EOSL Alerts

VMware SRM 8.7 End-of-Life October 11, 2025 – 90-Day Action Plan

Updated 3rd Party Support Team

Why VMware Site Recovery Manager 8.7’s October 11, 2025 end-of-life requires immediate action

VMware Site Recovery Manager (SRM) 8.7 reaches end of life on October 11, 2025 — roughly three months from today. This is not an LTS release. Both general support and active support end on that same date. There will be no additional patches, security fixes, or vendor SLA coverage after October 11.

If you are running SRM 8.7 — or any 8.7.x build — the window for a full migration to a newer release is effectively closed for most estates. Planning, testing, and validating a new SRM version across production recovery sites rarely fits inside 90 days for organizations with multiple protected workloads. The priority now shifts to isolation, hardening, documentation, and securing a support bridge until you can complete the upgrade.

What changes on October 11, 2025

On the end-of-life date:

  • No more patches or hotfixes. Any newly discovered vulnerabilities in SRM 8.7 will remain unpatched by Broadcom/VMware.
  • No more bug fixes. Vendor engineering will not release fixes for functional defects.
  • No more technical support. Broadcom/VMware will not accept support requests for SRM 8.7. Cases opened before the date may be closed upon expiration.
  • No more knowledge-base updates specific to 8.7.

What does not change?

  • The product will continue to run as built. Recovery plans, replication, and failover workflows that are currently working will keep working — until a failure reveals an unpatched issue or a compliance requirement that mandates a supported configuration.

Inventory and isolate affected systems — first 30 days

Week 1–2: Full inventory of SRM 8.7 deployments

Use your vCenter inventory or scripting to identify every SRM 8.7 instance, including:

  • Protected sites and recovery sites
  • Recovery plans and their associated protection groups
  • Replication configurations (vSphere Replication or array-based)
  • Any integrated components (vCenter, NSX, storage arrays)

Record the exact build version. SRM 8.7’s latest release is 8.7.0.4. If you are on an earlier 8.7.x build, you are running an even older version that is already behind on fixes.

Week 3–4: Isolate and harden the environment

  • Air-gap or restrict network access to the SRM appliances to trusted management networks only. Block outbound internet access unless explicitly required for licensing.
  • Apply all remaining available patches. If you haven’t upgraded to 8.7.0.4, do that as a first step. While this does not change the October 11 end-of-life date, it applies the last cumulative fixes from the vendor.
  • Review firewall rules for SRM ports (usually TCP 8095 for those appliances). Tighten to allow only vCenter and replication traffic.
  • Disable or remove any unused recovery plans or test networks to reduce the attack surface.

Document exposure for auditors and insurers — by week 4

Risk registers and compliance frameworks often require explicit tracking of end-of-life components. You will need:

  • A list of every SRM 8.7 instance, its location, and the business-critical recovery plans it supports.
  • A note that the product is past end-of-life as of October 11, 2025, and that no vendor patches are available.
  • A mitigation statement showing compensating controls (network isolation, access controls, monitoring, backup of SRM appliance config).
  • A planned migration date (realistic, typically 6–12 months out).

Do not wait for an auditor to ask for this. Having it ready before October 11 shows due diligence and may satisfy insurance or regulatory requirements.

Secure a support contract for day one after end-of-life

When vendor support ends, you have two options:

  1. Upgrade to a supported SRM version (e.g., 8.8.x or later) before October 11 — only realistic if you have a small estate and can execute a rapid migration.
  2. Contract for third-party support to cover SRM 8.7 after the vendor date.

Third-party support from 3rd Party Support can provide:

  • Critical bug fixes and patches for vulnerabilities discovered after October 11.
  • Technical support against documented SLAs.
  • Lifecycle extensions while you plan and execute a methodical upgrade.

This approach eliminates the pressure to rush an upgrade and lets you move at a pace that matches your change-window availability.

Week-by-week action checklist

Timeframe Action Owner
Week 1 Inventory all SRM 8.7 appliances, recovery plans, and replication configs. Record build version. Infrastructure team
Week 2 Upgrading to SRM 8.7.0.4 (if not already on that build). Platform engineering
Week 3 Network isolation: restrict SRM appliance access, block outbound internet, tighten firewall rules. Network/security team
Week 4 Draft documentation: list all SRM 8.7 instances, compensating controls, planned migration date. Share with compliance officer. Operations / compliance
Week 5 Engage third-party support provider to ensure coverage begins right after October 11. Procurement / IT leadership
Week 6 Run a recovery plan test on isolated SRM 8.7 environment to confirm hardening hasn't broken failover. DR team
Week 7–8 Finalize risk-register entry and submit to internal audit or insurer for review. Compliance
Week 9–12 Begin migration planning to a supported SRM version. Set realistic timeline (3–12 months). DR team / IT leadership

What to do if you cannot complete everything before October 11

Even if you follow the checklist, some tasks may slip. The two non-negotiable items that must be completed before October 11 are:

  1. Inventory — you must know where SRM 8.7 is running.
  2. Third-party support contract — so you have some form of coverage from October 12 onward.

Hardening and documentation can follow days or weeks after the end-of-life date, but you should not operate without any support contract in place.

Final recommendation

VMware SRM 8.7’s October 11, 2025 end-of-life is a known, immovable date. Don’t rely on a last-minute upgrade that will likely fail under the pressure of production recovery plan testing. Instead, use the next 90 days to systematically inventory, isolate, and document your environment while securing a third-party support contract to maintain coverage from day one of end-of-life.

Contact us today to discuss how third-party support can keep your SRM 8.7 estates safe, patched, and compliant while you plan a controlled migration.

How we can help

Keep it supported after end of life

The vendor's date doesn't have to be yours. Our engineers keep VMware Site Recovery Manager 8.7 running after official support ends — independent third-party support that covers most operational issues, typically at 40-70% below the last renewal quote.

VMware software support →

Migration services

When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.

Migration & hybrid cloud services →

24×7 remote administration

Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.

24/7 operations & remote administration →

Talk to a support specialist

Speak with an engineer, not a sales rep. We respond within 24 hours.

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.