The official dates
| Milestone | What it means | Date |
|---|---|---|
| End of sale | Last day to order new Umbrella DNS or SIG subscriptions | January 31, 2027 |
| End of change or renewal | Last day to renew or add to an existing subscription | January 31, 2028 |
| Last date of support | Service and support end for active subscriptions | January 31, 2029 |
Service doesn't stop right away: existing customers keep working until their subscription ends, within these dates. Plan the move before your next renewal after January 2028 at the latest.
What Cisco recommends
Cisco is moving Umbrella DNS customers to Cisco Secure Access – DNS Defense and Umbrella SIG customers to the wider Cisco Secure Access platform, which adds capabilities such as zero-trust network access. If you rely on Umbrella's roaming client, SWG, CASB or deep Cisco integrations such as Meraki, staying in the Cisco family is often the least disruptive route.
When an alternative makes sense
A migration is a natural moment to check you're paying for what you use. An alternative is worth a look if:
- you mainly use Umbrella for DNS-layer threat blocking and content filtering at your offices;
- per-user pricing is expensive for sites with many shared or unmanaged devices;
- you're an MSP and want flat, multi-tenant pricing with room for margin; or
- you want a simpler portal and faster setup.
Stay with Cisco's path if you depend on features beyond DNS filtering, such as SWG, CASB, DLP, cloud firewall or ZTNA, or on a managed agent with tamper protection for off-network laptops.
What to compare
| Question | Why it matters | DNSAFE |
|---|---|---|
| Is protection network-level, per device, or both? | Roaming laptops need an agent or device-level encrypted DNS | Both: networks (offices, Wi-Fi, guest networks), plus per-device encrypted DNS for laptops and phones that leave the office. No agent |
| How is it priced? | Per-user costs grow with headcount and devices | Per network: business from $19/month, MSPs from $49/month flat |
| Where are the resolvers? | Latency and resilience | US, UK and Singapore with health-checked failover |
| What integrations do you need? | SIEM, PSA, SSO | SIEM, ConnectWise and Autotask, SAML SSO and Duo, REST API |
| How much migration work? | Downtime risk | Change the DNS servers in DHCP or AD forwarders; about 15 minutes per site |
Try DNSAFE on your own network: 14 days free, no card, set up in minutes.
Start free trialHow to migrate DNS filtering with no downtime
- Export your Umbrella policies: allow and block lists and blocked categories.
- Recreate them in the new service, and register each site's public IP.
- Move one site first: change the DHCP DNS servers or AD forwarders from the Umbrella addresses (
208.67.222.222and208.67.220.220) to the new ones. See firewall steps. - Watch for a week, tune the allow list, then move the other sites.
- Remove old components such as virtual appliances, roaming clients and Meraki integrations once every site is moved.
Frequently asked questions
Is Cisco Umbrella being discontinued?
Cisco announced the end of sale and end of life of Umbrella DNS and SIG on September 1, 2026. New orders end January 31, 2027, renewals January 31, 2028, and support January 31, 2029. Cisco is moving customers to Cisco Secure Access.
Will my Umbrella service stop working in 2027?
No. Existing subscriptions keep working. January 31, 2027 is only the last day to buy new subscriptions. Support continues for active subscriptions until January 31, 2029.
Does DNSAFE have a roaming client like Umbrella?
Not as an agent. Each laptop or phone can get its own encrypted DNS setup (DNS-over-HTTPS or DNS-over-TLS) from the portal, and the network’s policy follows it to home Wi-Fi, hotels and mobile data. There’s nothing to install, so a user with admin rights on the device can remove the setting. If you need a locked-down agent, keep an agent-based tool for those devices.