Year One of Microsoft’s Windows 10 Extended Security Updates program ends on 13 October 2026. Organisations that stay on Windows 10 beyond that date pay US$122 per device for Year Two — double the Year One price — and the cost doubles again in Year Three. For most Australian IT teams the decision is already made. The open question is what happens to the devices coming out.
That question is usually answered late, badly, and expensively. The refresh gets planned in detail; the retirement of the outgoing fleet gets handled in the final fortnight by whoever is available. It is the point where data risk, residual value and audit evidence are all decided at once — and the point where most of the value leaks away.
What happens on 13 October 2026?
Windows 10 reached end of support on 14 October 2025. The Extended Security Updates program lets organisations keep receiving critical and important security updates while they migrate, and it runs to 12 October 2027.
For commercial customers, the program is priced per device per year and escalates deliberately:
- Year One (to 13 October 2026): US$61 per device, or US$45 for devices managed through Microsoft Intune or Windows Autopatch
- Year Two (to October 2027): US$122 per device
- Year Three: US$244 per device
Two details catch organisations out. First, the pricing is cumulative — enrol late and you must purchase the prior years of coverage before you receive current-year updates. Deferring the decision does not defer the cost. Second, ESU delivers security updates only. It does not include technical support, bug fixes, feature updates or driver support.
| Year One — ends 13 Oct 2026 | US$61 per device (US$45 via Intune or Autopatch) |
| Year Two — to Oct 2027 | US$122 per device |
| Year Three | US$244 per device |
| Program ends | 12 October 2027 — no further extension offered |
Can businesses use the $30 consumer ESU option?
No, and this is a common and expensive misreading. Microsoft’s consumer ESU option — free with PC settings sync, 1,000 Microsoft Rewards points, or a one-off US$30 — explicitly cannot be used in commercial scenarios. Enrolment is not offered for devices joined to an Active Directory domain or Microsoft Entra, devices enrolled in a mobile device management solution, or devices in kiosk mode. If a device enrolled under the consumer program is later used in one of those scenarios, its consumer enrolment is suspended.
In practical terms: if your fleet is managed, the commercial pricing applies.
What does a refresh actually cost once disposal is included?
Most refresh business cases model three lines — new hardware, deployment labour, and licensing. Two more belong there.
Storage of the outgoing fleet. Retired devices rarely leave the building on schedule. They accumulate in a store room, a corner of the comms room, or a locked cage, and they sit there for months while someone decides what to do. Every month of storage costs floor space and, more importantly, costs resale value: a three-year-old business laptop loses value continuously, and the market for a given model does not wait.
The data risk still attached to them. A device in a store room is still a device holding recoverable data, still within the scope of Australian Privacy Principle 11, and still your responsibility. The OAIC recorded 1,205 notifiable data breaches in 2025 — the highest annual figure since the scheme began in 2018. Very few of those originated in a store room, but the exposure is real and it is entirely avoidable.
Both of these are costs of indecision, not costs of disposal. They are also the two lines most easily removed from the model.
What should you do with the laptops you’re replacing?
Segment before you decide. A retiring fleet is rarely homogeneous, and treating it as one pile guarantees you get some of it wrong.
Redeploy. Devices with useful life that meet the requirements of a lower-demand role. This is the cheapest laptop your organisation will ever provision, and it removes a device from the purchase order entirely.
Resell or hand to a buyback partner. Devices with genuine market value — typically business-grade machines three to five years old with intact chassis and batteries. These are worth materially more processed promptly than processed eventually.
Recycle. Genuinely end-of-life equipment: failed boards, swollen batteries, obsolete form factors. This is the smallest category in a well-run refresh, not the default one.
We have written in more detail about why this ordering matters in the business case for a reuse-first IT asset policy. The short version is that recycling a working laptop destroys value that would otherwise have offset the refresh.
How do you avoid the three common refresh mistakes?
Wiping in-house without producing evidence. A factory reset is not certified data sanitisation, and an IT technician’s word is not an audit artefact. What you need is a per-device certificate naming the erasure standard applied, the method used, the device serial number, and the operator. We have set out the full comparison in in-house vs outsourced device disposal.
Recycling devices with resale value. Weight-based recycling reports look like environmental performance and are frequently the opposite. A high recycling rate on a fleet of three-year-old laptops means functional hardware was shredded.
Treating disposal as a project rather than a process. Refreshes recur. Devices fail, staff leave, and equipment retires continuously between refresh cycles. An organisation that solves this once, as a one-off project, solves it again from scratch in three years.
What does a well-run refresh handover look like?
Five things, in order:
- Inventory before collection — serial numbers captured while the devices are still yours, not reconstructed afterwards
- Sealed, tracked collection — tamper-evident packaging and a tracked courier, so custody is documented from your door onward
- Certified erasure — data sanitisation against a named standard, with a certificate per device
- Functional grading — an honest assessment of what each device is worth, not a flat rate per box
- Reporting you can hand to an auditor — what was collected, what was erased, what was reused, what was recycled
CirculaTech runs exactly this sequence, and our commercial model is built around the outcome rather than the activity: under a three-year exclusive agreement we invoice nothing, because the process is funded by the resale value recovered from your retired devices. You can see the full chain on our How It Works page, and the evidence produced at each stage on our Security & Compliance page.
If your Windows 11 migration is scheduled for the next twelve months, the outgoing fleet is worth deciding about now — while the devices still have value and while you still have time to do it properly.
Frequently asked questions
When does Windows 10 ESU Year One end?
Year One of the commercial Extended Security Updates program ends on 13 October 2026. Year Two coverage runs from that date at US$122 per device, and the program closes entirely on 12 October 2027.
Can a business use the US$30 consumer Windows 10 ESU?
No. The consumer ESU program cannot be used in commercial scenarios and enrolment is not offered for devices joined to Active Directory or Microsoft Entra, devices enrolled in an MDM solution, or devices in kiosk mode.
Is a factory reset enough before disposing of a corporate laptop?
No. A factory reset does not produce evidence and does not reliably sanitise all storage media. Certified erasure against a named standard, with a per-device certificate referencing the serial number, is what satisfies an audit or a privacy assessment.
What should we do with retired laptops that still work?
Assess them for redeployment first, then resale or buyback, and only recycle genuinely end-of-life hardware. Working business-grade laptops retain meaningful market value, and that value declines every month they sit in storage.
Should we store retired devices until the refresh is finished?
Storing devices costs residual value and keeps data risk on your premises. Collecting in batches as each tranche is decommissioned is generally cheaper and lower-risk than a single handover at the end.
Jakub Wolanski, Founder, CirculaTech