Haink KnowledgeCase StudiesAbout Contact sales
Home / Knowledge / Brands / Cisco / End-of-Life Guide

Cisco End-of-Life: the Dates, the Replacements, and the Deadline That Actually Binds

Written and maintained by Haink's network infrastructure team · Milestones verified against Cisco bulletins, 22 August 2026 · authorized-channel, serial-verified

Every EOL checker on the internet will tell you a Cisco product's end-of-sale date. That is rarely the date that matters. End-of-sale means you can no longer buy it new — inconvenient, but the secondary market and channel inventory absorb it. The dates that actually constrain a network team sit further down the bulletin, and two of them do real damage if you miss them.

This page reproduces the verified milestones for the Cisco families currently in migration, and explains which milestone binds in which situation. Every date below comes from the Cisco end-of-life bulletin for that family; the bulletin URLs are at the bottom.

Two deadlines inside 90 days, as of 22 August 2026

ASA 5508-X and ASA 5516-X — last date of support 31 August 2026. Nine days. After that Cisco's own wording applies: "all support services for the product are unavailable, and the product becomes obsolete." Service contract renewal for these closed on 28 October 2025, so there is no longer a way to buy coverage.

Catalyst 3650 — last date of support 31 October 2026. Seventy days. Contract renewal closed 29 January 2026; existing contracts run to the LDoS date and stop.

The six milestones, and what each one costs you

A Cisco EOL bulletin lists up to eight milestones. Most readers look at two of them. Here is what each one actually means for an operating network.

MilestoneWhat changes on that dateHow much it hurts
End-of-SaleCisco stops taking ordersLow — channel inventory and the secondary market continue
Last ShipCisco stops shipping against existing ordersLow, but it is the real cut-off for new-in-box from the vendor
End of SW MaintenanceNo more software releases, including bug fixesModerate — you freeze on whatever train you are on
End of Routine Failure AnalysisCisco stops investigating hardware failuresLow in practice
End of New Service AttachmentYou can no longer put an uncovered unit onto a contractHigh if you buy second-hand — see below
End of Service Contract RenewalYou can no longer renew coverage at allHighest — this is the deadline that binds
End of Vulnerability / Security SupportNo more security fixesHigh, and often a compliance problem before it is a technical one
Last Date of Support (LDoS)Nothing at all: no TAC, no RMATerminal

Why service contract renewal is the date that matters

Because it is the point at which the decision stops being yours. Up to that date you can pay Cisco to keep supporting the estate, and "run it a bit longer" remains a legitimate option. After it, the equipment runs uncovered until LDoS whether you like it or not — and if it fails, you replace it under time pressure at whatever price the market offers that week.

The gap is larger than people expect. On the Catalyst 3650 the renewal window closed on 29 January 2026 while LDoS is 31 October 2026 — nine months during which the platform is alive, in production, and uninsurable. On the Catalyst 2960-X the same window closes on 29 January 2027, with LDoS a further nine months out on 31 October 2027. If you have 2960-X in production and no plan to replace it before 2027, that January date is the one to put in the calendar, not the October one.

Verified milestones by family

Dates as published in the Cisco bulletin for each family. Where a family is covered by more than one bulletin — which is common — the table shows the bulletin covering the mainstream hardware, and the notes flag the rest.

Campus switching

FamilyEnd-of-SaleSW maintenance endsContract renewal closesLDoSCisco's replacement
Catalyst 385030 Oct 202030 Oct 202128 Jan 202531 Oct 2025 — passedCatalyst 9300
Catalyst 365031 Oct 202131 Oct 202229 Jan 2026 — closed31 Oct 2026Catalyst 9300L
Catalyst 2960-X31 Oct 202231 Oct 202329 Jan 202731 Oct 2027Catalyst 9200L
Catalyst 2960-XR31 Oct 202231 Oct 202329 Jan 202731 Oct 2027Catalyst 9200

Two things worth knowing here. The 2960-X and 2960-XR are covered by separate bulletins with identical dates but different replacements — the X maps to the 9200L, the XR to the full 9200. And there is a second Catalyst 3850 document that is easy to mistake for the hardware bulletin: it announces end-of-sale in September 2023 and covers only re-licensing SKUs with an LL- prefix. If you find "September 2023" quoted as the 3850 end-of-sale date somewhere, that is the confusion.

Routing

FamilyEnd-of-SaleSW maintenance endsContract renewal closesLDoSCisco's replacement
ISR 4221 / 4321 / 4331 / 4351 / 4431 / 44517 Nov 202331 Aug 2025 — passed5 Feb 202830 Nov 2028Catalyst 8200 / 8300 (per model)
ISR 446120 Jan 202520 Jan 2026 — passed17 Apr 202931 Jan 2030C8300-2N2S-4T2X
ASR 1006-X, ASR 1009-X31 Jul 2026 — just passed31 Jul 202726 Oct 203031 Jul 2031Catalyst 8500 Series
ASR 1002-HX31 Mar 202531 Mar 2026 — passed26 Jun 202931 Mar 2030C8500-12X / 12X4QC
Catalyst 8300 Edge uCPE1 Aug 2026 — passed31 Jul 2031None — Cisco states no replacement

The ISR 4000 replacement mapping is per-model, not per-family: ISR4221 → C8200L-1N-4T; ISR4321 and ISR4331 → C8200-1N-4T; ISR4351 → C8300-2N2S-6T; ISR4431 → C8300-1N1S-4T2X or -6T; ISR4451 → C8300-2N2S-4T2X or C8300-2N2S-6T; ISR4461 → C8300-2N2S-4T2X.

Note the software position on the ISR 4000: maintenance releases ended on 31 August 2025, and the supported trains are 17.9.x and 17.12.x — 17.10.x and 17.11.x are not supported on this hardware. If your branch estate is on ISR 4000 and you are planning a software-driven feature (a new SD-WAN capability, a TLS change), the platform will not follow you there, LDoS in 2028 notwithstanding.

The Catalyst 8300 Edge uCPE line is the awkward one. Cisco discontinued it with no successor product named in the bulletin — the migration section offers trade-in credit and remanufactured units, not a replacement platform. Anyone running network functions on that box needs an architecture conversation, not a part swap.

Security

FamilyEnd-of-SaleSW maintenance endsContract renewal closesLDoSCisco's replacement
ASA 5508-X, ASA 5516-X2 Aug 2021Signatures end 31 Aug 202628 Oct 2025 — closed31 Aug 2026Firepower 1000 Series
Firepower 2100 (FPR2110–2140)27 May 202527 May 2026 — passed22 Aug 202931 May 2030Secure Firewall 3100 Series

Two caveats on this table, both worth raising with anyone selling you a migration.

First, the ASA 5508-X bulletin dates from February 2021 and names the Firepower 1000 Series as the migration path. That recommendation is five years old. Before committing to it, check the current lifecycle position of whatever Firepower 1000 model is proposed — a migration onto a platform that is itself well into its cycle buys less runway than the bulletin implies.

Second, the Firepower 2100 bulletin names only the Secure Firewall 3100 Series. It does not mention the 1200 or the 4200, and it gives no per-model mapping — no FPR2110 → specific 3100 SKU. Sizing across that gap is a design exercise, and a quote that assumes a one-to-one swap has skipped it. On Firepower 2100 the practical deadline has already passed quietly: software maintenance ended on 27 May 2026, so those appliances are frozen on their current release with four years of LDoS still nominally ahead.

Wireless

The Cisco and Meraki Wi-Fi 6 indoor access points — the whole Catalyst 9100AX family — went end-of-sale on 31 December 2026, except the C9120AXE and C9120AXP, which Cisco moved up to 10 July 2026, and the C9120AXI, moved to 31 July 2026, "due to exhaustion of available materials." Last ship is 31 March 2027, software maintenance ends 31 December 2027, LDoS is 31 December 2031.

This migration deserves its own page because the replacement changes the switch underneath it: the Wi-Fi 7 access points need 802.3bt where the Wi-Fi 6 ones ran happily on PoE+, and the controller minimum software version varies by access point model. The full analysis, with the PoE budget arithmetic, is in the Wi-Fi 6 end-of-sale guide.

Compute and management

ProductEnd-of-SaleLDoSCisco's replacement
Catalyst Center Appliance Gen 3 (DN3-HW-APL / -L / -XL)31 Dec 202631 Dec 2031Gen 4: DN4-HW-APL / -L / -XL
HyperFlex — HXDP software11 Sep 202428 Feb 2029Cisco Compute Hyperconverged with Nutanix
HyperFlex M6 nodes12 Mar 202430 Jun 2031
HyperFlex M5 nodes30 Oct 202331 Oct 2028

On the Catalyst Center appliance the Gen 3 → Gen 4 mapping is direct but the core counts change: the Gen 3 32-core maps to a Gen 4 32-core, but the 56-core maps to a 48-core and the 80-core to a 72-core. Sizing should be re-checked rather than assumed.

HyperFlex is not a single end-of-life event but a platform being closed through a series of bulletins — software, each hardware generation, and components separately. The software advisory is unusually direct: Cisco "strongly recommends that customers plan and start their migration from HyperFlex to Nutanix HCI on Cisco UCS, or another suitable solution, as soon as possible," and lists the workaround as "None." Worth knowing before you start: Cisco's own HyperFlex EOL FAQ contains a line stating that HyperFlex M6 has not reached end of sale, which contradicts the EOL15171 and EOL15369 bulletins that announce exactly that. Where the FAQ and the bulletin disagree, the bulletin is the formal document. We cover the target architecture in Nutanix versus VxRail and hyperconverged infrastructure.

What is already behind you

If any of the following is in production, the decision window has closed and what remains is risk management:

The pattern in that list is worth naming. In four of the five cases the hardware is still supported and the software stopped years earlier. A fleet can be simultaneously "under support" and unable to receive a security fix. When a scan flags a CVE on a platform whose software maintenance ended, the remediation is a hardware refresh, on whatever timeline the auditor sets.

What the replacement actually costs

Every migration in the tables above looks like a part swap and is not. The recurring hidden costs, in rough order of how often they surprise people:

  1. Licensing model. The 2960-X and 3650 predate the subscription model that the Catalyst 9000 assumes. Replacing them means adding a per-switch Network Essentials or Advantage subscription that did not exist in the old cost line.
  2. Power. Covered in detail on the Wi-Fi 6 migration page, and it is the largest of these on any wireless refresh: the new access points can require a different PoE class and a bigger power supply in the access switch.
  3. Optics. Uplink modules do not always carry across. Check the transceiver list against the new platform before assuming the existing optics are reusable.
  4. Software train. A replacement platform often has a minimum IOS-XE version that is newer than what the rest of the estate runs, which pulls a controller or core upgrade into scope.
  5. Rack and power envelope. Mostly a non-issue on switching, decidedly not on the routing migrations to Catalyst 8500.

How to work through this

  1. Inventory by part number, not by family name. Nearly every family above is split across multiple bulletins with different dates. "We run 2960s" is not a position you can plan from.
  2. Sort by contract renewal date, not end-of-sale. That is the date after which "wait and see" stops being available.
  3. Check software maintenance separately from hardware support. They diverge by years, and the software date is usually the one that triggers a compliance finding.
  4. Price the migration, not the box. Licences, power, optics and the software train, per the section above.
  5. Then decide per site: replace now, extend on remaining channel inventory, or move to a different vendor. All three are legitimate; the third is worth pricing on Aruba or Fortinet where the Cisco licensing step-up is what makes the refresh expensive.

Send us your SKU list

Send the part numbers from your current estate. We return the replacement mapping, the binding dates per SKU, what changes beyond the hardware, and firm lead times — within one business day.

Get the replacement mapping   Prefer email? sales@haink.org

Frequently asked questions

Can I keep using Cisco hardware after end-of-life?

Yes, until last date of support, and physically for as long as it runs after that. What changes at LDoS is that Cisco provides nothing: no TAC case, no RMA, no software. Before LDoS the more important date is end of service contract renewal — after that you cannot buy coverage even if you want to.

Which Cisco EOL date should I actually plan around?

End of service contract renewal, in most cases. It is the last point at which continuing to run the equipment is a decision rather than an exposure. For estates with a compliance obligation, end of vulnerability and security support usually binds earlier.

Can I still get support on second-hand Cisco hardware?

Only if the unit is already covered, or if the End of New Service Attachment date has not passed. That milestone is the one that determines whether an uncovered unit can be put onto a contract at all — and on the ISR 4000, for example, it passed in November 2024. Buying uncovered hardware after that date means it can never be brought under Cisco support.

Is Cisco Refresh (remanufactured) a real option for EOL platforms?

It is, and for a discontinued platform with no successor — the Catalyst 8300 Edge uCPE is the current example — Cisco itself points at it. Availability is limited to whatever has been returned and remanufactured, so it works as a spares strategy and rarely as a growth strategy.

How do I check the EOL status of a specific part number?

Cisco publishes a bulletin per product family at cisco.com/c/en/us/products/<category>/<series>/eos-eol-notice-listing.html. Read the bulletin itself, not the listing page — the listing shows announcement and amendment dates, while the milestone table lives inside the document. Watch for amended bulletins: the date shown in a listing is often the amendment date, not the original announcement, which is how the ISR 4000 announcement gets quoted as 2024 when the bulletin says November 2022.

Does Haink supply end-of-life Cisco hardware?

Where it exists in the channel, yes — extending an estate on remaining inventory is often the right answer when the replacement pulls a licensing or power change with it. All units are serial-verified against Cisco before payment, which matters more on discontinued hardware than on current product: see gray-market and channel risk and how to verify an in-stock claim.

Related

Sources

Every milestone above was read from the Cisco bulletin for that family. Where a family has multiple bulletins, the one covering mainstream hardware is cited.

Haink
info@haink.org

Winning House
72–76 Wing Lok Street
Sheung Wan, Hong Kong

© 2026 Haink. All rights reserved.  ·  Privacy Policy  ·  TermsHong Kong · Dubai · Singapore · Mainland China · Delaware (USA)