endoflife.ai
EOL Checker Products EOL Watch Get Support

NetApp ONTAP End of Life: Every Version's Support Dates — and Why the Patch Cliff Comes Two Years Before "End of Support"

By Scott Bissett  ·  Published: August 12, 2026  ·  EOL Watch — lifecycle coverage  ·  Dates verified against NetApp's ONTAP Software Version Support pages and our tracked lifecycle data — methodology

Storage arrays are the ultimate "it just works" infrastructure. A NetApp filer gets racked, provisioned, and then disappears from everyone's attention precisely because it does its job — serving the NFS exports, SMB shares, and VM datastores that everything else runs on. The applications on top get patched monthly. The hypervisors get patched quarterly. The ONTAP release underneath frequently runs untouched from install to hardware refresh, five or more years later. That habit collides with a lifecycle most teams have never actually read: an ONTAP release stops receiving patches roughly three years after it ships — and NetApp's support matrix will keep calling it "supported" for two more years after that.

That last part is the detail this article exists for. NetApp's lifecycle for an ONTAP release is 3 years of full support, then 2 years of limited support, then 3 years of self-service support. Most vendors' second-phase support still ships security fixes. NetApp's does not: per NetApp's own support definitions, under limited support "Service Updates (including any form of software update) are not provided." The patch cliff — including security patches — is the end of full support, not the end of the lifecycle. A filer on ONTAP 9.12.1 today is "in limited support" until February 2028 and has not been eligible for a single update since February 2026.

The dates are close, and some have already passed. ONTAP 9.13.1 left full support on June 30, 2026 — six weeks before this article's publication — the same day 9.9.1 exited even its limited support window. ONTAP 9.14.1 has 172 days of full support left (January 31, 2027). ONTAP 9.15.1 — a common landing for fleets refreshed in 2024 — has under a year, to July 31, 2027. ONTAP 9.16.1 follows on January 31, 2028.

State of play, August 12, 2026: Past the patch cliff (end of full support): 9.13.1, 9.12.1, 9.11.1, 9.10.1, 9.9.1 — none of these can receive another update at any price. On the clock: 9.14.1 to January 31, 2027 (172 days), 9.15.1 to July 31, 2027, 9.16.1 to January 31, 2028. Longest runways: 9.17.1 and 9.18.1 (September 30, 2028 per tracked data — see the 9.18.1 note under the table) and 9.19.1, the current release, to July 30, 2029.

How ONTAP support actually works: 3 + 2 + 3, and only the first number ships patches

NetApp's upgrade guidance states it plainly: "New ONTAP releases are entitled to full support for 3 years." What each phase means comes from NetApp's Software Version Support Definitions, and the differences are worth quoting rather than paraphrasing:

Full support is "the time period where NetApp provides full support for a version of a software product including: technical support, root cause analysis, security vulnerability evaluation, documentation, and software available online and Service Updates (P-releases)." This is the whole package — and note that security vulnerability evaluation is on the list. During full support, fixes ship as P-releases (9.15.1Px) on the release line, which NetApp's guidance says to apply "every 3-6 months" for non-critical updates and "as soon as possible" for critical ones.

Limited support, the next two years, keeps "technical support, root cause analysis, documentation and software available online" — but "Service Updates (including any form of software update) are not provided for versions under limited support." You can open a case. NetApp will help you troubleshoot. What nobody can do is patch the release, because no patch will ever be built. There is no paid tier that changes this — ONTAP has no equivalent of Microsoft's ESU or Oracle's Extended Support fee.

Self-service support, the final three years, is the documentation staying online. After it, the version is considered obsolete.

The practical consequence: for security planning, the only date that matters is the end of full support. That is the date our tracked data records as EOL for each ONTAP release — consistent with endoflife.date, which notes that the limited and self-service phases ship no software updates and treats them as post-EOL. The limited-support dates are worth knowing anyway — they tell you how long NetApp will still answer the phone — so the table below carries both clocks.

One naming note, because ONTAP's version numbers confuse people coming from other ecosystems: every current ONTAP release is numbered 9.x.1 — 9.14.1, 9.15.1, 9.16.1 and so on. The "9.x.1" is the release; updates within it ship as numbered P-releases (9.15.1P13), which NetApp's definitions call Service Updates. Asking "when does ONTAP 9.15 die?" and "when does 9.15.1 die?" is asking the same question. The release rhythm is observable in the table's dates: three releases have gone GA in 2026 alone (9.17.1 in January, 9.18.1 in February, 9.19.1 in July), after a quieter 2025 — roughly two releases a year on average across the tracked window.

Running NetApp ONTAP past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers NetApp ONTAP is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

Every ONTAP version's dates

Release dates and end-of-full-support dates below are from our tracked lifecycle data (verification pass 2026-08-12), cross-checked against NetApp's ONTAP Software Version Support dates KB; limited-support dates are from that KB directly. Each version links to its lifecycle page with live status and risk score. Status badges reflect August 12, 2026.

VersionStatusReleasedFull support ends (EOL)Limited support endsNotes
ONTAP 9.19.1SupportedJul 2026Jul 30, 2029Current release; not yet listed in NetApp's support-dates KB at publication.
ONTAP 9.18.1SupportedFeb 4, 2026Sep 30, 2028Jan 31, 2031NetApp's KB lists full support to Jan 31, 2029 — see note below.
ONTAP 9.17.1SupportedJan 15, 2026Sep 30, 2028Sep 30, 2030Same full-support end date as 9.18.1 per tracked data.
ONTAP 9.16.1SupportedJan 2025Jan 31, 2028Jan 31, 2030The 2025 release — sole GA of that year in tracked data.
ONTAP 9.15.1SupportedMay 2024Jul 31, 2027Jul 31, 2029Under a year of patches left at publication.
ONTAP 9.14.1WarningJan 2024Jan 31, 2027Jan 31, 2029172 days of full support left at publication.
ONTAP 9.13.1EOLJun 2023Jun 30, 2026Jun 30, 2028Crossed the patch cliff six weeks before publication.
ONTAP 9.12.1EOLFeb 2023Feb 28, 2026Feb 28, 2028No updates of any form since February 2026.
ONTAP 9.11.1EOLJul 2022Jul 31, 2025Jul 31, 2027Unpatched for over a year.
ONTAP 9.10.1EOLJan 2022Jan 31, 2025Jan 31, 2027Limited support closes in under six months.
ONTAP 9.9.1EOLJun 2021Jun 30, 2024Jun 30, 2026Out of even limited support since June 30, 2026 — self-service only.

The 9.18.1 note: our tracked data and endoflife.date list 9.18.1's full support ending September 30, 2028 — the same day as 9.17.1 — while NetApp's support-dates KB lists January 31, 2029, which matches the three-years-from-GA policy exactly (9.18.1 went GA February 4, 2026). The sources disagree; we show the tracked (earlier, more conservative) date in the table and flag the difference here rather than silently picking one. NetApp's KB itself defers to the login-gated Software Version Support page as the latest word. Release dates shown at month precision are month-precision in the source data.

The hardware clock underneath the software clock

ONTAP dates are only half the lifecycle math, because ONTAP runs on FAS and AFF platforms that carry their own end-of-availability schedule — and the two clocks are coupled. Per NetApp's hardware support policy KB, once a platform reaches its End of Availability (EOA) date, there is a "Feature Release Period" of two years — "During this period you can expect new Feature Releases to support your hardware or platform" — followed by a patch-only period, with the platform's End of Support arriving "typically 5 years after the EOA date."

Read that as an upgrade ceiling: a filer whose platform left sale more than two years ago should be assumed unable to run the newest ONTAP release. At that point the software lifecycle table above stops being a menu and becomes a countdown — the last ONTAP release your hardware supports has a fixed end-of-full-support date, and when it passes, no newer release can rescue the box. The authoritative per-platform answer (which ONTAP versions a given FAS/AFF model can run, and its EOA/EOS dates) lives in NetApp's Hardware Universe; checking it belongs in the same review as the version table. This coupling is why storage estates hit end of life in a way software estates don't: the fix for an aging ONTAP release is sometimes a purchase order, not an upgrade window. We cover that broader pattern in our hardware EOSL guide.

The upgrade rhythm: a filer installed three years ago is six releases behind

NetApp's release cadence means ONTAP versions age faster than filer attention cycles. A cluster deployed on 9.13.1 in mid-2023 — a perfectly current choice at the time — is now six releases behind 9.19.1 and past its patch cliff. NetApp's own guidance anticipates this: "NetApp recommends that you run the newest release for 1 year after general availability (GA) and then use the remaining time within the full support window to plan for your transition to a newer ONTAP release." That is a vendor telling you, in policy language, that the three-year window is meant to contain two planned events — adoption and the next migration — not one install and four years of silence.

The mechanics are better than storage folklore remembers. Per NetApp's upgrade methods documentation, "if available, the automated nondisruptive upgrade (ANDU) using System Manager is the preferred method" — clusters under eight nodes upgrade node by node with partners taking over storage (rolling), larger clusters in batches, both without taking data offline. Nondisruptive does not mean unplanned: version upgrade paths, mixed-version windows, and the hardware ceiling above still need checking per the release notes. But "we can't take the downtime" stopped being a valid reason to run a dead ONTAP release years ago.

For a fleet, the sustainable rhythm falls out of the dates: land on a release in its first year (NetApp's one-year recommendation), run it while it's patched, and begin the next transition before your release's full-support date is inside a budget cycle. Fleets refreshed onto 9.15.1 in 2024 are at exactly that point now — July 31, 2027 is close enough that the upgrade to 9.17.1, 9.18.1 or 9.19.1 belongs in this fiscal year's plan, not next year's.

The security stakes: zero KEV entries, one giant blast radius

Honesty first: we checked the live CISA Known Exploited Vulnerabilities catalog (August 10, 2026 release, 1,662 entries) and there are no NetApp or ONTAP entries in it. No documented in-the-wild exploitation of ONTAP appears in the KEV record, and we won't manufacture urgency by implying otherwise.

The structural argument doesn't need it. The filer is the layer everything else stands on: the NFS and SMB shares holding user and application data, the LUNs and datastores under the virtualization estate, the snapshots and replication targets that are the recovery plan. Storage systems concentrate exactly what ransomware operators want — the data and the backups of the data — which is why hardening guidance for storage focuses so heavily on admin-interface exposure and snapshot immutability. An ONTAP release past its full-support date has also lost something quieter than patches: per NetApp's definitions, full support is when "security vulnerability evaluation" happens. Past the cliff, new CVEs aren't just unfixed on your release — nobody is on the hook to assess it at all. For the machine holding every other machine's data, running a release the vendor no longer evaluates is a single point of exposure that no amount of patching above it repairs.

We track NetApp ONTAP and 480+ other products against vendor-verified datesevery ONTAP release with live status and risk score, check your version in seconds, or see what else hits end of life this quarter.

What to do about it

NetApp ONTAP currently carries an EOL Risk Score™ of 35/100 — Grade B, moderate risk, recalculated at every site build from EOL recency, attack surface, CISA KEV exposure, and extended-support availability. Per-version scores and dates are on the NetApp ONTAP lifecycle page.

The right response comes down to one question: how many more years does this system need to run? Under a year, extended support (where it exists) is usually cheaper than an emergency migration. One to three years, migrate — support fees paid repeatedly cost more than doing the project once. Indefinitely, migrate now and plan the next one before it surprises you. Extended support is often the more expensive choice over a multi-year horizon — a bridge, not a destination.

Frequently Asked Questions

How long does NetApp support an ONTAP release?

Per NetApp's documentation, new ONTAP releases are entitled to full support for 3 years from release. Full support is followed by 2 years of limited support and then 3 years of self-service support — but per NetApp's own support definitions, service updates (including any form of software update) are not provided for versions under limited support. In practice that means an ONTAP release receives patches, including security fixes, for roughly three years; the remaining five years of the lifecycle provide documentation, technical support in the limited phase, and nothing else.

When do ONTAP 9.15.1 and 9.16.1 reach end of support?

ONTAP 9.15.1 reaches the end of full support on July 31, 2027, and ONTAP 9.16.1 on January 31, 2028, per our tracked data and NetApp's published support-dates table. Limited support — which ships no patches — continues to July 31, 2029 for 9.15.1 and January 31, 2030 for 9.16.1. Because no software updates of any kind are released after full support ends, July 31, 2027 and January 31, 2028 are the dates that matter for security planning on those releases.

What is the difference between full support and limited support for ONTAP?

Full support includes technical support, root cause analysis, security vulnerability evaluation, documentation, software downloads, and service updates delivered as P-releases. Limited support keeps technical support, root cause analysis, documentation, and existing software downloads — but per NetApp's definitions, service updates including any form of software update are not provided under limited support. A release in limited support still shows as supported in NetApp's matrix and you can still open a case about it, but it will never receive another patch, security or otherwise.

Which ONTAP versions are already end of life?

As of August 12, 2026, five tracked ONTAP releases are past the end of full support and no longer receive any patches: 9.13.1 (ended June 30, 2026), 9.12.1 (February 28, 2026), 9.11.1 (July 31, 2025), 9.10.1 (January 31, 2025), and 9.9.1 (June 30, 2024). ONTAP 9.9.1 is furthest gone — its limited support window also closed on June 30, 2026, the same day 9.13.1 left full support. Releases older than 9.9.1 predate our tracked data and are further out of support still.

Related

The Monthly EOL Digest™

Once a month — critical EOL dates, CVE blind spots, and lifecycle changes worth knowing.

© 2026 endoflife.ai · How we verify our dates · API · About · Data from endoflife.date (MIT)