Service-disabled veteran-owned. Mobile on-site destruction anywhere in the lower 48.330-704-1641    contact@mansfieldtech.us

Windows 10 Extended Security Updates End October 13, 2026: The Last Retirement Checklist

Every fleet that bought the year is retiring this fall.

Windows 10 reached end of support on October 14, 2025. Organizations that were not ready bought time through Extended Security Updates, and for most of them that time ends on October 13, 2026: the consumer ESU program ends outright, and the first year of the commercial program expires, with renewal for a second and third year at a higher price. Whichever path you took, the machines that could not run Windows 11 are leaving service in the next few weeks, and the drives inside them hold everything those users touched for the last decade. This is the checklist we walk clients through.

1. Count what you actually have

Export the fleet from your asset system, then reconcile it against what is physically in the building. The gap between the two is the list of devices nobody can find, and those are the ones that end up in a breach report. Log every device by asset tag, and for laptops note whether the storage is a removable drive or soldered to the board, because that decides how it is destroyed.

2. Decide what gets a second life

Machines that fail the Windows 11 hardware check are often fine hardware. A lightweight Linux distribution turns them into kiosks, training-room PCs, or test systems, and NIST 800-88 Clear is sufficient for a device that stays inside your organization. If you go this route, wipe before reimaging and record it; a reused machine with a ghost of its old profile is still a data exposure.

3. Everything else gets its storage destroyed

For devices leaving your control, NIST SP 800-88 Rev. 2 sets the floor at Purge and, for anything regulated, we recommend Destroy. Removable drives are pulled and destroyed; laptops with soldered storage are destroyed whole. Solid-state media should go to 2 mm if the data was CUI, PHI, or anything a regulator cares about, because a software wipe on an SSD is a promise you cannot verify per device without a program most IT departments do not have.

4. Check the rules that apply to your data

  • Healthcare: HIPAA device and media controls, and a Business Associate Agreement with whoever destroys the drives.
  • Law enforcement and courts: CJIS requires disposal by authorized personnel with a record; witnessed destruction on-site satisfies it.
  • Defense contractors: NIST 800-171 requirement 3.8.3 for CUI, and NSA/CSS 9-12 for anything classified. With CMMC Phase 2 suspended, the senior official's affirmation is the signature that vouches for this refresh.
  • Ohio political subdivisions: HB 96 puts hardware disposal inside the cybersecurity program every county, city, township, school district, and library now has to run.
  • Financial institutions: GLBA, the Safeguards Rule, and FACTA's Disposal Rule.

5. Get the record before the truck leaves

A Certificate of Destruction with one line per serial number, the method, the machine, the date, and the witness is what closes the refresh in an audit. Match it to the inventory from step one. Devices that turn out to have no drive should appear on the log as \u201cnone found,\u201D so nobody has to wonder later whether a drive was pulled before it reached the shredder.

6. Do not let the pallet sit

The most common failure we see is not a bad wipe; it is retired machines staged in a storage room for months, unlabeled and uncounted, while someone waits for a big enough pile to justify a pickup. The Inspector General found exactly that at the FBI. Schedule the destruction for the week the machines come out of service, and the pile never exists.

What we can do in the next four weeks

In our next-day metros we can usually be at your dock the day after you call, with no minimum; a school district's carts, a hospital's clinic PCs, and a county's office fleet are all routine. Larger fleets are staged over consecutive days. For a handful of machines, Shred by Mail takes whole laptops at $16 each with the drive destroyed to 2 mm and the chassis recycled. Tell us what you have and we will send a number in writing.

About the author. Christopher McDevitt is the founder of Mansfield Technologies, a service-disabled veteran-owned company that performs on-site data destruction to NSA/CSS 9-12 and NIST 800-88. He spent ten years in the U.S. Army Signal Corps and six years supporting the U.S. Intelligence Community. More about the company.

More from the blog

  • CMMC, NIST 800-171, and DCSA: Why We Now Recommend Physical Destruction for CUI Media

    The CMMC third-party assessment deadline moved in July 2026. The obligation to sanitize CUI media did not, and the signature on the affirmation is now yours. What NIST 800-171, 32 CFR 2002, DoDI 5200.48, and DCSA's guidance require, why a wipe is harder to prove than it looks, and why we recommend destroying CUI media rather than purging it.

  • Windows 10 Recycling: A Guide to Secure Disposal and Compliance

    Windows 10 has entered its post-support era. What to do with the fleet you are decommissioning: which machines can get a second life, and what NIST 800-88r2, CJIS, and NSA 9-12 require of the rest.

  • NIST 800-88r2: Navigating Data Disposal

    The finalized Revision 2 of NIST SP 800-88 gives businesses a modernized framework for sanitizing data across physical, virtual, and cloud environments. What changed, what the documentation now has to show, and how to choose Clear, Purge, or Destroy.

Retiring hardware? Start with the destruction.

Request a custom quote