Skip to main content
Decision guide

Windows 11 or Windows 10, for a business in 2026

For any device that meets the hardware bar, Windows 11 now, because Windows 10 stopped receiving security updates in October 2025 and the only supported alternative is a per-device bridge that is priced to become more expensive every year. For devices that do not meet the bar, the question is not which operating system but whether to replace the device or bridge it briefly on Extended Security Updates with a named exit date. The one answer that has no defensible position is the one most fleets have by default: unenrolled, unpatched, and working fine.

What is actually being compared

Windows 11
The supported platform, with monthly security updates, feature updates, and a security architecture that depends on the hardware requirements Microsoft has confirmed will not change.
Windows 10 on ESU
Critical and important security updates only, per device, in annual periods to October 2028, at a price that steps up each year and is cumulative. A bridge for devices that cannot move yet.
Windows 10, unenrolled
No security updates since October 2025, no support, and no defensible position under DPDP Rule 6, customer questionnaires or cyber insurance. What most fleets are doing without having chosen it.
Side by side

How they differ in practice

Feature
Feature
Windows 11
Windows 10 on ESU
Windows 10, unenrolled
Security updates
Monthly, full coverageCritical and important onlyNone since October 2025
Feature updates and new capabilities
YesNoNo
Microsoft support
YesNo, ESU is updates onlyNo
Hardware requirement
TPM 2.0, Secure Boot, supported processorNone, runs on existing hardwareNone
Cost model
Included with the device or licencePer device, escalating, cumulativeNothing, and that is the problem
Duration
OngoingThree annual periods to October 2028Indefinite, and indefinitely exposed
Third-party software support
CurrentBeing dropped on vendor schedulesBeing dropped on vendor schedules
DPDP Rule 6 position
DefensibleA documented mitigationDifficult to describe as reasonable
Security questionnaire answer
Yes, supportedA named exception list to explainNo, or a representation you cannot evidence
Right for
Every device that can run itA short list with exit datesNothing, by design

Move to Windows 11 if

  • The device meets the hardware bar. TPM 2.0, Secure Boot and a supported processor, which is Intel 8th generation, AMD Ryzen 2000 or later. A scan tells you, and a surprising share of devices that look ineligible only need TPM enabled in firmware.
  • You want the security architecture the hardware requirements exist for: virtualisation-based security, hardware-backed credential protection and a firmware baseline Windows 10 could not assume. The upgrade only delivers this if the configuration follows.
  • You are answering customer security questionnaires, holding ISO 27001 or SOC 2, or carrying a DPDP obligation, all of which ask whether every endpoint runs a supported operating system.
  • You are provisioning new devices. Autopilot with Intune provisions Windows 11 devices without an engineer, and there is no reason to provision a new device onto an unsupported platform.

Bridge on Windows 10 ESU if

  • The device cannot meet the hardware bar and cannot be replaced before the current ESU period ends. This is a real category and it should be a short, named list, not the fleet.
  • The device runs an application with no Windows 11 path yet, and the vendor has a date. The ESU exit date should match the vendor date, and the alternative of a Windows 365 Cloud PC should be costed first.
  • A funded replacement is ordered and delivery falls after the period boundary. A short bridge with the exit date set to the delivery date.
  • You can document the risk acceptance: which devices, why, until when, signed by an accountable owner. That is what an auditor or an enterprise customer will accept in place of a clean yes.

Stay on unenrolled Windows 10 if

  • There is no scenario in which this is the right answer for a business device that handles email, browses the web, or touches personal data. It is included here because it is what most fleets are actually doing, and naming it is the first step to leaving it.
  • The only near-legitimate case is a device that must stay on Windows 10 for a hard application dependency, in which case it belongs on an isolated network segment with no internet and no email, treated as operational technology, with a signed risk acceptance and a review date.

When the other option is right

We are a Microsoft Partner and we sell Windows 11 migrations, so weigh that. Two things against our own interest. First, if a device is capable but has TPM disabled in firmware, the answer is a free setting change, not a replacement, and we will find those before proposing hardware. Second, if your fleet is small and your risk is genuinely low, a short ESU bridge while you plan a sensible refresh is a perfectly reasonable position and we will say so rather than push an immediate rollout. What we will not do is help you describe an unenrolled Windows 10 fleet as acceptable, because it is not, and because the day it goes wrong the question of who said it was fine will be asked.

Whichever you choose, do these first

  1. Scan the fleet from the device side. Not the asset register. Processor generation, TPM presence and state, Secure Boot and firmware mode. This sorts every device into upgrade, fix, replace or retire, and it is the only input the decision actually needs.
  2. Apply the firmware fixes before counting anything. Enabling TPM and Secure Boot on capable hardware routinely moves a meaningful share of the fleet from the replace bucket to the upgrade bucket at no cost. Budget after this recount, not before.
  3. Find out which devices handle personal data and which are internet-facing. Those are the priority whichever path they take, because they carry the DPDP exposure.
  4. If any device needs ESU, enrol it at the start of the current period, not at the boundary. Cumulative pricing means waiting costs the skipped months for nothing.
  5. Give every ESU device an exit date at enrolment and align it to a procurement order. An exit date with nothing behind it is an intention.
  6. Retire the devices nobody uses. Every fleet has them, they need neither upgrade nor ESU, and removing them shrinks every other number.
Questions

Common questions

Still deciding?

Talk it through with an engineer, not a salesperson

Tell us your situation and we will tell you which option fits, including when that is not us. Initial reply within 4 business hours.