Drupal 10 reaches end of life on December 9, 2026. That is about nine weeks from today. The same week, Drupal 12.0 and Drupal 11.5 are released.
If your site still runs Drupal 10, this is the moment to plan the move to Drupal 11. Here is what the date means, why Drupal 12 does not change the answer, and what to do between now and December.
What end of life means for a Drupal 10 site
Nothing switches off on December 9. Your site will keep serving pages and your editors will keep working.
What ends is security support. After that date, the Drupal Security Team stops fixing newly discovered vulnerabilities in Drupal 10, and contributed modules stop releasing fixes for their Drupal 10 versions. Drupal 10.6 is the last minor release of Drupal 10, and its security support ends with the Drupal 12 release. Sites still on Drupal 10.5 already lost security coverage when Drupal 11.4 was released at the end of June.
The risk grows over time. The first serious vulnerability disclosed after December 9 will be fixed for Drupal 11 and Drupal 12, but not for you.
Why not wait and go straight to Drupal 12?
It is tempting to skip a version. It does not work that way here.
Drupal 12 only upgrades from recent Drupal 11 releases, so a Drupal 10 site has to pass through Drupal 11 anyway. Drupal 12 also raises the platform requirements: it needs PHP 8.5, and its minimum database versions are MySQL 8.0, MariaDB 10.11, PostgreSQL 18 and SQLite 3.45. Plenty of hosting setups will not meet those on release day.
There is a practical reason too. Contributed modules need time to support each new major version. In December, Drupal 11 will have a mature module ecosystem while Drupal 12 support will still be arriving. Moving to Drupal 11 now gets you onto a supported version with the least friction, and leaves a smaller step to Drupal 12 later.
A plan for the next nine weeks
This week: find out where you stand
Check which Drupal version each of your sites runs. Install the Upgrade Status module on a development copy and run it. It lists custom code that uses deprecated APIs and contributed modules that do not yet have a Drupal 11 compatible release.
At the same time, confirm that your hosting supports Drupal 11's requirements, including PHP 8.3 and supported database versions, in every environment you use.
Weeks 2 to 4: remove the blockers
Update to the latest Drupal 10 release first. Then work through the Upgrade Status report:
- Replace deprecated code in custom modules and themes. The Drupal Rector tool automates a large share of this.
- Update contributed modules to versions that support Drupal 11.
- For modules with no Drupal 11 release, find a replacement, help the maintainer, or move the functionality into custom code.
- If you use modules that were removed from Drupal core in Drupal 11, such as Book, Forum, Statistics or Tour, install their contributed versions first.
We covered these steps in more detail when Drupal 11 was released, in our post on upgrading from Drupal 10 to Drupal 11.
Weeks 5 to 7: upgrade and test on staging
Run the upgrade on a staging copy of the site, never directly on production. Test the journeys that matter to your business: forms, logins, search, checkout, and every integration that sends or receives data. Ask the people who use the site daily to review it.
Weeks 8 to 9: release with a safety net
Take a full backup, agree on a rollback plan and release to production. Watch error logs and forms closely for the following days. Leave buffer time before December 9, because something always takes longer than planned.
If you cannot finish in time
Some sites will not make the deadline, especially ones with a lot of custom code or abandoned modules. If that is you:
- Apply every remaining Drupal 10 security release, so you start from the safest possible state.
- Remove modules you do not use. Code that is not installed cannot be exploited.
- Review user accounts and remove access nobody needs.
- Put a firm date on the upgrade, and do not let it slip into the following year.
A site that misses the deadline by a few weeks with a plan is in a very different position from one that simply stays on Drupal 10.
What about Drupal 7 sites?
If you still run Drupal 7, the situation is more urgent. Community support ended on January 5, 2025, and moving to a supported version is a migration rather than an upgrade. Our post on what happens to Drupal 7 sites after end of life covers the options.
Need help getting off Drupal 10 before December 9? See our Drupal 10 to 11 upgrade service or contact us for an assessment.