Drupal 10 End of Life: Drupal 11 Now or Wait for 12?
Knowledge
Drupal 10 reaches end of life on 9 December 2026, the same week Drupal 12 is released. After that date there are no more security advisories, patches or releases for Drupal 10.
If you run Drupal 10, the question in the title has a short answer: move to Drupal 11 now. Drupal 12 cannot be reached from Drupal 10 directly — its update system refuses any site older than Drupal 11.3 — so "waiting for 12" still means doing the Drupal 11 upgrade, just later and against a hard deadline. The rest of this article is the longer answer: the dates, what end of life means in practice, and how to plan the move without turning it into a rebuild.
The dates that matter
- 9 December 2026 — Drupal 10 reaches end of life.
- Week of 7 December 2026 — Drupal 12.0.0 and Drupal 11.5.0 are released. In the same week, security support ends for 10.6.x, the last Drupal 10 line, and for 11.3.x.
- Already past — 10.5.x lost security support in June 2026, and 10.4.x has been unsupported since December 2025. If you are on either, you are already running without security coverage.
- 30 September 2026 — Drupal 12.0.0-beta1 was tagged, so the target is now concrete enough to test against.
Count it in sprints rather than weeks: from the start of October there are just over nine weeks left, and the December holidays eat into the end of that.
What end of life means in practice
End of life does not switch your site off. It keeps working on 10 December. What stops is the security process around it: the Drupal Security Team no longer publishes advisories or patches for Drupal 10 core or for the contributed modules running on it, and no new core releases follow. A vulnerability found the next day has no official fix.
The consequences reach beyond the codebase. Contributed module maintainers drop Drupal 10 from their supported versions, so the modules you depend on stop receiving fixes too. Hosting platforms move their PHP baselines on. And for regulated organisations — public sector, finance, insurance, healthcare — unsupported software is typically flagged as a finding in its own right in a security audit or a client's vendor assessment, whether or not anything has been exploited.
As of October 2026, no official extended security support has been announced for Drupal 10. Once official support ends, the only fixes your site receives are the ones someone on your side writes.
Drupal 11 now, or wait for 12?
It looks like a choice. It is mostly a sequence.
- There is no direct path from 10 to 12. Drupal 12 removes the update functions added before Drupal 11.3.0, and its update system refuses to upgrade a site running 11.2 or earlier. Every Drupal 10 site has to pass through Drupal 11 first.
- Drupal 11 is the stable target today. It has been available since August 2024, the contributed ecosystem has had two years to catch up, and the upgrade from Drupal 10.3 or later is well-trodden. Drupal 12 will be at 12.0.0 in December — a first release most enterprise teams will not want in production in its first weeks.
- Waiting buys nothing. A team that waits for 12 still has to do the 10 to 11 work, but in December, against the end-of-life date, with less time to test.
- Do not stop at 11.3. 11.3.x also loses security support in the week Drupal 12 ships. Aim for the current 11.x minor, and plan to move onto 11.5 when it arrives alongside Drupal 12.
Our recommendation for almost every Drupal 10 platform: upgrade to Drupal 11 this quarter, keep the upgrade compatibility-only, and schedule Drupal 12 for 2027, once its first maintenance releases are out and the contributed modules you rely on have declared support.
An upgrade readiness checklist
Most Drupal 10 to 11 upgrades are not hard. The ones that go badly are the ones that start without an inventory. Before you schedule the work, check:
- Your current core version. Drupal 11 can only be reached from Drupal 10.3 or later. Sites on 10.2 or earlier need a minor update first — and given the dates above, should go to 10.6 anyway.
- Hosting and PHP. Drupal 11 requires PHP 8.3 and MySQL 8.0, MariaDB 10.6, PostgreSQL 16 or SQLite 3.45. Drupal 12 will require PHP 8.5 and raises the MariaDB minimum to 10.11. If your hosting cannot offer both, there is a second project hiding inside the first. Drush users need Drush 13.
- Contributed modules. Install the Upgrade Status module on a development copy. It reports which contributed projects already have Drupal 11 releases, which need an update and which have none. Abandoned modules are where upgrades stall — decide early whether to replace, patch or drop them.
- Custom modules and themes. Upgrade Status also scans custom code for deprecated APIs, and Drupal Rector fixes a large share of them automatically. Update
core_version_requirementin each.info.ymlso the code declares support for both versions during the transition. - Composer patches and pinned versions. Patches in
composer.jsonusually target a specific module version, and depending on your setup a patch that no longer applies may be skipped with nothing more than a warning. List them and check that each one is still needed. - The road to 12. Several modules leave core in Drupal 12, including Ban, Contact, Field Layout and History. If you use any of them, switch to the contributed version while you are on Drupal 11 rather than during the next upgrade.
- Testing. A staging environment with production-like content, automated tests where they exist and — the step most often skipped — an hour with the editors who use the site every day. They find what automated tests miss.
If you cannot make December
Some platforms will not be on Drupal 11 by 9 December — large multisites, heavily customised builds, or teams whose budget year starts in January. If that is you, the worst plan is no plan. The workable ones:
- Shrink the upgrade. Separate the version upgrade from everything else. No redesign, no refactor, no new features in the same release. A compatibility-only upgrade is usually far less effort than teams expect.
- Reduce your exposure in the gap. Remove unused modules, restrict access to administrative paths, put a web application firewall in front of the site, and make sure backups and restore procedures are actually tested.
- Watch the advisories that still exist. Security advisories for Drupal 11 will keep coming. Someone has to read each one, decide whether the same weakness exists in your Drupal 10 code and, if it does, patch it by hand. That is real engineering work, and it is a bridge, not a strategy.
- Put a date on it. Whatever the interim measure, agree the upgrade date now and write it into the plan, so the gap is measured in weeks rather than becoming the new normal.
What you get on the other side
An upgrade done only to stay supported is a cost. It is worth knowing what it also unlocks, because the platform has moved a long way since most Drupal 10 sites were built.
- Drupal CMS 2.0 and Canvas. Drupal CMS 2.0, launched in January 2026, made Canvas the default visual page builder for new Drupal CMS sites. At DrupalCon Rotterdam in September, Canvas gained full multilingual support and code components written in React.
- Headless on more frameworks. Drupal's headless support now spans five front-end frameworks, Angular among them — relevant if your front end is already an Angular or React application.
- AI tooling with guardrails. The building blocks of the Drupal AI Initiative — the MCP Server and Tool API modules, Simple OAuth for authentication, FlowDrop for workflows — are available today, and the public Drupal AI demo shows drafting with human review, content quality checks and grounded answers with source citations. A prototype shown in Rotterdam cut an AI assistant integration from roughly 1,000 lines of code to about 20 PHP attributes.
None of that is a reason to fold a redesign into your upgrade. It is a reason to make sure the upgrade happens, so the next decision is about what to build rather than whether you are still supported.
How we run Drupal upgrades
We plan and run Drupal upgrades as part of long-term support for enterprise platforms: an inventory first, a compatibility-only upgrade second, and everything else once the platform is supported again. If you want to know how far your Drupal 10 site is from Drupal 11, our managed services team can tell you, and our approach to enterprise Drupal support covers what comes after the upgrade. Get in touch before the December rush.