Cisco uses four milestones for Umbrella and they are not interchangeable. End of Sale stops new purchases while everything you already run keeps working. End of Software Maintenance freezes the codebase, so no more patches. End of Service Contract Renewal closes extensions and seat additions. Last Day of Support terminates the tenant. For current Umbrella DNS and SIG packages those dates are 31 January 2027, 31 January 2027, 31 January 2028 and 31 January 2029.
Cisco’s own bulletin publishes all of that, and it ranks first for these queries, so a summary of it is worth nothing to you. What the bulletin does not say is what happens inside the product on each of those dates. That is the rest of this article, and one item on the list should change how you plan the exit: when an Umbrella subscription lapses, DNS does not stop. It fails open.
Why the distinction is a commercial problem before it is a technical one
Most procurement teams read an End of Sale notice as an instruction to move. It is not. Under Cisco’s End-of-Life Policy, a multi-year subscription signed before End of Sale is honoured for its full paid term, up to the Last Day of Support. An organisation that signs a three-year agreement for Umbrella SIG Essentials in December 2026 keeps full entitlements, TAC access and cloud inspection until that term ends, provided it ends on or before 31 January 2029. Cisco Commerce Workspace enforces this by restricting the selectable end date to the platform’s final support date.
The milestone that actually constrains you is the renewal date, and it differs sharply between the two Umbrella retirements. For current DNS and SIG packages, Cisco left a twelve-month buffer: End of Sale is 31 January 2027 but you can still renew and add seats until 31 January 2028. For the legacy tiers retired under bulletin EOL15688 — Insights, Platform, Professional, the standalone Roaming SKU, Branch for routers — End of Sale and End of Renewal were the same day, 30 September 2025. If you are on a legacy SKU, you already cannot add a seat. Hiring ten people means buying a different product.
The vocabulary, in Cisco’s terms and in plain ones
| Milestone | Cisco’s definition | What it means for you |
|---|---|---|
| End-of-Life Announcement | The date on which the end of sale and end-of-life milestones are communicated publicly | Nothing changes yet. Ordering, licensing, operations and support all continue normally. |
| End of Sale | The date after which the product is no longer offered for sale or available for order | Point-of-sale rejects new contracts for those part numbers. Your existing service is untouched: policies, dashboard, TAC, all normal. |
| Last Ship Date | The last date Cisco can be asked to ship or fulfil | For a cloud product this is tenant provisioning. After it, no new tenant instances are created. |
| End of Software Maintenance | The last date Cisco Engineering may release software maintenance releases or bug fixes | Code patches stop. For local components this is the risk date. For the cloud service, threat feeds carry on. |
| End of Vulnerability and Security Support | Security fixes provided for a specified duration from End of Sale | After this, Cisco has no contractual obligation to patch a CVE in the roaming client, virtual appliance or container components. |
| End of Routine Failure Analysis | The last date Cisco Engineering performs root-cause analysis on defective product | Written for hardware. For software it means TAC handles known configuration workflows, not deep crash triage. |
| End of New Service Attachment | The last date to order a new support contract or add software to one | An uncovered deployment can no longer buy TAC entitlement at all. |
| End of Service Contract Renewal | The last date to extend or renew an existing contract or subscription | No extensions, no seat additions, no co-termination under that part number. This is usually the date that forces the decision. |
| Last Day of Support | The last date to receive entitlements, service and support | Tenant deactivated, dashboard gone, TAC refuses cases, API calls fail. Unmigrated traffic fails open. |
Every Umbrella package and its dates
Last verified: September 2026.
| Package | Representative SKU | End of Sale | End of SW Maintenance | End of Renewal | Last Day of Support | Cisco replacement |
|---|---|---|---|---|---|---|
| Umbrella DNS Security Essentials | UMB-DNS-ESS-K9 | 31 Jan 2027 | 31 Jan 2027 | 31 Jan 2028 | 31 Jan 2029 | Secure Access DNS Essentials |
| Umbrella DNS Security Advantage | UMB-DNS-ADV-K9 | 31 Jan 2027 | 31 Jan 2027 | 31 Jan 2028 | 31 Jan 2029 | Secure Access DNS Advantage |
| Umbrella SIG Essentials | UMB-SIG-ESS-K9 | 31 Jan 2027 | 31 Jan 2027 | 31 Jan 2028 | 31 Jan 2029 | Secure Access Internet Access Essentials |
| Umbrella SIG Advantage | UMB-SIG-ADV | 31 Jan 2027 | 31 Jan 2027 | 31 Jan 2028 | 31 Jan 2029 | Secure Access Internet Access Advantage |
| Umbrella DNS Security for Education | E2SF-U-R-EDUCATION | 31 Jan 2027 | 31 Jan 2027 | 31 Jan 2028 | 31 Jan 2029 | Secure Access DNS EDU Essentials |
| Multi-Org console add-ons | E2SF-UA-MULTIORG | 31 Jan 2027 | 31 Jan 2027 | 31 Jan 2028 | 31 Jan 2029 | Secure Access Multi-Org entitlements |
| Umbrella Remote Browser Isolation | E2SF-U-RBI-ALL | 31 Jan 2027 | 31 Jan 2027 | 31 Jan 2028 | 31 Jan 2029 | Secure Access RBI Advanced |
| Umbrella Data Loss Prevention | E2SF-U-DLP | 31 Jan 2027 | 31 Jan 2027 | 31 Jan 2028 | 31 Jan 2029 | Secure Access Data Loss Prevention |
| Umbrella Investigate console and API | E2SF-U-INVA-API-L/M/S | 31 Jan 2027 | 31 Jan 2027 | 31 Jan 2028 | 31 Jan 2029 | Secure Access Investigate Console and API |
| Umbrella for Catalyst SD-WAN / DNA | SDWAN-UMB-ESS / ADV | 31 Jan 2027 | 31 Jan 2027 | 31 Jan 2028 | 31 Jan 2029 | No direct replacement listed |
| Umbrella Insights (legacy) | UMB-INSIGHTS-K9 | 30 Sep 2025 | 30 Sep 2026 | 30 Sep 2025 | 30 Sep 2030 | Umbrella DNS Security Advantage |
| Umbrella Platform (legacy) | UMB-PLATFORM-K9 | 30 Sep 2025 | 30 Sep 2026 | 30 Sep 2025 | 30 Sep 2030 | Umbrella DNS Security Advantage |
| Umbrella Professional (legacy) | UMB-PROFESSIONAL | 30 Sep 2025 | 30 Sep 2026 | 30 Sep 2025 | 30 Sep 2030 | Umbrella DNS Security Essentials |
| Umbrella Roaming (legacy SKU) | UMB-ROAM | 30 Sep 2025 | 30 Sep 2026 | 30 Sep 2025 | 30 Sep 2030 | Umbrella DNS Security Essentials |
| Umbrella Branch for routers | UMB-BRAN-4331 / 4431 / 1100 | 30 Sep 2025 | 30 Sep 2026 | 30 Sep 2025 | 30 Sep 2030 | Umbrella DNS Security Essentials |
| App Discovery for Professional | UMB-APP-DISC | 30 Sep 2025 | 30 Sep 2026 | 30 Sep 2025 | 30 Sep 2030 | No replacement available |
| L3/L4 Cloud Firewall add-on | UMB-L3L4-CDFW | 30 Sep 2025 | 30 Sep 2026 | 30 Sep 2025 | 30 Sep 2030 | No replacement available |
| Umbrella Roaming Client (agent) | UMB-ROAM-CLIENT | 2 Apr 2025 | 2 Apr 2025 | 2 Apr 2025 | 2 Apr 2025 | Cisco Secure Client, Umbrella module |
| Reserved IP add-on | UMB-RESERVED-IP | 3 Jan 2025 | Not published | 3 Jan 2025 | 31 Jan 2028 | Direct cloud egress / Secure Access |
| Umbrella Virtual Appliance below v3.4.5 | Software build | 31 May 2024 | 31 May 2024 | Not applicable | 31 May 2024 | Upgrade to VA v3.4.5 or later |
Source: Cisco’s End-of-Sale and End-of-Life announcement for Umbrella SIG and DNS, and bulletin EOL15688 for the legacy offers. Three rows are worth reading twice. The Reserved IP add-on has no published End of Software Maintenance date — that cell is blank in Cisco’s notice, and it was still blank when we checked in September 2026, so treat it as unknown rather than as “not applicable”. And three products have no replacement at all: App Discovery, the L3/L4 Cloud Firewall add-on, and Umbrella for Catalyst SD-WAN. If you rely on any of those, the migration is not a like-for-like swap, it is a redesign.
What actually stops working, milestone by milestone
| Capability | Active contract | After End of Sale | After End of SW Maintenance | After End of Renewal | After Last Day of Support |
|---|---|---|---|---|---|
| Buy new subscriptions | Yes | No | No | No | No |
| Renew or add seats | Yes | Yes, to 31 Jan 2028 (modern packages) | Yes, to 31 Jan 2028 | No | No |
| Security patches and bug fixes | Yes | Yes | No. No CVE fixes compiled. | No | No |
| Talos threat intelligence feeds | Yes | Yes | Yes — feeds continue to the resolvers | Yes | No, tenant unlinked |
| Standalone Roaming Client | Supported | New registrations blocked since 2 Apr 2025 | Unmaintained | Installer removed from dashboard | Unsupported, fails open on TLS errors |
| Anycast DNS filtering | Enforced | Enforced | Enforced | Enforced | Fails open, downgrades to DNS Monitoring |
| Cloud proxy and SWG inspection | Active | Active | Active | Active | Tunnels purged after a 7-day grace period |
| Open a TAC case | Full 24/7 | Full 24/7 | Operational setup only | For remaining contract term | Blocked, entitlement void |
| Dashboard logs and export | Per licensed tier | Per licensed tier | Per licensed tier | Per licensed tier | Purged permanently after 30 days |
Two rows in that table matter more than the rest.
Talos keeps running after End of Software Maintenance. That milestone halts engineering work on the codebase — client releases, virtual appliance patches, bug fixes. It does not stop the cloud resolvers receiving threat intelligence. If your architecture is DNS filtering with no local components, End of Software Maintenance changes surprisingly little on the day it passes. Cisco has not published whether cloud-side machine learning, such as dynamic domain generation algorithm detection, continues to be tuned for deprecated subscriptions or is reserved for Secure Access. That is an unanswered question, not a known outcome, and it is worth asking your account team directly.
Expiry fails open, silently. When a subscription lapses, Cisco does not stop resolving DNS. The tenant is downgraded to an unmanaged DNS Monitoring tier. Names resolve, the internet works, nobody raises a ticket — and every filtering policy, malware block, botnet callback prevention and category restriction is switched off. Administrators in the field have reported discovering a lapse weeks later, when someone noticed the security telemetry had gone quiet. There is no outage to alert you. This is the single most important operational fact about an Umbrella contract end, and it is the reason to treat the renewal date as a hard calendar item rather than a procurement formality. The wider architectural version of this problem is in why traditional DNS is a blind spot in zero trust.
If you run SIG packages, there is a seven-day clock inside that. IPsec tunnels and cloud firewall rules are retained but inactive for seven days after expiry, passing traffic uninspected. On the eighth day the tunnel parameters and firewall configuration are permanently deleted from Cisco’s cloud. Recovering a policy set after that means rebuilding it.
What your account team will propose, and how to read it
Field reports from administrator communities and partner communications describe a consistent pattern during this window, and they are worth knowing before the meeting rather than during it. These are practitioner accounts rather than Cisco policy.
Single-year renewals on legacy Umbrella SKUs are discouraged, and discounting on them has tightened, which narrows the gap between extending and moving to Secure Access. Accounts migrating from Umbrella DNS to Secure Access DNS Defense are reported to receive 100 promotional Secure Private Access licences for the subscription term, which introduces ZTNA into the estate alongside the DNS renewal. And there is steady pressure towards Enterprise Agreement 3.0 frameworks that consolidate subscriptions.
None of that is improper, and the promotional seats may be genuinely useful. It is worth being clear with yourself about which decision you are making: whether to keep DNS filtering with the same vendor, or whether to adopt a broader security service edge platform. Those are different decisions with different timelines, and a renewal conversation tends to merge them.
Export your logs before the last day, not after
This is the part almost every migration plan omits, and in a regulated environment it is the part that creates liability.
Umbrella’s retention is tighter than most teams assume. Interactive Activity Search and Security Activity are capped at a rolling 30 days: raw DNS queries, firewall connection events and secure web gateway transactions older than that are purged from interactive queries. Aggregate reporting is kept for one calendar year, but it holds totals and top-N summaries without client IP addresses, directory usernames or URL strings, which makes it useless for a forensic reconstruction. A Cisco-managed S3 bucket offers 7, 14 or 30 days, and Cisco’s lifecycle rules delete beyond the window permanently. After contract termination, configuration and stored data are marked for deletion with full removal within a year of ingestion.
Set that against what European regulation expects. NIS2 Article 23 requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within one month. An intrusion where command-and-control traffic began months before detection cannot be reconstructed from 30 days of logs. DORA requires financial entities to keep ICT logging that supports root-cause analysis well past a 30-day window, and to have contractual exit plans that include data extraction before an account closes. In Belgium, CyFun detection and response controls expect event logs from edge security infrastructure to be centralised and retained for six to twelve months.
Four things to do before your last day of support, in this order:
- Move log management to your own storage. In the Umbrella dashboard, switch Log Management from Cisco-managed storage to a customer-owned S3 bucket. That gives indefinite retention and a direct path into your own SIEM.
- Export policy state via the API. Security policies, custom allow and block lists, application categorisation rules and bypass domains. This is your evidence of what was enforced and when, which an auditor will ask for after the tenant is gone.
- Archive the admin audit log. It holds administrative and policy changes for one year, accessible in three-month increments. Export to CSV.
- Check virtual appliance syslog forwarding. If you run on-premises VAs, confirm they forward internal DNS metadata to your own collectors rather than relying on cloud reporting for attribution.
Do this even if you intend to renew. The retention limits apply regardless of lifecycle stage, and a customer-managed bucket costs very little next to a failed audit.
The case for riding it out to 2029
A cost-conscious IT manager can make a genuinely strong argument for staying put until the last day of support, and it deserves a proper hearing.
First, capital and friction. A multi-year agreement signed at negotiated volume pricing is hard to match in an off-cycle transition, and migrating early means paying twice, redeploying agents and retraining people. Because Talos keeps feeding the resolvers regardless of the software maintenance milestone, DNS-layer filtering stays effective right through to January 2029 with no additional spend.
Second, architectural stability. Going from DNS filtering to a full SSE or SASE platform means endpoint agents, a decryption root certificate distributed to every trust store, bypass lists for sensitive traffic and network tunnels. For a lean team, running an established service to its scheduled retirement is a defensible choice while the market matures.
Third, the endpoint problem is separable. Active Umbrella subscriptions include entitlement to Cisco Secure Client with the Umbrella Roaming Security Module at no extra licence cost, so you can solve operating system compatibility on endpoints without touching the backend architecture.
All three hold. The counterweight is not technical, it is the two dates that are earlier than 2029 and that most plans overlook. If you are on a legacy SKU, your renewal door shut in September 2025 and your headcount can no longer grow on that contract. And if the products you depend on include App Discovery, the L3/L4 firewall add-on or Umbrella for Catalyst SD-WAN, there is no replacement to migrate to, which means the redesign work exists whether you start it in 2026 or discover it in 2028. Riding it out is a legitimate plan for a DNS-only estate on a modern SKU. It is a worse plan for everyone else, and the difference is worth establishing before the next renewal quote lands.
What to do with this
Three actions, whatever you decide about the platform. Put your End of Renewal date in the calendar, not your End of Sale date, because that is the one that closes options. Move log export to your own storage this quarter. And check whether anything you depend on sits in the “no replacement available” rows, because that determines whether you are planning a migration or a redesign.
If you are weighing what comes after, we have written the comparison two ways: the migration paths available in 2026 for the options at a high level, and a 60-day replacement plan for the sequence itself. For the narrower question of what DNS-layer filtering should cost and cover at mid-market scale, see our DNS filtering guide, and for the DNS-first versus full-platform question specifically, this comparison. If the feature you are actually trying to replace is selective proxying, the Intelligent Proxy timeline covers where that capability went.
Jimber replaces the DNS filtering and secure web gateway layer on one EU-hosted platform, with logging you control rather than logging you rent for 30 days. Book a demo, or get in touch if you want to walk through your specific SKUs and dates first.
Frequently asked questions
What is the difference between Cisco Umbrella End of Sale and End of Life?
End of Sale is the date Cisco stops selling a package; existing contracts continue to run normally with full service and support. End of Life, in Cisco’s terms the Last Day of Support, is when the product stops: tenants are deactivated, dashboards decommissioned and TAC cases refused. They are years apart.
When is the Cisco Umbrella End of Sale date?
Current Umbrella DNS Security and SIG packages reach End of Sale on 31 January 2027, announced on 1 September 2026. Legacy packages retired under bulletin EOL15688 — Insights, Platform, Professional and others — reached End of Sale earlier, on 30 September 2025.
What is the Last Day of Support for Cisco Umbrella DNS and SIG?
31 January 2029 for current DNS and SIG packages. Legacy packages under bulletin EOL15688 run to 30 September 2030, which is later, so a legacy SKU can outlive a modern one in support terms even though it stopped being sellable first.
Does internet access stop if our Umbrella licence expires?
No, and that is the risk. Cisco downgrades the tenant to an unmanaged DNS Monitoring tier. Names resolve and browsing works, but all filtering, malware blocking, botnet callback prevention and category enforcement are disabled. Nothing breaks visibly, so a lapse can go unnoticed for weeks.
Can we renew Cisco Umbrella after the End of Sale date?
For current DNS and SIG packages, yes, until 31 January 2028, and you can add seats during that window provided the term ends by 31 January 2029. For legacy packages retired under EOL15688, no: End of Sale and End of Renewal were the same date, 30 September 2025.
Are multi-year Umbrella contracts honoured past End of Sale?
Yes. A subscription signed before End of Sale runs its full paid term with complete entitlements, TAC access and cloud inspection, up to the Last Day of Support. Cisco Commerce Workspace will not let you select a term end date beyond that final support date.
What replaced the Cisco Umbrella Roaming Client?
Cisco Secure Client with the Umbrella Roaming Security Module, included at no additional licence cost with an active subscription. The standalone client reached end of support on 2 April 2025, and new device registrations were blocked from that date, so newly imaged machines cannot register the old agent.
How long does Umbrella keep activity logs?
Interactive Activity Search is capped at a rolling 30 days. Aggregate reporting is kept for a year but without client IPs, usernames or URL strings. Cisco-managed S3 storage offers 7, 14 or 30 days. Only a customer-owned S3 bucket gives indefinite retention.
What happens to Umbrella firewall rules and tunnels when a contract ends?
For SIG packages, IPsec tunnels and cloud firewall rules are retained but inactive for seven days after expiry, with traffic passing uninspected. After those seven days the tunnel parameters and firewall configuration are permanently deleted from Cisco’s cloud and must be rebuilt from scratch.
Does Talos threat intelligence stop after End of Software Maintenance?
No. That milestone halts engineering work on the codebase: bug fixes, client releases and virtual appliance patches. Talos continues streaming threat intelligence to the Anycast resolvers for active subscriptions. Cisco has not published whether cloud-side machine learning models are still tuned for deprecated subscriptions.