
The Cisco Catalyst 3560-X 24-port PoE IP Base switch (PID WS-C3560X-24P-S) was a workhorse access-layer switch for the better part of a decade. That era is over. This switch went End of Sale on October 30, 2016, lost software maintenance on October 30, 2017, and crossed its Last Day of Support on October 31, 2021. In 2026 it is not merely aging hardware, it is unsupported infrastructure carrying production traffic with zero vendor backing. This guide explains exactly what that means and walks through a concrete refresh onto the Catalyst 3650 WS-C3650-24PD-S, the successor Cisco itself named.
Why running an unsupported 3560-X is a problem right now
Past Last Day of Support, three things stop at once, and each maps to a real risk. First, security: Cisco's PSIRT no longer issues fixes for this platform. When a new vulnerability lands in the IOS 15.x code the 3560-X runs, there is no patched image coming, ever. The switch terminates user VLANs, runs your access ACLs, and often acts as a Layer 3 gateway, so an unpatched flaw here is directly reachable. Second, operations: there is no TAC case and no hardware RMA. A failed power supply or a dead unit means scavenging the gray market for another end-of-life box, not a next-business-day replacement. Third, compliance: frameworks your buyers live under, including FISMA, FedRAMP, CMMC, HIPAA, and PCI-DSS, expect supported, patchable infrastructure. An out-of-support switch is a documented, repeatable audit finding that will not clear until the hardware is gone.
What each milestone actually means
End of Sale, October 30, 2016
The last date Cisco would accept an order for a new WS-C3560X-24P-S. After this, every unit in service is on a fixed support clock and the only new supply is secondary-market stock.
End of SW Maintenance, October 30, 2017
The last date for maintenance releases and routine bug fixes. From here the code base is frozen except for a narrowing window of severe security fixes, and even those end at LDoS.
Last Day of Support, October 31, 2021
The hard stop. No software, no PSIRT fixes, no TAC, no RMA. A contract you hold today provides no Cisco entitlement on this PID. Everything after this point is self-insured risk.
The recommended replacement: Catalyst 3650 WS-C3650-24PD-S
Cisco's bulletin pointed 3560-X owners at the Catalyst 3650 family, and the like-for-like SKU is the WS-C3650-24PD-S: 24 ports of PoE+, IP Base feature set, the same access-layer role. The upgrades are meaningful for this exact switch type:
- Native 10G uplinks. The 3560-X base shipped with a 1G uplink posture and required a separate C3KX uplink module for 10G. The 3650-24PD has two built-in 10G SFP+ uplinks, so you get real uplink headroom without buying an add-on module.
- IOS-XE instead of classic IOS 15.x. The 3650 moves to the modular, Linux-based IOS-XE, which brings patchable subsystems, model-driven programmability hooks, and a far longer support runway.
- StackWise-160 stacking. The standalone 3560-X could not data-stack (StackWise was a 3750-X feature). The 3650 stacks up to nine units at 160 Gbps, so you can collapse multiple closets into one logical switch with a single management plane.
- UADP ASIC and convergence. The 3650 runs the programmable UADP 1.0 ASIC and includes a built-in wireless LAN controller (up to 25 APs / 1,000 clients per switch), enabling wired-wireless convergence the 3560-X never had.
- PoE budget. The 24-port PD model delivers a usable PoE+ budget (roughly 390W) at up to 30W per port for phones, APs, and cameras, with the option of dual power supplies for redundancy the base 3560-X often lacked.
Licensing: from perpetual feature images to subscriptions
This is the change that surprises teams. The 3560-X used perpetual, per-image feature licensing (IP Base versus IP Services), paid once and forgotten. The 3650 uses Right-to-Use licensing that trends toward Smart Licensing, and the Catalyst 9300 is fully Smart Licensing layered with Cisco DNA subscriptions (Essentials or Advantage) on a term. The practical impact: licenses do not transfer from the old PID, the new switch carries its own entitlement, and you must budget the DNA term up front rather than treating licensing as a one-time line item. Stand up a Smart Account before the gear arrives so registration is not a cutover-day blocker.
A practical migration plan
1. Assess and inventory
Find every WS-C3560X-24P-S in the estate, not just the ones you remember. Pull running configs, IOS versions, PoE draw per closet, uplink types and optics, and current VLAN/routing roles. Note which units are Layer 3 gateways versus pure access, because that drives the feature parity you need on the replacement. Our WS-C3560X-24P-S end-of-life detail page summarizes the dates and successor for your change record, and the EoL hub helps you catch sibling models hitting the same wall.
2. Plan the license transition
Map each old feature set to the new model's tier. IP Base on the 3560-X maps to IP Base / Network Essentials on the successor; if you ran IP Services for full dynamic routing, size the higher tier accordingly. Create the Smart Account and decide DNA term length now.
3. Build config and feature parity
Do not paste the old startup-config. Rebuild on IOS-XE and test parity for VLANs, trunking, SVIs, ACLs, QoS policy maps, DHCP snooping, and any routing. QoS and PoE behavior in particular need validation rather than assumption. Stage and verify on a bench switch before it ever sees production traffic.
4. Handle the physical layer
Confirm rack space, power (the new units may want dual supplies and a different power draw), and PoE budget against your actual endpoint count. Plan uplink optics: the 3650's 10G SFP+ cages need the right SR/LR transceivers or DACs, which the 3560-X's 1G module did not. If you are consolidating closets, design the StackWise stack and cabling now.
5. Phased cutover
Migrate one closet or stack at a time during a maintenance window. Pre-stage the new switch fully configured, move uplinks, then move access ports in batches with verification between each. Keep the old 3560-X powered as an immediate fallback until the new unit proves stable across a full business day.
6. Secure decommission
Once retired, wipe configs and credentials (the saved configs contain SNMP strings, local accounts, and keys), record asset disposal for your audit trail, and use a certified e-waste or ITAD process. For federal and healthcare environments, document sanitization to your data-handling policy.
Procurement notes for government and enterprise buyers
For federal, DoD, and SLED buyers, insist on TAA-compliant SKUs of the 3650 or 9300; both families ship in TAA configurations. We support GPC card payment and GSA-aligned purchasing, and provide the compliance documentation your contracting office requires. Lead times on current Catalyst gear fluctuate, so engage early rather than at the eleventh hour, and always source from an authorized Cisco partner to guarantee genuine hardware, valid Smart Licensing entitlement, and warranty coverage, none of which gray-market 3560-X stock can offer. Browse the successor lineup in our catalog and pull configurations into a refresh quote.
Frequently asked questions
Is the Cisco WS-C3560X-24P-S still supported in 2026?
No. The Catalyst 3560-X reached its Last Day of Support on October 31, 2021. As of 2026 there are no software updates, no PSIRT security fixes, and no TAC or hardware RMA coverage available from Cisco for the WS-C3560X-24P-S. Any unit still in production is operating without a safety net and is a recurring audit finding.
What is the direct replacement for the WS-C3560X-24P-S?
Cisco's end-of-life bulletin named the Catalyst 3650 24-port PoE model (WS-C3650-24PD-S) as the migration target. It matches the 24-port PoE+ IP Base profile but adds two native 10G SFP+ uplinks, IOS-XE, and StackWise-160. Note that the 3650 has itself since been superseded by the Catalyst 9300, which most buyers now choose to avoid a second refresh.
Should I move to the Catalyst 3650 or jump straight to the Catalyst 9300?
If you have an in-hand 3650 spare or a tight budget, the WS-C3650-24PD-S is a clean drop-in and a real improvement over the 3560-X. For a new purchase, most organizations skip directly to the Catalyst 9300 (UADP 2.0 ASIC, mGig, StackWise-480/1T, Wi-Fi-ready, Smart Licensing with DNA) so they are not refreshing again in a few years. We can quote either path.
Will my 3560-X configuration move over to the 3650?
Most of it ports cleanly because both run a familiar Cisco CLI, but the 3650 runs IOS-XE rather than the classic IOS 15.x on the 3560-X. VLANs, SVIs, ACLs, QoS policy, and routing port over with minor syntax changes, but you cannot copy the startup-config verbatim. Plan a config rebuild and parity test rather than a straight paste, especially for QoS and any IP Services features.
Does the licensing transfer from the 3560-X to the new switch?
No. The 3560-X used perpetual per-image feature licensing (IP Base / IP Services). The 3650 uses Right-to-Use licensing trending toward Smart Licensing, and the Catalyst 9300 is fully Smart Licensing with Cisco DNA subscription tiers (Essentials/Advantage). Licenses are tied to the platform, so the new switch ships with its own entitlement; budget the DNA subscription term up front.
Are the replacement switches TAA compliant for federal purchases?
Yes. The Catalyst 3650 and Catalyst 9300 are available in TAA-compliant configurations suitable for federal, DoD, and SLED procurement. As an authorized Cisco partner we source TAA-compliant SKUs, support GPC and GSA-aligned purchasing, and provide the documentation your contracting office needs.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read