SQL Server 2016 Reached End of Support on July 14, 2026: Upgrade, Migrate or Pay for ESUs
SQL Server 2016 reached the end of its support lifecycle on July 14, 2026. Microsoft's Extended Security Updates FAQ for SQL Server gives that date and confirms that paid Extended Security Updates (ESUs) are available until July 17, 2029.
Nearly three months on, plenty of business systems still sit on a SQL Server 2016 database: an ERP add-on, a booking platform, a reporting database behind a piece of custom software that has worked without complaint for years. Those databases did not stop on July 15. They simply stopped receiving security fixes unless the owner has subscribed to ESUs.
This article explains what ended, what the paid extension covers, one licensing change that catches people out, and how to decide between upgrading, migrating and paying for more time.
What ended on July 14, 2026
Microsoft's end of support options page explains that each SQL Server version gets at least ten years of support: five years of mainstream support, with functional, performance and security updates, followed by five years of extended support with security updates only. SQL Server 2016 has now passed the end of that second phase.
The ESU FAQ states the consequences plainly. After extended support ends, Microsoft does not provide patches or security updates, and it warns that this may cause security and compliance problems. Technical support stops as well: the FAQ says a customer on SQL Server 2016 without ESUs cannot log a support ticket, even with a support plan.
What Extended Security Updates cover
ESUs are a paid subscription that keeps critical security patches coming for up to three years after end of support. For SQL Server 2016, Microsoft's FAQ says they are available until July 17, 2029.
The coverage is narrow. Microsoft's ESU overview says updates are released only if needed, when a vulnerability is rated Critical by the Microsoft Security Response Center, so there is no regular release schedule. ESUs do not include new features, functional improvements or customer-requested fixes, and support is limited to problems with the updates themselves.
There are eligibility limits too. According to the FAQ, only Enterprise and Standard editions qualify. Express, Web and Developer editions cannot subscribe, which matters because many small applications run on Express. The FAQ also says the instance must be on the latest service pack to apply ESUs.
How ESUs are bought, and what changed for Azure
Microsoft's overview says instances connected to Azure Arc, or hosted as SQL Server on Azure virtual machines, can subscribe. That includes servers in your own data center or with another hosting provider, as long as they can be connected to Azure Arc; the page notes that connecting is free of charge and that Azure bills the ESU subscription hourly. On-premises customers need Software Assurance under an eligible agreement, or can enable a pay-as-you-go option through Azure Arc.
The change that surprises people is this. With SQL Server 2014, moving the workload to an Azure virtual machine brought free ESUs. Microsoft's overview states that, starting with SQL Server 2016, migrating to SQL Server on Azure VMs no longer provides free access to ESUs. Moving a 2016 instance to Azure as-is still requires a paid subscription.
Timing affects the bill. The FAQ says billing for SQL Server 2016 ESUs began at midnight UTC on July 15, 2026, and that subscribing after the end of support date triggers a one-time charge back to the first day of the ESU term. Waiting a few months does not save those months. Microsoft does not publish a single price on these pages, but its end of support options page describes ESUs as costly, at approximately 75% of the on-premises license cost annually.
The options Microsoft lists
Microsoft's end of support options page groups the choices into three paths:
- Upgrade to a current SQL Server version, on your own servers or on an Azure virtual machine. The page lists SQL Server 2025, 2022, 2019 and 2017 as upgrade targets.
- Migrate to a managed service, Azure SQL Managed Instance or Azure SQL Database, which Microsoft describes as services that never reach end of support.
- Stay on SQL Server 2016 and subscribe to ESUs, for up to three years.
Each has trade-offs that Microsoft sets out itself. An upgrade keeps the environment familiar but may involve downtime and, if the server runs an unsupported Windows Server version, an operating system upgrade as well. Managed Instance closely resembles on-premises SQL Server and removes patching, though Microsoft notes it can cost more than a virtual machine and has some compatibility differences. Azure SQL Database differs more, and applications using cross-database queries, linked servers or SQL Server Agent jobs may need changes.
One detail lowers the risk of an upgrade. Microsoft's page explains that when a database keeps the same compatibility level as the old system, existing applications are protected from functional and performance changes.
What this means for your business
What follows is our guidance, not Microsoft's position.
An unsupported database is a concentrated risk because it usually holds the most sensitive data in the business. For organizations with customer data, card payments, cyber insurance or security questionnaires from larger clients, running an unpatched database engine is likely to raise questions, whether you operate in the US, the UK or both. What your specific obligations require is a matter for your compliance or legal adviser; this article is not legal advice.
ESUs are best treated as a bridge with a known end date. They make sense when an application cannot be moved quickly, for example because a vendor has not certified a newer version. They make less sense as a default, since the money buys time and nothing else.
When choosing an upgrade target, look at the remaining support life. Microsoft's lifecycle table shows extended support for SQL Server 2017 ending in 2027 and for SQL Server 2019 in 2030, against 2033 for SQL Server 2022 and 2036 for SQL Server 2025. Moving from 2016 to 2017 would repeat this exercise next year.
The main cost drivers are the size and number of databases, how much downtime the business can accept, whether the application uses features that behave differently on the target, the state of the underlying Windows Server, and how much testing the application needs. If a third party maintains the system, our guide to outsourcing software development covers how to agree responsibility for upgrades like this one.
What to do next
Start with an inventory. Ask whoever manages your servers which SQL Server version and edition each database runs on, including instances installed quietly alongside third-party products. For anything on 2016, decide within weeks whether it will be upgraded, migrated or covered by ESUs, and write down the reason.
If the answer is ESUs, subscribe now, since the charge runs from July 15, 2026 either way and the patches only arrive once you are subscribed. If the answer is upgrade or migrate, have your developers test the application against the target version with the existing compatibility level first. Microsoft's page points to migration tooling in SQL Server Management Studio and to Azure Migrate for assessing instances. Express edition users, who cannot buy ESUs, should plan an upgrade directly.
Conclusion
SQL Server 2016 has been out of support since July 14, 2026. Critical security patches are available only through paid Extended Security Updates until July 17, 2029, and moving the database to an Azure virtual machine no longer makes them free. For most businesses the durable fix is an upgrade to a recent SQL Server version or a move to a managed Azure SQL service, with ESUs as a short bridge where needed.
If you need help working out which of your applications depend on SQL Server 2016 and what an upgrade would involve, get in touch and we can review it with you.