.NET 9 EOL: Week-by-Week Action Plan (Nov 2026)
When Microsoft .NET 9 reaches end of life (EOL) on November 10, 2026, you will lose vendor patch support, security fixes, and all formal SLAs. With about three months remaining, a full migration to .NET 10 (or even .NET 9 LTS, which doesn’t exist) is not realistic for most enterprise estates.
This means your remaining time should be spent on risk containment, not full remediation. Here is what changes on November 10, 2026, and a week-by-week action plan to get through the deadline safely.
What changes on November 10, 2026
- No more security patches or bug fixes from Microsoft for .NET 9.
- No new releases of the runtime or SDK (the latest is already 9.0.18).
- Microsoft will not provide vulnerability disclosures or hotfixes for any .NET 9 components.
- Any new CVEs discovered after that date will only be addressed in .NET 10 or via extended support agreements (which require separate paid contracts).
Week-by-week action plan (starting now)
Week 1: Inventory and classify
- Run a full scan of all production and staging servers, containers, and CI/CD pipelines for .NET 9 runtimes (SDK and hosting bundles).
- Create a register of every application using .NET 9, including version, host OS, and criticality (tier 1 = revenue-facing, tier 2 = internal, tier 3 = experimental).
- Mark which applications can be migrated to .NET 10 or a supported LTS release in the next three months.
Week 2-3: Isolate the long tail
- For applications that cannot migrate by Nov 10, isolate them in a separate network segment with restricted ingress/egress.
- Apply Web Application Firewall (WAF) rules and runtime monitoring (e.g., Defender for Cloud, AppDynamics) to detect anomalous behaviour.
- Disable unnecessary .NET 9 features (e.g., deprecated libraries, HTTP/3) to reduce the attack surface.
Week 4-5: Hardening and compensating controls
- Apply all remaining .NET 9 patches from the vendor update page (Windows Update, WSUS, or Red Hat repositories for Linux).
- Pin the runtime to an explicit version to prevent accidental auto-update to an unsupported one.
- Ensure all dependencies (NuGet packages) are pinned and verified for last-known-good signatures.
Week 6-7: Documentation and communication
- Create a formal risk acceptance document signed by application owners and security leadership.
- Record the EOL date, compensating controls, and a target migration date for each at-risk application.
- Share this with internal auditors and, if applicable, cyber insurance providers (many policies require documented risk acceptance for unsupported software).
Week 8-9: Rollback scripts and testing
- Test your rollback procedures for any applications still on .NET 9. Confirm backups are valid and recoverable.
- Run a full red team or penetration test against the isolated .NET 9 environment to identify weaknesses before the EOL date.
Week 10: Day-of prep
- On November 9, 2026, perform a final check that no auto-update services are still pointing to Microsoft’s .NET 9 feed.
- Verify that your third-party support contract (if you choose one) is active and tested. A third-party support provider can deliver post-EOL patches, legal cover, and compliance for SOC 2/PCI DSS/HIPAA.
- Confirm that your SIEM and alerting rules are updated to flag any .NET 9 environment change after the deadline.
After the EOL date (Nov 10, 2026+)
- Treat any .NET 9 application as unsupported legacy software — apply all internal compensating controls, restrict access, and schedule a forced migration in Q1 2027.
- If a critical vulnerability is disclosed after EOL and you cannot migrate, a third-party support provider can backport the patch under a custom agreement. This is often faster and more cost-effective than negotiating a Microsoft extended support contract.
The bottom line
You have three months to contain and document, not to rewrite every app. Use the plan above to get your .NET 9 estate under control. When you need a safety net for the applications that can’t move, explore third-party support options to keep them patched and auditable after Microsoft stops.
Reference: Microsoft .NET 9 lifecycle information from endoflife.date/dotnet and vendor policies on /software/microsoft.
Get support for what you run
How we can help
Keep it running after end of support
Hardware or software, the end-of-support date doesn’t have to force a refresh. We keep enterprise infrastructure maintained, secure and under SLA long after the vendor moves on — typically at 40-70% below OEM pricing.
End-of-life support →Migration services
When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.
Migration & hybrid cloud services →24×7 remote administration
Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.
24/7 operations & remote administration →More EOSL Alerts
VMware Site Recovery Manager 9.0: EOL September 2027
VMware Site Recovery Manager 9.0 reaches end of life on September 17, 2027. Learn what that means for your budget, migration timelines, and third-party support
August 17, 2026
VMware Cloud Foundation 9.0 EOL September 2027
Plan your budget now: VMware Cloud Foundation 9.0 ends support Sept 17, 2027. Compare upgrade, vendor extended support, and third-party support costs to stay se
August 17, 2026
VMware ESXi 9.0 EOL September 2027
VMware ESXi 9.0 ends support Sept 17, 2027 – 13 months away. Plan next year's budget: compare migration costs with third-party support savings of 40–70%.
August 17, 2026