NetApp ONTAP End of Life: Every Version's Support Dates — and Why the Patch Cliff Comes Two Years Before "End of Support"
Storage arrays are the ultimate "it just works" infrastructure. A NetApp filer gets racked, provisioned, and then disappears from everyone's attention precisely because it does its job — serving the NFS exports, SMB shares, and VM datastores that everything else runs on. The applications on top get patched monthly. The hypervisors get patched quarterly. The ONTAP release underneath frequently runs untouched from install to hardware refresh, five or more years later. That habit collides with a lifecycle most teams have never actually read: an ONTAP release stops receiving patches roughly three years after it ships — and NetApp's support matrix will keep calling it "supported" for two more years after that.
That last part is the detail this article exists for. NetApp's lifecycle for an ONTAP release is 3 years of full support, then 2 years of limited support, then 3 years of self-service support. Most vendors' second-phase support still ships security fixes. NetApp's does not: per NetApp's own support definitions, under limited support "Service Updates (including any form of software update) are not provided." The patch cliff — including security patches — is the end of full support, not the end of the lifecycle. A filer on ONTAP 9.12.1 today is "in limited support" until February 2028 and has not been eligible for a single update since February 2026.
The dates are close, and some have already passed. ONTAP 9.13.1 left full support on June 30, 2026 — six weeks before this article's publication — the same day 9.9.1 exited even its limited support window. ONTAP 9.14.1 has 172 days of full support left (January 31, 2027). ONTAP 9.15.1 — a common landing for fleets refreshed in 2024 — has under a year, to July 31, 2027. ONTAP 9.16.1 follows on January 31, 2028.
How ONTAP support actually works: 3 + 2 + 3, and only the first number ships patches
NetApp's upgrade guidance states it plainly: "New ONTAP releases are entitled to full support for 3 years." What each phase means comes from NetApp's Software Version Support Definitions, and the differences are worth quoting rather than paraphrasing:
Full support is "the time period where NetApp provides full support for a version of a software product including: technical support, root cause analysis, security vulnerability evaluation, documentation, and software available online and Service Updates (P-releases)." This is the whole package — and note that security vulnerability evaluation is on the list. During full support, fixes ship as P-releases (9.15.1Px) on the release line, which NetApp's guidance says to apply "every 3-6 months" for non-critical updates and "as soon as possible" for critical ones.
Limited support, the next two years, keeps "technical support, root cause analysis, documentation and software available online" — but "Service Updates (including any form of software update) are not provided for versions under limited support." You can open a case. NetApp will help you troubleshoot. What nobody can do is patch the release, because no patch will ever be built. There is no paid tier that changes this — ONTAP has no equivalent of Microsoft's ESU or Oracle's Extended Support fee.
Self-service support, the final three years, is the documentation staying online. After it, the version is considered obsolete.
The practical consequence: for security planning, the only date that matters is the end of full support. That is the date our tracked data records as EOL for each ONTAP release — consistent with endoflife.date, which notes that the limited and self-service phases ship no software updates and treats them as post-EOL. The limited-support dates are worth knowing anyway — they tell you how long NetApp will still answer the phone — so the table below carries both clocks.
One naming note, because ONTAP's version numbers confuse people coming from other ecosystems: every current ONTAP release is numbered 9.x.1 — 9.14.1, 9.15.1, 9.16.1 and so on. The "9.x.1" is the release; updates within it ship as numbered P-releases (9.15.1P13), which NetApp's definitions call Service Updates. Asking "when does ONTAP 9.15 die?" and "when does 9.15.1 die?" is asking the same question. The release rhythm is observable in the table's dates: three releases have gone GA in 2026 alone (9.17.1 in January, 9.18.1 in February, 9.19.1 in July), after a quieter 2025 — roughly two releases a year on average across the tracked window.
Every ONTAP version's dates
Release dates and end-of-full-support dates below are from our tracked lifecycle data (verification pass 2026-08-12), cross-checked against NetApp's ONTAP Software Version Support dates KB; limited-support dates are from that KB directly. Each version links to its lifecycle page with live status and risk score. Status badges reflect August 12, 2026.
| Version | Status | Released | Full support ends (EOL) | Limited support ends | Notes |
|---|---|---|---|---|---|
| ONTAP 9.19.1 | Supported | Jul 2026 | Jul 30, 2029 | — | Current release; not yet listed in NetApp's support-dates KB at publication. |
| ONTAP 9.18.1 | Supported | Feb 4, 2026 | Sep 30, 2028 | Jan 31, 2031 | NetApp's KB lists full support to Jan 31, 2029 — see note below. |
| ONTAP 9.17.1 | Supported | Jan 15, 2026 | Sep 30, 2028 | Sep 30, 2030 | Same full-support end date as 9.18.1 per tracked data. |
| ONTAP 9.16.1 | Supported | Jan 2025 | Jan 31, 2028 | Jan 31, 2030 | The 2025 release — sole GA of that year in tracked data. |
| ONTAP 9.15.1 | Supported | May 2024 | Jul 31, 2027 | Jul 31, 2029 | Under a year of patches left at publication. |
| ONTAP 9.14.1 | Warning | Jan 2024 | Jan 31, 2027 | Jan 31, 2029 | 172 days of full support left at publication. |
| ONTAP 9.13.1 | EOL | Jun 2023 | Jun 30, 2026 | Jun 30, 2028 | Crossed the patch cliff six weeks before publication. |
| ONTAP 9.12.1 | EOL | Feb 2023 | Feb 28, 2026 | Feb 28, 2028 | No updates of any form since February 2026. |
| ONTAP 9.11.1 | EOL | Jul 2022 | Jul 31, 2025 | Jul 31, 2027 | Unpatched for over a year. |
| ONTAP 9.10.1 | EOL | Jan 2022 | Jan 31, 2025 | Jan 31, 2027 | Limited support closes in under six months. |
| ONTAP 9.9.1 | EOL | Jun 2021 | Jun 30, 2024 | Jun 30, 2026 | Out of even limited support since June 30, 2026 — self-service only. |
The 9.18.1 note: our tracked data and endoflife.date list 9.18.1's full support ending September 30, 2028 — the same day as 9.17.1 — while NetApp's support-dates KB lists January 31, 2029, which matches the three-years-from-GA policy exactly (9.18.1 went GA February 4, 2026). The sources disagree; we show the tracked (earlier, more conservative) date in the table and flag the difference here rather than silently picking one. NetApp's KB itself defers to the login-gated Software Version Support page as the latest word. Release dates shown at month precision are month-precision in the source data.
The hardware clock underneath the software clock
ONTAP dates are only half the lifecycle math, because ONTAP runs on FAS and AFF platforms that carry their own end-of-availability schedule — and the two clocks are coupled. Per NetApp's hardware support policy KB, once a platform reaches its End of Availability (EOA) date, there is a "Feature Release Period" of two years — "During this period you can expect new Feature Releases to support your hardware or platform" — followed by a patch-only period, with the platform's End of Support arriving "typically 5 years after the EOA date."
Read that as an upgrade ceiling: a filer whose platform left sale more than two years ago should be assumed unable to run the newest ONTAP release. At that point the software lifecycle table above stops being a menu and becomes a countdown — the last ONTAP release your hardware supports has a fixed end-of-full-support date, and when it passes, no newer release can rescue the box. The authoritative per-platform answer (which ONTAP versions a given FAS/AFF model can run, and its EOA/EOS dates) lives in NetApp's Hardware Universe; checking it belongs in the same review as the version table. This coupling is why storage estates hit end of life in a way software estates don't: the fix for an aging ONTAP release is sometimes a purchase order, not an upgrade window. We cover that broader pattern in our hardware EOSL guide.
The upgrade rhythm: a filer installed three years ago is six releases behind
NetApp's release cadence means ONTAP versions age faster than filer attention cycles. A cluster deployed on 9.13.1 in mid-2023 — a perfectly current choice at the time — is now six releases behind 9.19.1 and past its patch cliff. NetApp's own guidance anticipates this: "NetApp recommends that you run the newest release for 1 year after general availability (GA) and then use the remaining time within the full support window to plan for your transition to a newer ONTAP release." That is a vendor telling you, in policy language, that the three-year window is meant to contain two planned events — adoption and the next migration — not one install and four years of silence.
The mechanics are better than storage folklore remembers. Per NetApp's upgrade methods documentation, "if available, the automated nondisruptive upgrade (ANDU) using System Manager is the preferred method" — clusters under eight nodes upgrade node by node with partners taking over storage (rolling), larger clusters in batches, both without taking data offline. Nondisruptive does not mean unplanned: version upgrade paths, mixed-version windows, and the hardware ceiling above still need checking per the release notes. But "we can't take the downtime" stopped being a valid reason to run a dead ONTAP release years ago.
For a fleet, the sustainable rhythm falls out of the dates: land on a release in its first year (NetApp's one-year recommendation), run it while it's patched, and begin the next transition before your release's full-support date is inside a budget cycle. Fleets refreshed onto 9.15.1 in 2024 are at exactly that point now — July 31, 2027 is close enough that the upgrade to 9.17.1, 9.18.1 or 9.19.1 belongs in this fiscal year's plan, not next year's.
The security stakes: zero KEV entries, one giant blast radius
Honesty first: we checked the live CISA Known Exploited Vulnerabilities catalog (August 10, 2026 release, 1,662 entries) and there are no NetApp or ONTAP entries in it. No documented in-the-wild exploitation of ONTAP appears in the KEV record, and we won't manufacture urgency by implying otherwise.
The structural argument doesn't need it. The filer is the layer everything else stands on: the NFS and SMB shares holding user and application data, the LUNs and datastores under the virtualization estate, the snapshots and replication targets that are the recovery plan. Storage systems concentrate exactly what ransomware operators want — the data and the backups of the data — which is why hardening guidance for storage focuses so heavily on admin-interface exposure and snapshot immutability. An ONTAP release past its full-support date has also lost something quieter than patches: per NetApp's definitions, full support is when "security vulnerability evaluation" happens. Past the cliff, new CVEs aren't just unfixed on your release — nobody is on the hook to assess it at all. For the machine holding every other machine's data, running a release the vendor no longer evaluates is a single point of exposure that no amount of patching above it repairs.
We track NetApp ONTAP and 480+ other products against vendor-verified dates — every ONTAP release with live status and risk score, check your version in seconds, or see what else hits end of life this quarter.
NetApp ONTAP currently carries an EOL Risk Score™ of 35/100 — Grade B, moderate risk, recalculated at every site build from EOL recency, attack surface, CISA KEV exposure, and extended-support availability. Per-version scores and dates are on the NetApp ONTAP lifecycle page.
The right response comes down to one question: how many more years does this system need to run? Under a year, extended support (where it exists) is usually cheaper than an emergency migration. One to three years, migrate — support fees paid repeatedly cost more than doing the project once. Indefinitely, migrate now and plan the next one before it surprises you. Extended support is often the more expensive choice over a multi-year horizon — a bridge, not a destination.
Frequently Asked Questions
How long does NetApp support an ONTAP release?
Per NetApp's documentation, new ONTAP releases are entitled to full support for 3 years from release. Full support is followed by 2 years of limited support and then 3 years of self-service support — but per NetApp's own support definitions, service updates (including any form of software update) are not provided for versions under limited support. In practice that means an ONTAP release receives patches, including security fixes, for roughly three years; the remaining five years of the lifecycle provide documentation, technical support in the limited phase, and nothing else.
When do ONTAP 9.15.1 and 9.16.1 reach end of support?
ONTAP 9.15.1 reaches the end of full support on July 31, 2027, and ONTAP 9.16.1 on January 31, 2028, per our tracked data and NetApp's published support-dates table. Limited support — which ships no patches — continues to July 31, 2029 for 9.15.1 and January 31, 2030 for 9.16.1. Because no software updates of any kind are released after full support ends, July 31, 2027 and January 31, 2028 are the dates that matter for security planning on those releases.
What is the difference between full support and limited support for ONTAP?
Full support includes technical support, root cause analysis, security vulnerability evaluation, documentation, software downloads, and service updates delivered as P-releases. Limited support keeps technical support, root cause analysis, documentation, and existing software downloads — but per NetApp's definitions, service updates including any form of software update are not provided under limited support. A release in limited support still shows as supported in NetApp's matrix and you can still open a case about it, but it will never receive another patch, security or otherwise.
Which ONTAP versions are already end of life?
As of August 12, 2026, five tracked ONTAP releases are past the end of full support and no longer receive any patches: 9.13.1 (ended June 30, 2026), 9.12.1 (February 28, 2026), 9.11.1 (July 31, 2025), 9.10.1 (January 31, 2025), and 9.9.1 (June 30, 2024). ONTAP 9.9.1 is furthest gone — its limited support window also closed on June 30, 2026, the same day 9.13.1 left full support. Releases older than 9.9.1 predate our tracked data and are further out of support still.
Related
- All NetApp ONTAP versions with live status · ONTAP 9.15.1 · ONTAP 9.16.1 — dates and risk scores
- Hardware EOSL: When the Box Itself Goes End of Life — the EOA/EOS clock this article's hardware section summarizes
- What Extended Support Actually Costs — the cross-vendor pricing reference (ONTAP is one of the products with no paid extension at all)
- The 2026 EOL Calendar — everything else with a date this year