Microsoft officially ended updates and security support for Windows 10 on October 14, 2025, completing a decade-long run. After this date, standard editions of Windows 10 no longer receive security patches, bug fixes, or technical support. While devices running Windows 10 will continue to function, the lack of updates raises significant cybersecurity and regulatory risks — particularly for medical devices that depend on the operating system.
What happens after October 2025?
- No more security patches — newly discovered vulnerabilities will go unpatched, making systems a target for ransomware, malware, and nation-state attacks.
- One-year extension (optional) — Microsoft offers Extended Security Updates (ESU) until October 2026, but only as a temporary measure.
- Windows 10 IoT Enterprise LTSC — for embedded or critical systems like medical devices, the LTSC 2021 edition will receive support until January 2032, offering the longest possible lifeline.
FDA cybersecurity expectations
For medical device manufacturers, cybersecurity is not just a technical issue — it is a regulatory obligation under the FDA. The FDA expects device makers to manage cybersecurity risks throughout the device lifecycle, and the end of Windows 10 support directly affects that responsibility.
- Secure product lifecycle management — the FDA requires manufacturers to design and maintain devices with resilience against evolving threats. Running an unsupported OS breaks this principle, since new vulnerabilities will remain unpatched.
- Threat modeling & risk management — FDA guidance emphasizes active threat modeling and ongoing risk assessments. Unsupported Windows 10 creates a permanent, unmitigable risk that must be documented and addressed in risk files.
- Patchability & software updates — manufacturers are expected to provide security updates or compensating controls. Without Microsoft updates, device makers must either migrate to supported platforms (Windows 11 or Windows 10 LTSC) or implement compensating controls such as network isolation, intrusion detection, and application whitelisting.
- Postmarket cybersecurity responsibilities — FDA’s 2016 postmarket guidance, aligned with the 21 CFR Part 820 Quality System Regulation, requires manufacturers to monitor vulnerabilities and deploy fixes. A device using Windows 10 beyond October 2025 without extended support may no longer meet these obligations.
- Premarket submissions and recertification — devices submitted for FDA clearance must demonstrate cybersecurity resilience. A manufacturer shipping a device with Windows 10 after support ends should expect FDA reviewers to treat it as noncompliant, requiring redesign or migration.
Practical implications
Devices left on Windows 10 become vulnerable to exploits, making hospitals and patients potential targets. Manufacturers cannot claim adherence to FDA cybersecurity expectations if devices run unsupported software — this can mean FDA requests for remediation plans, delays or denials in premarket clearance, and increased liability in postmarket surveillance or recalls. Healthcare providers may also refuse to purchase or operate devices on unsupported Windows versions due to security and HIPAA compliance risk, and service contracts may need renegotiation to cover OS transition costs.
Options for manufacturers and healthcare providers
| Path | Benefits | Challenges |
|---|---|---|
| Migrate to Windows 11 | Maintains ongoing security & compliance | Requires hardware/firmware compatibility and full revalidation |
| Purchase ESU (2025–2026) | Buys time for transition | Short-term fix, costly per device, still requires eventual migration |
| Adopt Windows 10 IoT Enterprise LTSC | Supported until 2032, stable, minimal feature changes | Requires volume licensing; regulatory re-submission may be needed |
| Implement compensating controls | Can reduce risk short-term (segmentation, monitoring) | Does not eliminate FDA compliance gaps long-term |
Migrating from one OS version to another isn’t always straightforward for medical devices. Some devices may need to be re-engineered to work with a new OS, which can trigger a new regulatory submission — adding cost and time for both manufacturers and providers. Others may need elaborate testing and validation, and healthcare providers cannot upgrade those devices without manufacturer approval and validation.
This is a good illustration of secure-by-design principles: medical devices should be planned around the most secure available option, which in Microsoft’s case typically means the Long-Term Servicing Channel (LTSC). Approaching medical device development with limited to no dependency on the underlying operating system is an important design practice to adopt going forward.
Key takeaways
- October 14, 2025 is the hard cutoff — after this, Windows 10 is a cybersecurity liability.
- Regulators and customers expect proactive cybersecurity risk management; unsupported OS usage will be difficult to justify.
- Short-term: enroll devices in ESU through 2026 to stay patched.
- Long-term: plan migration to Windows 11 or Windows 10 IoT Enterprise LTSC to maintain FDA compliance and protect patients.
- Start transition planning now if you haven’t already — OS migrations in regulated environments require revalidation, updated risk documentation, and potentially FDA interaction.
Reference: Microsoft — Windows 10 end of support