Official intent
Reduce technical debt by retiring the unsupported, end-of-life, and legacy systems attackers rely on. The official source remains authoritative.
Read the official campaign ↗Why it matters
Unsupported software stops receiving security fixes, so known exploits stay open forever. Legacy systems are also the ones with weak authentication and flat network access — exactly what an intruder needs to move. Paying down this debt removes whole classes of risk instead of patching them one at a time.
Minimum / Strong / Advanced
End-of-life and unsupported systems are identified and have a documented retirement or isolation plan.
Debt is ranked by exposure and business impact, and a funded roadmap retires or replaces the highest-risk systems on a schedule.
Lifecycle management is continuous: end-of-support dates are tracked ahead of time and systems are refreshed before they go unsupported.
Implementation timeline
- List systems already past end-of-support
- Flag any that are internet-facing
- Rank legacy systems by exposure and business impact
- Isolate the worst offenders that cannot be retired yet
- Build a funded retirement/upgrade roadmap
- Disable legacy protocols (SMBv1, TLS 1.0/1.1, basic auth)
- Retire or replace the top items
- Add end-of-support dates to the asset inventory
Implementation steps
- Use the asset inventory to find unsupported, end-of-life, and unmaintained systems and protocols.
- Rank each by exposure (internet-facing, holds CUI, widely reachable) and by business dependency.
- For each, choose a path: upgrade, replace, isolate behind compensating controls, or decommission.
- Sequence the work into a funded roadmap and put executive weight behind the deadlines.
- Track end-of-support dates in the inventory so future debt is retired before, not after, it goes unsupported.
Validation
- Confirm no internet-facing system is running unsupported software.
- Verify legacy protocols are disabled by testing that they no longer negotiate.
- Check that each remaining legacy system has a dated retirement or isolation plan.
Evidence to retain
Lifecycle/retirement policy and the funded roadmap
Evidence legacy protocols are disabled and systems are isolated
Roadmap progress report against retirement dates
Confirmation scan showing no unsupported internet-facing systems
Common failure modes
“We will retire it next year” repeated indefinitely, isolating a legacy box on paper but leaving it flat on the network, and forgetting appliances and firmware that also reach end-of-support. A migration that never funds the last 10% is not a retirement.
Framework mappings
Independent mappings are aids, not authoritative equivalence or compliance determinations.