End of Life (EOL)

The vendor milestone after which a product is no longer sold or manufactured; patches and support usually continue until a later End of Support date.

Full guide: End of Life vs End of Support: The Two Dates CISSP Candidates Confuse

End of Life is the point at which a vendor stops selling or manufacturing a product. After that date no new units or licences can be bought, although existing customers usually keep receiving patches and help for a transition period. Many vendors call it End of Sale, and some use End of Life for the whole retirement process, so the vendor’s lifecycle policy is the source to check. The ISC2 outline gives End of Life (EOL) and End of Support as examples under objective 2.5, ensuring appropriate asset retention.

The distinction that matters is from end of support. EOL is a planning signal: nothing about the product’s security changes on the day, but the replacement clock has started. End of support is when routine patches stop, so vulnerabilities found afterwards may stay open. Both dates belong in the asset inventory, and either should prompt a fresh risk assessment. Where a product must run past its support date, compensating controls such as isolation through network segmentation can reduce exposure, and retirement follows the decommissioning process.

Exam relevance: a scenario is likely to blur the two dates. Candidates are expected to treat EOL as the trigger to plan replacement, and end of support as the point from which unpatched risk grows.