Two separate clocks are running on your fielded Windows fleet. Windows 10 IoT Enterprise LTSB 2016 — the build behind most 2016-era POS and kiosk rollouts — reaches end of life October 13, 2026. A separate Secure Boot certificate expiration is an additional operational burden for fleet operators on its own unrelated timeline. Treating the two as the same problem is how fleets end up making the wrong call under pressure.
TL;DR
- Windows 10 IoT Enterprise LTSB 2016 reaches end of security support on October 13, 2026. Other editions run on different dates.
- The 2011 Secure Boot certificate expirations are a separate risk on a separate timer, and they hit supported and unsupported Windows alike.
- Extended Security Updates buy patches only. On the IoT SKU, pricing is set by your OEM and isn't published centrally.
- Four paths lead off Windows 10 IoT: Windows 11 IoT, Linux, new hardware, or converting the hardware you already own to Android.
When does Windows 10 IoT actually reach end of life?
Windows 10 IoT Enterprise LTSB 2016 reaches end of extended support on October 13, 2026, per Microsoft's lifecycle documentation. That is the date driving most 2016-era POS and kiosk builds. After it passes, the OS receives no further security patches from Microsoft.
Other Windows 10 IoT editions run on different clocks, and treating them as one date is a planning error. Windows 10 IoT Enterprise LTSC 2019 has extended support through January 9, 2029. LTSC 2021 runs through January 13, 2032, though mainstream support ends January 12, 2027.
The non-LTSC edition is already done. Non-LTSC Windows 10 IoT Enterprise reached end of support on October 14, 2025, under the Modern Lifecycle Policy. If that's your build, the clock has already run out understanding that most fleet operators are on LTSB/LTSC.
End of life is Microsoft's clock, not a hardware failure date. Your terminals keep booting and running after October 13, 2026. What stops is security patching, and that opens compliance exposure for PCI, HIPAA, and internal audit.
What is the Secure Boot certificate expiration, and how is it different from EOL?
The Secure Boot certificate expiration is a separate risk from end of life, and it runs on its own timer. Three 2011-era Microsoft certificates expire on a rolling schedule in 2026. This risk is independent of any OS end-of-life date.
The dates are specific. The KEK CA 2011 certificate expires June 24, 2026, and the Microsoft UEFI CA 2011 expires June 27, 2026. The Windows Production PCA 2011 certificate expires October 19, 2026.
Expiration doesn't brick your devices, and it doesn't cause boot failure. Machines without the updated 2023 certificates keep booting normally. What they lose is new Secure Boot protection for the early boot process, so exposure grows progressively rather than all at once.
This certificate risk affects supported and unsupported Windows alike. Windows 11 machines are exposed on the same terms as Windows 10. Patching status doesn't remove it.
This is the one place Esper's architecture is directly relevant to the deadline. Esper Foundation runs a custom Android build whose boot chain doesn't depend on Microsoft's Secure Boot certificate chain. A converted device steps around the certificate problem instead of inheriting it.
What are your replacement options?
You have four real paths off Windows 10 IoT, and each one changes a different layer of the stack. The table below compares them on hardware impact, lifecycle exposure, and best fit. Extended Security Updates are a stopgap, not a fifth path.
Extended Security Updates buy time, not a future. ESU delivers security updates only: no new features, no quality updates, and no technical support. For standard Windows 10, commercial ESU starts at $61 per device and doubles each year for up to three years.
Windows 10 IoT Enterprise LTSB 2016 prices differently. Activation keys come from your OEM partner, and Microsoft hasn't published a per-device IoT figure. Price it with your OEM, an ESU calculator, or your sales contact before you assume it's cheap.
Converting existing hardware to Android is one option among four, and it earns a closer look when the machines are healthy. We cover the mechanics of building a custom Android image for aging Windows devices in a separate deep-dive. For teams still standardizing their current estate, Esper also runs Windows device management in the same console.
It’s true you could move to Windows 10 IoT LTSC 2021, but you have to incur the licensing costs and you will still need to reimage your fleet.
Still weighing operating systems in the abstract? Our guide to the best OS for your edge device fleet frames the tradeoffs before you commit to a path.
Whether Windows survives the transition is a scoping decision, not an install method
You decide whether Windows survives an Android conversion during scoping, not by the install method a technician uses. The assumption that a USB install means one outcome and a network install means another is wrong. Preservation versus full conversion is a fleet decision, made before anyone touches a device.
Esper Firebolt is the assisted, scoped engagement that converts fielded x86 Windows machines to Esper Foundation for Android on the same hardware. It's not self-serve, not a standalone product, and not one identical process applied to every device. Firebolt separates three independent layers: the commitment, the delivery mechanism, and the configuration.
The commitment is the real decision. A clean install replaces Windows entirely and ensures the entire disk is devoted to Foundation, relevant if drive sizes on these devices are small. A dual-boot install preserves the Windows partition so you can prove Android in production first.
Dual-boot is reversible because the Windows partition is never removed. The default OS upon boot and boot order is a configuration in Firebolt, with no technician back in the field after the initial install. Dual-boot supports Android up to version 13 and applies to x86 only.
The delivery mechanism doesn't determine whether Windows is preserved. Firebolt dual-boot preserves Windows and stays reversible, while a bare-metal ISO install is destructive and can't be undone. Delivery options include USB media, bare-metal ISO, PXE network boot, or a push through the remote-management tooling you already run.
Eligibility runs through two gates, and both have to clear. The first is the device and peripheral compatibility. The second is whether your POS or kiosk application has an Android build, because a Windows-only app can't be converted in place.
A Firebolt conversion requires both Esper Foundation and an Esper Deploy subscription. Esper confirms device, peripheral, and application eligibility during a scoped evaluation before any commitment. That is why this is an engagement, not a download.
The deadline is fixed. The right path is a scoping question.
October 13, 2026 is fixed for Windows 10 IoT Enterprise LTSB 2016. The harder call is which path fits your fleet, and that's a scoping question, not a shopping question.
See how Firebolt works
FAQ
What is Windows 10 IoT end-of-life?
Windows 10 IoT Enterprise LTSB 2016 reaches end of security support on October 13, 2026. After that date, the OS receives no further patches or support directly from Microsoft (source).
How is the Secure Boot certificate expiration different from end-of-life?
End-of-life stops OS patching from Microsoft. The Secure Boot certificate expiration is a separate firmware-level risk that affects supported and unsupported Windows alike, on its own 2026 schedule (source).
Is ESU a real long-term fix for Windows 10 IoT?
No. ESU delivers security patches only, with no features, quality updates, or technical support, and its cost escalates each year (source). It's a runway, not a destination.
How much does ESU cost for Windows 10 IoT LTSB 2016?
Microsoft hasn't published a per-device IoT price. Keys come from your OEM partner, so price it with your OEM, an ESU calculator, or your sales contact (source).
Can a Windows POS or kiosk fleet move to Android without new hardware?
Yes, if two gates clear: a validated device and peripheral set, and an Android build of your POS or kiosk app. Esper Firebolt converts healthy x86 machines to Foundation in place.
Does keeping Windows depend on the install method?
No. Preservation versus full conversion is a scoping decision. Firebolt dual-boot preserves Windows and is reversible, while a bare-metal ISO install is destructive.
Book a demo
Windows 10 IoT end-of-life is a scoping question before it's a purchasing one. Bring us your fleet: device images, application stack, and deadline. We'll scope the right path and tell you whether converting in place is even eligible, or if you are better off with a hardware refresh.
Book a Demo

