Windows 10 End‑of‑Support Leaves 16.9 % of Devices Exposed, Raising Compliance and Security Risks
What Happened — Microsoft stopped providing security updates for Windows 10 on 14 Oct 2025. Despite that, ≈ 17 % of Windows devices (21 % at SMBs) still run the unsupported OS, many of which host high‑risk, unpatched vulnerabilities.
Why It Matters for Compliance & Audit Readiness
- Unsupported software violates most regulatory baselines (e.g., ISO 27001, NIST 800‑53, GDPR) that require “supported and patched” systems, creating a control gap that auditors will flag.
- The concentration of high/critical CVEs on Windows 10 drives higher cyber‑insurance premiums and can lead to coverage exclusions if an incident stems from an unpatched device.
- Continuous evidence of remediation (e.g., migration plans, risk‑mitigation documentation) is essential to demonstrate due diligence during a SOC 2 audit.
Who Is Affected — Healthcare & pharma, consumer‑retail, manufacturing, and SMBs that rely on legacy hardware or have budget constraints.
Recommended Actions
- Inventory all Windows 10 endpoints and map them to the “Supported Operating System” control in your SOC 2 framework.
- Prioritize migration or apply Microsoft’s paid Extended Security Updates (ESU) where migration is not feasible, and capture the justification as audit evidence.
- Integrate the OS‑lifecycle status into your continuous‑compliance monitoring platform to generate real‑time alerts for unsupported assets.
Technical Notes — Windows 10 devices average 1,903 known CVEs per system versus 652 on Windows 11; 66.6 % of those are rated high or critical, and 2.4 % are actively exploited. No single CVE is cited; the risk stems from the aggregate exposure of an unsupported platform. Source: Help Net Security