SQL Server Blog Post

Migrations & Upgrades

SQL Server 2016 – But still, it’s farewell…

Written by Mike Walsh

July 20, 2026

This post is part of our series “SQL Server 2016 – The Final Countdown.”

Welp, it’s all done. The final countdown came and went… SQL Server 2016 is as dead as the parrot purported to be pining the for the fjords. I mean actually, it’s a bit more like that parrot than you’d imagine. But if you’ve done nothing about it, it’s definitely dead for you. And in the song that Jeff and I decided to use as the theme song for the post series, Europe posited, “I guess there is no one to blame” a couple lines before asking “Will things ever b the same again?”. They’re wrong, if you’re still on SQL Server 2016, someone somewhere in your organization is to blame. And no, if you stay there, things will not be the same. I mean they literally will be, but when the compliance team or lawyers (or the CFO) come looking, they’ll want to find that one who is to blame. SQL Server 2016s resilience out there is some sort of a strange testament to how well it’s built, maybe we’ll all miss her so. But anyway it was the final countdown. Yeah.

SQL Server 2016 is Dead – What do you do now?

Jeff summed this up in the post he wrote when he kicked off the series. You have three options:

Choose Not To Decide – Neil Peart wrote it best – if you choose not to decide you still have made a choice… You can choose to stay on SQL Server 2016 and do nothing for the extended updates. If you’ve chosen that (or put of the decision) this is what you’ve decided:

  • No more feature updates or bug fixes
  • No more security updates – This is the one that should scare the heck out of your compliance folks and any executives in the path to that decision. You’re signing up for security risks just when the AI tools are making security patches get more and more serious. Vulnerabilities are being discovered left and right, vulnerability hunters are getting mad about missed payouts and threatening to release the things they are finding, bad actors are using just as many tokens as folks are for their homegrown tools. This is the kind of stuff that comes up in the lawsuits.
  • No new features/improvements/updates – If you are a software vendor and you aren’t supporting the latest versions of SQL Server, you are waving the white flag. If you are hosting data that anyone anywhere cares about and you aren’t on at least SQL Server 2019, it’s some sort of a strange message you are sending to your customers and partners about what you think of security. And if you aren’t paying through the nose for the potential to at least maybe get some security updates, you should just rip up any of your compliance attestations. You are more living on prayers.

Help Microsoft Get Richer – You can use the sort of complicated and expensive Extended Security Update (ESU) process Microsoft has created to let you pay through the nose for security updates. You can read about the options to pay for it here. But this is what this approach means:

  • You pay an expensive “license price” equivalent for this “privilege” – This is priced by 2 core pack (like licenses) and you are paying somewhere around $3,336 to $13,000 per two core pack per year from what I’ve seen. And I’ve seen some confusion around if it will be a stable price over the 3 years or an increasing one – it seems like it will now be a stable price – just shy of new licenses but I am not even 100% sure there because I’ve seen a few different articles published.
  • You are only getting Critical Security Updates – And it’s not you and I who decide what critical looks like. And if you look at the pace of vulnerabilities and even a recent argument between an exploit hunter and Microsoft that has spilled over into the public sphere, you can see that not all agree on what is critical and what isn’t. Microsoft is busy, they are obsessed with Fabric and Cloud and new products, I wouldn’t bet my clients’ data on SQL Server 2016 getting a lot of attention for critical updates.
  • You are kicking the can and getting complacent – For a tiny bit less than the cost of upgrading and getting modernized, you are purposefully deciding to stay on a ten year old product.

Upgrade/Migrate – You can upgrade to a more modern version of SQL Server (don’t go to SQL Server 2017, you’ll be reading these same posts next year and all we have to do is republish with a find and replace for 2016 to 2017…) Yeah upgrading sounds really scary (and if you do an in-place upgrade it will be) but in the grand scheme of things upgrading SQL Server isn’t really that big of a task for most folks. We have a ton of posts and an entire video series (it’s a bit older but much of it still applies) on upgrading SQL Server. Check out these tags on the blog (tell me you have some tag cleanup left to do without telling me you do…). You can modernize, eliminate the compliance and finance risk of the above two options and for a lot of clients, you can look to license efficiency, consolidation, and even look at if you still need Enterprise Edition (SQL Server 2025 gives you 256GB of RAM now… We’ve helped a lot of clients move from Enterprise to Standard and modernize to the cloud or their own data centers in the process of upgrades.)

A well-planned migration to SQL Server 2025 or SQL Server 2022 doesn’t have to be as scary as the prospect sounds. With some simple planning, simple build out, testing, and compatibility mode settings – we’ve helped many shops move to a supported version of SQL Server in as little as 20 hours of consulting time for simple environments and a bit more as complexity (sprawl, availability options, etc.) dictate. If you’d like to talk about this – reach out – we’re happy to have a consulting chat with you and you’ll probably walk away with some thoughts on how this can and should look even if you wind up doing the work yourself. I’m happy to point someone in the right direction especially if it means one more SQL Server 2016 (or 2017) instance is placed out of service on purpose.

Check Out the Rest of the Posts In this Series

Thanks to Jeff Iannucci for a lot of heavy lifting in this series and to Mike Lynn for the security take also. At the end of the day – we live in a litigious, risky world with lots of threat actors, tools that make exploiting holes easier, and if you are running SQL Server 2016 or SQL Server 2017 (because the SQL Server 2017 end of life is coming in 15 months.) and not paying scores to hundreds of thousands of dollars a year to Microsoft for the hope of maybe getting a security update, you are gambling with your customers’ data. It’s that simple. And I’m telling you – upgrading a SQL Server is a lot less risk and work than you’d imagine. We do dozens of them a year for our 130+ clients under management with us, so maybe it’s just become second nature. If you have any questions leave a comment or send an e-mail or contact us. I’m happy to point you in the right direction whether you become a customer or not.

Sign Up for Updates

Sign up for our newsletter to receive updates about new blog posts, webinars, DBA tools, and more.

Leave a Comment