Third-party support FAQ
Nearly 30% of the enterprise software running in production today is already past its vendor’s end-of-support date — and that share is growing every year. Running end-of-life software and hardware is completely normal; what’s dangerous is running it unsupported. Third-party support keeps your proven systems secure, patched, compliant and covered 24x7 — so you can keep them running on your own timeline instead of being forced into an upgrade you don’t need. Below is how it works.
Out-of-support software and hardware is a compliance problem
Almost every major security and compliance framework requires the same thing: known vulnerabilities in your systems must be remediated in a timely way, usually with vendor security patches. The moment a vendor ends support, those patches stop — so an unsupported system can’t meet that requirement on its own, and auditors treat it as a finding. Crucially, the standards below don’t forbid running end-of-life technology; they require you to compensate for it with documented, risk-based controls. That is exactly what third-party support provides: virtual patches, configuration mitigations, backported open-source fixes, and a written security management plan that gives an auditor the evidence they’re looking for.
PCI DSS 4.0
Requirement 6 says you must keep systems protected against known vulnerabilities and install applicable vendor security patches promptly. Where software is no longer vendor-supported, PCI DSS requires a documented plan of compensating controls to keep using it. No patches and no plan means a failed assessment. Third-party support supplies both the mitigations and the documentation.
HIPAA Security Rule
The risk-management and system-protection safeguards (45 CFR §164.308) require covered entities to identify and reduce vulnerabilities in systems handling ePHI to a reasonable level. Running unpatched, unsupported software with no mitigating controls is a textbook risk-analysis failure. A third-party security management plan documents how each risk is addressed.
ISO/IEC 27001:2022
Annex A control 8.8, management of technical vulnerabilities, requires you to obtain vulnerability information and take timely action. When the vendor stops issuing fixes, you need another source of remediation and evidence of it. Third-party support is that source, and the security plan is the auditable record.
SOC 2
The Trust Services Criteria — notably CC7.1 — require you to detect vulnerabilities and remediate them. An end-of-life system with no patch path and no compensating controls is a common exception in SOC 2 reports. Third-party virtual patching and mitigations close the gap and produce the evidence your auditor and customers expect.
NIST SP 800-53 / Cybersecurity Framework
Control SI-2 (flaw remediation) and the CSF Protect function require identifying and correcting system flaws, or applying compensating controls where correction is not possible. Unsupported software fails SI-2 outright unless a third party is remediating on your behalf — which is precisely the model third-party support provides.
Out-of-support software: your questions answered
How common is it to run software past end of support?+
Very common. Nearly 30% of all enterprise software in production is already out of vendor support, and that number grows every year as vendors accelerate end-of-life cycles. The systems keep working perfectly well — the vendor simply stops supporting them. The real question is not whether to run end-of-life software; it is whether to run it with a proper support plan behind it.
Is it safe to run out-of-support software without third-party support?+
No. Once a vendor ends support, security patches, bug fixes and expert help stop — but your compliance obligations and your attackers do not. Unsupported production software is one of the most common root causes of breaches and failed audits. Running end-of-life software is fine; running it unsupported is the risk. A third-party support plan closes that gap so you can keep proven systems in place safely and on your own timeline.
How does security patching work for software the vendor no longer updates?+
We analyse every relevant vulnerability individually and build a remediation plan for your environment. Depending on the issue and your licensing, that can mean a virtual patch at the network or host layer, mitigation through product or configuration settings, applying a vendor-permitted patch to their code where your end-user licence agreement allows it, or — for open-source components — reviewing each new upstream release, validating the fix against your current version and backporting it. Every environment gets a written security management plan built around your compliance requirements, architecture, risk profile and vendor licence restrictions.
Is support really 24x7?+
Yes. Every end-of-life support agreement we provide includes 24x7 product support as standard. Mission-critical systems do not keep office hours, so neither do we — you reach engineers who know your environment, not a call centre reading a script.
How does third-party support compare to vendor support?+
In our customers’ experience, favourably — which is why so many of them choose to stay with us. We tend to be far more responsive than a vendor support desk, and we help well beyond the narrow scope a vendor will typically cover, working your actual environment and the real problem in front of you rather than a scripted list of supported scenarios. The best way to judge it is to hear it first-hand: just ask, and we will happily put you in touch with existing customers who can tell you why, in many cases, third-party support turned out to be the right way to go.
Can you take us on if our system is already down?+
Generally, no — and it is important to be honest about that. Onboarding an environment into third-party support involves hundreds of steps across our engineering, development, security-operations and licence-management teams before we can support it safely. That work cannot be compressed into an outage. We do offer critical-system-down support to assess an emergency and see whether we can help your specific situation, but the right time to arrange support is before you need it, not during an incident.
Do you provide software downloads or installation media?+
No. We do not provide downloads or installers of any kind. Maintaining an archive of your own licensed software and media is the client’s responsibility. If you are currently under vendor support when you come to us, we can help make sure you have everything archived before that support lapses — but we cannot supply media you do not already hold a licence for.
If we stop renewing support, do our software licensing obligations stop too?+
No — and this catches a lot of teams out. Dropping vendor support does not switch off your underlying licensing obligations; those typically keep running for as long as the software is installed. Metric-based and sub-capacity licensing in particular — for example IBM’s ILMT (License Metric Tool) reporting — still has to be measured and reported, your entitlements still have to be tracked, and the vendor keeps the right to audit you. We help you stay on top of all of it: keeping license metrics measured and documented and your deployment inside entitlement, so an unsupported estate never turns into an unexpected licensing bill or a failed audit.
What are your SLAs and how do we reach support?+
We provide support over web, phone and live chat. Specific response and resolution SLAs vary by product and by your requirements — a break/fix estate has different needs from a mission-critical transaction platform. Tell us what you are running and how critical it is, and we will confirm the SLA options we can offer for your environment.
Can you support hardware or software that is still under vendor support?+
Yes. You do not have to wait until the vendor declares end-of-life to move to us. The main trade-off is that leaving vendor maintenance means giving up direct access to vendor patches — but for a defined period that is a common and sensible choice. A typical example is a migration: you no longer need to pay for full vendor support, you just need experienced engineers on hand to help if something goes wrong during the transition. Tell us your timeline and we will cover you for exactly as long as you need.
Can you help us migrate off the platform instead?+
Yes. Many clients use third-party support to buy the time and stability to migrate on their own terms rather than the vendor’s. Our engineers and developers deliver a wide range of migrations, covering target architecture, cost management and the actual cutover — so you move when it makes business sense, not when a support deadline forces you.
Do you handle day-to-day administration and management?+
Yes. Every package includes management as standard. We can work alongside your team to help you operate the system, or run it fully on your behalf. A big part of avoiding end-of-service disasters is simply making sure the system is administered and running properly day to day — so that is built into every plan, not sold as an extra.
Hardware maintenance: your questions answered
How long does it take to get replacement parts?+
It depends on your location and the severity of the situation. In and around major cities we stock parts locally for fast, often same-day replacement. For remote sites, parts are typically flown into the nearest local airport. Give us your site address and we will quote realistic replacement times for each location in your estate.
Do you support hardware the manufacturer has declared end-of-service-life?+
Yes — that is the core of what we do. When an OEM declares hardware end-of-service-life, the equipment does not stop working; the support does. We keep servers, storage and network gear running reliably well beyond the vendor’s end-of-service-life date, so you can hold on to proven, working hardware for as long as it serves you.
Can you cover multiple vendors under one contract?+
Yes. We support Cisco, Dell EMC, HPE, IBM, NetApp, Juniper, Oracle and more under a single agreement, with one point of contact for your whole estate — instead of juggling separate OEM contracts and renewal dates.
What on-site response times can you offer?+
On-site SLAs are tailored to each site and its criticality, from next-business-day through to same-day and 4-hour response backed by local spare-parts depots. Share your locations and coverage requirements and we will confirm what we can offer for each.
Are there any repairs you cannot carry out?+
Rarely. In a small number of cases a specific vendor restriction or local law can prevent a particular repair, and where that happens we stay fully compliant with every legal and licensing term and move to an approved alternative plan instead. This is exactly why onboarding matters: as we bring a customer on, we document the third-party support arrangement and operational runbooks for every situation, so if any individual repair is off-limits a tested backup plan is already in place. In practice it very rarely comes up — and whatever the situation, you are never left without a path forward.
Tell us what you’re running
Whether it’s a single end-of-life server or an entire estate of legacy software, we’ll put together a support and security plan that keeps it running safely — on your timeline, not the vendor’s.
Get in touch