Sitecore Extended Support no longer includes security updates: what changed on 1 June 2026
Sitecore's updated support model has been in operation since 1 June 2026. Two line items moved out of the included column for the Extended Support phase: assistance with production incidents, and security updates and fixes. What the source says, what it leaves open, and what that means for XP 9.x through 10.5.
Sitecore’s updated product support model has been in operation since 1 June 2026. Its knowledge base article KB0641167 now prints both matrices, the previous model and the updated one, on the same page, which makes the change checkable cell by cell.
Two cells moved. In the Extended Support phase, assistance with production incidents and security updates and fixes left the included column and now carry the $ marker. Everything else in the matrix is identical between the two tables, including the entire Sustaining column and all three phase durations.
What the two tables say
The matrix has three phases and seven service lines. Reading the Extended Support column against its previous self:
| Service line (Extended Support phase) | Previous model | Model in force since 1 Jun 2026 |
|---|---|---|
| Documentation, knowledge base, forums | Included | Included |
| Assistance with product version upgrades | Included | Included |
| Assistance with production incidents | Included | $ |
| Security updates and fixes | Included | $ |
| Errors during installation or development | $ | $ |
| Product defects as hotfixes or patches | $ | $ |
| Compatibility fixes for supported platforms | Not available | Not available |
Hotfixes, defect patches and installation or development errors were already in the $ column under the previous model, so they are not part of this change. Compatibility fixes sit at - in Extended Support in both matrices the article shows.
The Sustaining column is also unchanged. Production incident assistance was already marked $ there, and security updates were already marked as not available, which is the line that matters most for anything running on XP 9.x today.
Phase lengths did not move either. KB0641167 counts them from a product’s general availability date: Mainstream to three years, Extended to six, Sustaining to eight.
What the source does not say
The legend in KB0641167 defines $ as “Contact your Sitecore Account Representative to discuss options.” No price, no packaging and no terms appear anywhere in the article. Third-party commentary has filled that space: the Sitecore agency Fishtank, in its March 2026 breakdown, reads the marker as a paid arrangement and describes both services as paid from 1 June. That reading is Fishtank’s; Sitecore has published no equivalent statement.
The article also does not address how the updated model applies to a version already partway through its Extended Support phase, as against a version entering that phase after 1 June 2026. It gives one commencement date and prints the two matrices without transition wording. Fishtank closes the gap by stating that “by mid-2026, every customer in that phase will be on the new model”, which is again their sentence rather than the KB’s.
Sitecore has published no rationale for the change. There is no accompanying blog post, press release or customer FAQ, and KB0641167 carries only the standing note that Sitecore can update the document at its sole discretion, with any change applying 30 days from the date it is posted. That note is also the mechanism by which the next revision would arrive.
Where each version sits
All dates below are from the per-product table in KB0641167, and the three Sitecore rows on our CMS end-of-life page carry the same figures.
| Version | GA | Mainstream ends | Extended ends | Sustaining ends |
|---|---|---|---|---|
| XP 10.5 | Aug 2026 | 31 Dec 2029 | 31 Dec 2032 | 31 Dec 2034 |
| XP 10.4 | Apr 2024 | 31 Dec 2027 | 31 Dec 2030 | 31 Dec 2032 |
| XP 10.3 | Dec 2022 | 31 Dec 2025 | 31 Dec 2028 | 31 Dec 2030 |
| XP 10.2 | Nov 2021 | 31 Dec 2024 | 31 Dec 2027 | 31 Dec 2029 |
| XP 10.1 | Feb 2021 | 31 Dec 2023 | 31 Dec 2026 | 31 Dec 2028 |
| XP 10.0 | Aug 2020 | 31 Dec 2023 | 31 Dec 2026 | 31 Dec 2028 |
| XP 9.3 | Nov 2019 | 31 Dec 2022 | 31 Dec 2025 | 31 Dec 2027 |
XP 9.3 left Extended Support on 31 December 2025, and every version below it left earlier. Where that puts a version today depends on its second date. XP 9.1, 9.2 and 9.3 are in Sustaining, where the matrix lists security updates as not available and the $ column covers production incidents only. XP 9.0 and everything older passed the end of Sustaining on 31 December 2025 or before, which is the last date KB0641167 records for them at all. No arrangement with an account representative changes either position.
XP 10.0 and 10.1 are the versions where two things land in the same year. Both have been under the updated model since June, and both leave Extended Support on 31 December 2026, roughly four months from now. After that date they follow 9.3 into a phase with no security updates listed at any price.
The updated model applies to XP 10.2 and 10.3 now, with their Extended Support dates falling in December 2027 and December 2028. XP 10.4 is in Mainstream Support, where nothing changed, until 31 December 2027. It then enters Extended Support under whatever model is current at that point.
What to check this month
Four items, none of which requires a decision about replatforming.
- Get the number. The
$marker is an instruction to contact your account representative, so the useful output is a written quote for production incident assistance and security updates on your specific version and contract. Until that figure exists, the cost of staying put is unpriced. - Read your own agreement before the KB. Support entitlements usually sit in an order form or a negotiated agreement, and what those documents say outranks a knowledge base article for your estate. The question to answer in writing is whether your support terms track the published lifecycle policy or fix an entitlement for the term.
- Check what elsewhere assumes patching is included. Vendor management records under ISO 27001 or SOC 2, cyber insurance questionnaires, and customer security addenda tend to carry a statement that the CMS receives vendor security updates. Where a version has moved into the
$column or out of security coverage altogether, that statement needs to match what the agreement now delivers. - Date your own cliff. One line: current version, phase today, the date Extended Support ends, and the date Sustaining ends. Everything after this point is arithmetic against those two dates.
When to assess a move
Upgrade assistance is included in all three phases, under two conditions stated in the KB notes: the work follows Sitecore’s official version upgrade instructions, and the version being upgraded to is in Mainstream Support. Today that means XP 10.4, and XP 10.5 from the initial release date the article records for it. Those conditions are what make the Sustaining phase awkward, because the entitlement that survives longest is the one that helps you leave.
Assessing is warranted where any of these holds:
- You are on 9.x or older. No version in that range has security updates available at any price, and the exposure grows with each unpatched month rather than arriving on a date.
- You are on 10.0 or 10.1 and your Extended Support runs out on 31 December 2026. Budget cycles and approval windows tend to consume more of the remaining four months than the technical work does.
- The quote you get back for continued Extended Support coverage is large enough to fund part of an upgrade or a migration. That comparison becomes available once the number exists, which is why getting the number comes first.
- Your version is comfortable today and your renewal or planning horizon reaches past its Extended Support date. XP 10.3 has the longest runway of anything in Extended, which makes it the cheapest position from which to price alternatives.
Assessing means costing the alternative closely enough to hold it against the quote. Two of the paths are Sitecore’s own: an upgrade to a version in Mainstream Support, or a move to XM Cloud, whose lifecycle KB0641167 hands to a separate cloud services document rather than to these version dates. Fishtank’s breakdown refers to that platform as SitecoreAI. The third path is leaving Sitecore.
If the assessment says move
A Sitecore to Payload move is a transfer between two structured systems, and the work concentrates in templates, rendering, and whatever sits around the CMS rather than in the content itself. Our migration guide covers the item and template mapping, the export path, and the cutover in detail. The /migrate/sitecore page is where to tell us what you are running: a free consultation and a scoped, fixed quote come before any commitment, so pricing the option costs a conversation.
For most Sitecore estates the immediate task is smaller than a replatform. Asking your account representative what the two $ lines now cost is the work that makes the rest of it decidable. Two service lines changed columns on one vendor matrix, and the price attached to them has not been published.
FAQ
What changed in Sitecore’s support model on 1 June 2026? In the Extended Support phase, two line items moved from the included column into the column Sitecore marks with a $: assistance with production incidents, and security updates and fixes. Every other cell in the matrix is identical between the previous and updated models, including the whole Sustaining column.
Does the $ mean I have to pay for Sitecore security patches? KB0641167 publishes no price and no terms. Its legend defines $ only as an instruction to contact your Sitecore Account Representative to discuss options. The Sitecore agency Fishtank reads the change as moving both services behind a paid arrangement; that reading is Fishtank’s, and what applies to your estate is a question for your account representative and your existing agreement.
Which Sitecore versions still get security updates as part of the agreement? Versions in the Mainstream Support phase, where the matrix is unchanged. KB0641167 lists XP 10.4 in Mainstream to 31 December 2027 and XP 10.5, with an initial release date of August 2026, to 31 December 2029. Versions in Extended Support have security updates in the $ column; versions in Sustaining Support have them listed as not available.
When does Extended Support end for my version? KB0641167 records 31 December 2026 for XP 10.0 and 10.1, 31 December 2027 for 10.2, and 31 December 2028 for 10.3. XP 9.3 left Extended Support on 31 December 2025 and sits in Sustaining to 31 December 2027. Sustaining lists security updates as not available at any price.
Sources
- Sitecore, Product Support Lifecycle (KB0641167) — both support matrices, the
$legend, the per-product date table, and the 30-day revision note - Fishtank, Sitecore support changes for 2026: version-by-version breakdown (31 March 2026) — partner commentary; the source of the paid reading of
$and of the interpretation that everyone in Extended Support moves onto the new model - WAYF, CMS end-of-life dates — the three Sitecore rows carrying these dates alongside Drupal, AEM, TYPO3, Kentico, Umbraco and Optimizely
We're booking content platform
engagements for 2026.
Twenty-five minutes to walk through the work and decide if we're the right team for it. Scoping and a fixed price come after.