What Is EOL (End of Life)?

Related problems: Firewalls or switches the manufacturer no longer patches; Servers running an operating system that stopped getting security updates; Auditors or a cyber insurer flagging unsupported hardware and software; A surprise replacement bill because nobody tracked support dates

End of life (EOL) is a vendor-defined status for a hardware or software product that is being retired. What it means varies by vendor: some use it for the whole retirement process, others for one date within it. Either way, retirement usually happens in stages, with end of sale, the end of security updates or maintenance, and the last date of support set as separate milestones that can be years apart. The product doesn’t switch off at any of them, but as each passes, new security flaws are more likely to stay open, parts and vendor help may dry up, and the risk of keeping it rises. For buyers, the useful information is the specific dates in the vendor’s notice: they decide when hardware and software has to be replaced, upgraded or covered by some other kind of support.

At a glance

  • EOL is a vendor-defined lifecycle status or process, not a measure of whether the device still works, and its exact meaning varies by vendor.
  • End of sale, end of security updates or maintenance, and last date of support are separate milestones, often years apart; the abbreviation EOS can mean either end of sale or end of support.
  • Plan against each specific date in the vendor’s notice, especially the end of security updates, which matters most for firewalls, VPNs, servers and operating systems.
  • Extended support is sometimes available for a fee, and third-party maintenance can cover some hardware, but both are temporary.
  • Tracking these lifecycle dates in an asset inventory turns surprise replacements into planned budget items.

What problem it solves

Every piece of IT eventually ages out. The trouble is that it rarely fails loudly when it does. A firewall past its support date keeps passing traffic, an old server keeps running its application, and a phone system keeps ringing. What changes is quieter: new vulnerabilities go unpatched, firmware bugs stay unfixed, spare parts become hard to find and the vendor’s support line stops taking calls about it.

Vendor lifecycle notices give buyers dates to plan around. Knowing when each product stops getting security updates and when its support ends lets IT replace it on schedule, budget for it a year or two ahead and avoid running critical systems on software nobody is maintaining. It also gives finance and leadership a concrete reason for a replacement project that might otherwise look like spending money to fix something that isn’t broken.

How it works

Lifecycle policies. Most large hardware and software vendors publish lifecycle policies describing how long products are sold and supported. Some fix the timeline from the release date; others announce milestones product by product.

Milestones. Vendors name and space these differently, but a retirement commonly includes:

  • End of sale: the product can no longer be ordered, though existing units are still supported.
  • End of security updates or maintenance: routine fixes and, at some point, security patches stop; technical support may continue on a limited basis.
  • Last date of support: the vendor stops providing support, parts and updates.

These dates are often years apart. Some vendors call the whole sequence EOL; others use EOL for one of the dates. The notice for each product is the authority, and it is worth recording each date separately instead of a single “EOL” date.

Software versus hardware. For operating systems and applications, retirement mainly means no more security updates and growing incompatibility with newer tools. For network and server hardware, it also covers firmware updates, replacement parts and hardware warranty or maintenance contracts. Cloud and SaaS products retire features and versions too, often on a shorter notice period.

Bridging options. Some vendors sell extended security updates or extended support for a fee, typically for a limited time. Third-party maintenance providers support some out-of-support hardware with parts and engineering help, though they can’t usually produce vendor security patches.

When it matters for buyers

  • When you inherit an environment. After an acquisition or a change of IT provider, the first useful question about any device is when its security updates and support end. An inherited stack often hides several products already past it.
  • When internet-facing equipment ages. Firewalls, VPN concentrators and remote access appliances are frequent targets, so running them past end of support carries more risk than an old internal printer does.
  • When you set a hardware refresh cycle. Vendor lifecycle dates are one of the main inputs, alongside warranty, performance and budget.
  • When insurers and auditors ask. Questionnaires increasingly ask about unsupported systems and how you patch them.
  • When renewing maintenance. Paying full maintenance on a product the vendor no longer updates may not be good value.

Keeping each product’s lifecycle dates alongside the asset in your IT asset management (ITAM) or software asset management (SAM) records is the simplest way to see what’s coming. Our network firewalls page covers what to look for when an aging firewall needs replacing.

Questions to ask vendors

  • What are the end of sale, end of security updates and last support dates for this model or version, and where are they published?
  • How long will security updates continue after end of sale?
  • Is extended support available, for how long and at what cost?
  • What is the recommended replacement, and is there a migration path or trade-in credit?
  • If you’re a provider managing our equipment, how will you tell us when something we own is approaching end of support?
  • For third-party maintenance offers: what exactly is covered, and what happens when a security flaw is found?

How it differs from a hardware refresh cycle

End of life is set by the vendor and applies to a product. A hardware refresh cycle is set by you and applies to your fleet: it’s the schedule on which your organization replaces devices, based on warranty, performance, cost and the vendor’s lifecycle dates. A well-planned refresh cycle replaces equipment before its security updates end, so those dates become deadlines you meet in the normal course of business instead of an emergency. Broader device lifecycle management (DLM) covers the whole journey from purchase to disposal, of which the vendor’s lifecycle dates are milestones. Unsupported products that stay in service for years are a common form of technology debt.

Frequently Asked Questions

Is end of life the same as end of support?
Not necessarily. EOL means different things at different vendors: some use it for the whole retirement process, others for a single date. Within that process, end of sale, the end of security updates or maintenance, and the last date of support are usually separate milestones, often years apart. The abbreviation EOS can mean either end of sale or end of support. Plan against each specific date in the vendor's notice, not the EOL label.
Can we keep running equipment after its end of life?
It usually keeps working, but once the relevant milestones pass you stop getting security patches, bug fixes, replacement parts or vendor help, depending on the product and the vendor's policy. The risk grows over time, especially for internet-facing gear such as firewalls and VPN appliances. Some vendors sell paid extended support, and third-party maintenance providers cover some hardware for a time.
How much notice do vendors give before retiring a product?
It varies by vendor and product. Many publish lifecycle policies and announce milestones months or years ahead, but notice periods differ, so track the dates for everything you own instead of relying on a reminder from the vendor.
Does end of life affect cyber insurance or compliance?
It can. Insurers and auditors often ask about unsupported systems, and some security frameworks and payment card rules expect supported, patched software. Check your policy and the frameworks that apply to you.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.