PGH Networks

Windows Server 2022 Mainstream Support Ends October: Your 90-Day Plan

July 18, 2026· PGH Networks Team· 4 min readManaged IT
Windows Server 2022 Mainstream Support Ends October: Your 90-Day Plan

What happened

Microsoft has confirmed that Windows Server 2022 will reach the end of its mainstream support phase in October 2026, roughly 90 days from today. After that date, the product moves into extended support and will continue to receive security updates for another five years, per reporting from BleepingComputer.

In plain terms: your Server 2022 boxes are not about to go dark, and they will keep getting patched. What changes is the type of updates Microsoft provides. Mainstream support typically includes non-security bug fixes, design change requests, and free incident support. Extended support narrows the scope primarily to security fixes. If you run Server 2022 anywhere in your stack, this is a milestone worth planning around, not panicking over.

diagram

Why this matters for Pittsburgh SMBs

Most 10-to-200-employee shops we work with across Pittsburgh — CPA firms in the Strip, law offices downtown, healthcare practices in the South Hills, manufacturers in the Mon Valley, and defense subs in the Airport corridor — still run at least one on-prem or hybrid workload on Windows Server. Common examples: a domain controller, a file server hosting matter files or patient records, a line-of-business SQL host, a Remote Desktop / session host for a practice management app, or a Hyper-V host anchoring a hybrid Azure setup.

Three specific reasons this milestone matters for our client base:

  • Compliance auditors read release notes. If you carry HIPAA, SOC 2, PCI, or FTC Safeguards obligations, your auditor will ask whether supported software is in place and whether you have a documented lifecycle plan. "It still gets patches" is a defensible answer during extended support — but only if you can produce the plan on paper.
  • Defense contractors have a higher bar. Under CMMC Level 2 and DFARS 7012, systems that touch CUI must meet NIST SP 800-171 controls including SI-2 (flaw remediation) and CM-related lifecycle controls. Running an OS whose support model just changed is not a violation, but it is a change that belongs in your SSP and POA&M.
  • Cyber insurance renewals. Carriers have gotten sharper about asking whether every server on the network is inside its mainstream support window. Expect a checkbox on your next renewal application.
  • Feature velocity slows. Non-security bug fixes and new feature work stop. If you were counting on a Server 2022 fix for a niche issue, that ship has sailed.

None of this is an emergency. It is exactly the kind of thing a good vCIO conversation cleans up before it becomes one.

What to do about it in the next 90 days

Here is a practical checklist you could start this week. You do not need to migrate anything by October — you need a defensible, written plan.

  1. Inventory every Windows Server 2022 instance. Physical, virtual, Azure, and that one box in the closet nobody logs into. Pull the list from your RMM or from Azure Arc if you have it. Note role, application dependencies, and data classification (does it touch PHI, CUI, PII, cardholder data, or matter files?).
  2. Confirm the exact Microsoft lifecycle dates. The reporting cites October 2026 for mainstream end and roughly five more years of extended support. Verify the precise end-of-mainstream and end-of-extended dates for your SKU (Standard, Datacenter, Azure Edition) on Microsoft's Product Lifecycle page and record them in your asset register.
  3. Validate your patching pipeline. Confirm your patch management is actually catching every server, that reboots are happening on schedule, and that you have alerting on missed cycles. Extended support is only useful if the updates land.
  4. Review compensating controls on servers that touch regulated data. Confirm EDR/MDR is deployed on every Windows Server host, that admin accounts use MFA and separation of duties, that backups are immutable and tested, and that logging is forwarded to a SIEM if your framework requires it.
  5. Decide the disposition for each server: keep, migrate, or retire. Options include staying on Server 2022 through extended support, upgrading in place to Server 2025, re-platforming to Azure (where Azure Edition gets hotpatching and extended benefits), or eliminating the workload entirely by moving to SaaS or Microsoft 365 equivalents. Line-of-business app vendor support matrices drive this decision more than anything else.
  6. Draft a 12-to-24-month roadmap. Sequence the migrations by risk, budget cycle, and application dependency. Get it in front of ownership before Q4 budget conversations.
  7. Update your compliance documentation. Note the lifecycle change in your risk assessment, SSP (for CMMC), or written information security program (for FTC Safeguards). Auditors love seeing that you saw it coming.

From above contemporary server cable trays without wires located in modern data center

How PGH Networks helps

This is exactly the type of quiet, unglamorous planning work our managed IT and vCIO clients rely on us for. We inventory the estate, map it to your compliance obligations, price out the realistic migration paths (Server 2025 in place, Azure lift-and-shift, or SaaS replacement), and drive the project so your team can keep serving clients. If AI is on your roadmap too, we tie server modernization into a broader Copilot readiness plan so you are not paying to modernize infrastructure twice.

Talk to us

If you are not sure how many Server 2022 hosts you have, or you want a second opinion on your migration plan, we can help. Call 724.888.7007 or reach out through the contact form and we will get a short discovery on the calendar.

Share

Related reading