Uniqcli

Cisco 3925 (CISCO3925/K9) to ISR 4431: EoL Migration Guide

The Cisco 3925 ISR is past Last Day of Support — here is how to migrate cleanly to the ISR 4431 (or Catalyst 8300) without losing feature parity.

UT
Uniqcli Team
December 14, 2025 · 7 min read
Share
Cisco 3925 (CISCO3925/K9) to ISR 4431: EoL Migration Guide

The Cisco 3925 Integrated Services Router (CISCO3925/K9) was a workhorse for large branch and regional aggregation sites throughout the ISR G2 era. If you still have one (or a rack of them) carrying production traffic, that hardware is now fully past its support lifecycle and represents an open audit and security risk. This guide walks through exactly where the 3925 stands, what its milestone dates mean operationally, and how to migrate cleanly to its bulletin successor, the Cisco ISR 4431 (ISR4431/K9), with notes on the Catalyst 8300 as the active platform sold today.

Where the Cisco 3925 stands today

The 3925 was built on the ISR G2 architecture: a fixed multicore router with a swappable Services Performance Engine (the SPE100, upgradeable to SPE200), four EHWIC slots, two SM-X-compatible service module slots, an onboard ISM slot, three integrated Gigabit Ethernet ports, and a PVDM3-based DSP subsystem for voice. With the SPE100 it was rated for roughly 150 Mbps of CEF-switched throughput at large packet sizes, scaling higher with the SPE200. Its strengths were modularity and on-box services (firewall, VPN, voice, WAAS, UC) running on Cisco IOS 15.x. Those same strengths are now liabilities: it is a single-core-class control plane running an OS branch Cisco no longer patches.

For regulated buyers this is the crux. Running an unpatchable router in a federal, DoD, healthcare, or SLED environment creates direct findings against NIST 800-53 (SI-2 flaw remediation, SA-22 unsupported components), CMMC, HIPAA Security Rule, and PCI DSS 6.x. Auditors increasingly flag any device past LDoS as an automatic deficiency regardless of compensating controls.

What each milestone date actually means

End of Sale — December 9, 2017

The last date Cisco accepted new orders for the CISCO3925/K9 through normal channels. After this, any new unit is either old channel stock or used/refurbished gear. It does not affect operation, but it starts the clock on every date below.

End of Software Maintenance — December 9, 2020

The last date Cisco produced bug-fix IOS maintenance releases for the platform. After this point, even customers with an active contract stopped receiving routine software rebuilds; only limited fixes continued under support agreements until the final cutoff.

Last Day of Support — December 31, 2022

The terminal date. No TAC cases, no hardware RMA, no security vulnerability remediation. From an operations and compliance standpoint, the 3925 should be treated as decommission-pending from this date forward. Full milestone detail lives on the CISCO3925/K9 end-of-life page, and you can see related models on the Cisco EoL hub.

Cisco's migration bulletin maps the 3925 to the ISR 4431 (ISR4431/K9). It is a generational leap rather than a like-for-like swap, and the differences are concrete:

  • Throughput and licensing model: The 4431 ships with an aggregate forwarding rate of 500 Mbps by default, license-upgradeable to 1 Gbps — roughly 3x to 6x the 3925's SPE100 ceiling in a 1RU chassis. Performance is unlocked by a throughput license rather than by physically swapping a performance engine, so capacity scales with a license key, not a truck roll.
  • Interfaces and modularity: Four onboard GE ports (combinations of RJ-45 and SFP) plus three NIM (Network Interface Module) slots. NIM is the successor to EHWIC/HWIC; existing voice/serial/T1 modules generally need to be re-homed to NIM equivalents, which is the main parity item to plan for.
  • Operating system: IOS XE 16.x/17.x replaces classic IOS 15.x. IOS XE separates the control plane from a Linux-based data plane (QFP — Quantum Flow Processor), enabling guest-shell containers, model-driven programmability (NETCONF/YANG, RESTCONF), and far better software resilience (ISSU, sub-package upgrades).
  • SD-WAN ready: The 4431 runs Cisco SD-WAN (Catalyst SD-WAN, formerly Viptela) natively in controller mode. The 3925 was never an SD-WAN platform. If WAN modernization is on your roadmap, the 4431 lets you go from traditional routing to overlay/zero-trust segmentation without new hardware.
  • Smart Licensing: Licensing moves from node-locked IOS feature licenses (and PAKs) to Cisco Smart Licensing — IP Base / Security / AppX / DNA tiers managed through Smart Software Manager rather than per-box activation files.

A practical migration plan

1. Assess and inventory

Capture the running config, IOS version, installed EHWICs/SMs/PVDM3s, current throughput utilization, and active feature set (CUBE/SRST, IPsec VPN, zone-based firewall, NetFlow, QoS policy). This drives the right 4431 license tier and which NIMs you need. Pull serials and contract status for every 3925 so finance can plan the capital event.

2. License transition

Set up (or reuse) a Smart Account and Virtual Account before hardware arrives. Decide the throughput tier (500 Mbps vs 1 Gbps boost) and whether you need Security/AppX or full DNA. Pre-stage the license tokens so devices register on first boot rather than during a maintenance window.

3. Config and feature parity

Do not blindly paste IOS 15 config into IOS XE. Many constructs map cleanly, but voice (CUBE/SRST), crypto maps vs IKEv2 profiles, and zone-based firewall syntax should be rebuilt and validated. Convert PVDM3 voice modules to PVDM4 on NIM where DSP services are retained. Lab the converted config against a known-good baseline before touching production.

The 4431 is 1RU (the 3925 is 2RU), so you reclaim rack space and lower power draw. Confirm SFP/SFP+ optics — reuse what is compatible, order what is not. If the branch relied on inline-power EHWICs, note that PoE on the 4431 is handled via a NIM/SM PoE module, not the chassis; size that into the BOM. Map serial/T1 circuits to the equivalent NIM.

5. Phased cutover

Migrate per-site in a maintenance window: pre-stage the 4431 with the validated config, verify routing adjacencies and tunnels in a parallel/burn-in state where the topology allows, then cut the WAN handoff. Keep the 3925 on standby in the rack for one rollback window before removing it.

6. Secure decommission

Wipe configs and crypto material from the retired 3925 (erase startup-config, clear keys, zeroize). For federal/DoD, follow NIST 800-88 media sanitization and document chain of custody and disposition — this paperwork is what closes the audit finding the 3925 created.

Procurement notes for government and enterprise buyers

  • TAA compliance: Confirm country-of-origin for federal and DoD orders; specify TAA-compliant ISR4431/K9 (or C8300) SKUs and request documentation up front.
  • Authorized sourcing: Buy new, warrantied units with valid Smart Licensing entitlement from an authorized Cisco partner — gray-market routers carry no license rights and no warranty.
  • GPC and contract vehicles: Government Purchase Card is accepted for micro-purchases; for larger refreshes we quote against the appropriate contract vehicle and can structure phased delivery.
  • Lead times: Plan for variable lead times on 4431/8300 hardware and NIM modules — order optics and PoE/voice NIMs at the same time to avoid a second procurement cycle.

Browse the replacement platforms in the catalog, or hand us your install base and we will spec the exact 4431 (or 8300) configuration, license tier, and NIM/optic BOM per site.

Frequently asked questions

Is the Cisco 3925 (CISCO3925/K9) still supported by Cisco?

No. The 3925 hit End of Sale on December 9, 2017, End of Software Maintenance on December 9, 2020, and Last Day of Support on December 31, 2022. Past LDoS there are no security patches, no IOS maintenance rebuilds, and no TAC or RMA service of any kind.

What is the official replacement for the Cisco 3925?

Cisco's migration bulletin maps the 3925 to the ISR 4431 (ISR4431/K9), a 1RU IOS XE router with 500 Mbps to 1 Gbps of license-upgradeable throughput, four onboard GE ports, and three NIM slots. For new procurement in 2026 the Catalyst 8300 is the active forward-looking edge platform.

Can I reuse my EHWIC and PVDM3 modules in the ISR 4431?

Generally no. The 4431 uses NIM (Network Interface Modules) rather than EHWIC/HWIC, and PVDM4 rather than PVDM3 for DSP voice. Plan to re-home serial, T1, and voice services onto NIM equivalents as part of the migration BOM.

How does licensing change moving from the 3925 to the 4431?

The 3925 used node-locked IOS feature licenses and PAKs, with performance set by a physical Services Performance Engine. The 4431 uses Cisco Smart Licensing (IP Base / Security / AppX / DNA tiers) managed through a Smart Account, and unlocks throughput via a license key rather than a hardware swap.

Why does running a Cisco 3925 past LDoS create a compliance problem?

Because no security patches are issued, any post-2022 CVE remains permanently unfixed. That triggers findings under NIST 800-53 (SI-2, SA-22), CMMC, HIPAA, and PCI DSS for using unsupported components, which auditors typically flag automatically regardless of compensating controls.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote