Sophos hardware warranty, support, and RMA explained
For Sophos hardware, warranty, support coverage, and the RMA process are separate matters. The base warranty provides a remedy for a covered hardware defect. Suitable, continuous support may additionally provide Advance Hardware Replacement. Sophos Support must validate the fault and approve the RMA.
To check eligibility, collect the product family, serial number, order or purchase evidence, support status, management type, HA role, and current lifecycle status. A visible Sophos Firewall Base License does not by itself prove support or advance-RMA entitlement.
What the terms mean
- Base Warranty: manufacturer’s warranty against defects in materials and workmanship when the hardware is used as documented.
- Extended Warranty: longer cover for specifically listed product families and generally for the original purchaser.
- Support contract: access to the agreed support services; Advance Hardware Replacement depends on the product and licensing model.
- Standard Hardware Replacement: the defective unit is returned first, and Sophos ships the replacement after receiving it.
- Advance Hardware Replacement: after an approved RMA, Sophos may ship the replacement before receiving the defective unit.
- RMA: Return Merchandise Authorization, the return or replacement approved by Sophos.
For the concrete coverage decision, compare the serial number, order date, product family, and support status with the current Sophos Hardware Warranty Terms. Then record the outcome and binding return deadline in the support case together with the written RMA instructions.
Warranty duration and scope
The base warranty runs for 12 months from the date Sophos processes its channel partner’s order. This is not necessarily the purchase, delivery, or installation date. An invoice and delivery note help identify the order, but Sophos’s recorded processing date starts the period.
Sophos lists extended cover for these families:
- SD-RED and APX Series: five years from the processed partner order, but never beyond End-of-Life.
- Sophos Switch and AP6 Series: Limited Lifetime Warranty; Sophos defines “Lifetime” as ending at End-of-Life.
- XGS Appliances, XG, and SG: 12-month base warranty. Sophos expressly applies the EOL limit to extended warranty and support periods instead.
The warranty covers manufacturing defects, not software, configuration, or configuration assistance. Exclusions include misuse, power or environmental conditions outside the specification, accidents, natural disasters, and unauthorized repair or alteration. Missing or tampered warranty stickers may void cover. A replacement may be new, refurbished, repaired, or a newer equivalent and carries only the remainder of the original warranty. The same SFOS release and backward compatibility are not guaranteed.
Always check the Sophos Product Lifecycle before a renewal or replacement. A support term can’t extend beyond EOL.
When Advance Hardware Replacement applies
For appliances running SFOS, including SFOS 22, eligibility depends on licensing and HA mode:
- Standalone SG/XG and XGS Appliances with a Term License: active Enhanced Support, included with Standard Protection and Xstream Protection.
- Standalone SG/XG and XGS Appliances with an MSP License: active Standard Protection or Xstream Protection under the MSP model.
- Active-Active HA: each appliance needs its own applicable cover.
- Active-Passive HA: the Primary needs Enhanced Plus for Term Licensing or Xstream Protection for MSP Licensing; Primary and Auxiliary are then eligible.
- AP6 and Sophos Switch in Sophos Central: active support subscription.
- SD-RED 20/60 and APX managed by SFOS: the connected SFOS device needs active Enhanced Plus Support.
- Standalone APX: not eligible for Advance Hardware Replacement.
Advance-RMA eligibility for APX and SD-RED ends after five years from the processed partner order or at EOL, whichever comes first. The written RMA determines which devices, components, and accessories must be returned; don’t add or remove items based on assumption.
This matters at branch sites: an access point or SD-RED may look like a small inventory item but can connect the entire site. Plan its replacement path and emergency operation as carefully as those of a firewall.
For an HA cluster, verify both serial numbers, the mode, and the Primary and Auxiliary roles. Sophos Firewall HA clusters explains the technical roles.
Waiting period after a support gap
If support is purchased more than 30 days after the warranty or previous support contract expires, a three-month waiting period for replacement hardware may apply. The Warranty Terms revised in March 2026 name XG and XGS, while the current support-service footnote names only XGS. Because the Warranty Terms claim precedence in a conflict, don’t assume the narrower wording benefits an XG reactivation; obtain written confirmation before purchase. Paid reinstatement may waive the waiting period.
Don’t wait for a failure before reactivating support. The support-license change for Sophos Firewall customers explains the wider operational impact of missing support.
Handle the RMA safely
The detailed runbook is in Prepare a Sophos hardware fault and RMA. For an eligibility check, use this sequence:
- Record the model, revision, serial number, order details, support status, fault, and both HA nodes where applicable.
- While the unit is accessible, save logs and a current Sophos Firewall backup. Keep the backup password and, when applicable, the Secure Storage Master Key available separately.
- Open a technical support case. Only Sophos Support validates the hardware fault and creates the RMA number; don’t ship or dispose of anything without instructions.
- Follow the approval for standard or advance replacement, address, accessories, carrier, customs duties, and return date. “Next-business-day shipment” is a reasonable-efforts target after complete approval before the regional cut-off, not a delivery guarantee.
- Check the replacement model and firmware compatibility before restoring, transfer the paid firewall license, then test WAN, LAN, routing, NAT, VPN, HA, Central, logs, and monitoring.
- Return the defective unit or named components, securely packaged and displaying the RMA number, as instructed. For advance replacement, the current Warranty Terms require return within 15 calendar days after receiving the RMA. Sophos may charge for the replacement if the defective hardware hasn’t been returned as requested within 30 days after receipt of the replacement. The date in the RMA remains decisive.
If the replacement must be assigned to another Sophos account, resolve that before license transfer. See Transfer a Sophos Firewall to another account.
Shipping, title, and risk also differ. For standard replacement, the customer prepays return carriage; for advance replacement, Sophos specifies the carrier and pays freight. Title to the defective hardware passes to Sophos at the earlier of the customer’s receipt of the replacement or Sophos’s receipt of the defective hardware. Title to the replacement passes only at the later of shipment or Sophos’s receipt of the defective unit, while risk of loss for the replacement passes to the customer on shipment. Confirm the RMA instructions, tracking, and any desired transit insurance before dispatch.
Protect configuration and customer data
Sophos disclaims responsibility for configurations or data on returned hardware. The customer is responsible for removing all customer data before shipment:
- Save the backup and required logs first, and verify the recovery plan.
- Then remove data under your organization’s privacy and erasure procedure while the unit remains accessible.
- Don’t remove internal HDDs, SSDs, or other parts without explicit written authorization from Sophos.
- If the unit is inaccessible, disclose the data risk in the case and request written instructions rather than opening the chassis or damaging warranty stickers.
- Dispose of hardware only when Sophos instructs this in writing. Secure erasure, complete destruction, e-waste compliance, and proof of disposal then also apply.
A late, incomplete, or missing return can result in a charge for the replacement. Sophos may also charge for “no fault found” or missing components. Retain tracking, proof of delivery, and confirmation that the case is closed.
Operations and renewal checklist
- Record product family, model, revision, and serial number.
- Match Sophos’s recorded order date with purchase and delivery evidence.
- Check account, licensing model, support product, and expiry date.
- For HA, check both appliances, their roles, and cover.
- For SD-RED, APX, AP6, or Switch, identify the management type.
- Check EOS, Last Renewal, and EOL dates.
- Test backup, keys, firmware compatibility, and the recovery plan.
- Provide HA, a spare, or documented emergency operation for critical sites.
Warranty and advance replacement provide hardware, not a working configuration or guaranteed recovery time. Replacement strategy and restore testing therefore belong in operational planning.