Unsupported Software Findernotice of vendor support

HPE Zerto end of life dates

The support dates the endoflife.date record (community-maintained) holds for HPE Zerto, read on 30 Sep 2026: when security support ends for each version (cycle), when active support ends, and extended support where the record shows it. Below them, what Cyber Essentials, the Essential Eight, CIS Controls v8, PCI DSS and NIST SP 800-53 ask of a version past its end.

Oldest version still in support
10.0_u6 (10.0 Update 6), security support to 3 Dec 2027
Next end date
10.0_u7, security support ends 6 May 2027
Vendor's own notice
the vendor lifecycle policy for HPE Zerto, authoritative; each version below links its own notice where the record carries one
Record
HPE Zerto
Kind
application
Versions in the record
22
Versions past vendor support
17
Essential Eight class
an application outside the priority classes: Patch applications asks for its removal once no longer supported at ML3; at ML1 and ML2 no held Essential Eight clause turns on it.
Source
endoflife.date/zerto, community-maintained, MIT licence, read 30 Sep 2026; sources

HPE Zerto versions and their support dates

as at 30 Sep 2026
CycleReleasedActive support endsSecurity support endsExtended support endsOn the read dateVendor notice
10.913 May 202613 May 202713 May 2028none in the recordsupportednotice
10.8.113 Mar 20263 Mar 20273 Mar 2028none in the recordsupportednotice
10.828 Oct 202528 Oct 202628 Oct 2027none in the recordsupportednotice
10.0_u7 10.0 Update 76 May 20256 May 20266 May 2027none in the recordsecurity fixes onlynotice
10.0_u6 10.0 Update 63 Dec 20243 Dec 20263 Dec 2027none in the recordsupportednotice
10.0_u5 10.0 Update 56 Aug 20243 Dec 20246 Aug 2026none in the recordpast vendor supportnotice
10.0_u4 10.0 Update 415 May 20246 Aug 202415 May 2026none in the recordpast vendor supportnotice
10.0_u3 10.0 Update 312 Feb 202415 May 202412 Feb 2026none in the recordpast vendor supportnotice
10.0_u2 10.0 Update 228 Nov 202312 Feb 202431 Dec 2024none in the recordpast vendor supportnotice
10.0_u1 10.0 Update 17 Aug 202328 Nov 20237 Aug 2024none in the recordpast vendor supportnotice
10.05 Jul 20237 Aug 20235 Jul 2024none in the recordpast vendor supportnotice
9.78 Nov 202231 Dec 202331 Dec 2024none in the recordpast vendor supportnotice
9.55 Apr 20221 May 20231 May 2024none in the recordpast vendor supportnotice
9.013 Jul 20211 Aug 202215 Oct 2023none in the recordpast vendor supportnotice
8.51 Nov 20201 Jan 20221 Jan 2023none in the recordpast vendor supportnotice
8.022 Mar 202031 May 20211 Jun 2022none in the recordpast vendor supportaddress held, not linked
7.522 Sep 20195 Dec 20206 Dec 2021none in the recordpast vendor supportaddress held, not linked
7.026 Apr 201930 May 202030 May 2021none in the recordpast vendor supportnone in the record
6.516 Sep 201830 Oct 201930 Oct 2020none in the recordpast vendor supportnone in the record
6.015 Feb 201830 Mar 201930 Mar 2020none in the recordpast vendor supportnone in the record
5.531 Jul 201730 Sep 201830 Sep 2019none in the recordpast vendor supportnone in the record
5.08 Nov 201631 Aug 201831 Aug 2018none in the recordpast vendor supportnone in the record

A version this table does not list is not in the record: the finder reads it as unknown, never supported. The dates are the record's own; nothing here states a date the record does not hold.

What the schemes ask of a version past its end

Cyber Essentials
software on in-scope devices licensed and supported by the vendor, meaning it still receives security updates; unsupported software removed or segregated (SU.1, SU.4). Cyber Essentials Plus: removed, or isolated with compensating controls (PM-02).
Essential Eight
An application outside the priority classes: Patch applications asks for its removal once no longer supported at ML3; at ML1 and ML2 no held Essential Eight clause turns on it.
CIS Controls v8, Safeguard 2.2
only software that still receives vendor support may be marked authorised; unsupported software kept for the mission needs a recorded exception with compensating controls and the acceptance of the remaining risk; support status checked at least monthly.
PCI DSS 12.3.4
hardware and software reviewed at least every 12 months: that vendors still supply timely security fixes, end-of-life announcements documented, and a remediation plan for outdated technology approved by senior management.
NIST SP 800-53 SA-22
system components replaced when support is no longer available from the developer, vendor or manufacturer, or alternative sources of continued support provided.

See the specimen list runCheck your own list