Skip to content
Avanet

Sophos Product Lifecycle Calendar - End-of-Sale / End-of-Life

The Sophos Product Lifecycle Calendar supports procurement, renewal, migration and risk assessment. For Sophos Firewall environments, it is not only important whether an appliance is still running today. It is also crucial whether it is still being sold, whether support can be extended, whether RMA is possible, and when a clean transition to a successor model must be planned.

This overview summarises important lifecycle data for Sophos Firewall appliances, REDs, Access Points and Switches. The data should be checked against the current Sophos Retirement Calendar and current licensing documents for every major firewall plan, as availability, successors and renewal windows may change.

For concrete upgrade and migration planning, also consider Checking Sophos Firewall before SFOS 22 Upgrade, Creating or Restoring Sophos Firewall Backup and Selecting Sophos Firewall Hardware or Virtual Appliance.

Important: Lifecycle data are planning data. Before ordering, renewing, RMA or hardware replacement, you should verify serial number, license status, Sophos account, support entitlement and current Sophos lifecycle information.

Scope and Inventory

The tables cover XGS Appliances and XG Firewalls, SD-RED and RED, AP/APX/AP6 Access Points, and Sophos Switches. SG/UTM appliances and virtual or cloud firewalls must also be inventoried, but are not shown here as complete model matrices: SG/UTM also depends on the last supported software release; virtual and cloud instances depend on platform, hypervisor, image, and SFOS support rather than hardware EOL. Endpoint, Server, Mobile, and Email have separate lifecycle calendars and must not be assessed from these tables.

Before checking dates, consolidate the inventory from Sophos Central, the local configuration or backup, and the asset system. For each device, record the model and hardware revision from its label, serial number, management method, site, HA membership, firmware, license and contract end, and dependent REDs, Access Points, and Switches. Keep unknown or unreachable devices as open assets; do not silently treat them as retired.

Quick decision: renew or migrate?

  1. Check the exact model in the current Sophos Retirement Calendar and record End-of-Sale, Last Renewal, End-of-Life, and the Migration path. Search for the exact model name, verify the product section, and save the query date and footnotes in the asset record. The tables below reflect the review completed on September 6, 2026.
  2. If Last Renewal has passed, do not budget for a normal renewal. If it falls within the next budget or contract period, compare migration and renewal as separate options, including cost, outage window, and hardware availability.
  3. Verify the actual contract separately. The table proves neither active support nor RMA entitlement. On the firewall, Administration > Licensing shows registered licenses and terms; for a binding renewal or RMA decision, also reconcile the serial number and entitlement in the Sophos account or with the partner or Sophos Support.
  4. Assess hardware and firmware lifecycles separately. Software support follows its own release deadlines, and SFOS 22.0 GA excludes XG and SG hardware. A remaining hardware term therefore does not make these platforms eligible for SFOS 22.

If displays conflict, use the published product deadlines in the Retirement Calendar, the specific contract in the signed-in account, and the firmware compatibility in the release notes. Do not resolve a conflict by choosing the more favorable date; obtain written clarification before an order or maintenance window.

Warranty is a fourth, separate check. Warranty extensions and Advance Hardware Replacement end no later than the applicable EOL. Hardware replacement, support and subscription contracts can be extended for the last time twelve months before product EOL. XGS Appliances have a planned post-EOS support phase of at least five years. If a valid contract extends beyond EOL, its remaining term can be moved to a supported successor; this is not an entitlement to continue operating the old hardware after EOL. Sophos Hardware Warranty, Support and RMA explains the details and RMA boundaries.

Sophos publishes two differently worded statements for EOL: the Retirement Calendar says support ceases and RMAs are no longer processed, while the hardware lifecycle policy describes replacement for a customer whose valid support contract extends beyond the model’s EOL. Do not infer entitlement from either statement; obtain written, serial-number-specific confirmation from Sophos in advance.

Verification path and safe migration boundary

Before approving a renewal or migration, the asset record should contain at least the model, serial number, site, current SFOS version, contract end, and the four Retirement Calendar values. For a firewall, also record the active slot and full firmware version under Backup & Firmware > Firmware. This avoids treating hardware EOL and software support as the same deadline.

For software planning, Sophos maintains the current feature release and one additional feature release selected by Sophos. It aims to support the last two maintenance releases of each maintained feature release; a bug or vulnerability fix may still require an upgrade to a maintained release. A feature release is typically supported for 24 to 36 months, and its EOL is usually announced 90 days in advance. These periods are planning guidance, not a guarantee, so verify the currently maintained and supported releases in the Retirement Calendar.

Before replacing hardware, prepare a fresh externally stored backup, the Secure Storage Master Key, and an interface mapping. Do not deregister or retire the old appliance until WAN, DNS, DHCP, routing, VPN, published services, RED/wireless dependencies, and both HA nodes have been tested on the target. Falling back to the old appliance is dependable only while it remains unchanged, correctly licensed, and safe to operate. After EOL or an incompatible SFOS conversion, it is no longer a routine rollback; a replacement or reimage plan is required.

Glossary

End-of-Sale (EOS)

The End-of-Sale date is the last day a product is officially sold new. In practice, a model may become hard to obtain earlier depending on stock, distributor and region. Therefore, projects should not be planned up to the last day.

End-of-Life (EOL)

From this date onwards, Sophos no longer provides regular support for this product. RMA or replacement processes can no longer be planned as with supported hardware. Productive sites should be migrated before this date.

Last Renewal

Last Renewal is the final day on which an extension for hardware replacement, technical support, or subscription services can be ordered. A normal extension is no longer possible after that date. This is often more important for budget planning than the later End-of-Life date.

Buyer’s Guide (BG)

The Buyer’s Guide is an Avanet classification for procurement and planning.

🟒 - The product is current and has a clear purchase recommendation.

🟠 - The product is still officially sold, but there are indications of a successor.

πŸ”΄ - No purchase recommendation, the product is already or soon End of Life or there is already a successor.

How to Use the Lifecycle Data

Lifecycle data should not be read in isolation. For administrators, four questions are especially relevant:

  1. Can the hardware still be sensibly renewed? If Last Renewal is near, a migration is often more worthwhile than a short extension.
  2. Is the firmware strategy realistic? Old XG and SG hardware no longer supports current SFOS versions. For SFOS 22 and newer, the platform must be checked early.
  3. Is there a recovery scenario? Before EOL, it should be clear whether a replacement device, backup, SSMK, interface mapping and access documentation are available.
  4. Is the successor really suitable? A successor model does not automatically replace throughput, port layout, WLAN module, SFP/SFP+, PoE, RED design or rackmount requirements.

For an ongoing firewall project, you should therefore not only read the table but also include Finding the Sophos Firewall Serial Number, Activating Sophos Firewall License Key and Correctly Assessing Sophos Firewall Sizing.

Before renewal, hardware replacement or EOL migration, you should document at least the following points:

  • Serial number, model, firmware version and location,
  • current license and support status,
  • End-of-Sale, Last Renewal and End-of-Life,
  • planned successor including port layout and performance,
  • current backup and Secure Storage Master Key,
  • HA role, WAN design, RED locations and wireless dependencies,
  • planned migration path and rollback window.

If a firewall needs to be transferred to another account, this should be clarified before migration. The procedure is described in Transferring Sophos Firewall to Another Sophos Central Account.

XGS Appliances

ProductRelease DateEnd-of-SaleLast RenewalEnd-of-LifeSuccessor ProductBG
XGS 87April 202131.01.202530.09.202930.09.2030XGS 88πŸ”΄
XGS 87wApril 202114.04.202530.09.202930.09.2030XGS 88wπŸ”΄
XGS 107April 202101.03.202530.09.202930.09.2030XGS 108πŸ”΄
XGS 107wApril 202114.04.202530.09.202930.09.2030XGS 108wπŸ”΄
XGS 116April 202114.04.202530.09.202930.09.2030XGS 118πŸ”΄
XGS 116wApril 202114.04.202530.09.202930.09.2030XGS 118wπŸ”΄
XGS 126April 202114.04.202530.09.202930.09.2030XGS 128πŸ”΄
XGS 126wApril 202114.04.202530.09.202930.09.2030XGS 128wπŸ”΄
XGS 136April 202114.04.202530.09.202930.09.2030XGS 138πŸ”΄
XGS 136wApril 202114.04.202530.09.202930.09.2030XGS 128w / XGS 138 + AP6πŸ”΄
XGS 88October 2024Not declaredNot declaredNot declaredNot declared🟒
XGS 88wOctober 2024Not declaredNot declaredNot declaredNot declared🟒
XGS 108October 2024Not declaredNot declaredNot declaredNot declared🟒
XGS 108wOctober 2024Not declaredNot declaredNot declaredNot declared🟒
XGS 118October 2024Not declaredNot declaredNot declaredNot declared🟒
XGS 118wOctober 2024Not declaredNot declaredNot declaredNot declared🟒
XGS 128October 2024Not declaredNot declaredNot declaredNot declared🟒
XGS 128wOctober 2024Not declaredNot declaredNot declaredNot declared🟒
XGS 138October 2024Not declaredNot declaredNot declaredNot declared🟒
XGS 2100April 2021Not declaredNot declaredNot declaredNot declared🟒
XGS 2300April 2021Not declaredNot declaredNot declaredNot declared🟒
XGS 3100April 2021Not declaredNot declaredNot declaredNot declared🟒
XGS 3300April 2021Not declaredNot declaredNot declaredNot declared🟒
XGS 4300April 2021Not declaredNot declaredNot declaredNot declared🟒
XGS 4500April 2021Not declaredNot declaredNot declaredNot declared🟒
XGS 5500April 2021Not declaredNot declaredNot declaredNot declared🟒
XGS 6500April 2021Not declaredNot declaredNot declaredNot declared🟒
XGS 7500Not declaredNot declaredNot declaredNot declared🟒
XGS 8500Not declaredNot declaredNot declaredNot declared🟒

XG Firewall

ProductLast RevisionEnd-of-SaleLast RenewalEnd-of-LifeSuccessor ProductBG
XG 85317.08.201917.08.202117.08.2022XGS 88πŸ”΄
XG 85w317.08.201917.08.202117.08.2022XGS 88wπŸ”΄
XG 86130.09.202131.03.202431.03.2025XGS 87πŸ”΄
XG 86w130.09.202131.03.202431.03.2025XGS 87wπŸ”΄
XG 105317.08.201917.08.202117.08.2022XGS 108πŸ”΄
XG 105w317.08.201917.08.202117.08.2022XGS 108wπŸ”΄
XG 106130.09.202131.03.202431.03.2025XGS 107πŸ”΄
XG 106w130.09.202131.03.202431.03.2025XGS 107wπŸ”΄
XG 115330.09.202131.03.202431.03.2025XGS 116πŸ”΄
XG 115w330.09.202131.03.202431.03.2025XGS 116wπŸ”΄
XG 125330.09.202131.03.202431.03.2025XGS 126πŸ”΄
XG 125w330.09.202131.03.202431.03.2025XGS 126wπŸ”΄
XG 135330.09.202131.03.202431.03.2025XGS 136πŸ”΄
XG 135w330.09.202131.03.202431.03.2025XGS 136wπŸ”΄
XG 210330.09.202131.03.202431.03.2025XGS 2100πŸ”΄
XG 230230.09.202131.03.202431.03.2025XGS 2300πŸ”΄
XG 310230.09.202131.03.202431.03.2025XGS 3100πŸ”΄
XG 330230.09.202131.03.202431.03.2025XGS 3300πŸ”΄
XG 430230.09.202131.03.202431.03.2025XGS 4300πŸ”΄
XG 450230.09.202131.03.202431.03.2025XGS 4500πŸ”΄
XG 550230.09.202131.03.202431.03.2025XGS 5500πŸ”΄
XG 650230.09.202131.03.202431.03.2025XGS 6500 / XGS 7500πŸ”΄
XG 750230.09.202131.03.202431.03.2025XGS 7500 / XGS 8500πŸ”΄

SD-REDs

ProductEnd-of-SaleEnd-of-LifeSuccessor ProductBG
SD-RED 20Not declaredNot declaredNot declared🟒
SD-RED 60Not declaredNot declaredNot declared🟒

REDs

ProductEnd-of-SaleEnd-of-LifeSuccessor ProductBG
RED 1531.08.202031.08.2023SD-RED 20πŸ”΄
RED 15w31.08.202031.08.2023SD-RED 20 and WiFi Module or APXπŸ”΄
RED 5031.08.202031.08.2023SD-RED 60πŸ”΄

Access Points

AP Series

ProductEnd-of-SaleEnd-of-LifeSuccessor ProductBG
AP 15 / 15C31.03.202031.12.2023Sophos AP6 420πŸ”΄
AP 55 / 55C31.03.202031.12.2023Sophos AP6 420πŸ”΄
AP 100 / 100C31.03.202031.12.2023Sophos AP6 840 / Sophos AP6 840EπŸ”΄
AP 100X01.08.202131.12.2023Sophos AP6 420XπŸ”΄

APX Series

ProductEnd-of-SaleEnd-of-LifeSuccessor ProductBG
APX 12031.03.202431.12.2027Sophos AP6 420πŸ”΄
APX 32031.03.202431.12.2027Sophos AP6 420πŸ”΄
APX 53031.03.202431.12.2027Sophos AP6 420EπŸ”΄
APX 74031.03.202431.12.2027Sophos AP6 840 / Sophos AP6 840EπŸ”΄
APX 320X31.03.202431.12.2027Sophos AP6 420XπŸ”΄

AP6 Series

AP6 is Sophos’ current WiFi 6 generation. It requires management through Sophos Central; the Retirement Calendar states that firewall management is not supported. Wireless planning should also establish whether existing AP or APX models must be replaced and whether PoE, mounting, outdoor requirements, and the SSID/VLAN design are suitable.

ProductRelease DateEnd-of-SaleEnd-of-LifeSuccessor ProductBG
Sophos AP6 420August 2023N/A5 years after EOSN/A🟒
Sophos AP6 420EAugust 2023N/A5 years after EOSN/A🟒
Sophos AP6 840August 2023N/A5 years after EOSN/A🟒
Sophos AP6 840EAugust 2023N/A5 years after EOSN/A🟒
Sophos AP6 420XAugust 2023N/A5 years after EOSN/A🟒

Switches

ProductRelease DateEnd-of-SaleEnd-of-LifeSuccessor ProductBG
CS101-8December 2021N/A5 years after EOSN/A🟒
CS101-8FPDecember 2021N/A5 years after EOSN/A🟒
CS110-24December 2021N/A5 years after EOSN/A🟒
CS110-24FPDecember 2021N/A5 years after EOSN/A🟒
CS110-48December 2021N/A5 years after EOSN/A🟒
CS110-48PDecember 2021N/A5 years after EOSN/A🟒
CS110-48FPDecember 2021N/A5 years after EOSN/A🟒
CS210-8FPDecember 2021N/A5 years after EOSN/A🟒
CS210-24FPJune 2022N/A5 years after EOSN/A🟒
CS210-48FPJune 2022N/A5 years after EOSN/A🟒
CS1010-8FPFebruary 2025Not listed in Retirement CalendarNot listed in Retirement CalendarNot listed in Retirement Calendar🟒

Common Mistakes in Lifecycle Planning

Only checking End-of-Life: Renewal may already be impossible before then. Therefore, check End-of-Sale, Last Renewal and EOL together.

Replacing the model 1:1: Port layout, performance or WLAN will not automatically fit. Reassess sizing, interfaces, PoE, SFP/SFP+, rackmount, RED sites and location requirements.

Looking for the backup only during replacement: Migration is delayed or restore fails. Check backup, Secure Storage Master Key and restore compatibility before replacement.

Forgetting RED or Access Points: Branch offices or WLAN may be affected after the firewall replacement. Document dependencies per site.

Not maintaining lifecycle data in the asset system: Surprises around budget, renewal and support arise when data only exists in a spreadsheet. Record serial number, EOL, Last Renewal and planned successor per asset.

Exceptions and Troubleshooting

If a model is missing, reconcile its spelling, revision, and product family with the label and serial number. β€œNot listed” means neither β€œcurrent” nor β€œsupported indefinitely”: record the unresolved result and query date, then obtain written confirmation of the deadline, Migration Path, and entitlement from the partner or Sophos Support before ordering. If the calendar, account, and table disagree, track hardware deadline, software support, and contract end separately and plan against the earliest date until resolved.

Stop the migration while interface mapping, firmware compatibility, license transfer, or restore warnings remain unresolved. Do not deregister the old appliance or overwrite the only backup. Reset or rebuild the target, document the discrepancy, and approve it again only after successfully testing the services listed under β€œVerification path.”

FAQ

What is the difference between End-of-Sale and End-of-Life?

End-of-Sale means a product is no longer regularly sold new. End-of-Life means regular support ends. In between, depending on the product, renewal or support options may still be available.

Why is Last Renewal important for Sophos Firewalls?

Last Renewal is often the practical deadline for budget and operations. If this date is missed, support can no longer be normally extended, even if the End-of-Life date is later.

Should an XG Firewall still be renewed?

For productive environments, migrating to XGS Appliances or a suitable virtual or cloud firewall is usually more sensible. Before deciding, firmware support, performance, license duration, backup, RED, VPN and site dependencies should be checked.

Is a successor model from the table sufficient for planning?

No. The table is a starting point. Before ordering, throughput, security features, number of users, VPN, TLS inspection, ports, SFP/SFP+, PoE, HA and site design should be checked.

Where should lifecycle data be documented?

Lifecycle data belong in the asset or operational documentation system. At minimum, serial number, model, location, license status, Last Renewal, End-of-Life, backup status and planned successor should be maintained.