endoflife.ai
EOL Checker Products EOL Watch Get Support

End of Support vs. End of Life: What's the Difference?

By Scott Bissett  ·  Published: September 1, 2026  ·  Reference  ·  Definitions verified against each vendor's own lifecycle documentation; example dates drawn live from our tracked data at every site build — methodology

The short answer: there is no industry standard, so end of support (EOS) and end of life (EOL) mean whatever each vendor says they mean. Much of the time they are synonyms for the same date — the day the vendor stops maintaining a product. Where they differ, the most common pattern is that end of support comes first (standard support ends, sometimes with a paid extension available) and end of life comes last (nothing is available at any price). A few vendors invert or reshuffle the terms entirely. The only reliable method is to decode the specific vendor's vocabulary — which is what this page is for.

We maintain verified lifecycle dates for 500+ products, which means we read vendors' lifecycle policies for a living. This page is the decoder we wish had existed: the general phase model every vendor's vocabulary maps onto, the vendor-by-vendor translation table, the special cases that trip people up (SaaS retirements, end of sale, hardware service life, vendors that publish nothing at all), and what regulators mean when they use these words — because as of 2026, regulators use them a lot.

The phase model underneath every vendor's vocabulary

Strip away the branding and almost every software lifecycle moves through the same four phases. Vendors differ in what they call each phase, how many they expose, and where they hang the words "support" and "life":

PhaseWhat you actually getNames vendors use for its end
1 · Full supportBug fixes, security fixes, new features, vendor assistanceEnd of active support · end of mainstream support · end of full support · end of new features
2 · MaintenanceSecurity fixes (often only critical ones); no new features; sometimes no non-security bug fixesEnd of standard support · end of maintenance · end of security support · end of support (many vendors) · end of life (many vendors)
3 · Paid extensionSecurity fixes for paying customers only (ESU, ELS, ESM, Extended Support)End of extended support · end of ESU/ELS/ESM · end of life (in vocabularies where phase 2's end was "end of support")
4 · NothingNo fixes at any price; every new vulnerability is permanentEnd of service life (EOSL) · Last Date of Support · sustaining-only · obsolete

The ambiguity that launched a thousand confused change-tickets lives on the boundary between phases 2 and 3: when a vendor sells a paid extension, "end of support" usually means the end of phase 2 — while "end of life" might mean the end of phase 2 or phase 3 depending on who is writing. When there is no paid extension, the phases collapse and the terms genuinely are synonyms.

Facing an end-of-life deadline?
Tell us which product and we’ll reply with vetted extended-support options and pricing guidance — free, no obligation. Vendors don’t pay for placement.

Free · No obligation · Independent · dates verified against vendor sources · Not urgent? Follow the EOL radar or see the 2026 EOL calendar →

The vendor decoder

What the major vocabularies actually mean, from each vendor's own lifecycle documentation:

Vendor / sourceTheir words, decoded
Microsoft (Fixed Lifecycle)Mainstream support (5 yrs, full) → Extended support (5 yrs, security-only) → optional paid ESU (Extended Security Updates). "End of support" = the extended-support end date in most Microsoft communication. Windows feature releases add "end of servicing."
Microsoft (Modern Lifecycle / cloud)No fixed dates — the product is supported until Microsoft announces a retirement, after which the service stops existing (see Project Online, September 30, 2026). Retirement is harder than any EOS date: the switch turns off.
Red Hat (RHEL)Full supportMaintenance support → end of maintenance = what most people call RHEL's EOL → optional paid ELS (Extended Life-cycle Support). Note the vendor put "life" in the name of the thing that comes after most people's "end of life."
Canonical (Ubuntu LTS)Standard support (5 yrs of security maintenance) → paid ESM (Expanded Security Maintenance, via Ubuntu Pro) → optional Legacy add-on beyond that. Canonical rarely says "end of life" at all; the community does.
OraclePremier SupportExtended Support (paid, ~3 yrs) → Sustaining Support — which is indefinite but includes no new security fixes. Oracle products technically never leave "support," which is exactly why the no-new-fixes boundary is the date that matters (see the Oracle Database lifecycle).
Cisco"EOL" is a process, not a date: EOL announcement → End-of-Sale → end of software maintenance releases → end of vulnerability/security support → Last Date of Support (LDoS), typically years after end-of-sale. Every milestone is published per product in an EOL bulletin.
FortinetEnd of Engineering Support (EOES) → End of Support (EOS). Firmware lifecycles per release train (see FortiOS versions).
PHPActive support (bug fixes) → Security fixes onlyEnd of life. A clean three-phase example of EOS-then-EOL: active support ending is not the danger date; end of life is.
PythonBugfixSecurityEnd-of-life, with dates declared per minor version in the devguide.
CISA (BOD 26-02)Uses end of support (EOS) for the whole concept: devices "no longer maintained by their vendors." US federal directives standardized on the EOS vocabulary — see our end-of-support hub for the BOD 26-02 deadline clock.
Apple, and vendors like itPublishes no lifecycle dates at all — patches simply stop. Lifecycle status must be inferred from release behavior (a de facto EOL). PaperCut and many ISVs work the same way: support rides the contract, and the boundary only becomes visible when the vendor declines to patch (see the September 2026 PaperCut case).

One product, four vocabularies — with live dates

The fastest way to see the problem is the same three-column lifecycle expressed in four vendors' words. These dates are drawn from our verified data and refresh automatically at every site build:

ProductPhase 1 ends ("full/active/mainstream")Phase 2 ends (the commonly-cited "EOL/EOS")Paid extension ends
PHP 8.2Active support: Dec 31, 2024End of life: Dec 31, 2026— (no vendor extension; third-party ELS exists)
Ubuntu 22.04 LTSStandard support: May 31, 2027ESM: May 31, 2032
RHEL 8Full support: May 31, 2024Maintenance ends: May 31, 2029ELS: May 31, 2033
Windows Server 2016Mainstream: Jan 11, 2022Extended: Jan 12, 2027ESU: Jan 12, 2030

Four products, four vocabularies, one underlying model. Which column a vendor calls "end of support" and which "end of life" varies; the column that should drive your planning does not — it's the last date your entitlements get security fixes.

The special cases that trip people up

End of sale is not end of support

End of sale (also abbreviated EoS, because the industry hates you) is a procurement milestone: the vendor stops selling the product. Support typically continues for years afterward — Cisco's process runs from End-of-Sale to a Last Date of Support often five years later. End of sale starts the clock; it doesn't end the coverage.

SaaS retirement is harder than any EOS date

On-premises software at end of life keeps running, unpatched. A cloud service at retirement stops existing — along with access to the data in it. Microsoft's Modern Lifecycle Policy works this way, and 2026's clearest example is Project Online: not "unsupported after September 30," but unavailable. When you triage deadlines, retirements outrank everything.

End of service life (EOSL) — the hardware tail

In hardware and appliance vocabularies, EOSL is the true end: no paid support, no parts, no RMA. Between EOS and EOSL, third-party maintenance markets exist; after EOSL, replacement is the only path. (More in our EOSL guide.)

Deprecation is a warning, not a date

Deprecated means "still works, stop building on it." It is the earliest signal in the lifecycle — often years before any EOS/EOL date is even announced — and the cheapest moment to act.

De facto end of life — when the vendor publishes nothing

Apple publishes no lifecycle calendar. Neither do many ISVs. For those products, end of life is something you observe — releases stop, or the vendor declines to patch a branch in writing — rather than something you look up. Our data marks these as de facto dates with the evidence documented, because "the vendor never announced an EOL" and "the vendor still ships fixes" are very different statements.

What regulators mean by these words

The vocabulary stopped being academic in 2026. CISA's Binding Operational Directive 26-02 orders US federal civilian agencies to inventory and decommission end-of-support edge devices — defining EOS devices simply as those "no longer maintained by their vendors" — and its companion BOD 26-04 rewrote federal patching rules around risk. The EU Cyber Resilience Act is built around a manufacturer-declared support period. NIS2, DORA and PCI DSS all reach the same requirement from different directions: know whether the software you run still receives security fixes, and be able to prove it. None of them care which word the vendor used — they care about the no-more-fixes boundary.

How we use the terms

endoflife.ai tracks three dates per version wherever a vendor exposes them, mapped onto the phase model above: the end of active/full support (phase 1), the main end-of-life/end-of-support date (phase 2 — the date most people mean, and the one our EOL Risk Score keys on), and the end of any extended/paid program (phase 3). Where a vendor defines the words differently, the product page says so; where a vendor publishes nothing, we say the dates are de facto and show the evidence. When in doubt about any product, check the version — the answer comes with its provenance.

The one-sentence rule for your risk register: record the date after which the version you run gets no security fixes under your actual entitlements — the end of standard support if you don't pay for an extension, the end of the paid program if you do — and treat every vendor's choice of "EOS" or "EOL" as packaging around that date.

Frequently Asked Questions

Is end of support the same as end of life?

Often yes, sometimes no — there is no industry standard, so the terms mean whatever each vendor says they mean. Many vendors and CISA use them interchangeably for the date the vendor stops maintaining a product. Others split them: EOS when standard support ends but paid extended support continues, EOL as the final end of everything. The only reliable method is to check the specific vendor's own lifecycle definitions.

What comes first, end of support or end of life?

It depends on the vendor's vocabulary. In the most common enterprise pattern (Microsoft, Red Hat, Oracle), standard support ends first, a paid extension follows, and the true end of the lifecycle comes last — so "end of support" precedes "end of life." At Cisco, End-of-Sale comes first and the Last Date of Support ends a published multi-milestone process. When a vendor uses the terms as synonyms, they are the same date.

What is end of service life (EOSL)?

Usually the final date a product — most often hardware or an appliance — can receive any vendor service at all, including paid support, parts and RMA. Common in storage, networking and server vocabularies, and equivalent to Cisco's Last Date of Support. After EOSL, third-party maintenance is typically the only option.

What does end of sale mean?

The date a product can no longer be purchased from the vendor — confusingly abbreviated EoS by some vendors, same as end of support. It typically comes years before support ends and is a procurement signal, not a security one. But it starts the clock.

Does software stop working at end of life?

Installed software doesn't — it keeps running and simply stops receiving fixes, making every vulnerability discovered afterward permanent. Cloud services are the exception: a SaaS retirement means the service actually stops existing, as with Microsoft's Project Online. That keeps-running versus switched-off distinction often matters more than the EOS/EOL wording.

Which date should go in a risk register or compliance report?

The date after which the version you run receives no security fixes under your actual entitlements. Regulations are converging on the same idea: the EU Cyber Resilience Act is built around a declared support period, and CISA's BOD 26-02 defines end-of-support devices as those no longer maintained by their vendors. Track the no-more-fixes date, whatever the vendor calls it.

Related

The Monthly EOL Digest™

Once a month — critical EOL dates, CVE blind spots, and lifecycle changes worth knowing.

© 2026 endoflife.ai · How we verify our dates · API · About · Data from endoflife.date (MIT)