PHP 8.2 end of support on 31 December 2026: what it means for PCI DSS and SOC 2
PHP 8.2 reaches end of support on 31 December 2026. After that date it becomes an unsupported runtime — a classic finding in PCI DSS and SOC 2 audits.
UptimeMag editorial team · 11 October 2026 · 2 min read

The date to mark on your calendar
PHP 8.2 reaches end-of-life on 31 December 2026. This is confirmed by the official version registry on php.net, as reported by php.watch: PHP 8.2, released 3 years and 10 months ago (08 Dec 2022), ended active support 1 year and 9 months ago (31 Dec 2024), and security support ends in 2 months and 3 weeks (31 Dec 2026). The last release before the cut-off is 8.2.34, published on 24 September 2026.
The detail that matters for anyone running production servers: since 31 December 2024, PHP 8.2 has already been in security-only maintenance mode, no longer receiving bug fixes. After 31 December 2026, any newly discovered CVE will not get an official patch for 8.2. This is exactly what a PCI DSS or SOC 2 auditor checks: not whether the site "still works", but whether the runtime vendor is still publishing security patches.
Why it ends up as an audit finding
PCI DSS Requirement 6 is dedicated to developing and maintaining secure systems and software. One guide to the standard puts it plainly: end-of-life software — whether an operating system, a database, or an unsupported application — poses a huge risk to PCI DSS compliance. The practical consequences listed are concrete: using EOL software can cause a failure against requirement 6 (secure systems) and requirement 5 (malware protection), and in the event of a breach, the use of EOL software can be interpreted as negligence, leading to harsher penalties.
The same principle applies to continuous monitoring frameworks: an unsupported PHP runtime, if present in an environment that processes or stores sensitive data, is exactly the kind of evidence an auditor flags as an exception requiring a remediation plan — regardless of whether the application is still "online and working".
The practical plan
There's no need to wait until December. Anyone with a SOC 2 Type II audit or a PCI DSS assessment scheduled for early 2027 needs to have the runtime already updated before the audit window opens, not by the deadline itself: auditors assess the state of systems throughout the period covered by the report, not the state on the day the report is delivered.
The concrete steps: inventory which applications are still running on PHP 8.2 (php -v on every host), check dependency compatibility with PHP 8.3 or 8.4, and plan testing in staging before switching production over. Shared hosting providers also need to notify customers in writing of the date by which the control panel will stop offering PHP 8.2 as a selectable option.
Practical information
- Deadline: 31 December 2026, end of security patches for PHP 8.2 (source: endoflife.date/php, php.watch)
- Target versions: PHP 8.3 or PHP 8.4, both still within their active support window
- Version check: run the
php -vcommand on every server involved - Regulatory reference: PCI DSS, Requirement 6 (develop and maintain secure systems and software)
- Operational advice: complete the migration before the start of the period covered by your next SOC 2 or PCI DSS audit, not by the EOL deadline itself
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50).