Talk to us

1.
TLDR

  • Umbraco 13 reaches end of life on 14 December 2026. After that, it gets no security patches under standard support.

  • Your site will keep working, but it'll be harder to tell auditors, insurers, customers and regulators that your systems are supported.

  • Cyber Essentials requires in-scope software to be vendor-supported. ISO 27001, UK GDPR and FCA rules all expect known risks to be managed.

  • Upgrading to Umbraco 17 LTS is the long-term answer. Umbraco's XLTS can buy up to two years of security patches if you need more time.

If your website runs on Umbraco 13, there's one date that matters this winter: 14 December 2026, when Umbraco 13 reaches end of life.

For organisations that are regulated, accredited or regularly scrutinised by insurers and customers, this is no longer just an IT maintenance issue. With only weeks remaining, it's a business risk that needs an owner, a decision and a plan before December.

In our experience, organisations still on Umbraco 13 fall into one of three groups: those who've started or planned their upgrade, those looking at interim support, and those hoping it won't really matter. If your organisation is still in the third group, October is the point at which doing nothing starts to become a decision in itself.

2.
What actually happens on 14 December?

There's a lot of overstatement around end-of-life software, so it's worth being clear about what changes.

From 14 December, Umbraco stops releasing security patches and technical support for Umbraco 13 under standard support. Your website won't stop working. What changes is that newly discovered vulnerabilities won't be fixed unless you've put extended support in place.

3.
“It’s working fine, we’ll be OK” isn’t enough…

The risk isn't that your site falls over on 15 December. It's that you lose the ability to say, with certainty, that your systems are supported and patched.

For many businesses, that statement matters a great deal. It appears in accreditation assessments, audit evidence, insurance proposal forms, supplier security questionnaires and, for regulated firms, in what regulators expect of your systems and controls. Running unsupported software doesn't automatically mean you've breached anything, but you'll need a good answer when someone asks.

4.
Where the questions will come from

  • Cyber Essentials. The scheme's requirements say software in scope must be licensed and supported by the vendor. Unsupported software must be removed or moved out of scope. If your website and its hosting fall within your certification boundary, an unsupported CMS is a problem you'll need to resolve before your next assessment.

  • ISO 27001. Annex A control 8.8 covers the management of technical vulnerabilities. An auditor won't fail you simply because unsupported software exists. They will, however, expect to see that the risk has been identified, assessed and treated, and that someone with authority has made a decision.

  • UK GDPR. Article 32 requires "appropriate technical and organisational measures" to protect personal data. If your site collects enquiries, quotes, applications or account details, consider how easy it would be to argue that knowingly running unpatchable software was appropriate, particularly after an incident.

  • FCA-regulated firms. The FCA expects firms to organise and control their affairs responsibly, with adequate risk management systems (Principle 3 and the SYSC requirements). The Consumer Duty adds a focus on avoiding foreseeable harm to customers. Firms within scope of the operational resilience rules have additional obligations around vulnerabilities in important business services. None of this names a CMS version. But a regulated firm that has been told about an end-of-life platform and chosen to do nothing will find that decision difficult to defend.

  • Insurers and customers. Cyber insurance proposals and renewals commonly ask about unsupported software. So do the security questionnaires larger customers and public sector buyers send to suppliers. Those forms usually carry a signature. At that point there are only two answers: say the software is supported when it isn't, or put in writing that you're knowingly running it unsupported. Neither is a comfortable thing to sign.

We asked Fresh Egg's retained lawyers, Acumen Law, how they'd view this from a legal standpoint:

End-of-life software isn’t unlawful in itself, but it changes the question a business will be asked after an incident.

Regulators, insurers and courts look at what you knew and what you did about it. Once a vendor has announced an end-of-life date, the risk is known. Boards should make sure there’s a clear, documented decision about how it’s being managed, made by someone with the authority to make it. Drifting past the deadline without one is the position that’s hardest to defend.

Alvin Ittoo

Partner & Head of Corporate

Acumen Law

5.
Your three options

There are three realistic routes available. For most organisations, upgrading is the right long-term answer. The other two are ways of managing the position if an upgrade can't be completed in time.

  1. Upgrade. This should now be the default plan. Moving to Umbraco 17 LTS or above restores vendor support and security patching, and gives you a much easier answer for auditors, insurers and customers. It also resets the clock for several years. The cost depends on how customised your site is, but for many sites it's a contained, predictable project.

  2. Extended support (XLTS). If an upgrade can't happen before December, Umbraco offers Extended Long-Term Support for Umbraco 13, with 6, 12 or 24 months of critical security patches. It covers security only, with no new features, and coverage has to start the day after end of life and run continuously. It isn't a permanent answer, but it gives you something credible to say while an upgrade is planned and budgeted.

  3. Accept the risk, formally. This is a legitimate choice in some frameworks. ISO 27001, for example, allows a documented risk acceptance. But it isn't a universal answer. Cyber Essentials doesn't permit it: unsupported software must be removed or taken out of scope. Formally accepting the risk also doesn't change what you'll have to say on an insurance proposal or a customer's security questionnaire. If you go this way, it should be a recorded decision, signed off at the right level, with the reasoning documented in your risk register. In our experience, few directors are comfortable putting their name to "we knowingly accept running unpatched software on a customer-facing system". That discomfort is usually a useful signal.

6.
Questions to ask internally this month

  • Is our website within the scope of our Cyber Essentials or ISO 27001 certification?

  • When are our next assessment, audit and cyber insurance renewal, and what will we be asked?

  • Does our site handle personal or financial data, and what would a breach look like?

  • Who in the business has the authority to accept this risk, and do they know it exists?

  • Have we budgeted for an upgrade, and what is our timeline if we start now?

7.
How Fresh Egg can help

If you're still running Umbraco 13, the first step is to establish how exposed you are and how much work an upgrade will actually involve.

As an Umbraco Platinum Partner, Fresh Egg can carry out an Umbraco 13 upgrade assessment covering your current platform, customisations, integrations, hosting and likely migration effort. We'll give you a clear view of the work required, realistic timescales and your options if the upgrade can't be completed before December.

The date isn't moving. The sooner you make a decision, the more options you have.

Speak to our Umbraco development team now

Don't wait, get an upgrade plan in place before support ends.

Talk to us about Umbraco upgrades

Get Fresh Thinking in your inbox

Get expert insights, event invites, and practical guides on digital marketing - every fortnight, in our newsletter.

This site is protected by reCAPTCHA.
You may unsubscribe from these communications at any time. Please review our Privacy Policy.