End-of-support & retirement
Retire products and services without abandoning customers, evidence, or residual cybersecurity obligations.
PSLF-08G8Retirement acceptedPhase 9 of 9
Gate
G8
Pending
Retirement accepted
Target date
Not set
Gate review
Open blockers
0
none recorded
Accountable
Portfolio Owner
Product, Service, Legal, Quality, and Security approve transition
Manage legacy risk, customer transition, final updates, decommissioning, data disposal, and evidence retention.
- Installed-base exposure and transition controls are understood.
- Support termination is communicated and auditable.
- Support-horizon decision
- Installed-base and customer inventory
- Legacy capability assessment
- 1Assess whether the product can remain reasonably protected
- 2Publish end-of-support milestones and compensating controls
- 3Provide migration, decommissioning, credential/certificate revocation, and secure data-disposal guidance
- 4Archive required records and close monitoring responsibly
- End-of-Life Security Plan
- Legacy Risk Assessment (LRA)
- Customer transition notice
- Decommissioning and evidence-retention record
- Executive risk authority accepts residual legacy riskPending
- Customer and regulator communication obligations completePending
- Data and identity disposal verifiedPending
- Retention and audit package sealedPending
- Accountable
- Portfolio Owner accountable
- Supporting
- Product, Service, Legal, Quality, and Security approve transition
- Retirement trigger (pending)
- Installed base (pending)
- Residual exposure (pending)
- Transition control (pending)
- Notice (pending)
- Archive (pending)
- Products with approved retirement plans
- Notification coverage
- Unresolved end-of-support risks