Cisco End-of-Life: the Dates, the Replacements, and the Deadline That Actually Binds
Written and maintained by Haink's network infrastructure team · Milestones verified against Cisco bulletins, 22 August 2026 · authorized-channel, serial-verified
Every EOL checker on the internet will tell you a Cisco product's end-of-sale date. That is rarely the date that matters. End-of-sale means you can no longer buy it new — inconvenient, but the secondary market and channel inventory absorb it. The dates that actually constrain a network team sit further down the bulletin, and two of them do real damage if you miss them.
This page reproduces the verified milestones for the Cisco families currently in migration, and explains which milestone binds in which situation. Every date below comes from the Cisco end-of-life bulletin for that family; the bulletin URLs are at the bottom.
Two deadlines inside 90 days, as of 22 August 2026
ASA 5508-X and ASA 5516-X — last date of support 31 August 2026. Nine days. After that Cisco's own wording applies: "all support services for the product are unavailable, and the product becomes obsolete." Service contract renewal for these closed on 28 October 2025, so there is no longer a way to buy coverage.
Catalyst 3650 — last date of support 31 October 2026. Seventy days. Contract renewal closed 29 January 2026; existing contracts run to the LDoS date and stop.
The six milestones, and what each one costs you
A Cisco EOL bulletin lists up to eight milestones. Most readers look at two of them. Here is what each one actually means for an operating network.
| Milestone | What changes on that date | How much it hurts |
|---|---|---|
| End-of-Sale | Cisco stops taking orders | Low — channel inventory and the secondary market continue |
| Last Ship | Cisco stops shipping against existing orders | Low, but it is the real cut-off for new-in-box from the vendor |
| End of SW Maintenance | No more software releases, including bug fixes | Moderate — you freeze on whatever train you are on |
| End of Routine Failure Analysis | Cisco stops investigating hardware failures | Low in practice |
| End of New Service Attachment | You can no longer put an uncovered unit onto a contract | High if you buy second-hand — see below |
| End of Service Contract Renewal | You can no longer renew coverage at all | Highest — this is the deadline that binds |
| End of Vulnerability / Security Support | No more security fixes | High, and often a compliance problem before it is a technical one |
| Last Date of Support (LDoS) | Nothing at all: no TAC, no RMA | Terminal |
Why service contract renewal is the date that matters
Because it is the point at which the decision stops being yours. Up to that date you can pay Cisco to keep supporting the estate, and "run it a bit longer" remains a legitimate option. After it, the equipment runs uncovered until LDoS whether you like it or not — and if it fails, you replace it under time pressure at whatever price the market offers that week.
The gap is larger than people expect. On the Catalyst 3650 the renewal window closed on 29 January 2026 while LDoS is 31 October 2026 — nine months during which the platform is alive, in production, and uninsurable. On the Catalyst 2960-X the same window closes on 29 January 2027, with LDoS a further nine months out on 31 October 2027. If you have 2960-X in production and no plan to replace it before 2027, that January date is the one to put in the calendar, not the October one.
Verified milestones by family
Dates as published in the Cisco bulletin for each family. Where a family is covered by more than one bulletin — which is common — the table shows the bulletin covering the mainstream hardware, and the notes flag the rest.
Campus switching
| Family | End-of-Sale | SW maintenance ends | Contract renewal closes | LDoS | Cisco's replacement |
|---|---|---|---|---|---|
| Catalyst 3850 | 30 Oct 2020 | 30 Oct 2021 | 28 Jan 2025 | 31 Oct 2025 — passed | Catalyst 9300 |
| Catalyst 3650 | 31 Oct 2021 | 31 Oct 2022 | 29 Jan 2026 — closed | 31 Oct 2026 | Catalyst 9300L |
| Catalyst 2960-X | 31 Oct 2022 | 31 Oct 2023 | 29 Jan 2027 | 31 Oct 2027 | Catalyst 9200L |
| Catalyst 2960-XR | 31 Oct 2022 | 31 Oct 2023 | 29 Jan 2027 | 31 Oct 2027 | Catalyst 9200 |
Two things worth knowing here. The 2960-X and 2960-XR are covered by separate bulletins with identical dates but different replacements — the X maps to the 9200L, the XR to the full 9200. And there is a second Catalyst 3850 document that is easy to mistake for the hardware bulletin: it announces end-of-sale in September 2023 and covers only re-licensing SKUs with an LL- prefix. If you find "September 2023" quoted as the 3850 end-of-sale date somewhere, that is the confusion.
Routing
| Family | End-of-Sale | SW maintenance ends | Contract renewal closes | LDoS | Cisco's replacement |
|---|---|---|---|---|---|
| ISR 4221 / 4321 / 4331 / 4351 / 4431 / 4451 | 7 Nov 2023 | 31 Aug 2025 — passed | 5 Feb 2028 | 30 Nov 2028 | Catalyst 8200 / 8300 (per model) |
| ISR 4461 | 20 Jan 2025 | 20 Jan 2026 — passed | 17 Apr 2029 | 31 Jan 2030 | C8300-2N2S-4T2X |
| ASR 1006-X, ASR 1009-X | 31 Jul 2026 — just passed | 31 Jul 2027 | 26 Oct 2030 | 31 Jul 2031 | Catalyst 8500 Series |
| ASR 1002-HX | 31 Mar 2025 | 31 Mar 2026 — passed | 26 Jun 2029 | 31 Mar 2030 | C8500-12X / 12X4QC |
| Catalyst 8300 Edge uCPE | 1 Aug 2026 — passed | — | — | 31 Jul 2031 | None — Cisco states no replacement |
The ISR 4000 replacement mapping is per-model, not per-family: ISR4221 → C8200L-1N-4T; ISR4321 and ISR4331 → C8200-1N-4T; ISR4351 → C8300-2N2S-6T; ISR4431 → C8300-1N1S-4T2X or -6T; ISR4451 → C8300-2N2S-4T2X or C8300-2N2S-6T; ISR4461 → C8300-2N2S-4T2X.
Note the software position on the ISR 4000: maintenance releases ended on 31 August 2025, and the supported trains are 17.9.x and 17.12.x — 17.10.x and 17.11.x are not supported on this hardware. If your branch estate is on ISR 4000 and you are planning a software-driven feature (a new SD-WAN capability, a TLS change), the platform will not follow you there, LDoS in 2028 notwithstanding.
The Catalyst 8300 Edge uCPE line is the awkward one. Cisco discontinued it with no successor product named in the bulletin — the migration section offers trade-in credit and remanufactured units, not a replacement platform. Anyone running network functions on that box needs an architecture conversation, not a part swap.
Security
| Family | End-of-Sale | SW maintenance ends | Contract renewal closes | LDoS | Cisco's replacement |
|---|---|---|---|---|---|
| ASA 5508-X, ASA 5516-X | 2 Aug 2021 | Signatures end 31 Aug 2026 | 28 Oct 2025 — closed | 31 Aug 2026 | Firepower 1000 Series |
| Firepower 2100 (FPR2110–2140) | 27 May 2025 | 27 May 2026 — passed | 22 Aug 2029 | 31 May 2030 | Secure Firewall 3100 Series |
Two caveats on this table, both worth raising with anyone selling you a migration.
First, the ASA 5508-X bulletin dates from February 2021 and names the Firepower 1000 Series as the migration path. That recommendation is five years old. Before committing to it, check the current lifecycle position of whatever Firepower 1000 model is proposed — a migration onto a platform that is itself well into its cycle buys less runway than the bulletin implies.
Second, the Firepower 2100 bulletin names only the Secure Firewall 3100 Series. It does not mention the 1200 or the 4200, and it gives no per-model mapping — no FPR2110 → specific 3100 SKU. Sizing across that gap is a design exercise, and a quote that assumes a one-to-one swap has skipped it. On Firepower 2100 the practical deadline has already passed quietly: software maintenance ended on 27 May 2026, so those appliances are frozen on their current release with four years of LDoS still nominally ahead.
Wireless
The Cisco and Meraki Wi-Fi 6 indoor access points — the whole Catalyst 9100AX family — went end-of-sale on 31 December 2026, except the C9120AXE and C9120AXP, which Cisco moved up to 10 July 2026, and the C9120AXI, moved to 31 July 2026, "due to exhaustion of available materials." Last ship is 31 March 2027, software maintenance ends 31 December 2027, LDoS is 31 December 2031.
This migration deserves its own page because the replacement changes the switch underneath it: the Wi-Fi 7 access points need 802.3bt where the Wi-Fi 6 ones ran happily on PoE+, and the controller minimum software version varies by access point model. The full analysis, with the PoE budget arithmetic, is in the Wi-Fi 6 end-of-sale guide.
Compute and management
| Product | End-of-Sale | LDoS | Cisco's replacement |
|---|---|---|---|
| Catalyst Center Appliance Gen 3 (DN3-HW-APL / -L / -XL) | 31 Dec 2026 | 31 Dec 2031 | Gen 4: DN4-HW-APL / -L / -XL |
| HyperFlex — HXDP software | 11 Sep 2024 | 28 Feb 2029 | Cisco Compute Hyperconverged with Nutanix |
| HyperFlex M6 nodes | 12 Mar 2024 | 30 Jun 2031 | |
| HyperFlex M5 nodes | 30 Oct 2023 | 31 Oct 2028 |
On the Catalyst Center appliance the Gen 3 → Gen 4 mapping is direct but the core counts change: the Gen 3 32-core maps to a Gen 4 32-core, but the 56-core maps to a 48-core and the 80-core to a 72-core. Sizing should be re-checked rather than assumed.
HyperFlex is not a single end-of-life event but a platform being closed through a series of bulletins — software, each hardware generation, and components separately. The software advisory is unusually direct: Cisco "strongly recommends that customers plan and start their migration from HyperFlex to Nutanix HCI on Cisco UCS, or another suitable solution, as soon as possible," and lists the workaround as "None." Worth knowing before you start: Cisco's own HyperFlex EOL FAQ contains a line stating that HyperFlex M6 has not reached end of sale, which contradicts the EOL15171 and EOL15369 bulletins that announce exactly that. Where the FAQ and the bulletin disagree, the bulletin is the formal document. We cover the target architecture in Nutanix versus VxRail and hyperconverged infrastructure.
What is already behind you
If any of the following is in production, the decision window has closed and what remains is risk management:
- Catalyst 3850 — LDoS passed October 2025. No TAC, no RMA, no contract.
- ASA 5508-X / 5516-X — LDoS 31 August 2026, renewal closed a year ago.
- Catalyst 3650 — renewal closed January 2026; LDoS 31 October 2026.
- ISR 4000 — software maintenance ended August 2025; hardware support continues to 2028.
- Firepower 2100 — software maintenance ended May 2026; hardware support to 2030.
The pattern in that list is worth naming. In four of the five cases the hardware is still supported and the software stopped years earlier. A fleet can be simultaneously "under support" and unable to receive a security fix. When a scan flags a CVE on a platform whose software maintenance ended, the remediation is a hardware refresh, on whatever timeline the auditor sets.
What the replacement actually costs
Every migration in the tables above looks like a part swap and is not. The recurring hidden costs, in rough order of how often they surprise people:
- Licensing model. The 2960-X and 3650 predate the subscription model that the Catalyst 9000 assumes. Replacing them means adding a per-switch Network Essentials or Advantage subscription that did not exist in the old cost line.
- Power. Covered in detail on the Wi-Fi 6 migration page, and it is the largest of these on any wireless refresh: the new access points can require a different PoE class and a bigger power supply in the access switch.
- Optics. Uplink modules do not always carry across. Check the transceiver list against the new platform before assuming the existing optics are reusable.
- Software train. A replacement platform often has a minimum IOS-XE version that is newer than what the rest of the estate runs, which pulls a controller or core upgrade into scope.
- Rack and power envelope. Mostly a non-issue on switching, decidedly not on the routing migrations to Catalyst 8500.
How to work through this
- Inventory by part number, not by family name. Nearly every family above is split across multiple bulletins with different dates. "We run 2960s" is not a position you can plan from.
- Sort by contract renewal date, not end-of-sale. That is the date after which "wait and see" stops being available.
- Check software maintenance separately from hardware support. They diverge by years, and the software date is usually the one that triggers a compliance finding.
- Price the migration, not the box. Licences, power, optics and the software train, per the section above.
- Then decide per site: replace now, extend on remaining channel inventory, or move to a different vendor. All three are legitimate; the third is worth pricing on Aruba or Fortinet where the Cisco licensing step-up is what makes the refresh expensive.
Send us your SKU list
Send the part numbers from your current estate. We return the replacement mapping, the binding dates per SKU, what changes beyond the hardware, and firm lead times — within one business day.
Frequently asked questions
Can I keep using Cisco hardware after end-of-life?
Yes, until last date of support, and physically for as long as it runs after that. What changes at LDoS is that Cisco provides nothing: no TAC case, no RMA, no software. Before LDoS the more important date is end of service contract renewal — after that you cannot buy coverage even if you want to.
Which Cisco EOL date should I actually plan around?
End of service contract renewal, in most cases. It is the last point at which continuing to run the equipment is a decision rather than an exposure. For estates with a compliance obligation, end of vulnerability and security support usually binds earlier.
Can I still get support on second-hand Cisco hardware?
Only if the unit is already covered, or if the End of New Service Attachment date has not passed. That milestone is the one that determines whether an uncovered unit can be put onto a contract at all — and on the ISR 4000, for example, it passed in November 2024. Buying uncovered hardware after that date means it can never be brought under Cisco support.
Is Cisco Refresh (remanufactured) a real option for EOL platforms?
It is, and for a discontinued platform with no successor — the Catalyst 8300 Edge uCPE is the current example — Cisco itself points at it. Availability is limited to whatever has been returned and remanufactured, so it works as a spares strategy and rarely as a growth strategy.
How do I check the EOL status of a specific part number?
Cisco publishes a bulletin per product family at cisco.com/c/en/us/products/<category>/<series>/eos-eol-notice-listing.html. Read the bulletin itself, not the listing page — the listing shows announcement and amendment dates, while the milestone table lives inside the document. Watch for amended bulletins: the date shown in a listing is often the amendment date, not the original announcement, which is how the ISR 4000 announcement gets quoted as 2024 when the bulletin says November 2022.
Does Haink supply end-of-life Cisco hardware?
Where it exists in the channel, yes — extending an estate on remaining inventory is often the right answer when the replacement pulls a licensing or power change with it. All units are serial-verified against Cisco before payment, which matters more on discontinued hardware than on current product: see gray-market and channel risk and how to verify an in-stock claim.
Related
- How to choose Cisco switches, routers and firewalls — the selection guide
- Cisco Wi-Fi 6 AP end-of-sale — the migration worked through in full
- Catalyst 2960-X replacement guide
- ISR 4000 to Catalyst 8000 migration
- Nexus 9300 EX and FX refresh guide
- Firepower 2100 replacement and sizing
- HyperFlex migration to Nutanix
- Catalyst 8300 Edge uCPE end-of-sale
- Enterprise switches · Routers · Networking overview · Wireless access points
- Cisco vs Juniper switching — worth pricing when a refresh is forced anyway
- Research institution network — 52 Cisco switches, 2,400 ports, eight buildings
- Gulf fintech network — 30-site Catalyst 9300/9500 rollout in six weeks
- Cisco stock and lead times
Sources
Every milestone above was read from the Cisco bulletin for that family. Where a family has multiple bulletins, the one covering mainstream hardware is cited.
- Switching: Catalyst 2960-X · 2960-XR · 3650 · 3850
- Routing: ISR 4200/4300/select 4400 · ISR 4461 · ASR 1009-X · ASR 1006-X · Catalyst 8300 Edge uCPE
- Security: ASA 5508-X / 5516-X · Firepower 2100
- Wireless: Cisco and Meraki Wi-Fi 6 indoor access points
- Compute and management: Catalyst Center Gen 3 appliance · HyperFlex HXDP · HyperFlex M5 · HyperFlex software advisory
