Windows 10 End of Life: What Canadian SMBs Still Running the Unsupported OS Need to Do Before Year-End
Nine months have passed since Microsoft ended support for Windows 10 on October 14, 2025. For many Canadian SMBs, that date came and went without a plan. The machines still work. The accounting software still runs. The employees have not complained. And the security bill is accumulating quietly in the background.
The Scale of the Problem
According to global desktop tracking data from StatCounter, Windows 10 still held approximately 28% of worldwide Windows device share as of June 2026 — down from roughly 49% the year before EOL, but still representing hundreds of millions of active machines that have not received a security patch from Microsoft since last October. StatCounter, as reported by MedhaCloud
In Canadian SMB environments, the proportion running Windows 10 is higher than the enterprise average. Research from Lansweeper — which scans millions of IT assets globally — found that 21.4% of SMB devices still run Windows 10, compared to 16.6% at large organizations. Larger enterprises have dedicated IT resources to drive OS refresh cycles; most SMBs do not. Lansweeper, Windows 10 Holdouts Carry Three Times the Risk of Windows 11
The security gap between an unpatched Windows 10 endpoint and a Windows 11 device is not a rounding error. Lansweeper's vulnerability analysis found the average Windows 10 device carries 1,903 active CVEs (Common Vulnerabilities and Exposures) while the average Windows 11 device carries 652 — roughly 2.9 times the exposure. That gap widens every Patch Tuesday that Windows 10 misses. Lansweeper, Windows 10 Holdouts Carry Three Times the Risk of Windows 11
Why Canadian SMBs Haven't Upgraded
The most common barrier is hardware. Windows 11 requires a TPM 2.0 chip, an 8th-generation Intel Core processor or later (or AMD Ryzen 2000 series or later), and at least 4 GB of RAM. Business laptops and desktops purchased before 2018 frequently fail the TPM 2.0 requirement — and Microsoft confirmed in 2024 that this threshold is non-negotiable. Windows Central, Microsoft Makes TPM 2.0 Requirement Non-Negotiable
For pre-2018 devices, upgrading the operating system is not possible. The only options are to replace the hardware, extend Windows 10 coverage through Extended Security Updates, or accept the exposure.
The business case for inaction feels compelling in the short term: why spend $1,000 to $1,750 CAD per device (hardware plus deployment labour) on a computer refresh when the machine still opens Outlook and runs the project management software? The answer is what that same machine costs when attackers find it first.
What CCCS Requires
The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025–2026 identifies ransomware as the top cybercrime threat to Canadian businesses and explicitly names unpatched software as a primary initial access vector — alongside compromised credentials, phishing, and exposed Remote Desktop Protocol. The CCCS notes that entities with limited ability to invest in IT infrastructure face "particular vulnerabilities" from unpatched systems — a precise description of the average Canadian SMB running a fleet of pre-2019 computers.
The CCCS's Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089) requires organizations to apply critical security patches within 15 days of release and to replace or isolate systems that can no longer receive patches. A Windows 10 device not enrolled in Extended Security Updates stopped receiving critical patches nine months ago. It does not meet the CCCS baseline.
This is not a theoretical compliance concern. Cyber insurers are actively reviewing OS versions on renewals, and several carriers have begun flagging unpatched endpoints as coverage conditions. An incident traced to an unmanaged, unpatched Windows 10 machine may affect your ability to collect on a cyber insurance claim.
The Real Attack Surface
The 2025 Verizon Data Breach Investigations Report found that vulnerability exploitation was the initial access vector in one in five breaches — a 34% year-over-year increase. Organizations take a median of 32 days to patch after a critical vulnerability is disclosed, and only 54% of vulnerable devices are fully remediated within the year. Among endpoint and edge-infrastructure compromises, the window between public disclosure and active exploitation is typically measured in days.
For Windows 10 endpoints, the arithmetic is direct. Every month since October 2025, Microsoft has disclosed Windows vulnerabilities and issued patches for Windows 11. Windows 10 devices outside the ESU program received no equivalent patch for those same vulnerability classes. The CISA Known Exploited Vulnerabilities catalog has catalogued multiple actively exploited Microsoft Windows flaws through 2026, including vulnerabilities leveraged by state-sponsored threat groups targeting organizations across North America and Europe.
The financial consequences when an attack succeeds are significant. According to IBM's 2025 Cost of a Data Breach Report, the average data breach cost for Canadian organizations reached CA$6.98 million in 2025 — a 10.4% increase from CA$6.32 million in 2024. Even at a fraction of that scale, a ransomware incident that locks a 15-person team out of systems for a week, combined with legal notification obligations under PIPEDA, regularly reaches six figures for Canadian SMBs.
The Extended Security Updates Option — And Its Limits
Microsoft's Extended Security Updates (ESU) program provides continued critical-security-update coverage for Windows 10 beyond October 14, 2025. Commercial pricing follows a doubling structure across three annual tiers:
| Year | Coverage Period | Commercial Price per Device |
|---|---|---|
| Year 1 | Oct 15, 2025 – Oct 13, 2026 | US$61 |
| Year 2 | Oct 14, 2026 – Oct 12, 2027 | US$122 |
| Year 3 | Oct 13, 2027 – Oct 10, 2028 | US$244 |
The program is cumulative. If you are enrolling today for Year 1 backdated coverage, you must pay for it in full. A 20-device SMB enrolling now for Year 1 pays approximately US$1,220 — roughly CAD$1,680. At Year 2 rates, that doubles to CAD$3,360 for the same fleet. Microsoft Learn, Extended Security Updates Program for Windows 10
ESU is not a complete solution. It provides only critical and important security updates — not new features, not bug fixes unrelated to security, and not coverage for compatibility issues that arise as software vendors drop Windows 10 from their support matrices. Google Chrome extended Windows 10 support through its own timeline, but business application vendors — including ERP, accounting, and vertical software providers — are progressively ending Windows 10 support as their development cycles advance. ESU keeps the OS off the "critical unpatched" list; it does not keep it compatible with the rest of your software stack indefinitely.
ESU also has an end. After October 2028, the program closes entirely. Organizations that use ESU to defer a hardware refresh are buying time, not eliminating the problem.
Choosing Your Path
The right path depends on the hardware generation of your affected devices:
Devices that can upgrade to Windows 11 (TPM 2.0 capable, 8th-gen+ CPU, 4 GB+ RAM): upgrade directly. Microsoft provides a free in-place upgrade for eligible Windows 10 devices. A managed rollout through an IT provider typically costs $150–$250 CAD per device in labour. For a 20-device eligible fleet, that is a $3,000–$5,000 CAD project — the most cost-effective outcome.
Devices that cannot meet Windows 11 hardware requirements — typically pre-2018 hardware lacking TPM 2.0: two sub-paths apply.
- Replace now: Business-class laptops run $850–$1,500 CAD per device; deployment adds $150–$250 per device. A 20-device hardware refresh costs approximately $20,000–$35,000 CAD. This is a capital expense many SMBs can manage through a device-as-a-service arrangement or phased over two budget cycles.
- ESU Year 1, then replace: Purchase Year 1 ESU ($61 USD per device) to maintain minimal patch coverage through October 2026 while planning and funding the hardware refresh. At Year 2 pricing ($122/device), ESU is rarely the better total-cost-of-ownership choice compared to replacement.
Rule of thumb: if a device is 6+ years old and would cost more than CA$200 in ESU over the next 12 months to keep minimally patched, hardware replacement is almost always the better investment over a two-year horizon.
A Practical 90-Day Action Plan
Month 1 — Inventory: Enumerate every Windows 10 device in your environment. Microsoft Intune (included in Microsoft 365 Business Premium) provides OS version, CPU generation, TPM status, and patch compliance for every enrolled device. If Intune is not deployed, a manual audit with a spreadsheet works. The output should be a list of devices, their Windows version, their hardware generation, and whether they are ESU-eligible.
Month 2 — Segment: Classify each device into three buckets: (1) upgradeable to Windows 11 now, (2) requires hardware replacement, (3) borderline — firmware TPM needs checking before deciding. For bucket 2 and 3 devices, check line-of-business software compatibility with Windows 11, which in most cases is a non-issue for mainstream business software in 2026.
Month 3 — Act: Push Windows 11 upgrades to eligible devices through a managed deployment. Initiate hardware procurement for non-upgradeable devices, prioritizing those that handle the most sensitive data or are most directly internet-facing. For devices that will not be replaced this cycle, enroll in ESU Year 1 before October 2026. Document the decisions — your CCCS-aligned security posture and your cyber insurance renewal both benefit from evidence of systematic patch management.
The devices that have not been patched since October 2025 are not waiting quietly. The vulnerability catalogue on each one is growing every month. The practical question for Canadian SMBs is not whether to act, but in which order.
Sources
- Microsoft. *Windows 10 Support Has Ended.* support.microsoft.com
- Lansweeper. *Windows 10 Holdouts Carry Three Times the Risk of Windows 11.* lansweeper.com
- MedhaCloud. *Windows Market Share 2026.* medhacloud.com
- Windows Central. *Microsoft Makes TPM 2.0 Requirement Non-Negotiable.* windowscentral.com
- Canadian Centre for Cyber Security. *National Cyber Threat Assessment 2025–2026.* cyber.gc.ca
- Canadian Centre for Cyber Security. *Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089).* cyber.gc.ca
- Verizon. *2025 Data Breach Investigations Report.* verizon.com
- CISA. *Known Exploited Vulnerabilities Catalog.* cisa.gov
- IBM. *Cost of a Data Breach Report 2025 — Canada.* canada.newsroom.ibm.com
- Microsoft Learn. *Extended Security Updates Program for Windows 10.* learn.microsoft.com
- CIRA. *2025 Cybersecurity Survey.* cira.ca
Cloud Forces helps Canadian SMBs audit their endpoint fleet, identify Windows 10 upgrade and replacement paths, and implement managed patching through Microsoft Intune — so that you have documented patch compliance satisfying both the CCCS baseline and your cyber insurance requirements. Explore our Cybersecurity services or contact us to book a complimentary endpoint security audit.
Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.
Ready to bring AI to your business?
Book a free AI Readiness Consultation — no commitment required.
Book Free Consultation