Buying a NAS by its update promise: Synology, QNAP, TrueNAS and openmediavault
A Synology DS1812+ has had no security updates since 1 October 2024. The box still runs. It is simply stuck on DSM 6.2, and that branch finished its last support phase on that date — Synology published both facts itself. Around twelve years, then nothing. Anyone asking how long the next box will last has to separate two questions that every buying guide runs together.
Two clocks, and the shorter one wins
The first clock belongs to the model and stops when the vendor no longer carries your hardware onto the next OS branch. The second belongs to the operating system branch and stops when the vendor retires it, however new the hardware underneath. While your model keeps following the current branch, only the second matters: you update, and the date moves with you. Once the vendor stops lifting your model onwards, the end date of the last branch it reached becomes yours. That is why a search like “synology eol list” lands on two different lists, depending on which question you were asking.
What Synology commits to
patchletter records thirteen DSM support cycles — the same thirteen that appear in Synology’s software life cycle policy (document dated 3 July 2026). As of 19/08/2026, two are still ahead of their final date. The recent branches:
| Branch | Available | Maintenance ends | Extended life ends |
|---|---|---|---|
| DSM 7.4 | 06/2026 | 06/2028 | — |
| DSM 7.3 (LTS) | 10/2025 | 10/2027 | 10/2028 |
| DSM 7.2 | 06/2023 | 12/2025 | — |
| DSM 7.1 (LTS) | 04/2022 | 06/2024 | 06/2025 |
| DSM 6.2 (LTS) | 05/2018 | 06/2021 | 09/2024 |
DSM 7.4 has no extended life phase at all; support stops in June 2028. DSM 7.3 shipped eight months earlier and runs to October 2028 — but its maintenance phase ends a year before that. The difference matters: in the maintenance phase Synology ships critical security fixes plus selected urgent bug fixes, in the extended life phase only critical security fixes. The later date buys a year of the thinner service.
And the branch date does not apply to everyone. Footnote 2 of that policy states that the extended life phase for DSM 7.1 covers only a named list of models — the same devices Synology elsewhere labels the 13 to 15 series. Run 7.1 on anything else and your end date was June 2024, not June 2025. The same document adds its own caveat: “All future dates mentioned for life-cycle phases are close approximations, non-definitive, and subject to be extended.”
And your model? A state, not a date
The model clock lives elsewhere — on the product support status page, searched by model name. Availability is Generally Available or Discontinued; the update column holds Full (firmware and software updates continue), Limited (only security updates) or End of Life (future firmware, software and security updates are discontinued). No date appears anywhere in that table — only a state that changes when Synology decides it does. Dates turn up in one-off announcements instead, such as the end-of-life notice for DSM 6.2, which names the series capped at that branch: the 11 and 12 series, and with them the DS1812+ from the first paragraph.
QNAP: both clocks, both published
QNAP prints the model clock more precisely. Its product support status gives every model four status columns: availability, hardware repair, OS and application updates, and technical support plus security updates. Per the legend, the last two hold either “Full” / “Active” or an end date as year and month; for retired models the OS column instead names the last QTS or QES version the model can reach. The same page also carries an operating system lifecycle overview with four phases, as specific as Synology’s: QTS 5.2 (LTS) has been generally available since August 2024, left the production phase in August 2025 and the maintenance phase in December 2025, and its LTS phase runs to August 2029 — with only critical security updates and major stability fixes in that phase. QTS 5.1 had no LTS phase and was finished in November 2024; QuTS hero h5.2 (LTS), like QTS 5.2, runs to August 2029.
Below the model table sits a note that reframes everything above it: “The latest version contains fixes for all security issues. Due to architectural and system changes that require the latest version of QTS, not all security issues are addressed in earlier versions.” A model whose row still says Full, but which sits on an older QTS branch, is not receiving every fix. The date is an upper bound, not a guarantee.
Build it yourself: the clock sits in the base
Build the box yourself and the model clock disappears — nobody withdraws support from your motherboard. Nobody writes down an end date either. The TrueNAS software status page shows trains and their state, not their expiry: 25.04 (Fangtooth) went Stable on 15 April 2025, 25.10 (Goldeye) on 28 October 2025, and TrueNAS 26 is still in early release (BETA.2, 17 June 2026). The only lifecycle statement is that bug tickets are typically accepted for the latest release of the current stable version. End points are readable only in hindsight: the 24.10 train got its last maintenance release on 7 August 2025, and 25.04 got its last, 25.04.2.6, on 30 October 2025 — two days after 25.10 went stable.
With openmediavault the clock belongs to Debian. The project’s release table says so plainly: 7.0 (Sandworm) sits on Debian 12 and is marked EOL as of June 2026, 8.0 (Synchrony) sits on Debian 13 and has been Stable since December 2025. Debian 13 (Trixie) was released on 09/08/2025, is supported until 09/08/2028 and has extended security support until 30/06/2030, per endoflife.date. On paper the longest runway of the four — but it is Debian’s runway, and your NAS only benefits while the openmediavault major version on top is maintained as well.
The honest limitation
As of 19/08/2026, none of these products has an entry from the CISA catalogue of known exploited vulnerabilities mapped to it in our dataset. That is a statement about our mapping, not about the devices. KEV lists only flaws whose exploitation has been observed and confirmed, its entries hang off specific product identifiers, and network storage has a long public history as a target. Reading an empty column as “safer” would be the wrong conclusion.
The lifecycle data is uneven too. endoflife.date, the usual public source for support cycles, carried none of these four products when we queried its product list on 19/08/2026. Our own dataset holds support cycles for DSM and for none of the other three, so every QNAP, TrueNAS and openmediavault date above comes straight from the vendor or the project. Where the data does not exist, saying so is the whole service.
If it ends up being Synology or QNAP
Then the OS branch is the clock to watch, because it is the one that moves. The Synology DSM and QNAP QTS product pages list the recorded versions, and you can tick a product to get an email whenever a new version ships — free, no account, one-click unsubscribe. A new branch appearing is also the moment you find out whether your model came along. What is running out elsewhere is on the end-of-life overview.
Thirteen DSM cycles and the two still ahead of their final date: our own dataset, as of 19/08/2026. All other dates and quotes from the linked sources, retrieved on 19/08/2026: Synology software life cycle policy (3 July 2026), product support status and the DSM 6.2 end-of-life announcement; QNAP product support status including its operating system lifecycle overview; TrueNAS software status; the openmediavault release table; Debian cycles from endoflife.date.