SLES 15.6 End of Life Dec 2025: Final 12-Week Action Plan
SUSE Linux Enterprise Server 15.6 — What Changes on January 1, 2026
On December 31, 2025, SLES 15.6 reaches its end of life (EOL). After this date, SUSE will no longer provide:
- Security patches and bug fixes
- Technical support or SLA-backed incident response
- Kernel updates or driver backports
- New package versions via official repositories
The system will not stop running. But running an unpatched enterprise OS exposes you to compliance violations (PCI-DSS, SOC 2, HIPAA), voids most cyber insurance policies that require active vendor support, and increases risk from CVEs that will never be fixed by SUSE.
Why a Full Migration Is No Longer Realistic
A complete, tested migration from SLES 15.6 to a supported OS (e.g., SLES 16 or an alternative Linux distribution) typically takes 4–6 months for a medium-sized estate — longer if you have custom packages, legacy kernels, or certified applications. With only about 12 weeks left, attempting a full migration before the deadline carries high risk of rollback, downtime, and missed patches.
Instead, focus on three achievable goals:
- Identify and isolate all SLES 15.6 systems.
- Harden them for the unprotected period.
- Secure a support contract to cover the gap until migration completes.
Your Week-by-Week Action Checklist
Use this plan starting now. Adjust timings based on your estate size.
Weeks 1–2: Inventory & Discovery
- Run a discovery scan (e.g., NMAP, Ansible, or your CMDB) to find every SLES 15.6 instance.
- Record hostname, IP, function, application owner, and last patching date.
- Identify systems that cannot be patched or rebooted (legacy apps, certified appliances).
- Flag systems that store sensitive data or face the internet.
Weeks 3–4: Risk Categorization
- Sort systems into three tiers:
- Tier 1: Internet-facing, critical data. Must be migrated or isolated before EOL.
- Tier 2: Internal but business-critical. Can stay on SLES 15.6 short-term with third-party support.
- Tier 3: Dev/test or low-impact. Can remain with hardening until migration window opens.
- Update your risk register and inform the compliance/audit team.
Weeks 5–6: Isolation & Hardening
- Move Tier 1 systems behind a hardened WAF or VPN. Remove unnecessary services.
- For Tier 2–3 systems:
- Disable SSH password auth; enforce key-only or certificate-based access.
- Enable
auditdand log forwarding to your SIEM. - Review and close all unused ports using
firewalldoriptables. - Apply current kernel and package updates (last chance for official patches).
- Document all exceptions and compensating controls for auditors.
Weeks 7–8: Third-Party Support Assessment
- Evaluate third-party maintenance providers that support SLES 15.6 after EOL.
- Ensure the provider offers:
- Backport security patches for SLES 15.6-specific CVEs
- Technical support (24/7 or business hours with defined SLAs)
- Kernel live patching if needed
- Negotiate contract start date of January 1, 2026 (or earlier to cover transition).
Weeks 9–10: Communication & Documentation
- Notify application owners, security team, and line-of-business managers of the SLES 15.6 EOL status and your mitigation plan.
- Draft a brief for the board or CIO explaining the risk, the third-party support solution, and the extended migration timeline.
- Prepare an incident response plan for a zero-day exploit discovered after SUSE support ends.
Weeks 11–12: Final Readiness
- Conduct a pre-EOL security scan on all Tier 2 and 3 systems.
- Confirm third-party support contract is signed and active for January 1.
- Perform a dry run of the support escalation process with your new provider.
- Set a calendar reminder for January 1 to verify that monitoring and patching have transitioned.
What About Compliance & Insurance?
Regulatory frameworks and cyber insurers increasingly require active vendor support for all operating systems in production. Running SLES 15.6 after December 31 without a support contract may:
- Breach PCI DSS Requirement 6.2 (install applicable vendor-supplied security patches within a month)
- Void cyber insurance coverage if a breach occurs on an unsupported OS
- Attract non-compliance findings during audits
Having a signed third-party support agreement in place by January 1, 2026, documents that you have a supported lifecycle plan and closes this gap.
The Realistic Path Forward
You cannot migrate 100% of SLES 15.6 in 12 weeks without cutting corners. The responsible approach is:
- Migrate only internet-facing or high-criticality systems immediately.
- Isolate and harden internal systems to reduce attack surface.
- Contract third-party support to keep receiving critical patches and technical assistance for the systems that remain.
Third-party support for SLES 15.6 can provide security patches, hotfixes, and vendor-grade SLAs after SUSE walks away — giving you the time to plan and execute a proper migration without rushing.
Summary
| Deadline | Action |
|---|---|
| December 31, 2025 | SUSE support ends — no more patches, fixes, or SLAs |
| Before December 31 | Inventory, harden, isolate, and document |
| January 1, 2026 | Third-party support contract activates |
| Q1–Q2 2026 | Complete staged migration to a supported OS |
Start your week 1 inventory today. With a structured plan and a third-party support partner, you can pass the EOL deadline without panic.
Get support for what you run
How we can help
Keep it supported after end of life
The vendor's date doesn't have to be yours. Our engineers keep SUSE Linux Enterprise Server 15.6 running after official support ends — independent third-party support that covers most operational issues, typically at 40-70% below the last renewal quote.
SUSE software support →Migration services
When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.
Migration & hybrid cloud services →24×7 remote administration
Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.
24/7 operations & remote administration →More EOSL Alerts
VMware Site Recovery Manager 9.0: EOL September 2027
VMware Site Recovery Manager 9.0 reaches end of life on September 17, 2027. Learn what that means for your budget, migration timelines, and third-party support
August 17, 2026
VMware Cloud Foundation 9.0 EOL September 2027
Plan your budget now: VMware Cloud Foundation 9.0 ends support Sept 17, 2027. Compare upgrade, vendor extended support, and third-party support costs to stay se
August 17, 2026
VMware ESXi 9.0 EOL September 2027
VMware ESXi 9.0 ends support Sept 17, 2027 – 13 months away. Plan next year's budget: compare migration costs with third-party support savings of 40–70%.
August 17, 2026