Somebody forwards your executive director an article with a date in it: .NET 8 and .NET 9 stop getting security fixes on November 10, 2026. Your association runs Sitecore, or Sitefinity, or Optimizely, and the article says those are .NET platforms. By the end of the week there is a line in a budget conversation about an emergency upgrade, and nobody in the room can say whether it applies to you.
For most association sites on Sitecore or Sitefinity, it does not. The deadline is real, Microsoft's date is right, and it is worth ten minutes of your time, but the platform underneath those two products is on a different lifecycle entirely, and the deadline that probably does apply to you falls in January rather than November.
What is sourced here, and from where. Microsoft's dates are from Microsoft's own .NET blog and support policy. The platform requirements are from each vendor's own published system requirements, read in August 2026. Where a vendor has published nothing, we say so rather than infer.
What Microsoft Actually Announced
On June 29, 2026 Microsoft confirmed that .NET 8 and .NET 9 both reach end of support on November 10, 2026. After that date, in Microsoft's words, it will no longer provide servicing updates, security fixes, or technical support. The recommended target is .NET 10, a long-term support release Microsoft supports through November 2028.
Nothing breaks on November 11. Microsoft says so directly: applications built on .NET 8 or .NET 9 will continue to run. That is precisely why this gets deprioritized. There is no outage, no error page, no vendor phone call. There is only the quiet end of security patching, which becomes visible the first time somebody sends you a security questionnaire.
And here is the counterintuitive part. .NET 8 is a long-term support release and .NET 9 is a short-term one, yet both expire on the same day. Being on the LTS version, which is what a cautious IT lead would have chosen, buys you nothing at all in this instance.
The Question That Decides Whether Any of This Is Yours
There are two different things called .NET, and the entire answer turns on which one your CMS runs on.
.NET Framework is a component of Windows. Microsoft's policy states that from version 4.5.2 onward it is defined as a component of the operating system and follows the lifecycle of the Windows version it is installed on. .NET Framework 4.8 and 4.8.1 are listed as active with no end-of-support date at all.
Modern .NET, 8, 9, 10, is a separate product with its own clock. That is the clock that stops on November 10.
Most enterprise CMS platforms that associations bought a decade ago are on the first one. Which means the November date does not touch them.
Platform by Platform
Read this against the version you are actually running, not the product name.
- Sitecore XP and XM. Sitecore's own installation documentation for 10.5 states that Sitecore Experience Platform requires .NET Framework 4.8.0. The CMS platform is not affected by November 10. We could find no public Sitecore advisory about the .NET 8 and 9 end of support at all, which is consistent with it not applying to the platform.
- Progress Sitefinity. Sitefinity's system requirements list .NET Framework 4.8 on supported Windows versions for the backend. Its ASP.NET Core Renderer is a separate matter and already requires .NET SDK 10.0, so on the modern half of the stack Progress is ahead of the deadline, not behind it.
- Optimizely CMS 11, and the Episerver legacy. Requires .NET Framework 4.6.1 and higher. Not affected by the November date either.
- Optimizely CMS 12. This is the one that genuinely is on the clock. It targets an older framework moniker and runs on .NET 8. Be aware that Optimizely's own documentation is inconsistent here: the system requirements page still says .NET 8, while an Optimizely developer blog post from May 2026 states that CMS 12 is fully compatible with .NET 10 given recent enough package versions. Both are Optimizely's, and the documentation lags the blog.
So of the three platforms in the original scare, one is affected. If you are on Optimizely CMS 12, this is a real November item and there is a documented in-place path, moving to .NET 10 on current CMS 12 packages, rather than jumping to CMS 13. If you are on Sitecore or Sitefinity, the November date is not your problem.
The Deadline That Probably Is Yours
If .NET Framework follows the Windows lifecycle, then Windows is your deadline. And for a great many association sites running Sitecore or Sitefinity on hardware specified during the last redesign, that means Windows Server 2016, whose extended support ends on January 13, 2027.
That is nine weeks after the date everyone is talking about, and it is considerably more consequential. When Windows Server 2016 goes out of support, the .NET Framework 4.8 installed on it goes with it, because it inherits that lifecycle. The CMS vendor's support matrix will not save you, and neither will the fact that your CMS version is current.
Windows Server 2019 runs to January 10, 2029, so if that is what you are on, you have real breathing room and can plan this into a normal budget cycle rather than a scramble.
Where Modern .NET Actually Lives on an Association Site
The November date does apply to association infrastructure, just usually not the CMS. It applies to the small things nobody inventories.
- Integration services. The payment bridge, the single sign-on shim, the nightly membership sync to your AMS, the job that pushes event registrations into your CRM. These are far more likely to be .NET 8 than your CMS is, because they were written recently by whoever built the last integration.
- Headless rendering hosts. If you run Sitecore XM Cloud, the content management side is Sitecore-managed but the rendering host is yours to deploy, and Sitecore's own ASP.NET Core starter kit lists .NET 8 as a prerequisite. That is a genuine in-scope item that sits outside the CMS support matrix.
- Supporting services shipped with the platform. Sitecore's Identity Server is an ASP.NET Core application, and on 10.5 the documentation calls for the .NET 10 hosting bundle. On earlier versions it runs on something older. We could not confirm from Sitecore's own documentation which runtime it targets on 10.4 and earlier, so that is a question for your partner rather than a claim we will make.
Three Questions to Put in Writing
These are answerable in an afternoon by whoever administers the site, and the answers are what any honest quote has to be built from.
- Which runtime does each application in our environment target? Not the CMS version. The runtime, listed per application, including every integration service and scheduled job. If the answer is a product name rather than a version number, the inventory has not been done.
- What Windows Server version are we on, and when does it leave support? For most Sitecore and Sitefinity associations this is the question that matters, and it is the one nobody is asking this month.
- Does our vendor publish a supported in-place upgrade for the version we run, and what does it cost? Ask for the vendor's own compatibility matrix, not a summary of it. Sitefinity, for instance, publishes retirement dates by version, 15.3 and 15.2 retire in November 2026, while 15.4 LTS runs to no earlier than January 2030. Those are vendor lifecycle dates that have nothing to do with .NET and everything to do with whether you get patches.
Sometimes the Answer Is an Upgrade, Not a Re-Platform
The incentive here runs the other way, which is why it needs saying. An agency that discovers you are on an unsupported stack has every commercial reason to propose a rebuild. Often that is not the right answer.
If your Sitefinity implementation is well built and you are on 15.2, moving to 15.4 LTS buys you until 2030 and is a fraction of the cost of leaving the platform. If you are on Optimizely CMS 12, updating packages and moving to .NET 10 is a documented path that does not require CMS 13. If you are on Sitecore 10.5 on Windows Server 2019, you may have nothing urgent to do at all.
The re-platform conversation is a separate one, and it should be driven by whether the platform still fits your association, the license cost, whether your staff can edit their own pages, whether it integrates with your AMS, not by a runtime date that may not even apply to you.
Why This Matters More Than Usual Right Now
The timing is genuinely difficult for the sector. The NonProfit Times has reported that federal grants to nonprofits outside hospitals and universities fell more than 40 percent when comparing February to September 2025 against the same period a year earlier, and that growth in private foundation giving of five to seven percent does not offset that. ASAE's own reporting describes the membership model as straining, with half of associations reporting no growth or a decline.
In that climate, an unbudgeted six-figure platform project is not a hard sell. It is an impossible one. Which is exactly why sizing this accurately matters. An organization that establishes it is on Sitecore 10.5 on Windows Server 2019 has just removed a phantom line item from a difficult budget. An organization that discovers it is on Windows Server 2016 has found a real one with seventeen months of warning instead of a surprise.
One honest caveat on the risk framing. Microsoft describes running out-of-support .NET as a security risk, its wording is that doing so may put your applications, application data, and computing environment at risk. It does not make claims about your regulatory compliance. The reason unpatched infrastructure shows up in cyber insurance renewals and security questionnaires is real, but that is a consequence we are describing from experience, not something Microsoft states.
Find Out Which Deadline Is Actually Yours
Put us in touch with whoever administers the environment, or give us access directly. We will inventory every application in your stack against the runtime it targets, identify your Windows Server version and its support date, check your CMS version against the vendor's own published lifecycle, and tell you which of the three deadlines in this post applies to you and when. You will get back a written inventory with a date and a recommendation next to every line, including, where it is the honest answer, that nothing needs to happen this year.