Windows 10's free support ended on 14 October 2025. What most coverage misses is the harder deadline sitting inside 2026: Microsoft's consumer Extended Security Updates programme — the only route left to patched devices — closes for good on 13 October 2026, with no supported path beyond it described anywhere in Microsoft's own material. Enterprise and education customers get up to three years of paper-thin runway on the same clock; everyone else gets one. This study lays out the exact dates, the UK compliance exposure they create, and a decision framework for closing the gap before the window shuts.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| Free support ends | 0 | 1 |
| Consumer ESU | 0 | 52 |
| Enterprise ESU | 0 | 156 |
The 2026 Deadline Map: What Windows 10's End of Support Actually Means
Microsoft's Windows 10 free support ended on 14 October 2025 — the point at which the vendor stopped issuing software updates, security fixes and technical assistance for the operating system. That's confirmed on Microsoft's own end-of-support page and was reported by The Guardian on the day it took effect. It's now well behind us, but it isn't the number that should be driving 2026 budgets.
The date UK IT leaders need pinned to the wall is 13 October 2026, when Microsoft's consumer Extended Security Updates (ESU) programme itself closes. Microsoft Q&A material, and reporting from The Register and WindowsForum, all converge on the same line: consumer ESU coverage runs for one year from the end-of-support date, and there is no supported mechanism described in Microsoft's public material for extending that consumer coverage beyond the cutoff. Devices can be enrolled at any point before the deadline and will still receive prior and future ESU updates issued during the programme — but once 13 October 2026 passes, the route closes for consumer-class devices, permanently.
Note on the timeline figure below: '14 October 2025' marks the specific date free support ended, not a multi-week event. It is shown with a short visual band purely to align it clearly against the longer ESU bars on the same chart — the underlying fact is a single point in time, not a duration.

How Many Windows 10 Devices Are Still Exposed?
The honest answer, based on the material available, is that no verified global or UK count of unpatched Windows 10 endpoints — or Windows Server 2016 instances — currently exists to cite. That's a genuine gap in the public data, not a detail we're choosing to omit for convenience, and any figure offered without a credible source would be a guess dressed up as a statistic.
What can be said with confidence is the shape of the exposure rather than its exact size. The risk sits in a sharply defined window: devices still running Windows 10 that haven't moved to Windows 11 or into a supported ESU arrangement before 13 October 2026 fall out of vendor patching entirely, with consumer devices given a single year of bridge coverage and enterprise/education devices given up to three. Windows Server 2016 sits inside the same broader end-of-support cycle and is described as a material part of this same 'unpatched wave', but how exposed any particular estate actually is varies widely — organisations that have bought ESU or built compensating controls carry a very different risk profile from those that have done neither.
For UK IT leaders, that means the useful exercise isn't waiting for an industry-wide count to appear, but running your own device and server inventory against the dates above now, so your organisation's contribution to that unpatched wave is known internally even where the national total isn't.
Why 'Still Working' Doesn't Mean 'Still Safe'
Microsoft's position after end of support is unambiguous: no further security fixes are issued for the affected operating system. The Guardian's coverage is careful to note this is about support ending, not the OS ceasing to function — which is precisely why so many organisations quietly carry on running unsupported machines. The hardware keeps working; the patch stream does not.
That distinction matters more with every month that passes. Every flaw discovered in an unsupported version stays open indefinitely rather than being closed in a routine update cycle, and the tooling used to find and weaponise such flaws has only become faster and more automated industry-wide. None of this requires a single new vulnerability count to make the point: a system with a permanently frozen patch baseline is, by definition, an expanding rather than a static risk. Treating vulnerability management as an ongoing discipline — not a one-off scan — is the practical response while migration is still in progress.
The UK Compliance Angle: GDPR, NCSC Expectations and Insurance
For UK organisations, the Windows 10 and Windows Server end-of-support waves aren't purely a technical maintenance question — they're a data-protection and operational-resilience one. Running software that no longer receives security fixes sits awkwardly against the UK GDPR expectation of 'appropriate technical measures', and against the wider NCSC posture that unsupported software should not be relied on for sensitive processing. Procurement and risk teams should frame the 13 October 2026 cutoff as a compliance deadline, not just an IT one.
Cyber insurance adds a further pressure point. Renewal and proposal processes increasingly probe whether an estate is running fully supported software, and a breach traced back to a system that had already lost vendor support — while a policy assumed supported systems were in place — is exactly the kind of gap that invites disputes over cover. The safest position is to have the migration or ESU decision documented and actioned well before the deadline, not argued over after an incident.
Windows 10 in 2026: A One-Year Bridge, Not a Destination
The practical baseline for late-stage Windows 10 support is version 22H2, which Microsoft Q&A material identifies as the version still eligible for ESU security updates once enrolled. Enrolling late doesn't forfeit earlier fixes — devices that join the programme after launch still receive both the updates issued before their enrolment and those issued afterwards, right up to the programme's close.
What it doesn't do is buy indefinite time. Consumer ESU is explicitly a one-year bridge, running from the 2025 end-of-support date to 13 October 2026, and Microsoft's own Q&A confirms there's no supported way to keep that consumer coverage running past the cutoff. Understanding exactly what a term like 'Extended Security Updates' does and doesn't cover matters here — our OEM end-of-support jargon guide breaks down the vocabulary vendors use so it's clear precisely what's being bought.
Enterprise and Server Estates: A Longer, Still Finite Runway
Enterprise and education customers get a materially different deal: Microsoft describes enterprise/education ESU as purchasable for up to three years, versus the single year available to consumer devices. That gap is significant for planning purposes — it changes a frantic six-month sprint into a genuine multi-year migration programme, but it doesn't remove the deadline, it just moves it further out.
Windows Server's 2016 family sits inside the same broader end-of-support cycle and is a material part of this wave, though how exposed any given estate actually is varies widely — organisations relying on paid ESU or internal compensating controls carry a very different risk profile from those that have done nothing. Estates still running Server 2016 workloads should treat this as a live planning item now rather than a 2028 problem; our server EOL/EOSL planning guide sets out how to sequence that work against budget cycles.
View the data behind this chart
| Consumer ESU | Enterprise/Education ESU | |
|---|---|---|
| Coverage duration | years1 | years3 |
What It Costs to Close the Gap — And Why We Won't Guess
A responsible cost comparison needs a verified, current UK price list for both consumer-class ESU coverage and any Windows Server 2016 ESU purchase — and no such verified figures exist in the material available at the time of writing. Rather than invent a per-device or per-server number, the honest position is that the real cost driver is your own estate profile: how many devices are Windows 11-eligible, how many aren't, how old the fleet is, and whether standardising on Windows 11 now is cheaper over three years than buying successive rounds of ESU.
Those are answerable questions with real internal numbers, even without a published market price list. Running your own device count and age profile through a structured model — our Windows Server EOL cost calculator is built for exactly this — gives a defensible, board-ready figure specific to your estate rather than a generic industry average that may not reflect your licensing position or hardware age.
A Decision Framework for UK IT Leaders
Not every device or server in an estate needs the same treatment, and the deadline pressure is very different depending on where a given system sits. The framework below groups estates by their realistic options given the dates confirmed by Microsoft: upgrade where hardware allows it, buy a defined bridge where it doesn't, and treat anything still unaddressed after 13 October 2026 as an active incident risk rather than a backlog item.
Action Plan: Steps Before 13 October 2026
The sequence that keeps a migration programme on schedule against a fixed external deadline is straightforward, even where the estate is large or mixed.
- •Inventory every endpoint's current build, confirming which are on the 22H2 baseline needed for ESU eligibility
- •Run Windows 11 hardware-eligibility checks across the fleet to separate 'upgrade now' from 'needs a bridge'
- •Decide, per device class, between consumer ESU (one year, ending 13 October 2026) and enterprise/education ESU (up to three years) based on genuine eligibility
- •Inventory Windows Server 2016 instances separately from desktop estate, since server lifecycle decisions run on a different clock
- •Set an internal deadline meaningfully ahead of 13 October 2026 to allow for procurement, testing and rollback contingency, not a date-of-deadline cutover
Sources
Every figure in this article traces to the sources below.
- •Microsoft — Windows end-of-support dates (Windows 10 and Windows 8.1 precedent)
- •Microsoft Q&A — consumer ESU end date and no-extension confirmation
- •Microsoft Q&A — ESU duration, 22H2 baseline and late-enrolment rules
- •The Guardian — reporting on Windows 10 free support ending, 14 October 2025
- •The Register — confirmation of the 13 October 2026 consumer ESU end date
- •WindowsForum — summary of consumer ESU coverage window
View the data behind this chart
| Risk Level | Primary Driver | Recommended… | |
|---|---|---|---|
| Windows 11-eligible… | Low if migrated | Hardware supports Win11 | Upgrade before ESU ends |
| Non-eligible PCs, few… | Medium | No Win11 upgrade path | Consumer ESU for 1 year |
| Non-eligible PCs… | High | Budget/logistics | Enterprise ESU (3yrs) |
| Windows Server 2016… | High | Lifecycle overlap | Plan migration now |
| Devices past 13 Oct… | Critical | No consumer ESU exists | Replace or isolate |
The 8 verified data points behind this study are free to download and reuse with attribution (CC BY 4.0).
Cite as: Servnet Research, “End of Support Attack Surface 2026: The Unpatched Wave”, servnetuk.com, 2026.
