End-of-Life Network Devices: The Compliance Risk in 2026

August 2026 Security & VAPT Compliance & Frameworks Security, Network, Firewall, VAPT, India

The Firewall Nobody Wants to Touch Is Also the One Nobody Can Patch

Every enterprise network has one: the branch firewall that has been running since a previous IT manager's tenure, the access switch stack nobody wants to reboot, the wireless controller running a software train the vendor stopped maintaining two release cycles ago. These devices work — until the day a critical CVE is disclosed against exactly the platform they're running, and the honest answer is that no fix is coming because the vendor stopped shipping updates for that hardware years ago.

That is what end-of-life (EOL) actually means in practice. Not "old" in some vague sense, but a specific, dated point after which the vendor no longer issues software or security updates for the platform. Every vulnerability disclosed after that date stays open on your network indefinitely, and no amount of internal patching effort can close it — because there is nothing left to patch it with.

Why This Became a Compliance Question, Not Just a Technical One

Running unsupported infrastructure used to be a risk-management conversation between IT and the business. In 2026, for a growing share of Indian enterprises, it is a compliance conversation with a regulator or a customer's audit team.

  • DPDP Act 2023. If personal data traverses a device with a known, unpatched vulnerability, a breach through that device is a data-protection incident like any other — with the same notification obligations to the Data Protection Board and affected individuals as a breach through any other system.
  • CERT-In directions. The 6-hour incident-reporting mandate does not distinguish between a breach through current infrastructure and a breach through equipment that stopped receiving vendor fixes three years ago. An EOL device that gets exploited is still a reportable incident on the same clock.
  • RBI and sector regulators. BFSI IT-governance frameworks increasingly expect a documented technology lifecycle position for network and security infrastructure — not just for core banking systems, but for the firewalls and routers that sit in front of them. "We didn't know it was end-of-life" is not a defensible answer in an audit.
  • Customer security questionnaires and cyber insurance. Enterprise procurement and insurance renewal increasingly ask directly whether network infrastructure is under active vendor support. Unsupported hardware is now something you have to declare, not just manage quietly.

How Estates Drift Into This Without Anyone Deciding It Should

Nobody sets out to run an unsupported firewall in production. It happens through a series of individually reasonable decisions: a device that was working fine got deprioritised behind projects with visible deadlines, a support renewal lapsed and the invoice never got escalated, or the team that deployed the device moved on before its lifecycle milestones were ever documented anywhere. Multiply that across a multi-site, multi-vendor estate and the result is a set of devices whose exact software version, support status and end-of-support date nobody can currently state with confidence.

That is precisely the gap a network device health check is designed to close — establishing, device by device, current software version, hardware condition, support entitlement and lifecycle position, so the answer to "are we running anything unsupported" is a documented fact rather than a guess.

What to Do Once You Know the Answer

  • If the device is still within its support window but behind on software: a controlled firmware or software upgrade closes the gap — assessed, backed up and validated in a planned maintenance window, not a rushed emergency change.
  • If a specific advisory applies to your installed base: that is a patch management exercise — mapping the CVE against your actual estate and scheduling the fix by real exposure, not by severity score alone.
  • If the device is genuinely past end-of-support: that is an EOL/EOS management conversation — mapping the estate against published vendor milestones and planning a refresh before, not after, the next advisory lands on hardware with no fix available.
  • If a VAPT or scanner has already flagged the device: that finding needs to become a costed, sequenced remediation plan, not a line item that sits open until the next audit repeats it.

eNeoteric's Network & Security Device Lifecycle Management practice covers exactly this ground for multi-vendor estates across India — assessment, firmware and software upgrades, security patching, EOL/EOS tracking and remediation, delivered alongside our VAPT and threat intelligence services. Fortinet estates specifically can check their own exposure with our FortiGate EOL checker. For a scoped view of what's actually running in your environment, request a network device upgrade assessment or contact us.

Explore all ← Back to Insights

View all Insights