Treat these amounts as planning inputs, not a universal invoice. Education programs, cloud entitlements, reseller agreements, taxes, currency, and licensing changes can produce a different transaction. Microsoft says ESU is available at no additional cost for eligible Windows 10 virtual machines in several Microsoft-hosted services, and Windows 10 endpoints accessing Windows 365 Cloud PCs can receive entitlement under stated conditions. Verify that the exact deployment meets the current terms rather than applying a cloud exception to every device in a tenant.
For a focused cost model, use Windows 10 ESU cost, then replace list assumptions with a dated quote and licensing review.
Build a device-level decision file
A total such as “2,400 Windows 10 PCs remain” is not enough to choose a path. Export an inventory that includes device ID, assigned user or room, site, model, serial, processor, memory, storage, firmware state, TPM version and status, secure-boot state, Windows edition and build, management enrollment, last check-in, last patch, encryption status, primary applications, peripheral dependencies, and owner.
Add four business fields: planned disposition, exception reason, target date, and accountable approver. These turn a technical export into an operating plan.
Clean the data before pricing. Remove decommissioned records, duplicates, lab images, stale directory objects, and machines that have not checked in. Reconcile endpoint management with identity, procurement, and physical inventory. A device appearing in one tool but nowhere else is a question, not automatically a license.
Then place each device into a decision lane:
Upgrade in place
Hardware is eligible, applications are supported, and the device has adequate performance and storage.
Refresh
The device does not meet Windows 11 requirements, is near normal lifecycle replacement, or has reliability and performance problems that make further investment poor value.
ESU bridge
A documented dependency prevents migration before October, but the device has an approved exit date and compensating controls.
Cloud or virtual delivery
A legacy local endpoint can serve as controlled access to a supported desktop or application under verified licensing and security architecture.
Retire
The machine or workload is no longer needed.
Avoid an “unknown” lane that lasts indefinitely. Unknown devices should have a discovery owner and deadline.
Test Windows 11 eligibility as a system, not a checklist
Windows 11 eligibility is more than a CPU generation. Microsoft’s hardware requirements include a compatible 64-bit processor, memory and storage minimums, UEFI with Secure Boot capability, TPM 2.0, and graphics and display requirements. Enterprise deployment also depends on firmware configuration, drivers, management tooling, applications, peripherals, network services, and user workflows.
Run Microsoft’s supported readiness tooling through the management platform, then validate exceptions. TPM may exist but be disabled or not ready. Secure Boot may be supported but unavailable because of legacy partitioning. A compatible device can still lack storage headroom for a reliable feature update. A driver can pass basic installation and fail a specialized scanner, label printer, lab instrument, or assistive-technology workflow.
Do not use unsupported Windows 11 installation as a fleet strategy. It can produce machines outside the intended support model and obscure the lifecycle problem rather than solve it. When a hardware exception is proposed, document vendor support, update behavior, security implications, and the accountable risk decision.
Application testing is usually the real critical path
Many migrations stall because the organization tested Windows, not the work. Create an application catalog with business owner, technical owner, current version, vendor support statement, authentication dependencies, browser or runtime dependencies, add-ins, local data paths, printing, peripheral integration, packaging method, license method, and rollback plan.
Prioritize applications by impact and uncertainty. A widely deployed current browser needs less ceremony than a low-volume clinical, manufacturing, public-safety, finance, or classroom application tied to specialized hardware. Test representative workflows with actual users. “The executable opened” is not acceptance.
Record outcomes as pass, pass with remediation, fail, or not tested. A pass should name the version and test date. A remediation should have an owner and deployment method. A failure should identify the business consequence and alternative. “Vendor says compatible” is useful evidence but does not replace site testing when local integrations matter.
Include identity and management in the pilot. Check sign-in, MFA, certificates, VPN or zero-trust access, Wi-Fi, printing, endpoint detection, data-loss controls, disk encryption, patch rings, remote support, software delivery, and device recovery. Migration failures often live in these seams.
When ESU is a good bridge
ESU is defensible when it buys time for a specific constraint: a vendor-supported application update is scheduled, replacement equipment has a known lead time, a site renovation changes the endpoint need, or a business process has a funded redesign. The exception should identify the devices, reason, owner, coverage period, compensating controls, and final migration date.
An ESU bridge is weaker when it covers every unresolved device without distinction. The organization pays more while uncertainty remains. A Year 2 purchase should not become an automatic argument for Year 3.
Apply risk-based controls during the bridge. Remove local administrator rights where not required. Limit network access to necessary services. Strengthen application allowlisting and endpoint monitoring. Ensure supported browsers and business applications remain patched. Block direct internet access for fixed-function devices if the workflow permits. Separate specialized equipment from general user networks. Maintain tested backups and recovery instructions.
These measures do not turn Windows 10 into Windows 11 or replace ESU. They reduce exposure while the approved exit plan executes.
Compare refresh and ESU with full costs
The license line alone can favor delay, especially when a device still looks serviceable. Include the rest of the period.
For ESU, count cumulative licenses, deployment labor, exception administration, additional monitoring, application support, parts, battery or storage failures, help-desk time, and the eventual refresh. For replacement, count device and warranty, accessories, docking and display compatibility, imaging or provisioning, data migration, user downtime, disposal, application remediation, and financing or deployment services.
Then add the value of the result. A new device can improve performance, battery life, wireless capability, manageability, and warranty coverage. An ESU device preserves the current workflow and avoids immediate disruption. Neither value is universal; it depends on user role and site.
Model at least three scenarios: refresh before October, mixed refresh plus ESU bridge, and broad Year 2 enrollment. Show cash timing, labor capacity, device risk, and the number of unresolved exceptions at the end. The lowest first-year spend can be the most expensive two-year plan if it delays the same replacement without reducing the fleet.
A site-by-site schedule
August: settle the population
Reconcile inventory, assign decision lanes, verify licensing channels, and identify applications without owners. Order pilot hardware and confirm accessory standards. Freeze a baseline count so changes are visible.
September: prove the migration
Complete application and peripheral pilots. Remediate management and identity gaps. Issue purchase orders for approved refreshes with delivery and substitution rules. Build ESU deployment groups only for approved bridge devices.
Early October: deploy and verify
Move production waves by site and user type. Confirm data migration, encryption, management check-in, patching, application acceptance, and asset records. Test ESU activation and reporting on a small representative ring before broad enrollment.
After October 13: reconcile exceptions
Produce a report showing refreshed, upgraded, enrolled, isolated, retired, and unaccounted devices. Investigate failures quickly. Continue monthly reviews of the ESU bridge population and prevent new Windows 10 deployments unless an exception explicitly allows them.
Buying and receiving controls
For refresh hardware, define Windows 11 edition, processor platform, memory, storage, wireless, ports, camera and audio, security features, warranty, repair model, country-of-origin requirements when applicable, and approved substitutions. Ask for stable configurations when deployment tooling depends on driver consistency.
Do not let a price-only substitute break the tested image or accessory set. A “same or better” processor does not guarantee the same network adapter, dock behavior, firmware management, or repair process. Require written approval for material changes.
At receiving, capture serials and models, inspect damage, verify configuration, enroll devices, update asset assignment, and record acceptance failures. Keep a small spare pool sized to the user population and service model rather than ordering an arbitrary percentage.
Prove ESU deployment and patch health
Buying ESU does not prove a device receives updates. Build a compliance view that separates license assignment, activation, device eligibility, successful installation, last scan, and latest applicable security update. A device can appear in the purchasing record while activation failed or the endpoint stopped checking in.
Pilot the complete chain on representative devices and sites: licensing, activation key or subscription handling, prerequisite updates, deployment policy, restart, update installation, management reporting, and recovery after failure. Include machines behind proxies, on slow links, off the corporate network, and managed by different tools.
Create exception reasons that lead to action: not eligible, not activated, not reporting, update failed, insufficient disk, powered off, retired, duplicate, or pending replacement. Assign an owner and aging threshold to each. A single “noncompliant” count hides the work.
After each monthly release, reconcile the ESU population with vulnerability and endpoint records. Sample devices physically or through remote verification. Investigate systems that report updates but lack current security telemetry, or vice versa. Preserve the reports and remediation tickets as evidence that the bridge is being operated rather than merely licensed.
Manage user change and recovered equipment
Refresh projects often underestimate deskside details. Document how users back up local data, move browser state and certificates, reconnect printers and specialty devices, recover encrypted files, and return old equipment. Define what support can copy and what must not leave the old machine.
At handoff, verify the user can complete the critical workflow, not just sign in. Record the old and new asset assignments and enforce a return deadline. Quarantine returned devices, preserve data under records policy, sanitize with an approved method, and update disposition records. Devices held “just in case” should be offline and time-limited; otherwise they quietly re-enter service without ESU or management.
Communications should explain what changes, when, what the user must do, expected downtime, and where to get help. Avoid framing the project as a cosmetic Windows upgrade. Users are more likely to cooperate when they understand why local files, unsupported peripherals, or long-delayed restarts create real migration risk.
Keep the final exception list visible to site leadership. Each record should name the device, reason, ESU coverage, compensating controls, replacement date, and owner. Review it monthly until the count reaches zero or a newer approved plan replaces it.
Record approvals and closure evidence with the asset history.
Frequently asked questions
Does Windows 10 stop working after October 13, 2026?
No. Devices continue to operate, but an organizational device without Year 2 ESU no longer receives the program’s covered Windows security updates after Year 1 ends. Unsupported operation should be a documented risk decision, not an accidental state.
Can an organization buy only ESU Year 2?
Microsoft says no. ESU years are cumulative, so a customer entering in Year 2 must acquire Year 1 as well. Confirm the transaction and entitlement with the licensing provider.
Is the Year 2 price definitely $122 for every device?
Microsoft publishes $61 for commercial Year 1 and says pricing doubles each consecutive year, which supports a $122 list-planning amount for Year 2. Actual charges can differ by program, education status, cloud entitlement, currency, tax, or agreement. Use a current quote.
Does ESU include application or Microsoft 365 support?
ESU is for specified Windows security updates. It does not extend every application lifecycle or restore general Windows support. Review each application and service separately.
What evidence should an auditor see?
Maintain the approved device list, licensing records, activation and update reports, exception rationale, compensating controls, application testing, migration target dates, and proof that retired devices were removed from access and inventory.