Windows 10 and Cyber Essentials: Can You Still Pass in 2026/2027?
Published 6 October 2026
End of support vs Extended Security Updates
Microsoft ended standard support for Windows 10 (version 22H2, the final release) on 14 October 2025. From that date, ordinary Windows 10 Home, Pro, Enterprise and Education devices stopped receiving monthly security updates.
ESU is a paid programme that delivers Critical and Important security updates only. It does not add features or provide general technical support. For organisations, Microsoft sells commercial ESU in up to three annual blocks:
| Commercial ESU year | Security updates until |
|---|---|
| Year 1 | 13 October 2026 |
| Year 2 | 12 October 2027 |
| Year 3 | 10 October 2028 |
Do not confuse this with the consumer ESU option Microsoft offered to home users. It has different eligibility and a different end date. Organisational devices should have an applicable Microsoft ESU entitlement, with activation and current update evidence for each device. Talk to your licensing partner or IT provider about the commercial or education route.
What Cyber Essentials means by "supported"
The NCSC requirements say software in scope must be licensed and supported, and must be removed or isolated once it is no longer supported. "Supported" means the vendor is still producing security updates for that product and version, and the updates are being applied. Under NCSC v3.3, updates must be installed within 14 days of release where they fix vulnerabilities the vendor describes as critical or high risk, rated CVSS v3 7 or above, or where the vendor gives no severity level. Applying every released update within 14 days is recommended, not mandatory.
So the question for Windows 10 is not "is it Windows 10?" but "is this specific device still receiving and installing vendor security updates?" Our wider guide to unsupported software and Cyber Essentials covers other operating systems and applications.
How to prove a Windows 10 device is genuinely covered
Before you answer the self-assessment questions, check each Windows 10 device for:
- Version: it is on Windows 10 22H2. Earlier feature releases are not covered by ESU.
- Licence: an ESU licence or subscription has been purchased for that device (or covered through an eligible cloud or Windows 365 route Microsoft documents).
- Activation: the ESU key or entitlement has been activated on the device, not just bought.
- Update state: recent ESU security updates are installed, with CE-required vulnerability fixes applied within 14 days of release.
- Inventory: your device list records which machines rely on ESU and when the current ESU year ends.
Your management tool (Intune, an RMM platform or similar) should be able to report OS build and last update date across the estate. Keep that report. It is far more convincing than a statement that "all Windows 10 machines are on ESU".
The Windows 10 LTSC exception
Windows 10 Enterprise LTSC and IoT Enterprise LTSC editions follow their own fixed lifecycle dates, which are separate from the 22H2 end-of-support date. Some LTSC releases remain in support after October 2025 without ESU; others do not.
Check the specific edition and release (for example LTSC 2019 or LTSC 2021) against the Microsoft Lifecycle pages rather than assuming. LTSC is also rare on normal office laptops, so if your inventory says LTSC, confirm it is correct.
Upgrade or ESU?
| Situation | Usually the better choice |
|---|---|
| Hardware meets Windows 11 requirements | Upgrade to Windows 11. It removes the problem rather than deferring it. |
| Hardware cannot run Windows 11 and is due for replacement within a year | ESU as a short bridge, with a replacement date recorded. |
| Specialist software only works on Windows 10 | ESU while the vendor is chased for a supported version, or isolate the device out of scope. |
| A handful of forgotten devices | Find them, then upgrade, replace or retire them before submission. |
ESU costs money every year and the price rises each year. It is a bridge, not a strategy. Plan the year you will stop paying for it.
Removing a device from scope instead
If a Windows 10 device cannot be upgraded or enrolled, it can sit outside the certified scope only if it is properly segregated. That means it cannot access the internet or organisational services and data that are in scope. Simply not listing it, or putting it "behind the firewall", does not count. If the device is used by staff for normal work, it is in scope.
What it means for Cyber Essentials Plus
At Cyber Essentials Plus the assessor tests a sample of devices, including checking for missing security updates. An unenrolled Windows 10 machine, or one with ESU bought but not activated, will show up as missing updates in testing. Fixing only the sampled devices does not help, because the declaration covers the whole scope. Read common CE Plus failures for the wider picture.
Watch the ESU year boundaries
Your certificate lasts 12 months, but ESU coverage ends on fixed dates each October. If your renewal falls shortly after 13 October 2026 or 12 October 2027, check that the next ESU year has been bought and activated before you submit. Otherwise a device that was compliant last year will be unsupported this year.
