Drupal 10 reaches end of life on 9 December 2026. Twelve weeks from now.
After that date there are no security advisories and no patches. Not reduced support — none. If a critical vulnerability lands on 10 December, you are on your own, and the first question your auditor asks is why you were still running it.
Most teams assume this is a project. For a site that kept up with minor releases and doesn't lean on abandoned contrib, it usually isn't. Drupal 10 to 11 is the easiest major upgrade the platform has ever shipped — deprecated code is essentially the whole job, and the tooling tells you exactly where it is.
The sites in trouble are the ones that stopped at 10.0 or 10.1, sit on a patched fork of a module nobody maintains, or run a custom theme written by someone who left in 2023. That is not an upgrade, that is an excavation, and it takes months rather than weeks.
The honest test takes an afternoon: run the upgrade status report today. If it comes back clean, book a week in November and stop thinking about it. If it doesn't, you have found out in September instead of December.
Either answer is worth having now.