Drupal 10 End of Life 2026: Upgrade Guide

Drupal 10 end of life December 2026 — upgrade to Drupal 11

Drupal 10 End of Life: What It Means for Your Website (and What to Do Before December 2026)

If your website runs on Drupal, there is one date you need on your calendar: 9 December 2026. That is when Drupal 10 reaches end of life. After that day, the Drupal security team stops releasing patches for it — permanently.

Here is the part most owners miss: for a lot of sites, the deadline has already passed. Drupal’s support runs on a per-version clock, so plenty of live Indian business sites are running unpatched today without anyone realising it.

This is a straight-talk guide — what “end of life” actually means, whether you’re already exposed, and how to plan a calm upgrade instead of a December panic.

The short version

  • Drupal 10 core reaches end of life on 9 December 2026 (announced by Drupal.org and Acquia).
  • After that, no security patches for Drupal 10 core or contributed modules — ever.
  • Your real cutoff depends on which minor version (10.4, 10.5, 10.6…) you run — and some already ended.
  • You cannot jump straight from Drupal 10 to Drupal 12. The clean path is 10 → 11.
  • The audit that decides “upgrade vs rebuild” takes longer than teams expect. Start now.

What “end of life” actually means

End of life isn’t a gentle wind-down or a “recommended” upgrade nudge. It’s a hard stop. On 9 December 2026, the Drupal security team stops coordinating and publishing security advisories for Drupal 10 — for both core and contributed modules.

Your website won’t suddenly go dark. It will keep loading. That’s exactly what makes this risky: everything looks fine while any new vulnerability discovered after that date has no official fix. The hole gets published to the world; the patch never comes. Attackers scan for exactly these known-and-unpatched targets.

The deadline you might be missing: the per-version clock

Most coverage points at 9 December 2026. But Drupal ships a new minor version roughly every six months, and each minor gets about a year of coverage before its own security support ends. Two minor versions are supported at any time. So the version you’re running today may be on a much shorter clock.

Per Drupal’s published release-support schedule:

  • Drupal 10.4.x and earlier — security support ended in December 2025. Sites still on these are unsupported right now.
  • Drupal 10.5.x — security support ended in mid-2026 (around June 2026). Also unsupported now.
  • Drupal 10.6.x — the final Drupal 10 minor, supported until 9 December 2026.

So the honest question isn’t “when do I upgrade?” It’s “am I already exposed and unaware?” If you don’t know your exact minor version, that’s the first thing to check — it takes a few minutes.

Who should care the most

A hobby blog going a few weeks unpatched is a small risk. But a site that handles customer data, takes payments, or sits in front of the public as an official portal is a different story. For those, an unsupported CMS isn’t just a technical debt item — it becomes a compliance problem the day support ends. Many procurement and security review processes simply reject unsupported software.

In over ten years building Drupal portals for governments and universities, the sites I’ve seen most at risk are always the ones that “just work.” They were built well, went live, and then nobody looked under the hood for two years. That pattern is common across Indian MSMEs and Tier-2/3 institutions too: a Drupal site commissioned years ago, the original developer long since moved on, and no one tracking the version. If that sounds like your setup, this deadline is aimed at you.

Upgrade or rebuild?

There are two honest routes forward, and the right one depends on your site.

Upgrade to Drupal 11

The move from Drupal 10 to 11 is one of the smoothest major upgrades the project has ever offered — the code and APIs are close, so a well-maintained site can move across without a full rebuild. This is the default recommendation for most sites in good shape. Note: you go to Drupal 11, not straight to 12; from there your next step later is 11.x, then 12.

Rebuild instead

If your site has years of piled-up custom code, abandoned modules, or business needs that have drifted far from the original build, a rebuild on Drupal 11 can be cheaper over time than dragging technical debt forward. A rebuild is also the moment to gain from Drupal’s newer, AI-native tooling if that fits your roadmap.

You don’t have to guess which camp you’re in. A short audit tells you — and it’s the step teams consistently underestimate, so it pays to start it early.

Your Drupal 10 → 11 pre-upgrade checklist

  1. Confirm your exact version. Not just “Drupal 10” — the minor (10.4 / 10.5 / 10.6). This alone tells you whether you’re already unsupported.
  2. Inventory your modules and theme. List every contributed module and check which have a Drupal 11-ready release. Abandoned modules are the usual blocker.
  3. Back up everything first. Full database + files backup before you touch anything. Test the restore, don’t just assume it works.
  4. Upgrade on a staging copy, never live. Clone the site, run the upgrade there, fix issues, then push the tested result to production.
  5. Run the Upgrade Status check. Drupal’s own tooling flags deprecated code and incompatible modules before you begin.
  6. Protect your SEO. Keep URLs, redirects, meta and schema intact through the move so you don’t lose Google rankings you’ve earned.
  7. Set a maintenance habit after. The whole point is to stay on supported versions — schedule minor updates so you never end up here again.

Don’t wait until November

The temptation is to file this under “deal with it before December.” The problem: everyone else will too. Good Drupal developers get booked, contributed-module fixes queue up, and a rushed migration in the final weeks is where sites break. Starting the audit now costs you almost nothing and turns a hard deadline into a calm, planned piece of work. Starting in November turns it into an emergency — and emergencies cost more.

Frequently asked questions

When exactly does Drupal 10 reach end of life?

Drupal 10 core reaches end of life on 9 December 2026, per Drupal.org and Acquia. After that date, there are no more security updates for Drupal 10 core or contributed modules from the Drupal community.

Will my website stop working after that date?

No. Your site will keep running. What stops is security support — new vulnerabilities won’t be patched, which is the real risk, especially for sites handling data, payments, or public/government use.

How do I know if I’m already unsupported?

Check your exact minor version. Sites on Drupal 10.4 or older lost support in December 2025; Drupal 10.5 lost support around mid-2026. Only 10.6.x is covered up to the December 2026 deadline.

Can I upgrade straight from Drupal 10 to Drupal 12?

No. The supported path is Drupal 10 to Drupal 11. From Drupal 11 you later move within the 11.x line and on to 12 — but there’s no direct 10-to-12 jump.

Should I upgrade or rebuild?

A well-maintained site should upgrade to Drupal 11 — it’s a smooth move. A site heavy with old custom code or outdated needs may be cheaper to rebuild. A short audit gives you the answer before you commit.

Not sure where your site stands?

If you don’t know your Drupal version — or you know you’re behind and want a clear plan — that’s a quick conversation. We’ve handled Drupal migrations for government and university portals for over a decade, and we’ll tell you straight whether you should upgrade or rebuild.

Free 15-minute check: we’ll confirm your version, flag whether you’re already exposed, and map the move. See our web development & Drupal migration work, or message us directly on WhatsApp: +91 91026 01040. Planning a rebuild? Here’s our custom software side, and you can always get in touch here.