Getting your organisation ready for Windows 11 upgrade before Autumn 2025
Why you should act now to ensure you meet the new hardware standards, and prioritise security.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

At the NCSC we maintain recommended configurations for the main operating systems which help organisations to quickly deploy our recommended baselines, rather than needing to evaluate all the settings themselves. Today, we have released our updated configuration packs for Microsoft Windows and - as ever - we've selected the smallest group of settings for you to deploy which are both usable and deliver real world security benefits.
As we update our configurations, I want to use this opportunity to remind you about updating your devices in light of the nearing end of life date for Windows 10, on 14 October 2025.
In spite of its advanced age, Windows 10 still has a sizeable number of users, and some organisations are reticent to upgrade to Windows 11. A likely reason for this is very simple: to many people, Windows 10 works for them, and just doesn’t feel old. Thanks to its modern UI, users forget that it was released over a decade ago. But come this October, Windows 10 will transition into a legacy technology alongside the likes of Internet Explorer (IE).
It goes without saying that the security risks of not upgrading are significant. In addition to the difficulties associated with being out of support, an out-of-date operating system is a prime target for cyber criminals. We saw this when a vulnerability in IE 6-11 was exploited after Windows XP support ended on 8 April 2014, and before it was patched on 1 May 2014. And again in 2017, a vulnerability in unpatched versions of XP was exploited extensively by the WannaCry ransomware – an attack which resulted in huge costs and damage globally.
It's worth highlighting though that whilst some Windows 10 users have taken heed of the deadline and are keen to upgrade, they find themselves unable to due to the new hardware requirements which Windows 11 introduced, such as TPM 2.0, UEFI and support for Secure Boot. If your devices lack even one of these features, you'll be unable to upgrade easily. If your organisation is using unsupported devices, the upgrade to Windows 11 provides excellent justification for purchase of new hardware.
If you’re still unable to upgrade to Windows 11, you should consider using Windows 10 Extended Security Updates (ESU) program as a temporary measure. This is a paid program that gives customers the option to receive security updates for PCs enrolled in the program.
Windows 11 has introduced improvements to its secure-by-default approach. The new hardware is required to make use of some existing security features – many of which were available in Windows 10 but required manual activation or configuration – such as Bitlocker, Virtualization-Based Security (VBS) and Secure Launch. At the same time, Windows 11 has introduced additional security-enhancing features including Native passkey management, improvements to Windows Hello and changes to the default behaviour of features like Credential Guard.
Devices that don’t meet Windows 11 hardware requirements – and are therefore unable to use the features that are needed to secure Windows - remain fundamentally vulnerable to attack.
In summary, we strongly advise any organisation that isn't already on Windows 11 to prioritise migrating before Windows 10 becomes legacy in October 2025. And if upgrading requires you to replace hardware, consider it an opportunity to address security vulnerabilities in your devices rather than simply the nuisance of replacing old hardware.


