The short version
- For the Catalyst 3650, end of vulnerability/security support and the last date of support fall on 31 October 2026. Service contracts could only be renewed until 29 January 2026; Cisco maps each model to a Catalyst 9300L successor.
- For the Catalyst 2960-X and 2960-XR the date is 31 October 2027. The last date to renew a service contract is 29 January 2027; Cisco's successors come from the C9200L and the C9200 respectively.
- The critical IOS XE advisory of 5 August 2026 (CVSS 9.8) did not evaluate the Catalyst 3650 and 3850 because they run none of the affected software trains. An old platform can drop out of the security view before its last date of support.
- For the Catalyst 9200 and 9300, Cisco currently recommends IOS XE 17.18.4 or 17.15.6. From 26.1.1, a device without a startup configuration is designed to reject commands classed as insecure — review old configurations before carrying them over.
The Catalyst 3650 could last be ordered on 31 October 2021, the 2960-X on 31 October 2022. Now their support end dates are arriving. Four questions decide the migration: which date binds first, what it means, which successor fits, and which software and configuration the new switch starts with.
The dates at a glance
Cisco publishes an end-of-life bulletin with fixed milestones for every product family. For the 3650, the 2960-X, the 2960-XR and the 3850, these are the dates:
| Series | Last contract renewal | Security support and support until | Successor per bulletin |
|---|---|---|---|
| Catalyst 3650 | 29 January 2026 (passed) | 31 October 2026 | Catalyst 9300L |
| Catalyst 2960-X | 29 January 2027 | 31 October 2027 | Catalyst 9200L |
| Catalyst 2960-XR | 29 January 2027 | 31 October 2027 | Catalyst 9200 |
| Catalyst 3850 (copper models) | 28 January 2025 (passed) | 31 October 2025 (passed) | Catalyst 9300 |
| Catalyst 3850 (fibre models) | 29 July 2026 (passed) | 30 April 2027 | Catalyst 9300, partly 9300X or 9500 |
For all five, the end of security support and the last date of support fall on the same day. Bug fixes ended some time ago: software maintenance releases stopped on 31 October 2022 for the 3650 and on 31 October 2023 for the 2960-X and 2960-XR. Since then Cisco can only release fixes for security vulnerabilities, and those end on the dates in the table. The 3850 copper models are already past their last date of support; the fibre models follow on 30 April 2027.
What the milestones mean
Each bulletin defines its milestones. Four drive the planning; the definitions are quoted from the bulletins:
- End of SW Maintenance Releases: “The last date that Cisco Engineering may release any final software maintenance releases or bug fixes.” After that date, Cisco Engineering no longer develops, repairs, maintains or tests the product software.
- End of Vulnerability/Security Support: “The last date that Cisco Engineering may release a planned maintenance release or scheduled software remedy for a security vulnerability issue.”
- End of Service Contract Renewal: “The last date to extend or renew a service contract for the product.” Equipment without a contract could only be added until the earlier milestone, End of New Service Attachment — for the 2960-X, 31 October 2023.
- Last Date of Support: the last date to receive service and support under active service contracts or warranty terms. “After this date, all support services for the product are unavailable, and the product becomes obsolete.”
The security date is an upper bound
On 5 August 2026 Cisco published the advisory “Cisco IOS XE Software Security Hardening Release: August 2026”: seven vulnerabilities (CVE-2026-20267 to CVE-2026-20273), rated critical with a CVSS base score of 9.8, no workarounds. They were found in internal testing; Cisco's PSIRT is not aware of any public announcement or malicious use. IOS XE is affected in autonomous and controller mode regardless of device configuration, with fixes in 17.9.10, 17.12.8, 17.15.6, 17.18.4 and 26.1.2.
One sentence matters for planning: “Cisco Catalyst 3650 and 3850 Series Switches do not run any of these releases and therefore were not evaluated as part of this review.” The 3650 still had almost three months of security support left at that point. Whether the vulnerabilities affect its code, the advisory does not say — it did not examine it.
Our rule from this: finish the migration before security support ends, do not start it on that day. For the 3650 that makes the replacement due; for the 2960-X, now is the time to plan it.
Successors: Cisco's mapping or the C9350
Every bulletin maps each old model to a successor: from the Catalyst 9300L for the 3650, the 9200L for the 2960-X and the 9200 for the 2960-XR. A few rows, with the bulletins' descriptions:
| Old model | Successor per bulletin |
|---|---|
| WS-C3650-24PS-L | C9300L-24P-4G-E (24 ports PoE, Network Essentials, 4 × 1G uplink) |
| WS-C3650-24PS-S | C9300L-24P-4G-A (24 ports PoE, Network Advantage, 4 × 1G uplink) |
| WS-C2960X-48FPD-L | C9200L-48P-4X (48 ports PoE+, SFP+) |
| C2960X-STACK (stack module) | C9200L-STACK-KIT (9200L stack module) |
| WS-C2960XR-24PD-I (PoE 370 W, 2 × 10G SFP+) | C9200-24P (24 ports PoE+) |
| WS-C2960XR-24PS-I (PoE 370 W, 4 × 1G SFP) | C9200-24P (24 ports PoE+) |
| WS-C2960XR-48FPD-I (PoE 740 W, 2 × 10G SFP+) | C9200-48P (48 ports PoE+) |
Three things stand out. The mapping sets the successor's licence tier: WS-C3650-24PS-L becomes a 9300L with Network Essentials, WS-C3650-24PS-S one with Network Advantage. It covers the 2960-X stack module too. And it does not replace planning: two 2960-XR models with different uplinks get the same successor, and the 740-watt variant maps to one whose description states no wattage.
Cisco also names a second route. Its smart switches FAQ describes the C9350 as an upgrade path for end-of-sale Catalyst 3850 models and selected Catalyst 9300 models such as the 1G variants; its table of portfolio transitions also lists the 3650. The 2960-X does not appear in the FAQ. The C9350 requires a Cisco Networking Subscription with a mandatory three-year term, or at least 18 months when added to an existing one. Our article on C9350 licensing explains what that means for rights, support and procurement.
All five bulletins also point to the Cisco Technology Migration Program (TMP), through which customers may be able to trade in eligible products for credit toward new Cisco equipment where applicable.
Which software belongs on the new switches
With IOS XE 26, Cisco changed its version scheme. The first number stands for the calendar year, so 26 means 2026. From 26.1.1 there are two releases per year at intervals of about six months. Unless otherwise noted, each one is an Extended Support release with a sustaining support lifetime of 48 months from general availability.
For operation today, Cisco's recommended-releases page for the Catalyst 9200 to 9600 counts. As of 4 September 2026 it lists 17.18.4 and 17.15.6 for every model line, and no 26 release yet. Both are the first fixed releases of their trains in the August advisory; for the C9350 the page refers to a separate recommendation. Choosing a train against its support end dates is covered in our article on IOS XE release strategy.
The second change concerns configuration. From 17.18.2, many features classed as insecure are designed to warn when configured; from 26.1.1, restrictions apply. A device initialised without a startup configuration is designed to reject such commands. Only “system mode insecure” permits them, and the warnings remain. A device upgraded to such a release with insecure configuration enables that mode automatically to prevent outages, and returns to the hardened state only once all insecure entries are removed. From 26.1.1, “show system insecure configuration” lists them.
The migration order
The dates call for a sequence of wiring closets, not a single cut-off project. We recommend this order:
Inventory from the network
Read models, serial numbers, software versions, stack membership and contract status from the devices, not the asset list. That shows which deadline actually applies.
Stack mapping
Plan each stack as a unit — members, stack modules, member order, uplink distribution — and replace it as a whole.
Uplinks and optics
Which uplinks are in use, with which transceivers, towards which distribution layer? The mapping does not answer that; check transceiver support per optic, not by model number.
PoE budget
Measure the simultaneous load — phones, access points, cameras — against the successor's budget with the planned power supply. A 740-watt model mapped to one without a wattage is an open question, not an answer.
802.1X and MAB
Rebuild and test on the successor whatever acts on the port today: authentication, 802.1X and MAB order, behaviour when RADIUS fails, voice VLAN. The basics are in our article on 802.1X on wired ports.
Configuration translation and review
Translate the old configuration for the new platform, check it against the list of insecure features and load it onto a test device first.
Cutover per wiring closet
One closet per maintenance window, with a patch plan, a prepared configuration and a defined way back to the old device.
Acceptance with real traffic
A closet counts as migrated when real applications from the affected networks work: port authentication, telephony, wireless through the access points, printing. Link status and ping are diagnostics, not acceptance.
The contract question runs in parallel: every closet with 2960-X or 2960-XR switches still in service on 29 January 2027 needs a renewal decision before that day, because renewal is no longer possible afterwards. For the 3650 that deadline has passed; only replacement remains.
Our page on campus LAN and switching describes how we design and build access layers; migration and network operations covers cutovers with a plan and a handover. To check your 2960-X and 3650 installed base against these dates, talk to us about your switch migration.
Sources
Every evidenced claim in this article can be traced here. The retrieval date shows how fresh the check is.
- End-of-Sale and End-of-Life Announcement for the Cisco Catalyst 3650opens in a new tab
Cisco · 2026-05-26 · retrieved 25 September 2026
- End-of-Sale and End-of-Life Announcement for the Cisco Catalyst 2960X Product Familyopens in a new tab
Cisco · 2022-11-26 · retrieved 25 September 2026
- End-of-Sale and End-of-Life Announcement for the Cisco Catalyst 2960XR Product Family EOSopens in a new tab
Cisco · 2025-07-31 · retrieved 25 September 2026
- End-of-Sale and End-of-Life Announcement for the Cisco Catalyst 3850 switchesopens in a new tab
Cisco · 2022-11-11 · retrieved 25 September 2026
- End-of-Sale and End-of-Life Announcement for the Cisco C3850 Fiber SKUsopens in a new tab
Cisco · 2022-11-10 · retrieved 25 September 2026
- Cisco IOS XE Software Security Hardening Release: August 2026opens in a new tab
Cisco Security Advisory · 2026-08-05 · retrieved 25 September 2026
- Software Lifecycle Support Statement - IOS XEopens in a new tab
Cisco · 2026-04-10 · retrieved 25 September 2026
- Recommended Releases for Catalyst 9200/9300/9400/9500/9600 Platformsopens in a new tab
Cisco · 2026-09-04 · retrieved 25 September 2026
- Insecure Feature Restrictions on IOS XEopens in a new tab
Cisco · 2026-07-30 · retrieved 25 September 2026
- Cisco C9000 Smart Switching Platform FAQopens in a new tab
Cisco · 2026-09-21 · retrieved 25 September 2026

