Sophos UTM reached its official end-of-life on 30 June 2026. If an SG appliance still sits at your network edge, you are past the deadline, not approaching it: the SKUs were deactivated in early July, and the absolute hard stop — no support, no hotfixes, no threat updates, regardless of any licence dates — lands on 31 December 2026. Two paths remain: buy the next Sophos box, or use the forced rebuild to leave the appliance model altogether.
Key takeaways
- The dates are final: end-of-life for all UTM 9 software and SG hardware was 30 June 2026; the absolute support hard stop for every remaining deployment is 31 December 2026.
- The remote-access writing was on the wall earlier: the Sophos SSL VPN client died in January 2022, and SFOS 22.0 MR1 retired legacy remote-access IPsec entirely — Sophos itself now points to ZTNA.
- The threat record is exceptional: Sophos’ own “Pacific Rim” report documents five years of Chinese state-sponsored campaigns against its edge devices, with kernel implants, firmware persistence and sabotaged hotfix mechanisms.
- Staying means buying again: new XGS hardware plus Xstream subscriptions (an XGS 2100 bundle runs roughly $4,868–$5,800 for year one), a from-scratch config rebuild — and a Sophos price increase that took effect 1 July 2026.
- Under NIS2 and current cyber-insurance terms, an unpatched EOL firewall on the internet is a compliance breach and a claim-denial waiting to happen.
Where exactly does the countdown stand?
The lifecycle wound down in stages, per Sophos’ official EOL FAQ:
| Date | Milestone | Status as of September 2026 |
|---|---|---|
| 30 June 2023 | End-of-sale; UTM 9.6 end-of-maintenance | Passed |
| 31 December 2025 | Final order date for any renewal subscription | Passed |
| 1 April – 30 June 2026 | Final migration promo (up to 6 months free UTM overlap with an XGS order) | Expired |
| 30 June 2026 | End-of-life and end-of-support, UTM 9 + SG hardware | Passed |
| Early July 2026 | All UTM/SG SKUs deactivated; XGS price increase takes effect | In effect |
| 31 December 2026 | Absolute hard stop: no support, RMA, hotfixes or threat intelligence for anyone | <4 months away |
Two details bite hardest. Appliances keep passing traffic after EOL, which creates a false sense of continuity — but protection engines degrade as threat feeds stop, and when a licence expires past the threshold, IPS, antivirus and web filtering cease functioning outright. And the trade-in promotions are gone: waiting cost money, and further waiting costs more.
The SSL VPN story inside the story
Sophos retired its remote access piecemeal ahead of the platform itself: the dedicated SSL VPN client hit end-of-life on 31 January 2022, SFOS 20.0 MR1 deprecated site-to-site SSL VPN between UTM and SFOS, and SFOS 22.0 MR1 removed legacy remote-access IPsec configurations completely — appliances carrying them are blocked from upgrading until they are deleted. Sophos’ designated successor is its own ZTNA, delivered through Sophos Central agents and XGS gateways. Read that sequence for what it is: the vendor that sold you the SSL VPN has concluded the architecture is over, exactly as every other vendor in the SSL VPN deprecation timeline has.
How hard has this platform been hit?
Harder than almost any other edge product — and we know because Sophos itself published the evidence. The “Pacific Rim” investigation (October 2024) documents a five-year counter-offensive against Chinese state-sponsored groups operating from Chengdu, who used Sophos edge devices to build relay networks, sniff Active Directory credentials, plant in-memory Trojans and kernel implants, tamper with firmware update scripts to survive reboots, and repeatedly attempt to sabotage the hotfix mechanism itself. The exploited-CVE list beneath that campaign includes CVE-2020-12271 (Asnarök, pre-auth SQL injection to root), CVE-2020-15069, CVE-2022-1040 (auth bypass, CISA KEV, exploited as a zero-day) and CVE-2022-3236 (unauthenticated code injection, CISA KEV same day as disclosure). Every one targeted the WebAdmin or User Portal — the interfaces an appliance must expose to be an appliance. Thousands of those portals, disproportionately in the Benelux and France, are still visible on Shodan today.
Path A: the next Sophos box
The vendor path is XGS hardware running SFOS, licensed in Base, Standard and Xstream tiers. Honest accounting for a 100–300 user organisation: an XGS 2100 with one year of Xstream Protection streets at roughly $4,868–$5,800, three-year bundles at $7,800–$11,646, with annual Xstream renewals around €2,872 — all before the July 2026 price increase, and all repeating every three-to-five-year hardware cycle. The migration itself is a rebuild, not an upgrade: UTM 9 and SFOS are architecturally different, backups cannot be restored across, and practitioners on r/sophos consistently advise manual from-scratch configuration over the conversion tools’ “messy, unoptimized rule bases”. Add the forced move from local management (SUM died in 2022) to Sophos Central cloud, and the community friction — WebAdmin latency complaints, licensing step-ups — writes its own review. It works; it just re-enrols you in the cycle that produced this article.
Path B: rebuild once, in the right place
If the configuration must be rebuilt by hand anyway, the real question is where. A UTM did five jobs; each has a cloud-native equivalent that removes the exposed box instead of replacing it:
| UTM 9 function | XGS path | SASE path | What changes |
|---|---|---|---|
| Stateful firewall / NAT | XGS hardware rules | Firewall-as-a-Service | No hardware refresh cycle |
| Web filtering | SFOS DPI / Web Protection | Secure Web Gateway at the edge | Remote users inspected locally, no backhaul |
| Remote access SSL VPN | Sophos Connect / Sophos ZTNA | ZTNA | Per-app access; no exposed portal to exploit |
| Web Application Firewall | SFOS Webserver Protection | Cloud WAF / app connectors | Internal apps published without open WAN ports |
| Central management | Sophos Central | One SASE console | Multi-tenant by design — the MSP case made in managed SASE without tool sprawl |
A structured 16-week programme covers a 100–500 user estate: audit the rule base and VPN profiles (weeks 1–2), stand up connectors alongside the UTM (3–4), migrate identity and remote access while decommissioning SSL VPN profiles (5–8), cut web filtering and branch breakout over (9–12), then verify zero traffic and retire the SG (13–16) — the same phased pattern that worked for the SonicWall migrations and the Ivanti exits.
The 31 December deadline is also a legal one
NIS2 Article 21 requires appropriate technical measures, including vulnerability management; an internet-facing security appliance that can no longer receive patches fails that duty on its face, with the CCB holding enforcement powers and management carrying personal liability. Insurers reach the same verdict faster: underwriting terms routinely exclude or void claims where the initial compromise vector is unsupported EOL equipment. The sequence — unpatched box, known exploit, denied claim, unabsorbed loss — is predictable enough that the countdown to 31 December doubles as your remediation deadline.
Don’t buy the cycle again
The Sophos UTM story compresses everything this series has documented: an exposed appliance, a five-year nation-state campaign against it, a retired SSL VPN, and a vendor path that leads to the next box with a bigger invoice. If the rebuild is mandatory either way, rebuild into an architecture without an exposed management plane. For EU mid-market teams and the MSPs that serve them, Jimber replaces the whole UTM function list — FWaaS, SWG, ZTNA, application publishing — from one EU-sovereign platform with no inbound ports, no hardware cycle and one flat licence, run in parallel with the SG until the logs go quiet. With under four months to the hard stop, book a demo this week and put the 16-week plan against your calendar; the vendor EOL watchlist shows where this road leads for everyone else too.
Frequently asked questions
What is the exact end-of-life date for Sophos UTM and SG hardware?
30 June 2026 for all UTM 9 versions (including Home Edition and AWS BYOL) and all SG appliance revisions. The absolute technical-support hard stop for every remaining deployment, including extended licences, is 31 December 2026.
Our licence runs past June 2026 — can we just keep running UTM?
The appliance keeps passing traffic, but SKUs were deactivated in July 2026 and all support, RMA, hotfixes and threat-intelligence updates cease permanently on 31 December 2026. Protection quality degrades from the moment feeds stop.
What happens to the WebAdmin interface when a UTM licence expires post-EOL?
Protection engines — IPS, antivirus, web filtering — stop functioning, and the corresponding WebAdmin configuration tabs are disabled. The box becomes a router with a history of exploited management interfaces.
Can we restore a UTM 9 backup onto a new XGS appliance?
No. UTM 9 and SFOS are architecturally different, so backups cannot be imported. Sophos provides conversion tooling (Config Studio) and a Migration Desk, but practitioners consistently recommend a manual rebuild to avoid unoptimised rule bases.
Is the Sophos SSL VPN client still supported?
No — it reached end-of-life on 31 January 2022. SFOS 22.0 MR1 also retired legacy remote-access IPsec configurations, and Sophos positions its ZTNA as the successor for remote access.
Why are firewalls like the SG series such popular targets for state actors?
They expose privileged management interfaces (WebAdmin, User Portal) to the internet by design. Sophos’ own Pacific Rim report documents five years of Chinese APT campaigns using exactly those interfaces for root access, credential theft, persistent implants and relay networks.
How does running a post-EOL firewall affect our cyber insurance?
Most underwriters exclude or deny claims where the breach originates on unsupported, end-of-life or unpatched systems. A compromise through a post-EOL UTM leaves the organisation carrying forensics, interruption and liability costs alone.
Does NIS2 prohibit running an EOL firewall?
Article 21 requires appropriate security measures including vulnerability management. An internet-facing appliance that can no longer be patched breaches that duty of care, exposing the organisation to CCB enforcement and management to personal liability.