Now booking enterprise content platform builds for 2026. Contact us

All articles Practice 8 min read

Sitecore Extended Support no longer includes security updates: what changed on 1 June 2026

Sitecore's updated support model has been in operation since 1 June 2026. Two line items moved out of the included column for the Extended Support phase: assistance with production incidents, and security updates and fixes. What the source says, what it leaves open, and what that means for XP 9.x through 10.5.


Sitecore’s updated product support model has been in operation since 1 June 2026. Its knowledge base article KB0641167 now prints both matrices, the previous model and the updated one, on the same page, which makes the change checkable cell by cell.

Two cells moved. In the Extended Support phase, assistance with production incidents and security updates and fixes left the included column and now carry the $ marker. Everything else in the matrix is identical between the two tables, including the entire Sustaining column and all three phase durations.

What the two tables say

The matrix has three phases and seven service lines. Reading the Extended Support column against its previous self:

Service line (Extended Support phase)Previous modelModel in force since 1 Jun 2026
Documentation, knowledge base, forumsIncludedIncluded
Assistance with product version upgradesIncludedIncluded
Assistance with production incidentsIncluded$
Security updates and fixesIncluded$
Errors during installation or development$$
Product defects as hotfixes or patches$$
Compatibility fixes for supported platformsNot availableNot available

Hotfixes, defect patches and installation or development errors were already in the $ column under the previous model, so they are not part of this change. Compatibility fixes sit at - in Extended Support in both matrices the article shows.

The Sustaining column is also unchanged. Production incident assistance was already marked $ there, and security updates were already marked as not available, which is the line that matters most for anything running on XP 9.x today.

Phase lengths did not move either. KB0641167 counts them from a product’s general availability date: Mainstream to three years, Extended to six, Sustaining to eight.

What the source does not say

The legend in KB0641167 defines $ as “Contact your Sitecore Account Representative to discuss options.” No price, no packaging and no terms appear anywhere in the article. Third-party commentary has filled that space: the Sitecore agency Fishtank, in its March 2026 breakdown, reads the marker as a paid arrangement and describes both services as paid from 1 June. That reading is Fishtank’s; Sitecore has published no equivalent statement.

The article also does not address how the updated model applies to a version already partway through its Extended Support phase, as against a version entering that phase after 1 June 2026. It gives one commencement date and prints the two matrices without transition wording. Fishtank closes the gap by stating that “by mid-2026, every customer in that phase will be on the new model”, which is again their sentence rather than the KB’s.

Sitecore has published no rationale for the change. There is no accompanying blog post, press release or customer FAQ, and KB0641167 carries only the standing note that Sitecore can update the document at its sole discretion, with any change applying 30 days from the date it is posted. That note is also the mechanism by which the next revision would arrive.

Where each version sits

All dates below are from the per-product table in KB0641167, and the three Sitecore rows on our CMS end-of-life page carry the same figures.

VersionGAMainstream endsExtended endsSustaining ends
XP 10.5Aug 202631 Dec 202931 Dec 203231 Dec 2034
XP 10.4Apr 202431 Dec 202731 Dec 203031 Dec 2032
XP 10.3Dec 202231 Dec 202531 Dec 202831 Dec 2030
XP 10.2Nov 202131 Dec 202431 Dec 202731 Dec 2029
XP 10.1Feb 202131 Dec 202331 Dec 202631 Dec 2028
XP 10.0Aug 202031 Dec 202331 Dec 202631 Dec 2028
XP 9.3Nov 201931 Dec 202231 Dec 202531 Dec 2027

XP 9.3 left Extended Support on 31 December 2025, and every version below it left earlier. Where that puts a version today depends on its second date. XP 9.1, 9.2 and 9.3 are in Sustaining, where the matrix lists security updates as not available and the $ column covers production incidents only. XP 9.0 and everything older passed the end of Sustaining on 31 December 2025 or before, which is the last date KB0641167 records for them at all. No arrangement with an account representative changes either position.

XP 10.0 and 10.1 are the versions where two things land in the same year. Both have been under the updated model since June, and both leave Extended Support on 31 December 2026, roughly four months from now. After that date they follow 9.3 into a phase with no security updates listed at any price.

The updated model applies to XP 10.2 and 10.3 now, with their Extended Support dates falling in December 2027 and December 2028. XP 10.4 is in Mainstream Support, where nothing changed, until 31 December 2027. It then enters Extended Support under whatever model is current at that point.

What to check this month

Four items, none of which requires a decision about replatforming.

  • Get the number. The $ marker is an instruction to contact your account representative, so the useful output is a written quote for production incident assistance and security updates on your specific version and contract. Until that figure exists, the cost of staying put is unpriced.
  • Read your own agreement before the KB. Support entitlements usually sit in an order form or a negotiated agreement, and what those documents say outranks a knowledge base article for your estate. The question to answer in writing is whether your support terms track the published lifecycle policy or fix an entitlement for the term.
  • Check what elsewhere assumes patching is included. Vendor management records under ISO 27001 or SOC 2, cyber insurance questionnaires, and customer security addenda tend to carry a statement that the CMS receives vendor security updates. Where a version has moved into the $ column or out of security coverage altogether, that statement needs to match what the agreement now delivers.
  • Date your own cliff. One line: current version, phase today, the date Extended Support ends, and the date Sustaining ends. Everything after this point is arithmetic against those two dates.

When to assess a move

Upgrade assistance is included in all three phases, under two conditions stated in the KB notes: the work follows Sitecore’s official version upgrade instructions, and the version being upgraded to is in Mainstream Support. Today that means XP 10.4, and XP 10.5 from the initial release date the article records for it. Those conditions are what make the Sustaining phase awkward, because the entitlement that survives longest is the one that helps you leave.

Assessing is warranted where any of these holds:

  • You are on 9.x or older. No version in that range has security updates available at any price, and the exposure grows with each unpatched month rather than arriving on a date.
  • You are on 10.0 or 10.1 and your Extended Support runs out on 31 December 2026. Budget cycles and approval windows tend to consume more of the remaining four months than the technical work does.
  • The quote you get back for continued Extended Support coverage is large enough to fund part of an upgrade or a migration. That comparison becomes available once the number exists, which is why getting the number comes first.
  • Your version is comfortable today and your renewal or planning horizon reaches past its Extended Support date. XP 10.3 has the longest runway of anything in Extended, which makes it the cheapest position from which to price alternatives.

Assessing means costing the alternative closely enough to hold it against the quote. Two of the paths are Sitecore’s own: an upgrade to a version in Mainstream Support, or a move to XM Cloud, whose lifecycle KB0641167 hands to a separate cloud services document rather than to these version dates. Fishtank’s breakdown refers to that platform as SitecoreAI. The third path is leaving Sitecore.

If the assessment says move

A Sitecore to Payload move is a transfer between two structured systems, and the work concentrates in templates, rendering, and whatever sits around the CMS rather than in the content itself. Our migration guide covers the item and template mapping, the export path, and the cutover in detail. The /migrate/sitecore page is where to tell us what you are running: a free consultation and a scoped, fixed quote come before any commitment, so pricing the option costs a conversation.

For most Sitecore estates the immediate task is smaller than a replatform. Asking your account representative what the two $ lines now cost is the work that makes the rest of it decidable. Two service lines changed columns on one vendor matrix, and the price attached to them has not been published.

FAQ

What changed in Sitecore’s support model on 1 June 2026? In the Extended Support phase, two line items moved from the included column into the column Sitecore marks with a $: assistance with production incidents, and security updates and fixes. Every other cell in the matrix is identical between the previous and updated models, including the whole Sustaining column.

Does the $ mean I have to pay for Sitecore security patches? KB0641167 publishes no price and no terms. Its legend defines $ only as an instruction to contact your Sitecore Account Representative to discuss options. The Sitecore agency Fishtank reads the change as moving both services behind a paid arrangement; that reading is Fishtank’s, and what applies to your estate is a question for your account representative and your existing agreement.

Which Sitecore versions still get security updates as part of the agreement? Versions in the Mainstream Support phase, where the matrix is unchanged. KB0641167 lists XP 10.4 in Mainstream to 31 December 2027 and XP 10.5, with an initial release date of August 2026, to 31 December 2029. Versions in Extended Support have security updates in the $ column; versions in Sustaining Support have them listed as not available.

When does Extended Support end for my version? KB0641167 records 31 December 2026 for XP 10.0 and 10.1, 31 December 2027 for 10.2, and 31 December 2028 for 10.3. XP 9.3 left Extended Support on 31 December 2025 and sits in Sustaining to 31 December 2027. Sustaining lists security updates as not available at any price.

Sources


Author

Paul Utr

Co-founder, Chief Growth Officer

Paul has been launching online platforms since his teens, picking up UX and product design by building them. He led the Mailgun redesign at Netguru and was Principal Designer at Ramp Network through its seed-to-Series-B run. At WAYF he leads design and organisational alignment, and watches how language carries through every product we ship.


We're booking content platform
engagements for 2026.

Twenty-five minutes to walk through the work and decide if we're the right team for it. Scoping and a fixed price come after.