Windows 10 reached end of support on October 14, 2025. Organizations that were not ready bought time through Extended Security Updates, and for most of them that time ends on October 13, 2026: the consumer ESU program ends outright, and the first year of the commercial program expires, with renewal for a second and third year at a higher price. Whichever path you took, the machines that could not run Windows 11 are leaving service in the next few weeks, and the drives inside them hold everything those users touched for the last decade. This is the checklist we walk clients through.
1. Count what you actually have
Export the fleet from your asset system, then reconcile it against what is physically in the building. The gap between the two is the list of devices nobody can find, and those are the ones that end up in a breach report. Log every device by asset tag, and for laptops note whether the storage is a removable drive or soldered to the board, because that decides how it is destroyed.
2. Decide what gets a second life
Machines that fail the Windows 11 hardware check are often fine hardware. A lightweight Linux distribution turns them into kiosks, training-room PCs, or test systems, and NIST 800-88 Clear is sufficient for a device that stays inside your organization. If you go this route, wipe before reimaging and record it; a reused machine with a ghost of its old profile is still a data exposure.
3. Everything else gets its storage destroyed
For devices leaving your control, NIST SP 800-88 Rev. 2 sets the floor at Purge and, for anything regulated, we recommend Destroy. Removable drives are pulled and destroyed; laptops with soldered storage are destroyed whole. Solid-state media should go to 2 mm if the data was CUI, PHI, or anything a regulator cares about, because a software wipe on an SSD is a promise you cannot verify per device without a program most IT departments do not have.
4. Check the rules that apply to your data
- Healthcare: HIPAA device and media controls, and a Business Associate Agreement with whoever destroys the drives.
- Law enforcement and courts: CJIS requires disposal by authorized personnel with a record; witnessed destruction on-site satisfies it.
- Defense contractors: NIST 800-171 requirement 3.8.3 for CUI, and NSA/CSS 9-12 for anything classified. With CMMC Phase 2 suspended, the senior official's affirmation is the signature that vouches for this refresh.
- Ohio political subdivisions: HB 96 puts hardware disposal inside the cybersecurity program every county, city, township, school district, and library now has to run.
- Financial institutions: GLBA, the Safeguards Rule, and FACTA's Disposal Rule.
5. Get the record before the truck leaves
A Certificate of Destruction with one line per serial number, the method, the machine, the date, and the witness is what closes the refresh in an audit. Match it to the inventory from step one. Devices that turn out to have no drive should appear on the log as \u201cnone found,\u201D so nobody has to wonder later whether a drive was pulled before it reached the shredder.
6. Do not let the pallet sit
The most common failure we see is not a bad wipe; it is retired machines staged in a storage room for months, unlabeled and uncounted, while someone waits for a big enough pile to justify a pickup. The Inspector General found exactly that at the FBI. Schedule the destruction for the week the machines come out of service, and the pile never exists.
What we can do in the next four weeks
In our next-day metros we can usually be at your dock the day after you call, with no minimum; a school district's carts, a hospital's clinic PCs, and a county's office fleet are all routine. Larger fleets are staged over consecutive days. For a handful of machines, Shred by Mail takes whole laptops at $16 each with the drive destroyed to 2 mm and the chassis recycled. Tell us what you have and we will send a number in writing.
