Debian 11 Support Ends August 31:
Upgrade, ELTS, or Commercial Support?
Current Status
Debian 11 "Bullseye" receives its last free security updates on August 31, 2026, when its Long Term Support window closes. Standard support from the main Debian security team already ended on August 14, 2024 — the LTS team has carried Bullseye since then, and on August 31 that ends too. Nothing breaks on September 1: repositories stay up, systems keep booting, and that is exactly the problem. The patch stream simply stops, and every CVE disclosed afterwards stays open on your machines. You can see how that accumulating exposure is scored on the Debian lifecycle page, where the EOL Risk Score™ for each version is recalculated at every build.
Debian's Three-Tier Afterlife
Debian is unusual among free distributions in how gradually support winds down — which is precisely why the final cliff catches teams off guard. Bullseye has already moved through two of its three tiers:
| Tier | Who ships patches | Debian 11 dates | Status |
|---|---|---|---|
| Standard support | Debian security team — full coverage | Aug 2021 → Aug 14, 2024 | Ended |
| Long Term Support (LTS) | Debian LTS team — free, main packages | Aug 2024 → Aug 31, 2026 | Ending |
| Extended LTS (ELTS) | Freexian — paid, subscriber-driven packages | Sep 2026 → listed through Jun 30, 2031 | Paid bridge |
Two wrinkles make the Debian 11 decision different from a typical EOL. First, the comfortable-sounding upgrade to Debian 12 lands you on a release already in its own LTS phase — Bookworm left standard support in July 2026 and runs on LTS until June 30, 2028. Second, Debian supports in-place upgrades only from the immediately previous release: there is no supported single hop from 11 to 13. Getting to Debian 13 "Trixie" (standard support to August 2028, LTS to mid-2030) means upgrading twice — 11→12, then 12→13 — or rebuilding directly on 13.
The Decision Flow
Most teams still running Debian 11 land on one of three paths. Work through it in order:
Upgrade vs Extended Support vs Do Nothing
| Factor | Upgrade / rebuild | Extended support (ELTS or commercial) | Do nothing |
|---|---|---|---|
| Upfront cost profile | High — two sequential upgrades or a rebuild, plus app re-validation | Medium — recurring fee, minimal engineering lift | Low — no direct spend, but risk accrues silently |
| Time-to-safe | Weeks to months, depending on estate size | Days — coverage typically begins on contract signing | Never — exposure is open-ended from September 1 |
| Ongoing risk | Eliminated once complete (next deadline: Debian 13's, in 2028) | Reduced, bounded by the vendor's package-coverage scope | Unbounded and compounding |
| Compliance posture | Clean — current, supported platform | Defensible — documented active coverage plus a plan | Open finding under most audit frameworks |
Worth saying plainly, because vendors selling extended support rarely will: extended support is often the more expensive choice over a multi-year horizon. Freexian's ELTS precedent is genuinely long — Debian 10 is still receiving fixes two years past its LTS end — but every ELTS or commercial-support month is a month of paying to stand still. It is the right answer when August 31 is genuinely unreachable, not a default. The market knows this deadline is valuable: commercial vendors have launched dedicated Debian 11 coverage sold specifically against it, which tells you how much Bullseye is still running in production — and how much money is about to be made bridging it.
What Teams in Your Position Typically Weigh
Teams still on Bullseye tend to fall into recognizable situations. Some have a handful of well-understood servers — for those, the sequential upgrade to 13 is usually cleaner long-term, and 25 days is genuinely enough for a small estate if the work starts now. Others discover Bullseye embedded where nobody was looking: container base images pinned years ago, appliances a vendor never re-certified, the VM running the badge printer. For estates like that, discovery is the real work, and extended support earns its keep as a bridge that keeps the patch stream alive while the inventory gets built.
The workloads to prioritize are the ones with direct exposure: anything internet-facing, anything handling regulated data, anything that would be an audit finding on its own. Internal or air-gapped workloads sometimes get deprioritized — reasonably, as long as that decision is written down and revisited rather than left to drift.
One pattern worth naming honestly: extended support is frequently treated as a permanent fix once it's in place, the way any quietly-renewing subscription is. It works best explicitly scoped as a bridge with an end date attached to a migration plan — not an indefinite substitute for one.
Not sure which path fits your Debian 11 footprint?
Tell us your situation and we'll match you with a provider suited to it — migration partner or extended-support vendor.
Frequently Asked Questions
When does Debian 11 reach end of life?
Debian 11 (Bullseye) receives its last free security updates on August 31, 2026, when its Long Term Support window closes. Standard support from the main Debian security team already ended on August 14, 2024; the LTS team has carried it since. After August 31, 2026 the Debian project ships no further security updates for Bullseye at all.
Is there extended support for Debian 11 after August 31, 2026?
Yes, two flavors. Extended LTS (ELTS), a commercial service operated by Freexian with the Debian project's blessing, lists Bullseye coverage through June 30, 2031 — with the caveat that it maintains the packages its subscribers use, not the whole archive. Separately, commercial extended-lifecycle-support vendors sell dedicated Debian 11 CVE patching, often bundled into broader enterprise legacy-support contracts.
Can I upgrade straight from Debian 11 to Debian 13?
Not in one hop — Debian supports in-place upgrades only from the immediately previous release, so the path is 11→12, then 12→13. Each hop is well-documented and famously reliable, but it is two maintenance windows of work, which is why some teams rebuild directly on Debian 13 with configuration management instead of upgrading twice.
Does staying on Debian 11 after August 31 affect compliance audits?
Yes. Running software with no security-update source is a standard finding under frameworks like PCI DSS, SOC 2, ISO 27001, and HIPAA. A documented migration plan or an active extended-support contract (ELTS or commercial) typically converts that finding into a managed exception rather than an open gap.
Ready to move off Debian 11 — or bridge it safely while you plan?
We track the dates and match you with the right provider for your situation.