Debian 12 Bookworm EOL: 3-Month Action Plan
Debian 12 (Bookworm) End of Life: Your Last-Call Action Plan (July 11, 2026)
On July 11, 2026, Debian 12 (Bookworm) reaches end of life (EOL). That date is barely three months away. If your estate still runs Debian 12, a full migration to Debian 13 or 14 before the deadline is no longer realistic for most organizations. This article lays out what changes on that date, why you need to act now, and a concrete week-by-week checklist for the time you have left.
What changes on July 11, 2026?
Debian 12 (Bookworm) is not an LTS release. After July 11, 2026, the Debian Security Team will:
- Stop providing security patches for any packages in the Debian 12 repositories.
- Cease all bug fixes and non-security updates.
- No longer offer vendor SLAs or support for the distribution.
Vulnerabilities discovered after the EOL date will remain unpatched for the base release. The latest point release in this line is Debian 12.15, but applying that update does not extend the support window. Any system still running Debian 12 after July 11 will be exposed to new CVEs with no vendor fix.
Why a full migration is unlikely in three months
Migrating an entire estate from Debian 12 to a newer major release requires planning, testing, application compatibility checks, and staging. For anything beyond a handful of test servers, that timeline is too tight. Instead, you must focus on containment, documentation, and alternative support arrangements.
Week-by-week action checklist
Week 1: Inventory and classify
- Identify every system running Debian 12 (Bookworm). Use configuration management or a simple
lsb_release -asweep. - Classify each system by criticality: production, development, internal, or external-facing.
- Note any compliance or regulatory requirements that apply to each system (PCI-DSS, SOC 2, HIPAA, etc.).
Week 2: Isolate and harden what you cannot migrate
- Segment Debian 12 systems onto a restricted VLAN or network segment with minimal access to the internet and other internal networks.
- Apply the latest available patches (Debian 12.15) to all systems.
- Disable unnecessary services, remove unused packages, and enforce strict firewall rules.
- Enable and review logging and intrusion detection on these systems.
Week 3: Document exposure and risk
- Create a formal risk register for each Debian 12 system remaining after July 11.
- Document the lack of vendor patches, the mitigations applied (isolation, hardening), and the acceptable residual risk.
- Share this documentation with auditors, compliance officers, and cyber-insurance underwriters. Many insurers now require a documented plan for EOL systems.
Week 4: Line up post-EOL support
- Evaluate third-party support options for Debian 12. A reputable third-party maintenance provider can continue delivering security patches, bug fixes, and technical support for the distribution after the vendor’s EOL date.
- When evaluating a provider, ask about their patch delivery mechanism, CVE coverage, SLA terms, and whether they support the specific packages you rely on.
- Secure a contract that begins on July 11, 2026, so there is no coverage gap.
Week 5 and beyond: Test and migrate where possible
- Use the remaining weeks to migrate the lowest-risk systems to Debian 13 or 14. Focus on non-critical, internal-only servers first.
- For systems that must stay on Debian 12, ensure the third-party support contract is active and that you have tested a fallback patching process.
What about LTS releases?
Debian 12 (Bookworm) is not an LTS release. The Debian LTS team only supports select releases for a few additional years, but Bookworm is not one of them. Relying on community backports is not a substitute for a formal support arrangement.
The bottom line
You have three months to prepare. You cannot extend the vendor’s EOL date, but you can control how your estate handles it. Inventory, isolate, document, and secure a third-party support agreement before July 11, 2026. That is the only way to keep Debian 12 systems running safely past the vendor’s date.
For more information about how third-party support can protect your Debian 12 environment, contact our team.
Lifecycle data sourced from endoflife.date/debian.
Get support for what you run
How we can help
Keep it supported after end of life
The vendor's date doesn't have to be yours. Our engineers keep Debian 12 (Bookworm) running after official support ends — independent third-party support that covers most operational issues, typically at 40-70% below the last renewal quote.
Debian software support →Migration services
When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.
Migration & hybrid cloud services →24×7 remote administration
Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.
24/7 operations & remote administration →More EOSL Alerts
VMware Site Recovery Manager 9.0: EOL September 2027
VMware Site Recovery Manager 9.0 reaches end of life on September 17, 2027. Learn what that means for your budget, migration timelines, and third-party support
August 17, 2026
VMware Cloud Foundation 9.0 EOL September 2027
Plan your budget now: VMware Cloud Foundation 9.0 ends support Sept 17, 2027. Compare upgrade, vendor extended support, and third-party support costs to stay se
August 17, 2026
VMware ESXi 9.0 EOL September 2027
VMware ESXi 9.0 ends support Sept 17, 2027 – 13 months away. Plan next year's budget: compare migration costs with third-party support savings of 40–70%.
August 17, 2026