Skip to content
CONFIGLANE

Lifecycle · Migration

Catalyst 2960-X and 3650 end of life: dates, successors and a migration plan

Support for the Catalyst 3650 ends on 31 October 2026 and for the 2960-X a year later — and a 2960-X service contract can only be renewed until 29 January 2027. Planning now means replacing one wiring closet at a time rather than under deadline pressure.

By ConfiglanePublished 11 min readEnterprise Networks

The short version

  • For the Catalyst 3650, end of vulnerability/security support and the last date of support fall on 31 October 2026. Service contracts could only be renewed until 29 January 2026; Cisco maps each model to a Catalyst 9300L successor.
  • For the Catalyst 2960-X and 2960-XR the date is 31 October 2027. The last date to renew a service contract is 29 January 2027; Cisco's successors come from the C9200L and the C9200 respectively.
  • The critical IOS XE advisory of 5 August 2026 (CVSS 9.8) did not evaluate the Catalyst 3650 and 3850 because they run none of the affected software trains. An old platform can drop out of the security view before its last date of support.
  • For the Catalyst 9200 and 9300, Cisco currently recommends IOS XE 17.18.4 or 17.15.6. From 26.1.1, a device without a startup configuration is designed to reject commands classed as insecure — review old configurations before carrying them over.

The Catalyst 3650 could last be ordered on 31 October 2021, the 2960-X on 31 October 2022. Now their support end dates are arriving. Four questions decide the migration: which date binds first, what it means, which successor fits, and which software and configuration the new switch starts with.

The dates at a glance

Cisco publishes an end-of-life bulletin with fixed milestones for every product family. For the 3650, the 2960-X, the 2960-XR and the 3850, these are the dates:

SeriesLast contract renewalSecurity support and support untilSuccessor per bulletin
Catalyst 365029 January 2026 (passed)31 October 2026Catalyst 9300L
Catalyst 2960-X29 January 202731 October 2027Catalyst 9200L
Catalyst 2960-XR29 January 202731 October 2027Catalyst 9200
Catalyst 3850 (copper models)28 January 2025 (passed)31 October 2025 (passed)Catalyst 9300
Catalyst 3850 (fibre models)29 July 2026 (passed)30 April 2027Catalyst 9300, partly 9300X or 9500
Support end dates according to Cisco's end-of-life bulletins

For all five, the end of security support and the last date of support fall on the same day. Bug fixes ended some time ago: software maintenance releases stopped on 31 October 2022 for the 3650 and on 31 October 2023 for the 2960-X and 2960-XR. Since then Cisco can only release fixes for security vulnerabilities, and those end on the dates in the table. The 3850 copper models are already past their last date of support; the fibre models follow on 30 April 2027.

What the milestones mean

Each bulletin defines its milestones. Four drive the planning; the definitions are quoted from the bulletins:

  • End of SW Maintenance Releases: “The last date that Cisco Engineering may release any final software maintenance releases or bug fixes.” After that date, Cisco Engineering no longer develops, repairs, maintains or tests the product software.
  • End of Vulnerability/Security Support: “The last date that Cisco Engineering may release a planned maintenance release or scheduled software remedy for a security vulnerability issue.”
  • End of Service Contract Renewal: “The last date to extend or renew a service contract for the product.” Equipment without a contract could only be added until the earlier milestone, End of New Service Attachment — for the 2960-X, 31 October 2023.
  • Last Date of Support: the last date to receive service and support under active service contracts or warranty terms. “After this date, all support services for the product are unavailable, and the product becomes obsolete.”

The security date is an upper bound

On 5 August 2026 Cisco published the advisory “Cisco IOS XE Software Security Hardening Release: August 2026”: seven vulnerabilities (CVE-2026-20267 to CVE-2026-20273), rated critical with a CVSS base score of 9.8, no workarounds. They were found in internal testing; Cisco's PSIRT is not aware of any public announcement or malicious use. IOS XE is affected in autonomous and controller mode regardless of device configuration, with fixes in 17.9.10, 17.12.8, 17.15.6, 17.18.4 and 26.1.2.

One sentence matters for planning: “Cisco Catalyst 3650 and 3850 Series Switches do not run any of these releases and therefore were not evaluated as part of this review.” The 3650 still had almost three months of security support left at that point. Whether the vulnerabilities affect its code, the advisory does not say — it did not examine it.

Our rule from this: finish the migration before security support ends, do not start it on that day. For the 3650 that makes the replacement due; for the 2960-X, now is the time to plan it.

Successors: Cisco's mapping or the C9350

Every bulletin maps each old model to a successor: from the Catalyst 9300L for the 3650, the 9200L for the 2960-X and the 9200 for the 2960-XR. A few rows, with the bulletins' descriptions:

Old modelSuccessor per bulletin
WS-C3650-24PS-LC9300L-24P-4G-E (24 ports PoE, Network Essentials, 4 × 1G uplink)
WS-C3650-24PS-SC9300L-24P-4G-A (24 ports PoE, Network Advantage, 4 × 1G uplink)
WS-C2960X-48FPD-LC9200L-48P-4X (48 ports PoE+, SFP+)
C2960X-STACK (stack module)C9200L-STACK-KIT (9200L stack module)
WS-C2960XR-24PD-I (PoE 370 W, 2 × 10G SFP+)C9200-24P (24 ports PoE+)
WS-C2960XR-24PS-I (PoE 370 W, 4 × 1G SFP)C9200-24P (24 ports PoE+)
WS-C2960XR-48FPD-I (PoE 740 W, 2 × 10G SFP+)C9200-48P (48 ports PoE+)
Excerpt from Cisco's migration tables

Three things stand out. The mapping sets the successor's licence tier: WS-C3650-24PS-L becomes a 9300L with Network Essentials, WS-C3650-24PS-S one with Network Advantage. It covers the 2960-X stack module too. And it does not replace planning: two 2960-XR models with different uplinks get the same successor, and the 740-watt variant maps to one whose description states no wattage.

Cisco also names a second route. Its smart switches FAQ describes the C9350 as an upgrade path for end-of-sale Catalyst 3850 models and selected Catalyst 9300 models such as the 1G variants; its table of portfolio transitions also lists the 3650. The 2960-X does not appear in the FAQ. The C9350 requires a Cisco Networking Subscription with a mandatory three-year term, or at least 18 months when added to an existing one. Our article on C9350 licensing explains what that means for rights, support and procurement.

All five bulletins also point to the Cisco Technology Migration Program (TMP), through which customers may be able to trade in eligible products for credit toward new Cisco equipment where applicable.

Which software belongs on the new switches

With IOS XE 26, Cisco changed its version scheme. The first number stands for the calendar year, so 26 means 2026. From 26.1.1 there are two releases per year at intervals of about six months. Unless otherwise noted, each one is an Extended Support release with a sustaining support lifetime of 48 months from general availability.

For operation today, Cisco's recommended-releases page for the Catalyst 9200 to 9600 counts. As of 4 September 2026 it lists 17.18.4 and 17.15.6 for every model line, and no 26 release yet. Both are the first fixed releases of their trains in the August advisory; for the C9350 the page refers to a separate recommendation. Choosing a train against its support end dates is covered in our article on IOS XE release strategy.

The second change concerns configuration. From 17.18.2, many features classed as insecure are designed to warn when configured; from 26.1.1, restrictions apply. A device initialised without a startup configuration is designed to reject such commands. Only “system mode insecure” permits them, and the warnings remain. A device upgraded to such a release with insecure configuration enables that mode automatically to prevent outages, and returns to the hardened state only once all insecure entries are removed. From 26.1.1, “show system insecure configuration” lists them.

The migration order

The dates call for a sequence of wiring closets, not a single cut-off project. We recommend this order:

  1. Inventory from the network

    Read models, serial numbers, software versions, stack membership and contract status from the devices, not the asset list. That shows which deadline actually applies.

  2. Stack mapping

    Plan each stack as a unit — members, stack modules, member order, uplink distribution — and replace it as a whole.

  3. Uplinks and optics

    Which uplinks are in use, with which transceivers, towards which distribution layer? The mapping does not answer that; check transceiver support per optic, not by model number.

  4. PoE budget

    Measure the simultaneous load — phones, access points, cameras — against the successor's budget with the planned power supply. A 740-watt model mapped to one without a wattage is an open question, not an answer.

  5. 802.1X and MAB

    Rebuild and test on the successor whatever acts on the port today: authentication, 802.1X and MAB order, behaviour when RADIUS fails, voice VLAN. The basics are in our article on 802.1X on wired ports.

  6. Configuration translation and review

    Translate the old configuration for the new platform, check it against the list of insecure features and load it onto a test device first.

  7. Cutover per wiring closet

    One closet per maintenance window, with a patch plan, a prepared configuration and a defined way back to the old device.

  8. Acceptance with real traffic

    A closet counts as migrated when real applications from the affected networks work: port authentication, telephony, wireless through the access points, printing. Link status and ping are diagnostics, not acceptance.

The contract question runs in parallel: every closet with 2960-X or 2960-XR switches still in service on 29 January 2027 needs a renewal decision before that day, because renewal is no longer possible afterwards. For the 3650 that deadline has passed; only replacement remains.

Our page on campus LAN and switching describes how we design and build access layers; migration and network operations covers cutovers with a plan and a handover. To check your 2960-X and 3650 installed base against these dates, talk to us about your switch migration.

Sources

Every evidenced claim in this article can be traced here. The retrieval date shows how fresh the check is.

  1. Cisco IOS XE Software Security Hardening Release: August 2026opens in a new tab

    Cisco Security Advisory · 2026-08-05 · retrieved 25 September 2026

  2. Software Lifecycle Support Statement - IOS XEopens in a new tab

    Cisco · 2026-04-10 · retrieved 25 September 2026

  3. Insecure Feature Restrictions on IOS XEopens in a new tab

    Cisco · 2026-07-30 · retrieved 25 September 2026

  4. Cisco C9000 Smart Switching Platform FAQopens in a new tab

    Cisco · 2026-09-21 · retrieved 25 September 2026

FAQ

Frequently asked questions about the end of the 2960-X and 3650

When does support for the Catalyst 2960-X end?

On 31 October 2027: according to Cisco's bulletin, end of vulnerability/security support and the last date of support both fall on that day, as they do for the 2960-XR. Service contracts can only be renewed until 29 January 2027; software maintenance releases ended on 31 October 2023.

What is the successor to the Catalyst 2960-X?

The Catalyst 9200L, according to Cisco's bulletin; for the 2960-XR it is the Catalyst 9200. The bulletin maps each model, for example WS-C2960X-48FPD-L to C9200L-48P-4X and the C2960X-STACK stack module to C9200L-STACK-KIT. Still check uplinks and PoE budget against the actual load, because the mapping does not fully reflect them.

When does support for the Catalyst 3650 end?

On 31 October 2026, when end of vulnerability/security support and the last date of support coincide; after that, according to Cisco, all support services for the product are unavailable. Service contracts could only be renewed until 29 January 2026. The successors per bulletin are Catalyst 9300L models.

Can a 3650 keep running after 31 October 2026?

Technically yes: the bulletin describes the end of services, not a shutdown. But after that date there are neither security fixes nor support services, and the critical IOS XE advisory of August 2026 already left the 3650 unevaluated. We advise against pushing the replacement past that date.

Is the C9350 also a successor to the 2960-X?

Cisco does not name it as one. Its smart switches FAQ describes the C9350 as an upgrade path for the 3850 and selected 9300 models and also lists the 3650; the 2960-X does not appear there. For the 2960-X, the documented route is the C9200L from the bulletin.

Enterprise Networks

Campus LAN. From the access port to a dependable core.

A campus network works well when users, applications and operators do not have to think about its transitions. We design Cisco LANs from access to core, renew evolved estates and make resilience and acceptance testable.

Discuss your campus LAN

Assessment → first dependable change