Support periods for Craft CMS and Craft Commerce
Each major version of Craft CMS and Craft Commerce receives at least two years of active support and maintenance from its release date. After that, critical security vulnerabilities are patched for one additional year whenever possible. Once this period ends, the version is considered “end of life” and is no longer supported.
It’s strongly recommended to follow this release schedule, since after the active security update phase ends, no further security guarantees can be provided.
Pixel & Tonic (the creators of Craft CMS) have shown that in cases of severe security issues, exceptions can be made as part of their extended security architecture — even for older versions. This was demonstrated in April 2025.
In the Yii framework architecture, on which Craft CMS and Craft Commerce are based, a significant security vulnerability was discovered for the first time in years. Although Pixel & Tonic were not directly responsible, they released a patch within hours that also covered older Craft 3 versions.
Currently supported versions
| Product | Release date | Active support until | Security updates until |
|---|---|---|---|
| Craft CMS 4 | May 4, 2022 | April 30, 2025 | April 30, 2026 |
| Craft Commerce 4 | May 4, 2022 | April 30, 2025 | April 30, 2026 |
| Craft CMS 5 | March 26, 2024 | April 30, 2027 | April 30, 2028 |
| Craft Commerce 5 | April 30, 2024 | April 30, 2027 | April 30, 2028 |
No longer supported versions (end of life)
| Product | Release date | Support ended on | Security updates ended on |
|---|---|---|---|
| Craft CMS 3 | April 4, 2018 | April 30, 2023 | April 30, 2024 |
| Craft Commerce 3 | January 28, 2020 | April 30, 2023 | April 30, 2024 |
The responsible Craft CMS agency should be aware of all release timelines and apply patches accordingly. For major updates (such as from Craft version 4 to 5), which may require more extensive work depending on the project, it’s advisable to discuss these updates with the client in advance.