SQL Server 2016 end of life and end of support
Extended support for SQL Server 2016 ended on 14 July 2026. From that date security fixes are available only through paid Extended Security Updates, which run until 17 July 2029.
Status on 3 October 2026
- SQL Server 2016
- Support ended
- Security fixes
- Ended 14 July 2026
- Released
- 1 June 2016
- Mainstream support ended
- 13 July 20211,908 days ago
- Security fixes ended
- 14 July 202681 days ago
- Paid extension ends
- 17 July 20291,018 days from today
Dates come from the Microsoft product lifecycle; check there before relying on them for a decision.
What ends, and what carries on
On 14 July 2026 Microsoft stopped issuing free security fixes for SQL Server 2016. Mainstream support had ended on 13 July 2021, so by then it had already gone years without functional fixes.
What changes is that a vulnerability found in the database engine is fixed for newer versions and not for yours, and that the software around the database moves on: operating systems, drivers, backup tools and monitoring products stop being tested against it.
What it means for the applications that use the database
SQL Server 2016 sits under a great many business applications built between 2016 and 2020. For most of them an upgrade is a low-risk change, as long as it is rehearsed on a copy first. Two things are worth understanding.
Compatibility level. A database moved to SQL Server 2022 or 2025 keeps the compatibility level it had on 2016. The new server handles its queries the way the old one did until somebody deliberately raises the level. Raise it later, as a separate tested step.
What does not travel. The things around the database are stored elsewhere on the server and stay behind:
- Logins. Held by the server, not the database. Users in a restored database have to be matched to logins again.
- SQL Agent jobs. Overnight imports, exports, maintenance and emailed reports.
- Linked servers. Connections to other databases, sometimes through old drivers that need installing on the new server.
- SSIS packages. Data imports and exports.
- Reporting Services reports. Reports frequently contain business rules that exist nowhere else.
When an upgrade goes wrong, the cause is usually on this list, not in the database.
Your options
Upgrade to SQL Server 2022 or 2025. SQL Server 2022 receives security fixes until 11 January 2033 and SQL Server 2025 until 6 January 2036. Build the new server alongside the old one, restore a copy, test, then switch.
Move to the cloud at the same time. If the server hardware is the same age as the database, a hosted database avoids buying a replacement. See cloud migration.
Buy Extended Security Updates. A paid stopgap that runs to 17 July 2029. Reasonable if the application cannot be tested in time, as long as the time is used to upgrade.
Isolate and accept the risk. Limiting what can connect to the database server reduces the exposure but does not remove it.
What we would check first
We would establish the exact version and edition, the Windows Server version underneath (see the Windows Server dates), and everything on the list above. Then we would restore a copy of the production database onto the new version, point a test copy of the application at it and run the work the business depends on, including month-end jobs and the slowest reports.
If the database is already slow, deal with that as part of the same work. Our database performance service covers it.
Get a reminder
SQL Server 2016 stops receiving paid extended security updates on 17 July 2029. Put the date where you will see it.
Add a reminder to your calendarNot sure where SQL Server 2016 is still running?
Most organisations find more copies than they expected. Two ways to find out, depending on how much you want to know.
Check which version you have
The dates are the same for every edition: Enterprise, Standard, Web, Developer and Express. A free Express instance goes out of support on the same day as a licensed one.
How to check every productRun this query against each database server. The first two numbers of the product version identify the release.
SELECT SERVERPROPERTY('ProductVersion') AS Version, SERVERPROPERTY('Edition') AS Edition; | Version starts with | Product |
|---|---|
| 10.0 or 10.50 | SQL Server 2008 or 2008 R2 |
| 11.0 | SQL Server 2012 |
| 12.0 | SQL Server 2014 |
| 13.0 | SQL Server 2016 |
| 14.0 | SQL Server 2017 |
| 15.0 | SQL Server 2019 |
| 16.0 | SQL Server 2022 |
| 17.0 | SQL Server 2025 |
When it is not yours to upgrade
The copy of SQL Server most often missed is one you never chose. Accounting packages, door-entry and CCTV systems, telephone systems, backup tools and label printers commonly install SQL Server Express for their own use, and it stays at the version the product shipped with.
You cannot upgrade those yourself without risking the product that owns them. Ask each vendor which SQL Server versions the release you run is supported on, and whether a newer release of their product moves it for you. If the vendor has gone, that product has become unsupported software in its own right.
Making the case for the work
An upgrade nobody outside IT can see is easy to defer. These are the reasons that tend to move it up the list.
- Cyber Essentials
- The scheme requires software in scope to be supported by its vendor. Anything past its end-of-support date has to be removed, or cut off from the internet, before you can certify or renew.
- Cyber insurance
- Proposal forms commonly ask whether you run unsupported software. Check what yours asked, and what you answered.
- Customer questionnaires
- Larger customers ask the same question of their suppliers. An honest "yes, and here is the plan" is a better answer than a late discovery.
- Personal data
- UK data protection law expects appropriate technical measures to protect personal data. Software that can no longer be patched is hard to square with that.
- The cost of waiting
- An upgrade done to a deadline, after something has failed, costs more than the same upgrade planned. Where Microsoft sells a paid security extension, its price has risen each year it runs.
- Official guidance
- The National Cyber Security Centre is blunt: "The only fully effective way to mitigate this risk is to stop using the obsolete product." See its guidance on obsolete products.
What we do and do not sell: we do not sell Microsoft licences or Extended Security Updates, so we have no stake in which version you choose. Our part is the application: finding what depends on the old version, testing it against the new one and fixing what breaks.
Supported versions to move to
How long each would keep you in support. All SQL Server versions
| Version | Released | Mainstream support ended | Security fixes end | Status today |
|---|---|---|---|---|
| SQL Server 2022 | 16 November 2022 | 11 January 2028 | 11 January 2033 | Supported |
| SQL Server 2025 | 18 November 2025 | 6 January 2031 | 6 January 2036 | Supported |
Questions we are asked
When does SQL Server 2016 reach end of life?
Extended support for SQL Server 2016 ended on 14 July 2026. Mainstream support had ended on 13 July 2021. Paid Extended Security Updates are available until 17 July 2029.
Will SQL Server 2016 stop working after July 2026?
No. The database carries on running exactly as before. What stopped is the free security fixes, so vulnerabilities found after that date stay open unless you pay for Extended Security Updates.
Is there extended support for SQL Server 2016?
Extended support itself has ended. Microsoft sells Extended Security Updates, a paid programme covering security fixes only, until 17 July 2029. It is meant to cover the time needed to finish an upgrade.
Will our application still work after upgrading from SQL Server 2016?
In most cases, yes. The upgraded database can keep its SQL Server 2016 compatibility level, so queries are handled much as they were. Rehearse the upgrade on a copy of the database and run the application against it before changing the live system.
What does not come across when a SQL Server 2016 database is upgraded?
Anything held outside the database itself: server logins, SQL Agent jobs, linked servers, Integration Services packages and Reporting Services reports. These have to be listed and moved separately.
Still running SQL Server 2016?
Tell us which version, what depends on it and how it is hosted. We will set out the upgrade route and what it is likely to involve.