Guides → Practical guides
Windows 10 is out of support: planning the hardware refresh and disposal
Microsoft ended mainstream support for Windows 10 on 14 October 2025. Many organisations bought Extended Security Updates to buy themselves time, and the first business ESU year ends in October 2026. For a lot of fleets, the refresh can't be put off much longer.
Where things stand
Windows 10 no longer gets security updates unless a device is enrolled in the paid Extended Security Updates programme. For organisations, ESU is available for up to three years after end of support, priced per device, and the price rises each year. It's designed as a bridge, not somewhere to stay. A machine running Windows 10 without ESU is an unpatched endpoint on your network, and cyber insurers and frameworks such as Cyber Essentials take a dim view of unsupported operating systems.

Step 1: Sort the fleet into three groups
Windows 11 has firm hardware requirements, including TPM 2.0, Secure Boot and a processor on Microsoft's supported list. Broadly, that rules out most business machines from before about 2018. Run a compatibility report from your management tools and sort every device into one of three groups:
| Group | What to do |
|---|---|
| Eligible and in good condition | Upgrade in place. No hardware cost. |
| Eligible but tired | Replace on your normal cycle. It still has meaningful resale value. |
| Not eligible | Replace. Plan disposal carefully, because this is where most of the volume will be. |
Step 2: Use ESU for timing, not avoidance
Buy ESU for the machines that genuinely can't be replaced before the deadline, and give each one a replacement date. Paying for a second or third ESU year on a device you were always going to replace is money that could have gone towards the new one.
Step 3: Plan the disposal alongside the purchase
Refresh projects tend to put all their planning into the new machines and none into the old ones. Then a storeroom fills with retired laptops, each holding a user's data and each one a risk until it has been dealt with. Build disposal into the project from the start:
- Collect in waves that match your deployment waves, so retired kit never builds up.
- Record serials as machines are retired, not weeks later. See building the asset register.
- Don't let the deployment team "quickly wipe" old machines as part of the swap. In-house formats and resets leave no evidence (see why deleting doesn't erase).
- Lock retired devices away until they're collected.
- Remember the loose media: spare drives, USB sticks and the old file server that gets decommissioned at the end of the project.
What are old Windows 10 machines worth?
Less than they would have been a couple of years ago, because the market is full of them, but seldom nothing. Machines that don't meet Windows 11's requirements still have a second-hand market for other operating systems, parts and less demanding uses. Eligible machines being replaced early can hold decent value. Either way, the value is highest when the devices are recent, complete (with chargers) and collected promptly, and it drops for every month they sit in a cupboard.
That residual value is what usually covers the cost of collection and data destruction. For larger fleets of newer machines, it can mean you get paid.
Data is the part that can't slip
Whatever happens to the hardware, every drive needs to be sanitised or destroyed with a method matched to its type, and certified by serial number. A refresh project generates more retired media in a few months than most organisations produce in years, so it's exactly when a vague process lets devices slip through.
Planning a refresh? We'll schedule collections to match your rollout waves and certify every retired device.
Plan collections with us