End of support (EOS)
The date a vendor stops issuing security patches, updates and technical help for a product, after which newly found vulnerabilities may stay unfixed while the product keeps running.
Full guide: End of Life vs End of Support: The Two Dates CISSP Candidates Confuse
End of support is the point at which a vendor stops maintaining a product: routine security patches, bug fixes and technical assistance all end. Vendors name the milestone differently (end of service life and end of security updates are common variants), and some publish separate dates for patches, hardware servicing and help-desk support, so each date belongs in the asset record. The ISC2 exam outline gives End of Life and End of Support as its examples under objective 2.5, Ensure appropriate asset retention.
The date it is most often confused with is end of life, which usually comes first and stops sales, not fixes. A product past end of life is often still patched; a product past end of support cannot count on a fix. Where a system has to stay in service, the usual response is a documented, time-limited exception with compensating controls such as network segmentation and closer monitoring, with the residual risk accepted by a named owner and a funded replacement date.
Exam relevance: a scenario is likely to describe a system that still works but no longer receives patches. Candidates are expected to recognise that the security risk begins at end of support rather than end of life, and that compensating controls reduce the exposure without removing the unpatched vulnerability.