End of Support — the Vocabulary, the Federal Directive, and the Clock
"End of support" is the term the people who set deadlines actually use. Microsoft's lifecycle pages say end of support, not end of life. CISA's directives say EOS. The meaning is the one that matters operationally: the date a vendor stops maintaining a product — after which every newly discovered vulnerability in it is permanent until you upgrade or decommission. We track those dates for 500+ products, verified against vendor sources at every site build.
And as of this year, end of support is no longer just an operational concern — it is a compliance clock. On February 5, 2026, CISA issued Binding Operational Directive 26-02, "Mitigating Risk From End-of-Support Edge Devices" — a compulsory direction to US federal civilian agencies, developed with OMB, citing "widespread exploitation campaigns by advanced threat actors targeting EOS edge devices."
The BOD 26-02 clock
All deadlines run from the February 5, 2026 issuance. Quoting the directive's structure, with the resulting calendar dates:
| Deadline | ~When | Required action |
|---|---|---|
| Immediately | In force now | Update every vendor-supported edge device off EOS software (including firmware) to a supported version |
| +3 months | ~May 2026 (passed) | Inventory all devices on the CISA EOS Edge Device List; report to CISA |
| +12 months | ~February 2027 | Decommission listed devices whose EOS date has passed; inventory all edge devices that are EOS or will be within 12 months |
| +18 months | ~August 2027 | Decommission all EOS edge devices, replacing with vendor-supported hardware |
| +24 months | ~February 2028 | Continuous discovery: a standing process tracking every edge device that is EOS or will be within 12 months — decommissioned on or before the date it reaches EOS |
Scope, precisely
- Applies to edge devices — components physically or logically at an agency's network boundary (firewalls, VPN gateways, routers, and similar internet-facing infrastructure) that a vendor or CISA considers EOS.
- Applies to Federal Civilian Executive Branch agencies, including systems hosted by third parties on an agency's behalf — not to contractors directly, though the directive notes agencies "may need to modify contracts to comply."
- Excludes national security systems, Operational Technology devices, and FedRAMP-authorized cloud services out of scope under OMB M-24-15.
- And the directive's own aside is worth quoting: EOS devices "should not reside anywhere on federal networks" — the edge is where the clock starts, not where the problem ends.
The edge platforms, with live dates
Edge devices are exactly where end of support and active exploitation intersect — our Exploited & Unpatchable feed already documents KEV-listed vulnerabilities that end-of-support FortiOS lines will never receive fixes for. A sample of the edge platforms we track, with dates that update at every site build:
| Platform | Line | End of support |
|---|---|---|
| FortiOS | 7.2 | Sep 30, 2026 |
| FortiOS | 7.4 | Nov 11, 2028 |
| Cisco IOS XE | 17.16 | Dec 11, 2025 — passed |
| Cisco IOS XE | 17.17 | Mar 31, 2026 — passed |
Every tracked product's full version table lives on its own page — FortiOS, Cisco IOS XE, and the rest of the catalog — each with per-version EOL Risk Scores that factor CISA KEV exploitation.
Standing up continuous EOS tracking
Whether you're an FCEB agency under the directive, a contractor whose agency customers are amending contracts, or a security team treating BODs as the benchmark they usually become — the capability is the same:
- Stack Scanner — paste an inventory, get a verdict on every line: supported, approaching EOS, or past it.
- Free JSON API — batch lookup and CPE matching across the full dataset, for wiring EOS status into your own inventory, CMDB, or reporting pipeline. Machine-readable, the direction CISA itself says it is heading for directive reporting.
- Deadline alerts — watch your stack and get alerts at 365/90/60/30/7/0 days, plus security alerts when an actively-exploited CVE lands on a watched EOS version.
- Exploited & Unpatchable — the human-verified feed of CISA-KEV-listed vulnerabilities that end-of-support versions will never receive fixes for.
Frequently Asked Questions
What does end of support (EOS) mean?
End of support is the date a vendor stops maintaining a product or version: no more security patches, bug fixes, or vendor assistance. It is the vocabulary Microsoft's lifecycle pages and CISA's directives actually use — largely interchangeable with end of life (EOL), though some vendors use the two terms for different phases. After the date, every newly discovered vulnerability in that version is permanent unless you upgrade or decommission.
What is CISA BOD 26-02?
Binding Operational Directive 26-02, "Mitigating Risk From End-of-Support Edge Devices," issued by CISA on February 5, 2026 in coordination with OMB. It is a compulsory direction to US Federal Civilian Executive Branch agencies to inventory, report, and decommission end-of-support edge devices — devices at the network boundary such as firewalls, VPN gateways and routers — on a fixed clock, and then to keep discovering them continuously. CISA cites widespread exploitation campaigns by advanced threat actors targeting EOS edge devices as the driver.
What are the BOD 26-02 deadlines?
Counted from the February 5, 2026 issuance: immediately, agencies must update supported edge devices off EOS software. Within 3 months (~May 2026), inventory all devices on the CISA EOS Edge Device List and report to CISA. Within 12 months (~February 2027), decommission listed devices whose EOS date has passed, and inventory all edge devices that are EOS or will be within the next 12 months. Within 18 months (~August 2027), decommission all EOS edge devices. Within 24 months (~February 2028), establish continuous discovery — a standing process that tracks every edge device that is EOS or will be within 12 months, decommissioned on or before the date it reaches EOS.
Does BOD 26-02 apply to contractors or private companies?
The directive applies to Federal Civilian Executive Branch agencies, not contractors — but it notes agencies may need to modify contracts to comply, so contractors operating systems on an agency's behalf will feel it through their contracts. It excludes national security systems, Operational Technology devices, and FedRAMP-authorized cloud services defined as out of scope by OMB M-24-15. Outside government, BODs are also widely treated as best-practice benchmarks by state, local, and private-sector security teams.
How do you track end-of-support dates continuously?
The requirement that outlasts the deadlines is a standing process: know every product and version in the estate, know its end-of-support date, and see the 12-month horizon coming. That takes a maintained EOS date source — we track verified end-of-life and end-of-support dates for 500+ products including the major edge-device platforms, with per-version risk scores, CISA KEV exploitation context, a free JSON API with batch lookup and CPE matching, and deadline alerts at 365/90/60/30/7/0 days.
Related
- Exploited & Unpatchable — KEV-listed vulnerabilities that end-of-support versions will never get fixes for
- FortiOS · Cisco IOS XE — edge platforms with every line's live status
- The 2026 EOL calendar — every major deadline this year
- Why end of life is inevitable — the economics behind every vendor's support boundary