Microsoft plans to expand Windows 11 Memory Integrity to eligible devices through Windows quality updates beginning in October 2026. Microsoft says devices where users or administrators had already disabled the feature will retain that choice under the announced rollout. The change is aimed at extending kernel-level protection by default, while its gaming cost depends on the hardware, game and settings involved.
Microsoft prepares the October 2026 expansion
The planned update targets eligible Windows 11 devices rather than every PC indiscriminately. Microsoft says Windows evaluates hardware capability, driver compatibility and performance readiness before enabling Memory Integrity.
Microsoft’s documented baseline for automatic enablement includes Intel processors from the 8th generation onward, AMD Zen 2 or newer, Qualcomm Snapdragon 8180 or newer, at least 8 GB of RAM on x64 systems, a 64 GB SSD, compatible drivers and hardware virtualization enabled in BIOS or UEFI.
Clean Windows 11 installations already enable Memory Integrity by default when compatible hardware meets the requirements. The October change extends that protection through quality updates to eligible existing devices.
What Memory Integrity protects
Memory Integrity is Microsoft’s name for Hypervisor-protected Code Integrity, or HVCI. It uses Virtualization-based Security (VBS) and the Windows hypervisor to check kernel-mode code inside an isolated virtual environment.
The protection restricts kernel memory so code pages become executable only after passing integrity checks, while executable pages cannot remain writable. That boundary is designed to make it harder for malicious or untrusted drivers and code to tamper with the Windows kernel.
A diagnostic view can distinguish the different parts of that security stack: the hypervisor can be running, the Secure Kernel can be active, VBS can be enabled and HVCI can be enforced as separate status values.
What the gaming measurements found
A controlled comparison used an AMD Ryzen 5 7600X and an NVIDIA GeForce RTX 4070 Ti Super. In Counter-Strike 2, the game ran at 398.2 FPS with Memory Integrity enabled and 404.8 FPS with it disabled at 1080p on low settings. That is a 1.7% advantage for the disabled setting.
In Cyberpunk 2077, the averages were 183.1 FPS with the feature enabled and 186.5 FPS with it disabled under the same 1080p low preset. The average difference was 1.9%, but the 1% low results—an indicator of frame-time dips—were 116.8 FPS and 124.5 FPS, a 6.6% gap.
| Test | Memory Integrity enabled | Memory Integrity disabled | Difference | Conditions |
| Counter-Strike 2 average FPS | 398.2 FPS | 404.8 FPS | 1.7% higher with the feature disabled | 1080p, low; three 60-second runs per setting |
| Cyberpunk 2077 average FPS | 183.1 FPS | 186.5 FPS | 1.9% higher with the feature disabled | 1080p, low; three built-in benchmark runs per setting |
| Cyberpunk 2077 1% low FPS | 116.8 FPS | 124.5 FPS | 6.6% higher with the feature disabled | 1080p, low; three built-in benchmark runs per setting |
Those figures describe the Ryzen 5 7600X and GeForce RTX 4070 Ti Super configuration used for the comparison. They do not provide a single performance percentage for every processor, graphics card, game or frame-rate target.
The practical trade-off for your PC
Memory Integrity adds the HVCI protection layer; disabling it removes that layer. The decision therefore weighs kernel protection against the performance and compatibility behavior of a particular system.
Microsoft says incompatible drivers can prevent activation. Windows Security can identify the drivers involved, and Microsoft recommends updating them or removing the related device or application. Hardware virtualization must also be enabled in firmware, and unsupported hardware can block the feature.
To inspect the setting, open Windows Security > Device security > Core isolation details. The Memory integrity toggle appears there, and changing it may require a restart.
The October rollout will not automatically re-enable the feature on devices where a user or administrator had already turned it off.