Sophos Product Lifecycle Calendar - End-of-Sale / End-of-Life
The Sophos Product Lifecycle Calendar supports procurement, renewal, migration and risk assessment. For Sophos Firewall environments, it is not only important whether an appliance is still running today. It is also crucial whether it is still being sold, whether support can be extended, whether RMA is possible, and when a clean transition to a successor model must be planned.
This overview summarises important lifecycle data for Sophos Firewall appliances, REDs, Access Points and Switches. The data should be checked against the current Sophos Retirement Calendar and current licensing documents for every major firewall plan, as availability, successors and renewal windows may change.
For concrete upgrade and migration planning, also consider Checking Sophos Firewall before SFOS 22 Upgrade, Creating or Restoring Sophos Firewall Backup and Selecting Sophos Firewall Hardware or Virtual Appliance.
Important: Lifecycle data are planning data. Before ordering, renewing, RMA or hardware replacement, you should verify serial number, license status, Sophos account, support entitlement and current Sophos lifecycle information.
Scope and Inventory
The tables cover XGS Appliances and XG Firewalls, SD-RED and RED, AP/APX/AP6 Access Points, and Sophos Switches. SG/UTM appliances and virtual or cloud firewalls must also be inventoried, but are not shown here as complete model matrices: SG/UTM also depends on the last supported software release; virtual and cloud instances depend on platform, hypervisor, image, and SFOS support rather than hardware EOL. Endpoint, Server, Mobile, and Email have separate lifecycle calendars and must not be assessed from these tables.
Before checking dates, consolidate the inventory from Sophos Central, the local configuration or backup, and the asset system. For each device, record the model and hardware revision from its label, serial number, management method, site, HA membership, firmware, license and contract end, and dependent REDs, Access Points, and Switches. Keep unknown or unreachable devices as open assets; do not silently treat them as retired.
Quick decision: renew or migrate?
- Check the exact model in the current Sophos Retirement Calendar and record End-of-Sale, Last Renewal, End-of-Life, and the Migration path. Search for the exact model name, verify the product section, and save the query date and footnotes in the asset record. The tables below reflect the review completed on September 6, 2026.
- If Last Renewal has passed, do not budget for a normal renewal. If it falls within the next budget or contract period, compare migration and renewal as separate options, including cost, outage window, and hardware availability.
- Verify the actual contract separately. The table proves neither active support nor RMA entitlement. On the firewall,
Administration > Licensingshows registered licenses and terms; for a binding renewal or RMA decision, also reconcile the serial number and entitlement in the Sophos account or with the partner or Sophos Support. - Assess hardware and firmware lifecycles separately. Software support follows its own release deadlines, and SFOS 22.0 GA excludes XG and SG hardware. A remaining hardware term therefore does not make these platforms eligible for SFOS 22.
If displays conflict, use the published product deadlines in the Retirement Calendar, the specific contract in the signed-in account, and the firmware compatibility in the release notes. Do not resolve a conflict by choosing the more favorable date; obtain written clarification before an order or maintenance window.
Warranty is a fourth, separate check. Warranty extensions and Advance Hardware Replacement end no later than the applicable EOL. Hardware replacement, support and subscription contracts can be extended for the last time twelve months before product EOL. XGS Appliances have a planned post-EOS support phase of at least five years. If a valid contract extends beyond EOL, its remaining term can be moved to a supported successor; this is not an entitlement to continue operating the old hardware after EOL. Sophos Hardware Warranty, Support and RMA explains the details and RMA boundaries.
Sophos publishes two differently worded statements for EOL: the Retirement Calendar says support ceases and RMAs are no longer processed, while the hardware lifecycle policy describes replacement for a customer whose valid support contract extends beyond the model’s EOL. Do not infer entitlement from either statement; obtain written, serial-number-specific confirmation from Sophos in advance.
Verification path and safe migration boundary
Before approving a renewal or migration, the asset record should contain at least the model, serial number, site, current SFOS version, contract end, and the four Retirement Calendar values. For a firewall, also record the active slot and full firmware version under Backup & Firmware > Firmware. This avoids treating hardware EOL and software support as the same deadline.
For software planning, Sophos maintains the current feature release and one additional feature release selected by Sophos. It aims to support the last two maintenance releases of each maintained feature release; a bug or vulnerability fix may still require an upgrade to a maintained release. A feature release is typically supported for 24 to 36 months, and its EOL is usually announced 90 days in advance. These periods are planning guidance, not a guarantee, so verify the currently maintained and supported releases in the Retirement Calendar.
Before replacing hardware, prepare a fresh externally stored backup, the Secure Storage Master Key, and an interface mapping. Do not deregister or retire the old appliance until WAN, DNS, DHCP, routing, VPN, published services, RED/wireless dependencies, and both HA nodes have been tested on the target. Falling back to the old appliance is dependable only while it remains unchanged, correctly licensed, and safe to operate. After EOL or an incompatible SFOS conversion, it is no longer a routine rollback; a replacement or reimage plan is required.
Glossary
End-of-Sale (EOS)
The End-of-Sale date is the last day a product is officially sold new. In practice, a model may become hard to obtain earlier depending on stock, distributor and region. Therefore, projects should not be planned up to the last day.
End-of-Life (EOL)
From this date onwards, Sophos no longer provides regular support for this product. RMA or replacement processes can no longer be planned as with supported hardware. Productive sites should be migrated before this date.
Last Renewal
Last Renewal is the final day on which an extension for hardware replacement, technical support, or subscription services can be ordered. A normal extension is no longer possible after that date. This is often more important for budget planning than the later End-of-Life date.
Buyer’s Guide (BG)
The Buyer’s Guide is an Avanet classification for procurement and planning.
π’ - The product is current and has a clear purchase recommendation.
π - The product is still officially sold, but there are indications of a successor.
π΄ - No purchase recommendation, the product is already or soon End of Life or there is already a successor.
How to Use the Lifecycle Data
Lifecycle data should not be read in isolation. For administrators, four questions are especially relevant:
- Can the hardware still be sensibly renewed? If Last Renewal is near, a migration is often more worthwhile than a short extension.
- Is the firmware strategy realistic? Old XG and SG hardware no longer supports current SFOS versions. For SFOS 22 and newer, the platform must be checked early.
- Is there a recovery scenario? Before EOL, it should be clear whether a replacement device, backup, SSMK, interface mapping and access documentation are available.
- Is the successor really suitable? A successor model does not automatically replace throughput, port layout, WLAN module, SFP/SFP+, PoE, RED design or rackmount requirements.
For an ongoing firewall project, you should therefore not only read the table but also include Finding the Sophos Firewall Serial Number, Activating Sophos Firewall License Key and Correctly Assessing Sophos Firewall Sizing.
Recommended Checks Before Renewal or Replacement
Before renewal, hardware replacement or EOL migration, you should document at least the following points:
- Serial number, model, firmware version and location,
- current license and support status,
- End-of-Sale, Last Renewal and End-of-Life,
- planned successor including port layout and performance,
- current backup and Secure Storage Master Key,
- HA role, WAN design, RED locations and wireless dependencies,
- planned migration path and rollback window.
If a firewall needs to be transferred to another account, this should be clarified before migration. The procedure is described in Transferring Sophos Firewall to Another Sophos Central Account.
XGS Appliances
| Product | Release Date | End-of-Sale | Last Renewal | End-of-Life | Successor Product | BG |
|---|---|---|---|---|---|---|
| XGS 87 | April 2021 | 31.01.2025 | 30.09.2029 | 30.09.2030 | XGS 88 | π΄ |
| XGS 87w | April 2021 | 14.04.2025 | 30.09.2029 | 30.09.2030 | XGS 88w | π΄ |
| XGS 107 | April 2021 | 01.03.2025 | 30.09.2029 | 30.09.2030 | XGS 108 | π΄ |
| XGS 107w | April 2021 | 14.04.2025 | 30.09.2029 | 30.09.2030 | XGS 108w | π΄ |
| XGS 116 | April 2021 | 14.04.2025 | 30.09.2029 | 30.09.2030 | XGS 118 | π΄ |
| XGS 116w | April 2021 | 14.04.2025 | 30.09.2029 | 30.09.2030 | XGS 118w | π΄ |
| XGS 126 | April 2021 | 14.04.2025 | 30.09.2029 | 30.09.2030 | XGS 128 | π΄ |
| XGS 126w | April 2021 | 14.04.2025 | 30.09.2029 | 30.09.2030 | XGS 128w | π΄ |
| XGS 136 | April 2021 | 14.04.2025 | 30.09.2029 | 30.09.2030 | XGS 138 | π΄ |
| XGS 136w | April 2021 | 14.04.2025 | 30.09.2029 | 30.09.2030 | XGS 128w / XGS 138 + AP6 | π΄ |
| XGS 88 | October 2024 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 88w | October 2024 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 108 | October 2024 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 108w | October 2024 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 118 | October 2024 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 118w | October 2024 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 128 | October 2024 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 128w | October 2024 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 138 | October 2024 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 2100 | April 2021 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 2300 | April 2021 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 3100 | April 2021 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 3300 | April 2021 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 4300 | April 2021 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 4500 | April 2021 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 5500 | April 2021 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 6500 | April 2021 | Not declared | Not declared | Not declared | Not declared | π’ |
| XGS 7500 | Not declared | Not declared | Not declared | Not declared | π’ | |
| XGS 8500 | Not declared | Not declared | Not declared | Not declared | π’ |
XG Firewall
| Product | Last Revision | End-of-Sale | Last Renewal | End-of-Life | Successor Product | BG |
|---|---|---|---|---|---|---|
| XG 85 | 3 | 17.08.2019 | 17.08.2021 | 17.08.2022 | XGS 88 | π΄ |
| XG 85w | 3 | 17.08.2019 | 17.08.2021 | 17.08.2022 | XGS 88w | π΄ |
| XG 86 | 1 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 87 | π΄ |
| XG 86w | 1 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 87w | π΄ |
| XG 105 | 3 | 17.08.2019 | 17.08.2021 | 17.08.2022 | XGS 108 | π΄ |
| XG 105w | 3 | 17.08.2019 | 17.08.2021 | 17.08.2022 | XGS 108w | π΄ |
| XG 106 | 1 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 107 | π΄ |
| XG 106w | 1 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 107w | π΄ |
| XG 115 | 3 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 116 | π΄ |
| XG 115w | 3 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 116w | π΄ |
| XG 125 | 3 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 126 | π΄ |
| XG 125w | 3 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 126w | π΄ |
| XG 135 | 3 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 136 | π΄ |
| XG 135w | 3 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 136w | π΄ |
| XG 210 | 3 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 2100 | π΄ |
| XG 230 | 2 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 2300 | π΄ |
| XG 310 | 2 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 3100 | π΄ |
| XG 330 | 2 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 3300 | π΄ |
| XG 430 | 2 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 4300 | π΄ |
| XG 450 | 2 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 4500 | π΄ |
| XG 550 | 2 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 5500 | π΄ |
| XG 650 | 2 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 6500 / XGS 7500 | π΄ |
| XG 750 | 2 | 30.09.2021 | 31.03.2024 | 31.03.2025 | XGS 7500 / XGS 8500 | π΄ |
SD-REDs
| Product | End-of-Sale | End-of-Life | Successor Product | BG |
|---|---|---|---|---|
| SD-RED 20 | Not declared | Not declared | Not declared | π’ |
| SD-RED 60 | Not declared | Not declared | Not declared | π’ |
REDs
| Product | End-of-Sale | End-of-Life | Successor Product | BG |
|---|---|---|---|---|
| RED 15 | 31.08.2020 | 31.08.2023 | SD-RED 20 | π΄ |
| RED 15w | 31.08.2020 | 31.08.2023 | SD-RED 20 and WiFi Module or APX | π΄ |
| RED 50 | 31.08.2020 | 31.08.2023 | SD-RED 60 | π΄ |
Access Points
AP Series
| Product | End-of-Sale | End-of-Life | Successor Product | BG |
|---|---|---|---|---|
| AP 15 / 15C | 31.03.2020 | 31.12.2023 | Sophos AP6 420 | π΄ |
| AP 55 / 55C | 31.03.2020 | 31.12.2023 | Sophos AP6 420 | π΄ |
| AP 100 / 100C | 31.03.2020 | 31.12.2023 | Sophos AP6 840 / Sophos AP6 840E | π΄ |
| AP 100X | 01.08.2021 | 31.12.2023 | Sophos AP6 420X | π΄ |
APX Series
| Product | End-of-Sale | End-of-Life | Successor Product | BG |
|---|---|---|---|---|
| APX 120 | 31.03.2024 | 31.12.2027 | Sophos AP6 420 | π΄ |
| APX 320 | 31.03.2024 | 31.12.2027 | Sophos AP6 420 | π΄ |
| APX 530 | 31.03.2024 | 31.12.2027 | Sophos AP6 420E | π΄ |
| APX 740 | 31.03.2024 | 31.12.2027 | Sophos AP6 840 / Sophos AP6 840E | π΄ |
| APX 320X | 31.03.2024 | 31.12.2027 | Sophos AP6 420X | π΄ |
AP6 Series
AP6 is Sophos’ current WiFi 6 generation. It requires management through Sophos Central; the Retirement Calendar states that firewall management is not supported. Wireless planning should also establish whether existing AP or APX models must be replaced and whether PoE, mounting, outdoor requirements, and the SSID/VLAN design are suitable.
| Product | Release Date | End-of-Sale | End-of-Life | Successor Product | BG |
|---|---|---|---|---|---|
| Sophos AP6 420 | August 2023 | N/A | 5 years after EOS | N/A | π’ |
| Sophos AP6 420E | August 2023 | N/A | 5 years after EOS | N/A | π’ |
| Sophos AP6 840 | August 2023 | N/A | 5 years after EOS | N/A | π’ |
| Sophos AP6 840E | August 2023 | N/A | 5 years after EOS | N/A | π’ |
| Sophos AP6 420X | August 2023 | N/A | 5 years after EOS | N/A | π’ |
Switches
| Product | Release Date | End-of-Sale | End-of-Life | Successor Product | BG |
|---|---|---|---|---|---|
| CS101-8 | December 2021 | N/A | 5 years after EOS | N/A | π’ |
| CS101-8FP | December 2021 | N/A | 5 years after EOS | N/A | π’ |
| CS110-24 | December 2021 | N/A | 5 years after EOS | N/A | π’ |
| CS110-24FP | December 2021 | N/A | 5 years after EOS | N/A | π’ |
| CS110-48 | December 2021 | N/A | 5 years after EOS | N/A | π’ |
| CS110-48P | December 2021 | N/A | 5 years after EOS | N/A | π’ |
| CS110-48FP | December 2021 | N/A | 5 years after EOS | N/A | π’ |
| CS210-8FP | December 2021 | N/A | 5 years after EOS | N/A | π’ |
| CS210-24FP | June 2022 | N/A | 5 years after EOS | N/A | π’ |
| CS210-48FP | June 2022 | N/A | 5 years after EOS | N/A | π’ |
| CS1010-8FP | February 2025 | Not listed in Retirement Calendar | Not listed in Retirement Calendar | Not listed in Retirement Calendar | π’ |
Common Mistakes in Lifecycle Planning
Only checking End-of-Life: Renewal may already be impossible before then. Therefore, check End-of-Sale, Last Renewal and EOL together.
Replacing the model 1:1: Port layout, performance or WLAN will not automatically fit. Reassess sizing, interfaces, PoE, SFP/SFP+, rackmount, RED sites and location requirements.
Looking for the backup only during replacement: Migration is delayed or restore fails. Check backup, Secure Storage Master Key and restore compatibility before replacement.
Forgetting RED or Access Points: Branch offices or WLAN may be affected after the firewall replacement. Document dependencies per site.
Not maintaining lifecycle data in the asset system: Surprises around budget, renewal and support arise when data only exists in a spreadsheet. Record serial number, EOL, Last Renewal and planned successor per asset.
Exceptions and Troubleshooting
If a model is missing, reconcile its spelling, revision, and product family with the label and serial number. βNot listedβ means neither βcurrentβ nor βsupported indefinitelyβ: record the unresolved result and query date, then obtain written confirmation of the deadline, Migration Path, and entitlement from the partner or Sophos Support before ordering. If the calendar, account, and table disagree, track hardware deadline, software support, and contract end separately and plan against the earliest date until resolved.
Stop the migration while interface mapping, firmware compatibility, license transfer, or restore warnings remain unresolved. Do not deregister the old appliance or overwrite the only backup. Reset or rebuild the target, document the discrepancy, and approve it again only after successfully testing the services listed under βVerification path.β