End of Support vs. End of Life: What's the Difference?
We maintain verified lifecycle dates for 500+ products, which means we read vendors' lifecycle policies for a living. This page is the decoder we wish had existed: the general phase model every vendor's vocabulary maps onto, the vendor-by-vendor translation table, the special cases that trip people up (SaaS retirements, end of sale, hardware service life, vendors that publish nothing at all), and what regulators mean when they use these words — because as of 2026, regulators use them a lot.
The phase model underneath every vendor's vocabulary
Strip away the branding and almost every software lifecycle moves through the same four phases. Vendors differ in what they call each phase, how many they expose, and where they hang the words "support" and "life":
| Phase | What you actually get | Names vendors use for its end |
|---|---|---|
| 1 · Full support | Bug fixes, security fixes, new features, vendor assistance | End of active support · end of mainstream support · end of full support · end of new features |
| 2 · Maintenance | Security fixes (often only critical ones); no new features; sometimes no non-security bug fixes | End of standard support · end of maintenance · end of security support · end of support (many vendors) · end of life (many vendors) |
| 3 · Paid extension | Security fixes for paying customers only (ESU, ELS, ESM, Extended Support) | End of extended support · end of ESU/ELS/ESM · end of life (in vocabularies where phase 2's end was "end of support") |
| 4 · Nothing | No fixes at any price; every new vulnerability is permanent | End of service life (EOSL) · Last Date of Support · sustaining-only · obsolete |
The ambiguity that launched a thousand confused change-tickets lives on the boundary between phases 2 and 3: when a vendor sells a paid extension, "end of support" usually means the end of phase 2 — while "end of life" might mean the end of phase 2 or phase 3 depending on who is writing. When there is no paid extension, the phases collapse and the terms genuinely are synonyms.
The vendor decoder
What the major vocabularies actually mean, from each vendor's own lifecycle documentation:
| Vendor / source | Their words, decoded |
|---|---|
| Microsoft (Fixed Lifecycle) | Mainstream support (5 yrs, full) → Extended support (5 yrs, security-only) → optional paid ESU (Extended Security Updates). "End of support" = the extended-support end date in most Microsoft communication. Windows feature releases add "end of servicing." |
| Microsoft (Modern Lifecycle / cloud) | No fixed dates — the product is supported until Microsoft announces a retirement, after which the service stops existing (see Project Online, September 30, 2026). Retirement is harder than any EOS date: the switch turns off. |
| Red Hat (RHEL) | Full support → Maintenance support → end of maintenance = what most people call RHEL's EOL → optional paid ELS (Extended Life-cycle Support). Note the vendor put "life" in the name of the thing that comes after most people's "end of life." |
| Canonical (Ubuntu LTS) | Standard support (5 yrs of security maintenance) → paid ESM (Expanded Security Maintenance, via Ubuntu Pro) → optional Legacy add-on beyond that. Canonical rarely says "end of life" at all; the community does. |
| Oracle | Premier Support → Extended Support (paid, ~3 yrs) → Sustaining Support — which is indefinite but includes no new security fixes. Oracle products technically never leave "support," which is exactly why the no-new-fixes boundary is the date that matters (see the Oracle Database lifecycle). |
| Cisco | "EOL" is a process, not a date: EOL announcement → End-of-Sale → end of software maintenance releases → end of vulnerability/security support → Last Date of Support (LDoS), typically years after end-of-sale. Every milestone is published per product in an EOL bulletin. |
| Fortinet | End of Engineering Support (EOES) → End of Support (EOS). Firmware lifecycles per release train (see FortiOS versions). |
| PHP | Active support (bug fixes) → Security fixes only → End of life. A clean three-phase example of EOS-then-EOL: active support ending is not the danger date; end of life is. |
| Python | Bugfix → Security → End-of-life, with dates declared per minor version in the devguide. |
| CISA (BOD 26-02) | Uses end of support (EOS) for the whole concept: devices "no longer maintained by their vendors." US federal directives standardized on the EOS vocabulary — see our end-of-support hub for the BOD 26-02 deadline clock. |
| Apple, and vendors like it | Publishes no lifecycle dates at all — patches simply stop. Lifecycle status must be inferred from release behavior (a de facto EOL). PaperCut and many ISVs work the same way: support rides the contract, and the boundary only becomes visible when the vendor declines to patch (see the September 2026 PaperCut case). |
One product, four vocabularies — with live dates
The fastest way to see the problem is the same three-column lifecycle expressed in four vendors' words. These dates are drawn from our verified data and refresh automatically at every site build:
| Product | Phase 1 ends ("full/active/mainstream") | Phase 2 ends (the commonly-cited "EOL/EOS") | Paid extension ends |
|---|---|---|---|
| PHP 8.2 | Active support: Dec 31, 2024 | End of life: Dec 31, 2026 | — (no vendor extension; third-party ELS exists) |
| Ubuntu 22.04 LTS | — | Standard support: May 31, 2027 | ESM: May 31, 2032 |
| RHEL 8 | Full support: May 31, 2024 | Maintenance ends: May 31, 2029 | ELS: May 31, 2033 |
| Windows Server 2016 | Mainstream: Jan 11, 2022 | Extended: Jan 12, 2027 | ESU: Jan 12, 2030 |
Four products, four vocabularies, one underlying model. Which column a vendor calls "end of support" and which "end of life" varies; the column that should drive your planning does not — it's the last date your entitlements get security fixes.
The special cases that trip people up
End of sale is not end of support
End of sale (also abbreviated EoS, because the industry hates you) is a procurement milestone: the vendor stops selling the product. Support typically continues for years afterward — Cisco's process runs from End-of-Sale to a Last Date of Support often five years later. End of sale starts the clock; it doesn't end the coverage.
SaaS retirement is harder than any EOS date
On-premises software at end of life keeps running, unpatched. A cloud service at retirement stops existing — along with access to the data in it. Microsoft's Modern Lifecycle Policy works this way, and 2026's clearest example is Project Online: not "unsupported after September 30," but unavailable. When you triage deadlines, retirements outrank everything.
End of service life (EOSL) — the hardware tail
In hardware and appliance vocabularies, EOSL is the true end: no paid support, no parts, no RMA. Between EOS and EOSL, third-party maintenance markets exist; after EOSL, replacement is the only path. (More in our EOSL guide.)
Deprecation is a warning, not a date
Deprecated means "still works, stop building on it." It is the earliest signal in the lifecycle — often years before any EOS/EOL date is even announced — and the cheapest moment to act.
De facto end of life — when the vendor publishes nothing
Apple publishes no lifecycle calendar. Neither do many ISVs. For those products, end of life is something you observe — releases stop, or the vendor declines to patch a branch in writing — rather than something you look up. Our data marks these as de facto dates with the evidence documented, because "the vendor never announced an EOL" and "the vendor still ships fixes" are very different statements.
What regulators mean by these words
The vocabulary stopped being academic in 2026. CISA's Binding Operational Directive 26-02 orders US federal civilian agencies to inventory and decommission end-of-support edge devices — defining EOS devices simply as those "no longer maintained by their vendors" — and its companion BOD 26-04 rewrote federal patching rules around risk. The EU Cyber Resilience Act is built around a manufacturer-declared support period. NIS2, DORA and PCI DSS all reach the same requirement from different directions: know whether the software you run still receives security fixes, and be able to prove it. None of them care which word the vendor used — they care about the no-more-fixes boundary.
How we use the terms
endoflife.ai tracks three dates per version wherever a vendor exposes them, mapped onto the phase model above: the end of active/full support (phase 1), the main end-of-life/end-of-support date (phase 2 — the date most people mean, and the one our EOL Risk Score keys on), and the end of any extended/paid program (phase 3). Where a vendor defines the words differently, the product page says so; where a vendor publishes nothing, we say the dates are de facto and show the evidence. When in doubt about any product, check the version — the answer comes with its provenance.
Frequently Asked Questions
Is end of support the same as end of life?
Often yes, sometimes no — there is no industry standard, so the terms mean whatever each vendor says they mean. Many vendors and CISA use them interchangeably for the date the vendor stops maintaining a product. Others split them: EOS when standard support ends but paid extended support continues, EOL as the final end of everything. The only reliable method is to check the specific vendor's own lifecycle definitions.
What comes first, end of support or end of life?
It depends on the vendor's vocabulary. In the most common enterprise pattern (Microsoft, Red Hat, Oracle), standard support ends first, a paid extension follows, and the true end of the lifecycle comes last — so "end of support" precedes "end of life." At Cisco, End-of-Sale comes first and the Last Date of Support ends a published multi-milestone process. When a vendor uses the terms as synonyms, they are the same date.
What is end of service life (EOSL)?
Usually the final date a product — most often hardware or an appliance — can receive any vendor service at all, including paid support, parts and RMA. Common in storage, networking and server vocabularies, and equivalent to Cisco's Last Date of Support. After EOSL, third-party maintenance is typically the only option.
What does end of sale mean?
The date a product can no longer be purchased from the vendor — confusingly abbreviated EoS by some vendors, same as end of support. It typically comes years before support ends and is a procurement signal, not a security one. But it starts the clock.
Does software stop working at end of life?
Installed software doesn't — it keeps running and simply stops receiving fixes, making every vulnerability discovered afterward permanent. Cloud services are the exception: a SaaS retirement means the service actually stops existing, as with Microsoft's Project Online. That keeps-running versus switched-off distinction often matters more than the EOS/EOL wording.
Which date should go in a risk register or compliance report?
The date after which the version you run receives no security fixes under your actual entitlements. Regulations are converging on the same idea: the EU Cyber Resilience Act is built around a declared support period, and CISA's BOD 26-02 defines end-of-support devices as those no longer maintained by their vendors. Track the no-more-fixes date, whatever the vendor calls it.
Related
- End of support & the CISA BOD 26-02 clock — the federal directive that made EOS a compliance deadline
- What is end-of-life software? — the primer on why lifecycles exist at all
- Why end of life is inevitable — the economics behind every vendor's support boundary
- End of service life for hardware — the EOSL tail in depth
- Check any version in seconds — 500+ products, verified dates, live risk scores