
The Cisco Meraki MR33 (PID MR33-HW) was one of the most widely deployed entry-class cloud-managed access points of its generation — an 802.11ac Wave 2, 2x2:2 dual-band unit that found its way into branch offices, classrooms, clinic exam rooms, and retail back-of-house by the thousands. Its lifecycle is now closing. Cisco set End of Sale on May 7, 2021, and the Last Day of Support (LDoS) is July 21, 2026. If you still have MR33s in production, the window to plan a clean, funded refresh is measured in months, not years. The direct successor is the Wi-Fi 6 Meraki MR36 (PID MR36-HW), and this guide explains why the move matters and how to execute it.
What the MR33 end-of-life milestones actually mean
Lifecycle bulletins use precise terms that carry real operational and contractual weight. Here is how each applies to the MR33.
End of Sale: May 7, 2021
Cisco stopped selling new MR33-HW units through normal channels on this date. Any 'new' MR33 you encounter now is old channel inventory or used/refurbished gear. More importantly, the EoS date is the clock that all downstream milestones are measured from — it is why LDoS lands in mid-2026.
Last Day of Support (LDoS): July 21, 2026
This is the hard cutoff and the date that should drive your project plan. After July 21, 2026, Cisco Meraki provides no TAC support, no RMA hardware replacement, and no further firmware or security maintenance for the MR33. Because Meraki is a cloud-managed platform, this last point is sharper than it is for on-prem gear: the dashboard will eventually stop shipping new firmware features and PSIRT fixes to the MR33 hardware class, and an unsupported AP that fails in the field cannot be RMA'd — it is simply down until you replace it.
Why acting before LDoS matters
For regulated buyers — federal and DoD, SLED, and healthcare — running hardware past its Last Day of Support is not just a reliability question, it is a compliance and audit-exposure question.
- No more security patches: once firmware maintenance ends, any newly discovered Wi-Fi or platform vulnerability on the MR33 stays unpatched. For environments under FISMA, FedRAMP, HIPAA, or PCI-DSS, an unsupported, unpatchable device on the network is a documented finding waiting to happen.
- No TAC or RMA: a failed MR33 after LDoS means an unplanned coverage gap with no vendor recourse. You are self-insuring on cold spares of a product nobody sells new anymore.
- Cloud-platform drift: as the Meraki dashboard and newer firmware trains move forward, legacy hardware classes lose access to new features and, eventually, to the firmware versions that pair with current dashboard capabilities.
- Audit and accreditation: atOs (Authority to Operate) renewals and SLED security reviews increasingly flag past-LDoS network gear. Refreshing ahead of the date keeps your hardware inventory clean.
The recommended replacement: Meraki MR36 (Wi-Fi 6)
The MR36-HW is the intended one-for-one successor to the MR33, and Cisco designed it to drop into the same physical and power footprint. That makes it an unusually low-friction refresh — but the performance jump under the hood is significant.
Same footprint, same power budget
Both APs are 2x2:2 dual-radio units with a single 1G (10/100/1000BASE-T RJ45) uplink, and both run inside an 802.3af / 15W PoE budget — about 15W max. That means in most deployments your existing Cat 5e/6 cabling, your existing 802.3af switch ports, and your existing ceiling mounts carry straight over. You generally do not need new switches or a PoE upgrade to move from MR33 to MR36, which keeps the project scope tight and the budget predictable.
What is concretely better
- Wi-Fi 6 (802.11ax) vs. Wi-Fi 5 Wave 2: the MR36 moves to 802.11ax, lifting peak 5 GHz PHY rate to roughly 1,201 Mbps on a 2x2 radio versus the MR33's Wave 2 ceiling.
- OFDMA and MU-MIMO: 802.11ax OFDMA lets the MR36 subdivide a channel and service many small-frame clients in the same airtime slot — exactly the IoT-heavy, high-density profile (clinics, classrooms, conference rooms) where MR33s struggle. The MR33's Wave 2 silicon cannot do this.
- BSS Coloring and Target Wake Time: reduced co-channel interference in dense AP layouts, plus battery savings for IoT and mobile clients — real gains in DoD and healthcare environments saturated with handhelds and sensors.
- Dedicated third security radio: the MR36 carries a separate 24x7 WIDS/WIPS and RF-analytics radio, so air monitoring and rogue detection no longer steal airtime from client serving — a meaningful posture upgrade for security-conscious buyers.
- Integrated BLE/IoT radio: a fourth, built-in Bluetooth Low Energy radio supports beaconing and asset tracking natively, enabling location and IoT use cases the MR33 cannot.
- Higher effective client capacity: the combination of Wi-Fi 6 efficiency and OFDMA pushes practical, comfortable client counts toward ~100 per AP versus the ~50-device sweet spot of the MR33.
Licensing follows the standard Meraki model: the MR36 needs a per-AP Meraki Enterprise (or Advanced) cloud license for the term you choose. Plan the license alongside the hardware so the new APs come online in the dashboard without a coverage gap.
A practical migration plan
1. Assessment and inventory
Pull an exact MR33 count and per-site placement from the Meraki dashboard — it already knows every serial, model, and network. Note any sites where MR33s sit on 802.3af-only switch ports (good news: the MR36 is fine there) and any PoE injectors in play. Capture current SSID, RF profile, and group-policy configuration per network.
2. License transition
Confirm remaining Meraki license term and decide whether to co-term new MR36 licenses to your existing renewal date or start fresh. Order MR36 licenses to match the hardware quantity and term. Do this early — license posture is the most common cause of cutover-day surprises.
3. Config and feature parity
Because both APs live in the same Meraki dashboard, SSIDs, access control, group policies, and most RF settings carry forward when you add MR36s to the same network. Review RF profiles to take advantage of Wi-Fi 6 features (enable OFDMA-friendly settings, revisit channel width and minimum bitrates now that the airtime budget is healthier).
4. Physical, power, and uplink check
Verify each drop is 802.3af-capable (it almost certainly is if it ran an MR33), confirm Cat 5e/6 cabling, and reuse existing mount brackets where the form factor matches. The single 1G uplink is unchanged, so no optics or switch-uplink rework is required for a like-for-like swap.
5. Phased cutover
Stage MR36s in the dashboard, then swap site by site or floor by floor during maintenance windows. Because the dashboard treats both as Meraki APs, you can run mixed MR33/MR36 coverage during the transition with no client disruption, then retire MR33s as each zone is validated.
6. Secure decommission
Remove retired MR33s from the dashboard, factory-reset units before disposal, and for federal/DoD follow your media-sanitization and property-disposal process (NIST 800-88 guidelines, GPC/asset records updated). Document the swap in your hardware inventory to close the audit loop.
Procurement notes for regulated buyers
Lead times on Wi-Fi 6 APs can move with demand cycles, so order ahead of your cutover windows rather than at LDoS. For federal and SLED, confirm TAA compliance and country-of-origin documentation, align purchases with GPC thresholds and contract vehicles, and buy through an authorized Cisco/Meraki partner so warranty, licensing registration, and support entitlement attach cleanly. As an authorized partner, uniqcli can validate your dashboard inventory, scope the exact MR36 and license quantities, and confirm TAA paperwork before you commit.
Review the full lifecycle record for this product on our MR33-HW end-of-life page, browse all current Cisco end-of-life notices, or check live MR36 availability in our catalog.
Frequently asked questions
When does the Cisco Meraki MR33 reach end of support?
The MR33 (MR33-HW) hit End of Sale on May 7, 2021, and its Last Day of Support (LDoS) is July 21, 2026. After that date there is no TAC support, no RMA replacement, and no further firmware or security maintenance for the MR33 hardware class. Plan your refresh to complete before then.
What is the recommended replacement for the Meraki MR33?
The Wi-Fi 6 Meraki MR36 (MR36-HW) is the direct successor. It keeps the same 2x2:2 dual-radio design, single 1GbE uplink, and 802.3af/15W PoE budget as the MR33, so in most cases it reuses your existing cabling, switch ports, and mounts — while adding 802.11ax, OFDMA, a dedicated security radio, and integrated BLE.
Do I need to upgrade my switches or cabling to move from MR33 to MR36?
Usually no. The MR36 runs within the same 802.3af / 15W PoE envelope and uses a single 1G RJ45 uplink, identical to the MR33. Existing Cat 5e/6 runs and 802.3af switch ports generally carry over, which keeps the refresh low-cost and low-risk. Verify each drop during assessment, but a PoE or switch upgrade is typically not required.
What does the MR36 do better than the MR33?
The MR36 moves from Wi-Fi 5 (802.11ac Wave 2) to Wi-Fi 6 (802.11ax), raising peak 5 GHz rate to about 1,201 Mbps and adding OFDMA, MU-MIMO, BSS Coloring, and Target Wake Time. It also adds a dedicated 24x7 WIDS/WIPS security radio and an integrated BLE radio, and comfortably supports roughly twice the client density of the MR33 in high-density spaces.
Why does running MR33s past LDoS create compliance risk?
After Last Day of Support the MR33 receives no security patches, so any new vulnerability stays unpatched. For environments under FISMA, FedRAMP, HIPAA, or PCI-DSS, an unsupported and unpatchable device is a documented audit finding and can complicate ATO renewals. Refreshing to the MR36 before July 21, 2026 keeps your hardware inventory and accreditation posture clean.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read