Windows 11 or Windows 10, for a business in 2026
For any device that meets the hardware bar, Windows 11 now, because Windows 10 stopped receiving security updates in October 2025 and the only supported alternative is a per-device bridge that is priced to become more expensive every year. For devices that do not meet the bar, the question is not which operating system but whether to replace the device or bridge it briefly on Extended Security Updates with a named exit date. The one answer that has no defensible position is the one most fleets have by default: unenrolled, unpatched, and working fine.
What is actually being compared
- Windows 11
- The supported platform, with monthly security updates, feature updates, and a security architecture that depends on the hardware requirements Microsoft has confirmed will not change.
- Windows 10 on ESU
- Critical and important security updates only, per device, in annual periods to October 2028, at a price that steps up each year and is cumulative. A bridge for devices that cannot move yet.
- Windows 10, unenrolled
- No security updates since October 2025, no support, and no defensible position under DPDP Rule 6, customer questionnaires or cyber insurance. What most fleets are doing without having chosen it.
How they differ in practice
| Feature | Feature | Windows 11 | Windows 10 on ESU | Windows 10, unenrolled |
|---|---|---|---|---|
Security updates | Monthly, full coverage | Critical and important only | None since October 2025 | |
Feature updates and new capabilities | Yes | No | No | |
Microsoft support | Yes | No, ESU is updates only | No | |
Hardware requirement | TPM 2.0, Secure Boot, supported processor | None, runs on existing hardware | None | |
Cost model | Included with the device or licence | Per device, escalating, cumulative | Nothing, and that is the problem | |
Duration | Ongoing | Three annual periods to October 2028 | Indefinite, and indefinitely exposed | |
Third-party software support | Current | Being dropped on vendor schedules | Being dropped on vendor schedules | |
DPDP Rule 6 position | Defensible | A documented mitigation | Difficult to describe as reasonable | |
Security questionnaire answer | Yes, supported | A named exception list to explain | No, or a representation you cannot evidence | |
Right for | Every device that can run it | A short list with exit dates | Nothing, by design |
Move to Windows 11 if
- The device meets the hardware bar. TPM 2.0, Secure Boot and a supported processor, which is Intel 8th generation, AMD Ryzen 2000 or later. A scan tells you, and a surprising share of devices that look ineligible only need TPM enabled in firmware.
- You want the security architecture the hardware requirements exist for: virtualisation-based security, hardware-backed credential protection and a firmware baseline Windows 10 could not assume. The upgrade only delivers this if the configuration follows.
- You are answering customer security questionnaires, holding ISO 27001 or SOC 2, or carrying a DPDP obligation, all of which ask whether every endpoint runs a supported operating system.
- You are provisioning new devices. Autopilot with Intune provisions Windows 11 devices without an engineer, and there is no reason to provision a new device onto an unsupported platform.
Bridge on Windows 10 ESU if
- The device cannot meet the hardware bar and cannot be replaced before the current ESU period ends. This is a real category and it should be a short, named list, not the fleet.
- The device runs an application with no Windows 11 path yet, and the vendor has a date. The ESU exit date should match the vendor date, and the alternative of a Windows 365 Cloud PC should be costed first.
- A funded replacement is ordered and delivery falls after the period boundary. A short bridge with the exit date set to the delivery date.
- You can document the risk acceptance: which devices, why, until when, signed by an accountable owner. That is what an auditor or an enterprise customer will accept in place of a clean yes.
Stay on unenrolled Windows 10 if
- There is no scenario in which this is the right answer for a business device that handles email, browses the web, or touches personal data. It is included here because it is what most fleets are actually doing, and naming it is the first step to leaving it.
- The only near-legitimate case is a device that must stay on Windows 10 for a hard application dependency, in which case it belongs on an isolated network segment with no internet and no email, treated as operational technology, with a signed risk acceptance and a review date.
When the other option is right
We are a Microsoft Partner and we sell Windows 11 migrations, so weigh that. Two things against our own interest. First, if a device is capable but has TPM disabled in firmware, the answer is a free setting change, not a replacement, and we will find those before proposing hardware. Second, if your fleet is small and your risk is genuinely low, a short ESU bridge while you plan a sensible refresh is a perfectly reasonable position and we will say so rather than push an immediate rollout. What we will not do is help you describe an unenrolled Windows 10 fleet as acceptable, because it is not, and because the day it goes wrong the question of who said it was fine will be asked.
Whichever you choose, do these first
- Scan the fleet from the device side. Not the asset register. Processor generation, TPM presence and state, Secure Boot and firmware mode. This sorts every device into upgrade, fix, replace or retire, and it is the only input the decision actually needs.
- Apply the firmware fixes before counting anything. Enabling TPM and Secure Boot on capable hardware routinely moves a meaningful share of the fleet from the replace bucket to the upgrade bucket at no cost. Budget after this recount, not before.
- Find out which devices handle personal data and which are internet-facing. Those are the priority whichever path they take, because they carry the DPDP exposure.
- If any device needs ESU, enrol it at the start of the current period, not at the boundary. Cumulative pricing means waiting costs the skipped months for nothing.
- Give every ESU device an exit date at enrolment and align it to a procurement order. An exit date with nothing behind it is an intention.
- Retire the devices nobody uses. Every fleet has them, they need neither upgrade nor ESU, and removing them shrinks every other number.
Common questions
Talk it through with an engineer, not a salesperson
Tell us your situation and we will tell you which option fits, including when that is not us. Initial reply within 4 business hours.