EOL Tracking

IT ops playbooks

Hardware EOL policy template (and how to actually write one)

By Nico De Muynck · Updated July 19, 2026

What this is

A one-page hardware end-of-life policy you can copy, fill in and adopt this week — plus a short explanation of each section so you know what you're signing off on. A policy isn't bureaucracy; it's the thing that turns “we should keep an eye on that” into a rule that survives staff turnover and audits.

Why a written policy beats good intentions

Everyone “knows” old hardware should be replaced. What's missing is a document that says who watches the dates, how far ahead you act, and what counts as too old. Without it, EOL tracking depends on one person remembering — and the day they're on leave is the day a firewall quietly drops out of support. A policy makes the process a system, gives auditors and cyber-insurers something to point at, and settles the “can't we run it one more year?” debate before it starts.

The template — copy and fill in

HARDWARE END-OF-LIFE (EOL) POLICY Owner: [name / role] · Approved: [date] · Review: annually 1. PURPOSE To ensure no hardware runs beyond its vendor support window without a documented, approved decision — protecting security, compliance and uptime. 2. SCOPE Applies to all [servers, network equipment, firewalls, laptops, NAS, and other infrastructure] owned or managed by [organisation]. 3. DEFINITIONS EOL — End of Life: vendor announces the product is retiring. EOS — End of Support: no more patches, TAC or RMA. EOSL — End of Service Life: final support/parts date. (The binding date for planning is EOS/EOSL, not purchase age.) 4. REFRESH CYCLE TARGETS (vendor EOS date overrides if sooner) Laptops / workstations ........ 4 years Servers ....................... 5–6 years Network equipment ............. 6–7 years Firewalls / security appliances 5 years [adjust to your environment] 5. WARNING WINDOW Every asset must be flagged for planned replacement at least [6–12] months before its EOS/EOSL date, so it lands in the next budget cycle — never as an emergency. 6. ROLES & RESPONSIBILITIES [Role] maintains the asset inventory and EOL dates. [Role] reviews the upcoming-EOL list each [quarter]. [Role] approves refresh budgets and exceptions. 7. DATA SOURCE EOL dates are recorded per asset from vendor lifecycle pages and [tracking system], and reviewed [quarterly]. 8. EXCEPTIONS Running an asset past EOS requires written sign-off from [role], a documented risk assessment, a compensating control (e.g. network isolation), and a hard replacement deadline. 9. REVIEW This policy is reviewed annually and after any major infrastructure or compliance change.

Copy the block above into your document system, replace the [bracketed] fields, and get it signed off. One page is plenty — a policy nobody reads protects nobody.

The two sections people get wrong

The warning window (section 5) is the part that actually prevents surprises. A policy that only says “replace at EOL” still lets you get caught, because you find out on the day. Six-to-twelve months of lead time is what turns a refresh into a budgeted line item. The exception process (section 8) is the other one: without it, “let's run it another year” happens informally and undocumented. Force exceptions to be written, risk-assessed and time-boxed, and you kill the slow drift into unsupported infrastructure — which is where the real EOL risks live.

A policy is only as good as the list behind it

Sections 5 and 6 assume someone can produce an accurate “what's reaching EOS in the next 12 months” list on demand. If that list lives in a spreadsheet someone updates by hand, the policy will quietly rot. Pair the policy with an inventory that computes statuses automatically and warns ahead of time — start from our free asset inventory template, and when the manual upkeep gets old, let a tracker do the watching. (For the full method the policy operationalises, see the hardware lifecycle management guide.)

Give your policy a live inventory to stand on.

EOL Tracking holds every asset's EOL date, computes status automatically, and warns you months ahead — so section 5 of your policy runs itself.

Start free — up to 5 assets

No credit card · CSV import for whole fleets