Skip to content
CONFIGLANE

Lifecycle · Upgrade

Catalyst Center 2.3.7: maintenance ends in December, and the road to 3.x runs one way

Software maintenance for Catalyst Center 2.3.7 ends on 17 December 2026. Planning now means deciding on version, hardware and data flows at once — in a direction from which Cisco provides no way back.

By ConfiglanePublished 10 min readCisco Catalyst Center

The short version

  • Cisco lists 17 December 2026 as the end of software maintenance for Catalyst Center 2.3.7.x and 17 June 2027 as its last date of support; every older release in the table is already past its last date of support.
  • The upgrade from 2.3.7.x to 3.1.6 moves to a new architecture through a separate platform upgrade workflow, and according to Cisco there is no switching back to an earlier release afterwards.
  • The DN3 appliance can only be ordered until 31 December 2026; its successor DN4 requires Catalyst Center 3.3.1 or newer, which Cisco currently offers as a controlled availability release.
  • The AI Assistant requires registration with Cisco Catalyst Cloud, and according to Cisco the data is primarily processed and stored in the United States — a case for a data protection assessment before it is switched on.

A running Catalyst Center installation does not announce its end of support. The date sits in a Cisco table, and this time the answer is more than a patch: 3.x changes the architecture, touches the hardware question and brings features that can send data to Cisco cloud services.

What 17 December means

Cisco's guideline for Catalyst Center releases sets two end dates. After the end of software maintenance, a release gets no more maintenance releases or bug fixes and is no longer developed, repaired or tested. After the last date of support, all support services for it are unavailable. As a rule, the first date falls twelve months after release, the second 24 months.

ReleaseEnd of software maintenanceLast date of support
2.3.7.x17 December 202617 June 2027
2.3.6.x6 April 2024 (ended)6 April 2025 (ended)
2.3.5.x24 December 2024 (ended)24 December 2025 (ended)
Catalyst Center release end dates according to Cisco

The table goes back to 2.1.2.x; every release before 2.3.7 is past its last date of support too. What counts is the date in the table, not a period you work out yourself. For 3.x it has no entries yet (as of 16 March 2026), so settle the end of maintenance for your target release with Cisco or your partner before choosing it.

The road to 3.x runs one way

Cisco's upgrade guide records three things about the step from 2.3.7.x to 3.1.6: 3.1.6 is based on a new architecture, getting there requires the platform upgrade workflow, and afterwards you cannot switch back to an earlier release.

The guide also lists the permitted starting points: specific builds from the 2.3.7.7, 2.3.7.9, 2.3.7.10 and 2.3.7.11 patch lines. Anyone on another level patches within 2.3.7 first — and checks the build number against the list, not just the version.

So the target is not automatically the newest release. According to Cisco, the 3.x releases stand at different points:

  • 3.1.6 is the target of the step from 2.3.7.x in the upgrade guide.
  • 3.2.3 is generally available per its release notes, currently as maintenance update 3.2.3-75346.100.
  • 3.3.1 is a controlled availability release per its release notes; access is by request through Cisco sales.

For 3.2.3 or 3.3.1, both release notes refer to Cisco's upgrade guide; we plan every intermediate step against it.

Hardware or virtual: the appliance has a say

The second decision concerns the platform underneath. The three appliance generations have dates years apart.

ApplianceOrderable untilLast date of supportSoftware per Cisco
DN2 (2nd generation)30 March 2024 (ended)31 March 2029listed in the 3.2.3 and 3.3.1 release notes
DN3 (3rd generation)31 December 202631 December 2031likewise; migration product per the notice: DN4
DN4 (4th generation)——requires 3.3.1 or newer
Catalyst Center appliances: dates according to Cisco

For 3.2.3 and 3.3.1, the software does not force a hardware swap. The hardware clocks run regardless: per the notice, DN2 service contracts can only be renewed until 25 June 2028. Cisco announced the end of life of DN3 on 2 July 2026, with a last ship date of 31 March 2027, and names DN4-HW-APL, DN4-HW-APL-L and DN4-HW-APL-XL as migration products. Per the DN4 data sheet, these require Catalyst Center 3.3.1 or newer — which Cisco currently offers only as controlled availability.

The third option is the virtual appliance, where the documentation differs by release:

  • 3.1.6: per the data sheet VMware ESXi (vSphere 7.0.x or later), AWS and Microsoft Azure; for ESXi it lists 32 vCPUs, 256 GB RAM, 3 TB storage and 180 MB/s I/O bandwidth.
  • 3.2.3: per the release notes only VMware ESXi and Ubuntu KVM, both on-premises.
  • 3.3.1: per the release notes VMware ESXi on-premises and KVM (Ubuntu Native).

If you run in AWS or Azure, or plan to, check first that your target release is supported there. Moving from an appliance to a virtual instance is not an upgrade but a new platform design.

What 3.x brings, according to Cisco

Whether an upgrade is more than a met deadline depends on the features you use. The 3.1.6 data sheet and the 3.3.1 release notes name, among others:

  • AI-driven baselining: a baseline of your network's performance parameters that adapts continuously and enables the AI analytics.
  • AI-driven anomaly detection: detect performance issues, ignore harmless anomalies, reduce noise.
  • ThousandEyes agents: deployed to all supported switches directly from Catalyst Center, for visibility into application performance.
  • SWIM: central management of images, patches and maintenance updates; validated images as the standard per device family, role or tag — usually called the golden image.
  • Plug and Play: off-the-shelf Cisco devices are provisioned simply by connecting them to the network (zero-touch deployment).
  • Live Protect: new in 3.3.1 per the release notes; validates security shields that protect Cisco products without reloads or service interruptions.

The data sheet does not separate new from existing features; what is new for you only shows against what runs today. We recommend measuring each feature against an operational question: which current problem does it solve, and does it need licences, a cloud connection or a release you lack? Live Protect only arrives with 3.3.1.

How we bring Assurance into operations is covered under Assurance and troubleshooting; which IOS XE release makes a sound standard image, in the piece on IOS XE release strategy.

The AI Assistant: assess first, then switch on

The 3.1.6 data sheet presents the Cisco AI Assistant as a way to ask questions, analyse issues and take action across the network. Two points in Cisco's description of it matter before switching it on.

First, it requires registration with Cisco Catalyst Cloud, in the system settings under External Services, with a cisco.com account. Second, according to Cisco, customer content and customer systems information associated with the use of Catalyst Center are “primarily processed and stored in the United States, regardless of your physical location” — both the prompts and the deployment data the assistant analyses.

Per Cisco, this data is not used for training. The assistant is available for all licence tiers, but its functions follow the tiers of the features it uses.

The upgrade plan: maintenance tasks before, during and after the move

These points add up to a sequence that also answers which maintenance tasks a move to Catalyst Center 3.x involves.

  1. Take stock

    Release and build number, appliance or virtual platform, single node or three-node cluster, features in use, integrations and API consumers — read from the platform, not the project documents.

  2. Define the target

    Decide target release, platform and cloud features together, justified against the guideline and end-of-life dates.

  3. Reach a valid starting point

    If the installation is not on a listed build, patch within 2.3.7 first — as a change with its own acceptance.

  4. Back up and precheck

    A complete backup with a tested restore; work through the upgrade guide's prerequisites and procedure for exactly this path. The backup protects data; Cisco provides no way back to 2.3.7.

  5. Test

    Rehearse the path where a failure costs nothing, and practise the acceptance checks at the same time.

  6. Window and acceptance

    With a buffer, a go/no-go decision before the start and reachable owners for ISE, ITSM and automation. Accept operations, not the version string.

  • Assurance: health data for known devices and clients is current; a known fault shows up as expected.
  • Provisioning: a test device runs through Plug and Play to its approved configuration.
  • SWIM: an image distribution to a pilot device completes; standard images are still set.
  • Integrations: ISE, ITSM tickets and event subscriptions work; scripts and pipelines run against the new release.

The piece on the Catalyst Center API covers which interfaces typically hang off the platform. Three tasks stay: maintaining patch levels, tracking software and appliance dates, and planning the next move before maintenance ends.

How we plan platform upgrades and software levels is described under SWIM and lifecycle; a move to new hardware or a virtual instance belongs under deployment and platform design. If you need a sound decision before 17 December, discuss your Catalyst Center upgrade with us.

Sources

Every evidenced claim in this article can be traced here. The retrieval date shows how fresh the check is.

  1. Release Notes for Cisco Catalyst Center, Release 3.3.1opens in a new tab

    Cisco · 2026-09-09 · retrieved 25 September 2026

  2. Release Notes for Cisco Catalyst Center, Release 3.2.3opens in a new tab

    Cisco · 2026-09-21 · retrieved 25 September 2026

  3. Cisco Catalyst Center DN4 Data Sheetopens in a new tab

    Cisco · 2026-08-27 · retrieved 25 September 2026

  4. Cisco Catalyst Center 3.1.6 Data Sheetopens in a new tab

    Cisco · 2026-09-01 · retrieved 25 September 2026

  5. Cisco Catalyst Center AI Assistantopens in a new tab

    Cisco · 2026-05-14 · retrieved 25 September 2026

FAQ

Frequently asked questions about the Catalyst Center upgrade

When does Catalyst Center 2.3.7 reach end of life?

Software maintenance for 2.3.7.x ends on 17 December 2026 and the last date of support is 17 June 2027, per Cisco's end-of-life guideline. After the first date there are no more bug fixes, after the second no support. Every older release in the table is already past its last date of support.

Can I roll back from Catalyst Center 3.1.6 to 2.3.7?

No. Per Cisco's upgrade guide, you cannot switch back to an earlier release after upgrading to 3.1.6, which is based on a new architecture and reached through a separate platform upgrade workflow. Backup, prechecks, testing and acceptance criteria therefore belong before the maintenance window.

What maintenance tasks do I need to consider when switching to Catalyst Center 3.x?

Before the move: record build number, appliance and integrations, patch to a listed 2.3.7 starting point, take a backup with a tested restore and rehearse the path. In the window: the platform upgrade per the guide. Afterwards: accept Assurance, Plug and Play, SWIM and the ISE, ITSM and API integrations. Permanently: patching, support dates and the appliance lifecycle.

Do we need new hardware for Catalyst Center 3.x?

Not necessarily. The 3.2.3 and 3.3.1 release notes list DN2 and DN3 appliances as supported hardware. The hardware dates run separately: DN2's last date of support is 31 March 2029, DN3 is orderable until 31 December 2026 and supported until 31 December 2031, and DN4 requires Catalyst Center 3.3.1 or newer.

What does Catalyst Center 3.x bring for Assurance, SWIM and Plug and Play?

The 3.1.6 data sheet names AI-driven baselining and anomaly detection plus ThousandEyes agents deployable to supported switches directly from Catalyst Center. SWIM designates validated images as the standard per device family, role or tag; Plug and Play provisions devices once they are connected to the network. What is new for you only shows against what runs today.

What should we check before enabling the Catalyst Center AI Assistant?

Above all, where the data goes. The assistant requires registration with Cisco Catalyst Cloud, and per Cisco, customer content and customer systems information are primarily processed and stored in the United States, regardless of your location. We recommend having data protection and, where relevant, the works council assess activation beforehand — as a decision separate from the upgrade.

Cisco Catalyst Center

SWIM & lifecycle. Software maintenance needs more than a date.

We organise software maintenance for the managed device estate and the Catalyst Center platform. Target versions, prerequisites, sequence and acceptance are agreed before the maintenance window.

Plan lifecycle and SWIM

Assessment → first dependable change