Uniqcli

Cisco 5520 WLC (AIR-CT5520-K9) to Catalyst 9800-40 Migration

The AIR-CT5520-K9 is past End of Sale and reaches hardware Last Day of Support on January 31, 2027. Here is why this AireOS controller has to be retired, what the Catalyst 9800-40 (C9800-40-K9) gives you, and how to migrate without ripping out your access points.

UT
Uniqcli Team
February 19, 2026 · 10 min read
Share
Cisco 5520 WLC (AIR-CT5520-K9) to Catalyst 9800-40 Migration

If you still run a Cisco 5520 Wireless Controller (PID AIR-CT5520-K9) as the brain of a large campus or multi-site wireless deployment, you are operating an appliance that Cisco stopped selling on December 10, 2021. For years the 5520 was the workhorse high-scale controller of the AireOS era: a 1RU appliance supporting up to 1,500 access points and 20,000 clients, 20 Gbps of throughput, dual 10GbE SFP+ data ports, and stateful switchover (SSO) high availability tuned for the 802.11ac Wave 2 generation. It earned its reputation. But the hardware and its operating system are both on a published retirement clock, and for regulated buyers in federal, DoD, SLED, and healthcare environments, the back half of that clock is the dangerous part.

This guide is specific to your hardware. It covers what each end-of-life milestone actually means for an AIR-CT5520-K9, why the Catalyst 9800-40 (C9800-40-K9) is the right successor and where it concretely beats the 5520, and a practical migration plan that lets you keep most of your existing access points while you swap the controller underneath them. You can see the full milestone record for this PID on our dedicated Cisco 5520 (AIR-CT5520-K9) end-of-life page.

The end-of-life situation for the AIR-CT5520-K9, and why now is the deadline that matters

End of Life is not one switch that flips on a single date. For the 5520 it is a sequence, and the gap between those dates is where risk accumulates. Most teams anchor on the Last Day of Support, but two earlier milestones have already passed and are already shaping your exposure.

  • End of Sale: December 10, 2021. You can no longer buy a new AIR-CT5520-K9 through Cisco. Any unit you add now is secondary-market or refurbished, and it inherits the same end dates as the rest of your fleet.
  • End of Software Maintenance: January 31, 2023. This is the milestone that quietly turned the 5520 into a liability. After this date Cisco no longer ships maintenance or bug-fix releases for the AireOS train that runs on this controller. New PSIRT security advisories that affect this code generally do not get a fixed release on the platform, so a critical wireless CVE can leave you with no patch and only manual workarounds.
  • Application Software Last Date of Support: January 31, 2025. The AireOS software image on the 5520 has already reached its own end of support, separate from and earlier than the hardware.
  • Hardware Last Day of Support (LDoS): January 31, 2027. After this date Cisco TAC will not take support cases for the chassis, and RMA hardware replacement ends. A failed power supply or a dead controller becomes your problem to solve from spares, not a service request.

Read those two LDoS dates together, because the split is the trap. The application software is already unsupported as of early 2025, even though the hardware contract runs to January 2027. In practice that means you are running production wireless on an operating system that no longer receives fixes, on a box whose RMA safety net expires in 2027. Browse the wider Cisco end-of-life tracker and you will see this pattern across the AireOS line.

Cisco names the Catalyst 9800-40 Wireless Controller as the migration path for the 5520, and it is a genuine generational step rather than a like-for-like swap. The move is not only newer silicon, it is a different operating system and a different licensing world. The 5520 runs AireOS; the 9800-40 runs Cisco IOS XE, the same OS family as the Catalyst 9000 switching line, which means one config model, one set of programmability tools (NETCONF/YANG, RESTCONF, model-driven streaming telemetry), and one upgrade discipline across wired and wireless.

Scale and throughput, side by side

The 9800-40 raises every ceiling that mattered on the 5520. Where the 5520 topped out at 1,500 APs and 20,000 clients with 20 Gbps of throughput, the 9800-40 supports up to 2,000 access points and 32,000 clients, with up to 40 Gbps of sustained forwarding through the chassis and a dedicated security processor handling roughly 30 Gbps of crypto so that DTLS-encrypted CAPWAP control and data traffic does not steal cycles from forwarding. It stays in a 1RU footprint, draws around 250 W typical, and carries field-replaceable, ECC-protected memory plus RAID 1 storage for resilience the 5520 did not have.

Wi-Fi generation and airtime efficiency

This is the upgrade your users will actually feel. The 5520 was engineered for 802.11ac Wave 2. The 9800-40 is a Wi-Fi 6 (802.11ax) controller that also drives Wi-Fi 6E access points in the 6 GHz band, which unlocks OFDMA and uplink/downlink MU-MIMO for far better behavior in dense client environments, plus WPA3 and Enhanced Open. Keeping the 5520 caps your entire wireless estate at Wave 2 no matter how modern the APs you hang off it; the controller becomes the lid on the network. Moving to the 9800-40 lets you adopt current and next-generation Catalyst access points as you refresh radios, rather than re-architecting later.

High availability and zero-impact upgrades

The 5520 offered SSO with sub-second AP and client failover, which was strong for its day. The 9800-40 keeps SSO but adds operational maturity the AireOS box could not: N+1 redundancy without dedicated standby hardware, a Redundancy Management Interface (RMI) for cleaner split-brain handling, In-Service Software Upgrade (ISSU), patching/hot patches for targeted fixes without a full reload, and rolling AP upgrade with image pre-download so access points reboot once onto the new image and rejoin with minimal client disruption. For a hospital or a 24/7 agency facility, the ability to patch a CVE without a full maintenance outage is itself a reason to move.

Licensing: from AireOS feature licenses to Smart Licensing Using Policy

The licensing model changes completely and you must plan for it. The 9800-40 uses Cisco Smart Licensing Using Policy (SLUP) with the Cisco Catalyst (DNA/Network) software stack at Essentials or Advantage tiers, reported either directly to Cisco Smart Software Manager (SSM), through an on-prem SSM satellite for air-gapped or classified networks, or via offline reporting. The old AireOS right-to-use and PAK-style entitlements on the 5520 do not transfer. Budget for term-based subscription licensing per access point and confirm the tier early, because features like Catalyst Center assurance and SD-Access fabric integration live in the higher tier.

A practical migration plan

The good news for 5520 owners is that this is primarily a controller swap. Most access points already joined to a 5520 are CAPWAP-based and supported on the 9800-40 once they download the IOS XE-compatible image, so in many deployments you migrate the controller and keep the radios, then refresh APs to Wi-Fi 6/6E on your own schedule. Validate your exact AP models against the 9800 support matrix first, since the oldest Wave 1 APs are not supported.

1. Assess and inventory

  • Capture the running AireOS config from the 5520 (show run-config startup-commands) and a full backup, plus a current AP inventory with model, count, and per-site distribution.
  • Confirm each AP model is supported on the target 9800 IOS XE release; flag any end-of-life Wave 1 APs that need to be refreshed as part of the project rather than migrated.
  • Document WLAN/SSID count, RF profiles, AP groups, FlexConnect sites, mobility groups, RADIUS/ISE integration, ACLs, and any mesh or guest-anchor design so nothing is lost in translation.

2. Translate the configuration

Do not hand-rebuild the config. Cisco provides a Wireless Config Converter that ingests your AireOS startup config and produces an IOS XE configuration for the 9800, classifying every line as translated, unsupported, not-applicable, or unmapped. The unsupported and unmapped buckets are your real work list; that is where you redesign features that changed between AireOS and IOS XE (the FlexConnect, AP-group-to-policy-tag, and RF model differences are the usual ones). The 9800 also exposes the converter natively under Configuration > Services > AireOS Config Translator.

3. Plan licensing transition

  • Stand up Smart Licensing Using Policy and decide on direct SSM, on-prem SSM satellite (the right answer for most DoD/air-gapped sites), or offline reporting before cutover.
  • Size Catalyst (DNA) Essentials or Advantage subscriptions per AP for the term you intend to run, and align expiry with your support contract.
  • Confirm whether you also want Catalyst Center (formerly DNA Center) for assurance and automation, since that drives the tier decision.
  • Both controllers are 1RU, so rack space is rarely the constraint, but verify uplinks. The 5520 used 2x 10GbE SFP+; the 9800-40 offers a richer port set including 10G SFP+ and 40/100G QSFP28 uplinks, so confirm your distribution-switch ports and optics (and that optics are TAA-compliant where required).
  • Plan dual power supplies and matching circuits for HA, and keep the 9800 pair on the same code train for SSO.
  • Stage the controllers in parallel with the 5520 still in production so you can validate before any client moves.

5. Phased cutover

Migrate by site or AP group, not all at once. Pre-download the IOS XE AP image so the join is a single reboot, move a pilot AP group to the 9800-40, validate authentication (RADIUS/ISE), roaming, RF, guest, and any FlexConnect local switching, then expand in waves. Keep the 5520 available as a fallback join target until each wave is confirmed stable. This is the lowest-risk path for environments that cannot take a hard cutover.

6. Secure decommission

Once the 5520 is drained, wipe the configuration, remove RADIUS shared secrets and any stored credentials, and follow your sanitization standard (NIST SP 800-88 media sanitization for federal and DoD). Update your CMDB and your ATO/system boundary documentation to remove the AireOS controller and add the 9800-40 with its current software level so the next audit reflects supported infrastructure.

Procurement notes for regulated buyers

As an authorized Cisco partner, uniqcli sources the C9800-40-K9 and the matching Catalyst access points through compliant channels. For federal and DoD work that means Trade Agreements Act (TAA) compliant hardware, the ability to transact against GSA and government purchasing vehicles, and documented authenticity to keep counterfeit and gray-market gear out of your supply chain. Controller and AP lead times move with demand, so quote early and lock the licensing term alongside the hardware. You can compare current Catalyst wireless options in our catalog, and when you are ready to scope a 5520 refresh with real part numbers, licensing tier, and lead times, get a quote and our team will build the bill of materials and migration plan around your existing AP fleet.

Frequently asked questions

Is the Cisco 5520 (AIR-CT5520-K9) still supported in 2026?

Partially, and not for long. Hardware support (TAC cases and RMA) runs until the Last Day of Support on January 31, 2027. However, software maintenance ended January 31, 2023 and the AireOS application software reached its own Last Date of Support on January 31, 2025, so the controller already runs an unsupported OS that does not receive new security patches. You should plan migration before the January 2027 hardware cutoff.

Do I have to replace my access points when I move from the 5520 to the Catalyst 9800-40?

Usually not all of them. Most CAPWAP access points joined to a 5520 are supported on the 9800-40 once they load the IOS XE-compatible image, so a common approach is to migrate the controller first and keep the existing radios, then refresh APs to Wi-Fi 6/6E on your own schedule. The exception is the oldest 802.11ac Wave 1 APs, which are not supported on current 9800 releases and should be refreshed as part of the project. Always validate your exact AP models against the 9800 support matrix first.

How is the Catalyst 9800-40 better than the 5520 for a large deployment?

It raises every ceiling and adds operational maturity. The 9800-40 scales to 2,000 APs and 32,000 clients with up to 40 Gbps forwarding and a dedicated ~30 Gbps crypto processor, versus 1,500 APs, 20,000 clients, and 20 Gbps on the 5520. It is a Wi-Fi 6 controller that also drives Wi-Fi 6E APs (6 GHz, OFDMA, WPA3), runs IOS XE with full programmability and telemetry, and supports ISSU, hot patching, N+1, and rolling AP upgrades so you can patch CVEs without a full outage.

Does my AireOS configuration transfer to the Catalyst 9800-40?

Not directly, but Cisco provides a Wireless Config Converter that translates your AireOS startup config into an IOS XE configuration for the 9800, flagging each line as translated, unsupported, not-applicable, or unmapped. The converter is available online and embedded in the 9800 Web UI under Configuration > Services > AireOS Config Translator. Plan to redesign the features it cannot map, typically FlexConnect, the move from AP groups to policy/site/RF tags, and RF profiles.

What changes with licensing on the Catalyst 9800-40?

The 9800-40 uses Cisco Smart Licensing Using Policy with the Catalyst (DNA/Network) software stack at Essentials or Advantage tiers. AireOS PAK and right-to-use entitlements from the 5520 do not carry over, so you purchase term-based subscriptions per access point. Reporting can go directly to Cisco Smart Software Manager, through an on-prem SSM satellite for air-gapped or classified networks, or offline. Confirm the tier early since Catalyst Center assurance and SD-Access fabric features require Advantage.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote