Dev News Daily ENDE

Canonical offers 15 years of Zephyr security maintenance, upstream gives 5

Canonical announced on 21 September, from Anaheim and ahead of Embedded World North America, the upcoming release of Zephyr 26.04 LTS — a commercially supported distribution of the Zephyr real-time operating system, sold as part of an Ubuntu Pro for Devices subscription and aimed at silicon vendors and device makers building on microcontrollers.

The headline commitment is duration. Upstream Zephyr offers five years of standard support; Canonical's figure is up to 15 years of security maintenance. Around it sits a release cadence borrowed from the rest of the company's portfolio: an LTS every two years, interim releases every six months, mirroring Ubuntu and Canonical Kubernetes.

The scope claim is the less obvious one. The commitment is stated to extend past the RTOS itself to tooling from the wider microcontroller ecosystem — the example given is West, Zephyr's meta-tool for managing repositories, building and flashing firmware. Canonical frames the whole thing as letting a manufacturer buy support for Linux-class and microcontroller-class devices from one vendor.

The regulatory driver is named explicitly. The EU Cyber Resilience Act is in force and requires manufacturers to provide a minimum of five years of security maintenance, patching and record keeping for their devices. The announcement carries supporting quotes from Jonathan Beri, Canonical's head of product for IoT; from Kate Stewart, VP for Dependable Embedded Systems at the Linux Foundation and the Zephyr Project; and from the distributor Avnet.

One source, and it is the vendor's own. This is a corporate announcement about a product that has not shipped: it is described as upcoming, no general-availability date is given, no price is stated, and the components covered beyond West are not enumerated. The 15-year figure is a commitment, not yet a record.

Canonical offers 15 years of Zephyr security maintenance, upstream gives 5
Canonical offers 15 years of Zephyr security maintenance, upstream gives 5 — Dev News Daily

What it means

Support duration has become a product feature because a regulation made it one. Before the CRA, "we will patch this for fifteen years" was a differentiator nobody could price. With a statutory five-year floor, every manufacturer now has to answer the question in procurement — and a vendor who answers it in writing is selling compliance evidence as much as software.

The interesting move is the extension to the toolchain. An RTOS with a long support window and a build tool with none is not a supported system: the thing that breaks a seven-year-old firmware build is rarely the kernel, it is the tooling around it, the host compiler, the Python that drives the flasher. Naming West is a small claim with large implications, and it is the part to ask sharp questions about when the terms appear.

What a buyer should wait for. A date, a price, and the list of covered components with their individual support windows. Until those exist, this is a statement of intent from one party with a commercial interest in it.

Source: https://canonical.com/blog/zephyr-lts-announcement