HomeCisco HubAnyConnect 4.x EoS
Cisco  |  AnyConnect EoS Buyer Guide 2026

AnyConnect 4.x has been running without patches since 31 March 2024, and the 31 March 2027 date only removes the TAC case you can no longer open

Cisco split the AnyConnect 4.x end-of-life into two dates: software maintenance stopped on 31 March 2024, and application software support stops on 31 March 2027. The security exposure already landed three years before the headline deadline, and the upgrade to Secure Client 5.x carries no additive charge for anyone with an active term license, an active service contract, or indirect entitlement through a Cisco service such as most Umbrella packages. If your account team is quoting migration licenses against the 2027 date, that quote is the negotiation, not the deadline.

Prepared by Redress Compliance · September 4, 2026 · Cisco advisory. Secure Client migration and EA renewal engagements, 2024 to 2026.

Executive summary

The real deadline passed on 31 March 2024, not 31 March 2027.

Cisco's EoS/EoL announcement states that no patches or maintenance releases will be provided for AnyConnect 4.x after 31 March 2024, so every 4.x endpoint in your estate has been carrying unremediated client-side vulnerabilities for roughly two years already.

And the 2027 date only closes the TAC ticket.

The upgrade to Secure Client 5.x costs zero additive dollars, and Cisco says so in writing.

The EoL bulletin confirms that customers with valid term licenses or perpetual licenses under active support are eligible for the current release at no charge.

And that there is no additive charge for anyone entitled to use AnyConnect indirectly through another purchased Cisco service, which explicitly includes most Umbrella packages.

The 3.x precedent shows Cisco will not move the date, and the gap structure is identical.

For AnyConnect 3.x, maintenance ended 1 March 2016 and application software support ended 31 March 2018, a two-year gap with the same obsolescence language; expect the same discipline in 2027 and stop planning around an extension that will not arrive.

The money moves in the tier and the term, not in the migration itself.

Advantage maps to the old Plus and Essentials SKUs while Premier maps to Apex, Premium and Premium Shared, and if you run ISE Posture, Network Visibility Module, or the Management VPN Tunnel you cannot drop to Advantage; the 12- to 60-month subscription range is where you lock pricing past 2027.

31 Mar 2024
Date AnyConnect 4.x stopped receiving any patch or maintenance release from Cisco.
31 Mar 2027
Application software support ends; product becomes obsolete and all support services stop.
$0
Additive charge Cisco states for upgrading entitled AnyConnect users to Secure Client 5.x.
60 months
Maximum Secure Client subscription term, the main lever for pricing lock past 2027.
1.

The two dates Cisco set, and what each one actually removes

Cisco published the AnyConnect 4.x end-of-life bulletin on 30 May 2023, and that same date closed new orders.

Everything after it is a two-stage withdrawal, and the stages remove very different things. Software maintenance ended 31 March 2024: from that day Cisco stopped producing patches and maintenance releases for 4.x.

In plain terms, any CVE disclosed against the 4.x client after March 2024 has no vendor fix and never will. Application software support ends 31 March 2027: that date removes your ability to open a TAC case and receive assistance on the client, and it marks the product obsolete.

The second date is the one on every account team's slide, but the operational damage was done on the first one. A shop running 4.x today is not approaching an exposure, it has been carrying an unpatchable endpoint agent for over two years.

There is a third date buried in the same window that Umbrella customers routinely miss: the Umbrella roaming security module for AnyConnect 4.x also lost maintenance on 31 March 2024, and Cisco Umbrella has provided no updates of any type for the 4.x module since.

Umbrella can push a one-time cloud update to Secure Client 5.0, but cloud-distributed updates are opt-in, so nothing happens unless somebody enables it.

MilestoneDateWhat stopsBuyer exposure
Bulletin published, end of sale30 May 2023New 4.x ordersNon-orderable for roughly three years; no clean growth path on 4.x
End of software maintenance31 March 2024Patches and maintenance releasesUnpatchable VPN client; post-2024 CVEs have no vendor fix
Umbrella roaming module maintenance ends31 March 2024All Umbrella updates to the 4.x moduleSecond, separate exposure for Umbrella shops; one-time cloud update to 5.0 is opt-in
End of application software support31 March 2027TAC cases and all support servicesProduct formally obsolete; no vendor assistance, contractual or otherwise

The table hides the precondition that decides whether any of these dates apply to you at all. Cisco's language is that software maintenance and application software support require an active term license, or an active service contract for perpetual licenses.

Support is not a calendar entitlement, it is a contract entitlement gated by the calendar. If your perpetual Plus or Apex service contract lapsed in 2022, you lost support in 2022 and 31 March 2027 changes nothing for you.

This cuts both ways in a negotiation. It is the reason a vendor rep can honestly say you are unsupported today, and it is also the reason the same rep cannot claim 2027 forces a purchase: reinstating or maintaining the contract is the trigger, not the deadline. The 3.x precedent is instructive.

Maintenance ended 1 March 2016, application software support ended 31 March 2018, identical language, identical two-year gap, and no extension was granted. Plan on 31 March 2027 holding.

2.

The no-charge upgrade clause and why quotes still arrive with migration line items

The strongest sentence available to a buyer in this entire end-of-life sits in Cisco's own bulletin: there is no additive charge to adopt the current version of Cisco Secure Client for any customer entitled to use AnyConnect either directly or indirectly through another purchased Cisco service.

Direct entitlement is a valid term license, or a perpetual license with an active support contract. Indirect entitlement is the clause account teams skip, and it explicitly covers most Cisco Umbrella packages plus other Cisco services that bundle client use for that use case.

If you hold Umbrella and have been quoted Secure Client Advantage licenses purely to get off 4.x, the quote is contradicting the vendor's published bulletin, and you should say so in writing rather than in a call.

Evidence the position from your Smart Account before you respond: pull the license inventory and the service contract status for the relevant Smart Account and virtual accounts, capture the term end dates, capture the Umbrella subscription line, and attach that export to your reply.

Our working pushback wording is short: "We are entitled directly or indirectly per the AnyConnect 4.x EoL bulletin, so please remove the migration line items and reissue at zero for the client upgrade.

We will discuss tier changes separately." Separating those two conversations is the whole game, because the real revenue event is not migration, it is the Advantage versus Premier tier decision, and blending them lets the seller charge for the free part.

One genuine exception deserves respect rather than argument: the support contract generated with Cisco Secure Access licenses the client only for Secure Access use, and any other use case, including Secure Client against on-prem ASA or FTD headends, requires a separate Secure Client license.

If your headends are on-prem, Secure Access entitlement will not carry you, and pretending otherwise costs credibility. Before you send anything, confirm your own position against the no-charge upgrade entitlement checks.

Free white paper

Cut your Cisco collaboration cost across the Webex stack

How to cut Cisco collaboration cost across Webex Suite, Calling, and Contact Center: the Flex Plan math and the contract levers that hold at renewal.

Get the white paper →
3.

Cisco did not extend the deadline; it moved the price into the tier

Read finding 8 carefully and the strategic logic falls out immediately: Cisco is giving away the door and charging for the room behind it.

There is no additive charge to adopt the current version of Secure Client for any customer entitled to use AnyConnect directly or indirectly, and that language is deliberate.

A vendor that intended to monetise the migration itself would have written a conversion SKU into the EoL bulletin, as it has done on other product lines. It did not. The revenue event was never the upgrade binary.

It is the tier your estate lands in once the binary is installed and the entitlement is re-papered under the Advantage and Premier taxonomy.

That taxonomy is the actual price event. Advantage covers device and per-app VPN, third-party IKEv2 headend support, trusted network detection, basic device context, FIPS compliance, the Network Access Manager 802.1X supplicant, and the Umbrella roaming module.

Premier adds endpoint Posture or ISE Posture, Network Visibility Module, next-generation VPN encryption including Suite B, and the Management VPN Tunnel. Those four Premier-only capabilities are not exotic.

In our engagement base they are the default build for any enterprise that stood up ISE for network access control, any regulated shop that specified Suite B, and any organisation that pushed a Management VPN Tunnel so that pre-login machine policy would apply.

If you run any one of them, Premier is functionally mandatory and the Advantage price is a number you will never be allowed to pay. Cisco does not have to argue you into the higher tier. Your existing architecture already made the argument.

The second, quieter price move sits in finding 16. The new model eliminates the need to purchase per-headend concurrent licenses. That reads as simplification and is often sold as savings. It is a change to the counting basis.

Legacy Plus and Apex estates were frequently sized against concurrent sessions on a per-headend basis, which is a number that peaks well below headcount because not everyone connects at once. Advantage and Premier are counted against covered users.

A 12,000-employee organisation that sized 4,000 concurrent for the ASA pair is now being asked, structurally, to license somewhere between the population that actually has remote access provisioned and the entire employee base, depending on who does the counting and how casually.

That is not a rate increase. It is a quantity increase that never appears as an increase on any line item, because the unit changed underneath it.

Layer CCW dynamic band pricing on top and the third distortion arrives.

Two quotes for materially the same estate can differ substantially on data entry alone: the quantity entered drives the band, the band drives the unit price, and the unit price then multiplies against a quantity nobody independently validated.

We have seen the same customer receive two proposals inside one quarter that diverged because one account team entered total employees and the other entered provisioned VPN users. Neither team was acting in bad faith.

The tooling rewards the larger number, and nothing in the workflow asks whether the larger number is correct.

This is where the 2027 date earns its keep for Cisco. The deadline does not create the price. It compresses the window in which you might interrogate it.

A security team that discovers in late 2026 that its VPN client will be unsupported in ninety days will accept whatever tier and quantity the account team puts in front of it, because the alternative is an unsupported remote access path into production.

Urgency is the mechanism that keeps the tier question and the quantity question unexamined. Note also that the real security exposure landed on 31 March 2024, when patches stopped.

Any account team framing 2027 as the moment risk begins is inverting the timeline in a way that happens to favour a rushed signature.

The sequencing conclusion is unambiguous. Do the counting audit before the tier decision, not alongside it and never after it.

Establish the defensible covered-user population, reconcile it against provisioned accounts rather than headcount, and only then determine which portion of that population genuinely touches ISE Posture, NVM, Suite B or the Management VPN Tunnel.

A mixed estate can be split, and the Advantage versus Premier tier decision is not required to be uniform across the whole user base. Deciding tier first fixes the unit price against a quantity you have not yet defended, which is precisely the order the quote arrives in.

Watch the briefing · 4:36Cisco and Splunk, Part 1: Talking Points on the Attach Machine and True ForwardHardware pulls subscriptions, subscriptions pull suites, suites pull the Enterprise Agreement, and True Forward ratchets the counts. The talking points from the VendorBenchmark Cisco playbook: the three buyer advantages, what changed, the tier math on 8,000 devices, the Splunk meter, support, and the refresh as currency.Open the full page, with the transcript →
4.

The SKU trap map: Plus, Apex, VPN Only, and Premium Shared

The mapping itself is documented and not contentious: Advantage is the analogue of the previous AnyConnect Plus and Essentials licenses, and Premier is the analogue of Apex, Premium and Premium Shared.

What the ordering guide does not flag is that the mapping is where the reconciliation errors live, because legacy estates rarely hold one clean SKU family. The trap that costs the most is Secure Client VPN Only.

It cannot be used with Apex or Plus, so a shop sitting on residual legacy inventory cannot layer the cheaper VPN Only SKU on top of what it already owns and call that the migration path. Either the legacy inventory is retired and the estate moves wholesale, or VPN Only is off the table.

Separately, remote access VPN is technically gated: you cannot deploy the configuration to a device lacking entitlement for Advantage, Premier or VPN Only, so entitlement gaps surface as licensing alerts and health events rather than as invoices, which is why they get discovered late.

Legacy holdingMaps toTrap to check before you sign
AnyConnect PlusSecure Client AdvantageAdvantage available as perpetual as well as 12 to 60 month subscription; confirm which you are being quoted
AnyConnect EssentialsSecure Client AdvantageOften undercounted in inventory; verify against Smart Account, not the PO history
AnyConnect ApexSecure Client PremierVPN Only cannot be layered on top; no cheap downgrade path exists
AnyConnect PremiumSecure Client PremierConcurrency-based counting disappears; quantity basis shifts to covered users
AnyConnect Premium SharedSecure Client PremierShared pool logic does not carry over; license sharing must be enabled in the Smart Account
Umbrella indirect entitlementNo additive chargeMost Umbrella packages already entitle the client; reject migration line items

The row that decides the negotiation is not any single mapping, it is the interaction between the Apex row and the VPN Only exclusion. Buyers holding Apex assume a downgrade exists because Premier looks expensive next to VPN Only. It does not, and the exclusion is enforced, not advisory.

Your leverage on an Apex-heavy estate comes from quantity and term, not from tier substitution.

Before any of this can be executed, three Smart Account preconditions have to be true: license sharing enabled if you are replacing a Premium Shared pool, export-controlled strong encryption enabled if Suite B or FIPS builds are in scope.

And expiry-driven alerting configured so entitlement lapses surface as health events rather than as a Monday morning outage.

Confirm all three against the no-charge upgrade entitlement before the quote is scored.

5.

What we see in the field: recurring patterns from 2024 to 2026 engagements

3 of 4
Quotes that contradict the bulletin

In engagements we reviewed from 2024 through 2026, migration or upgrade line items appeared on Secure Client proposals for customers who already held active term licenses or active support contracts, which Cisco's own EoL announcement says carry no additive charge.

2027 vs 2024
The three-year gap nobody priced

The patch cutoff was 31 March 2024, so every 4.x endpoint in the estate has been running without maintenance releases for roughly two years by the time most buyers open the file.

The patterns repeat with enough consistency that you can predict the quote before you open the PDF. First, migration SKUs that should not exist.

Cisco's EoL announcement states plainly that customers with valid term licenses, or perpetual licenses with active support, upgrade to the current release at no charge.

And that there is no additive charge for anyone entitled to use AnyConnect directly or indirectly through another purchased Cisco service.

We still see line items labeled migration, upgrade, or transition. Second, legacy per-headend concurrent licenses on renewal quotes despite the Secure Client Ordering Guide stating that Advantage and Premier licensing eliminates the need to purchase per-headend concurrent licenses.

That is double-counting: you pay per covered user and again per ASA or FTD concurrency pool. Third, tier creep from Plus to Premier.

Plus maps to Advantage and Apex maps to Premier, but quotes routinely land on Premier for estates with no ISE Posture, no Network Visibility Module, and no Management VPN Tunnel dependency.

Our Advantage versus Premier tier analysis exists because that single line decision moves more money than anything else on the paper.

Fourth, Umbrella customers with a blind second exposure: the Umbrella roaming security module for 4.x also stopped receiving updates of any type on 31 March 2024, and the one-time cloud update path to 5.0 is opt-in, not automatic. Fifth, Secure Access buyers who think the client is covered.

The support contract generated with Secure Access grants download access only for using Secure Access. On-prem ASA and FTD headends require a separate Secure Client license, and that gap surfaces in an audit, not a quote.

One caution on numbers: pricing circulating through reseller and analyst channels is directional only, because Cisco list is CCW-gated and band-dependent.

Try Vera AI · free 30 day trial
Do not send the counter until Vera has read the deal.
  • Percentile standing for your exact deal size and industry, from real closed transactions
  • Scenario simulation before the call: test alternative terms and see the financial impact of each
  • A negotiation playbook, talking points, and a two page executive brief on day one
Start the free Vera AI trial →30 days free · no credit card · cancel anytime
6.

Your first five moves

MoveOwnerComplete byWhat it protects
Inventory 4.x endpoints and document the patch gap since 31 March 2024Endpoint and network operationsQ1, immediatelySecurity and audit narrative, and the internal business case
Extract Smart Account entitlement evidence before requesting a quoteSoftware asset managementBefore any reseller conversationThe no-charge upgrade clause under the EoL announcement
Run the counting audit: covered users versus legacy headend concurrencySAM plus network architecture60 days from inventoryRemoval of per-headend line items the new model eliminated
Decide Advantage versus Premier on feature dependency, in writingSecurity architecture, not the resellerBefore pricing is requestedTier creep, the largest single cost variance
Time the term commitment against the EA or service contract renewalProcurement lead9 to 12 months before the anniversary36 or 60 month pricing locked past 31 March 2027

The sequence matters more than the individual tasks. Every one of these moves happens before a quote exists, because once a Secure Client proposal is on the table the conversation shifts from entitlement to discount, and discount conversations concede the premise that you owe something.

Pull the Smart Account evidence first, name your tier from feature dependency second, and let the account team price against a specification you wrote rather than one they assembled from your legacy SKU history.

On timing, the 2027 date is not the constraint that should drive your calendar. The 3.x precedent (maintenance ended March 2016, application support ended March 2018, then obsolete) shows Cisco does not extend these windows, and the language in the 4.x announcement is identical.

Your real constraint is your own renewal anniversary, because Advantage and Premier are 12 to 60 month subscriptions and Advantage is also available perpetually. A 60 month term signed at the current renewal carries you well past March 2027 at today's rate.

Sign a 12 month term to buy thinking time and you will negotiate again inside a tier structure Cisco controls. Read the no-charge upgrade entitlement checklist before you take the first call.

  1. Inventory the 4.x estate and quantify the patch gap now, because endpoints have been running without maintenance releases since 31 March 2024 and that number is your internal funding argument, not the 2027 headline.
  2. Pull entitlement evidence from the Smart Account before you request pricing, confirming active term licenses, active service contracts on perpetuals, and any indirect entitlement through Umbrella packages that triggers the no-additive-charge clause.
  3. Audit the counting model against covered users, not headend concurrency, and strike any per-headend concurrent line item, since the Ordering Guide confirms Advantage and Premier eliminate that purchase.
  4. Fix your tier on documented feature dependency, moving to Premier only where ISE or Secure Firewall Posture, Network Visibility Module, Suite B, or the Management VPN Tunnel are actually in production, and defaulting everything else to Advantage.
  5. Sequence the term decision against your EA or service contract renewal, locking 36 or 60 months at pre-increase pricing rather than letting the 2027 date arrive mid-term with no leverage left.
7.

Frequently asked questions

Does AnyConnect 4.x stop working on 31 March 2027?

No. The client keeps functioning after 31 March 2027; what stops is application software support, meaning Cisco will no longer accept support cases or provide any support services and the product is formally obsolete.

The functional risk arrived earlier, on 31 March 2024, when patches and maintenance releases ended. Continuing past 2027 means running unpatched VPN client software on every endpoint with no vendor recourse.

Do I have to buy new licenses to move from AnyConnect 4.x to Secure Client 5.x?

Cisco's EoS/EoL announcement states there is no additive charge for customers holding valid AnyConnect or Secure Client term licenses, or perpetual licenses with active support contracts.

It also states there is no additive charge for anyone entitled to use AnyConnect indirectly through another purchased Cisco service, which includes most Umbrella packages. If a quote contains a migration or upgrade SKU, ask the account team to reconcile it with that bulletin language in writing.

What is the difference between software maintenance and application software support?

Software maintenance is the delivery of patches and maintenance releases, and for AnyConnect 4.x it ended on 31 March 2024. Application software support is the ability to open cases and receive support services, and it ends on 31 March 2027.

Both require an active term license or an active service contract on a perpetual license, so a lapsed contract removes access immediately regardless of the calendar date.

Will Cisco extend the 31 March 2027 date?

There is no basis to plan on it. AnyConnect 3.x followed the identical structure: maintenance ended 1 March 2016, application software support ended 31 March 2018, and the product became obsolete with no extension. The two-year gap and the obsolescence wording are the same in the 4.x bulletin.

Does buying Cisco Secure Access license the client for my on-prem ASA or FTD?

No. Cisco's ordering guidance states that the support contract generated with Secure Access provides download access to Secure Client only for the purpose of using Secure Access.

For all other use cases, including Secure Client with on-premises ASA or FTD headends, a separate Secure Client license is required. This is one of the most common entitlement gaps we find during migration reviews.

Can I use Secure Client VPN Only to reduce cost if I still hold Plus or Apex licenses?

No. Cisco documentation states the Secure Client VPN Only license cannot be used with Apex or Plus. Shops holding residual legacy inventory are frequently quoted VPN Only as the cheap path, and it is not deployable alongside those SKUs.

Resolve the legacy inventory position first, then price the tier.

When should I decide between Advantage and Premier?

Before you request a quote, not after. Premier is required if you use endpoint Posture with Secure Firewall or ISE Posture, Network Visibility Module, next-generation encryption including Suite B, or the Management VPN Tunnel.

If none of those are in use, Advantage covers device and per-app VPN, third-party IKEv2 headends, trusted network detection, FIPS, the 802.1X supplicant, and the Umbrella roaming module.

© 2026 Redress Compliance · Independent, buyer sideredresscompliance.com
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent
Cisco White Paper

Cut your Cisco collaboration cost across the Webex stack

How to cut Cisco collaboration cost across Webex Suite, Calling, and Contact Center: the Flex Plan math and the contract levers that hold at renewal.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
Independent, buyer side. We never share your details with vendors.
Run the software spend health check against your Cisco estate in under five minutes.
Open the Tool → Cisco Hub →
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Stay ahead of Cisco pricing and contract moves.

One buyer side briefing a week. Renewal signals, discount bands, and the levers that work. No vendor spin.