Support periods for Craft CMS and Craft Commerce

Each major version of Craft CMS and Craft Commerce receives at least two years of active support and maintenance from its release date. After that, critical security vulnerabilities are patched for one additional year whenever possible. Once this period ends, the version is considered “end of life” and is no longer supported.

It’s strongly recommended to follow this release schedule, since after the active security update phase ends, no further security guarantees can be provided. 

Pixel & Tonic (the creators of Craft CMS) have shown that in cases of severe security issues, exceptions can be made as part of their extended security architecture — even for older versions. This was demonstrated in April 2025.  

In the Yii framework architecture, on which Craft CMS and Craft Commerce are based, a significant security vulnerability was discovered for the first time in years. Although Pixel & Tonic were not directly responsible, they released a patch within hours that also covered older Craft 3 versions. 
 

Currently supported versions

ProductRelease dateActive support untilSecurity updates until
Craft CMS 4May 4, 2022April 30, 2025April 30, 2026
Craft Commerce 4May 4, 2022April 30, 2025April 30, 2026
Craft CMS 5March 26, 2024April 30, 2027April 30, 2028
Craft Commerce 5April 30, 2024April 30, 2027April 30, 2028

 

No longer supported versions (end of life)

ProductRelease dateSupport ended onSecurity updates ended on
Craft CMS 3April 4, 2018April 30, 2023April 30, 2024
Craft Commerce 3January 28, 2020April 30, 2023April 30, 2024

 

The responsible Craft CMS agency should be aware of all release timelines and apply patches accordingly. For major updates (such as from Craft version 4 to 5), which may require more extensive work depending on the project, it’s advisable to discuss these updates with the client in advance.