Last updated: October 1, 2026
By Jennifer Burdick, Recruiting Manager, KORE1
SQL Server 2016 reached end of life on July 14, 2026, and the choices now are paid Extended Security Updates through July 2029, an upgrade to SQL Server 2022 or 2025, Azure SQL, or a migration to PostgreSQL. Nothing switched off that day. The databases still start. The reports still run. The patches stopped. Each path costs something different, and three of the four need people most teams do not have on staff.

$278 a month. That is the line on Microsoft’s Azure Arc price list for SQL Server 2016 Extended Security Updates, Standard edition, per two-core pack. Enterprise is $1,081. I fill database seats for a living, and I have read that page more closely than I ever expected to, because since July it has started most of the DBA conversations that reach me.
One of them came in the last week of July, from the IT director at a building-products distributor in Dayton, Ohio. He had five SQL Server 2016 Standard servers sitting under an ERP, a warehouse system, and a reporting database. Three ran eight cores and two ran four. His reseller had priced a year of Extended Security Updates at $53,376. He did not want the quote explained. He had one question. Would a contract DBA for a single quarter cost less?
It would. Thirteen weeks at $95 an hour is $49,400, and his Software Assurance already covered the right to run a newer version. So we found him one. The DBA started on August 17. Three of the five servers are on SQL Server 2022 as I write this, and the last two move the weekend of November 7. In the meantime he put Extended Security Updates on the two servers that touch payment data, since Azure Arc bills by the hour and the charge stops the day a server is upgraded. A few months of patches. Not three years of them.
A lot of the advice on this date was written in 2025. Some of it has gone stale. Several guides still say the updates are free if you move the server to an Azure virtual machine. True for SQL Server 2014. Not true for 2016, and Microsoft’s own documentation says so. Others quote the price as 75 percent of the license, which does not match the rate Microsoft publishes today. Almost none of them say who does the work.
My interest in this is simple enough. KORE1 is a staffing firm, and three of the four paths below create contract work for our database administrator staffing desk. The first path creates none. For some servers it is still the right answer, and I will say which. I am also a recruiter and not a licensing advisor, so treat every price here as what Microsoft’s public pages showed on October 1, 2026, and get your own quote in writing.
What Stopped on July 14, and What Kept Running
SQL Server 2016 end of life means Microsoft’s extended support for the product ended on July 14, 2026. From that date the company issues no free security patches, no bug fixes, and no technical support for any edition. The software keeps running and stays licensed. It is no longer maintained unless the owner pays for Extended Security Updates.
The dates that matter, all from the Microsoft Lifecycle page for SQL Server 2016 and its neighbors.
- Mainstream support ended back in July 2021. No new features after that, and no fixes that were not about security.
- July 14, 2026 was the last day of extended support for every edition, Express and Developer included.
- Paid Extended Security Updates began the next morning and run in three one-year terms. The first ends July 13, 2027.
- July 17, 2029 closes the third and final term. Nothing is offered after it.
- Windows Server 2016, which sits under a great many of these instances, loses its own extended support on January 12, 2027.
That last one is easy to miss. It changes what an upgrade looks like, and I will come back to it.
Three things are different in practice. Security fixes no longer arrive. Support does not answer. Microsoft’s ESU questions page is blunt about it, saying that for SQL Server 2014 or 2016 “you can’t log a support ticket even if you have a support plan.” And the people who review your controls have a new line item. The Cybersecurity and Infrastructure Security Agency keeps a short list of bad practices, and the first entry calls the use of unsupported or end-of-life software in critical infrastructure “dangerous.” Your auditor has read that page. So has your insurer.
One group had the decision made for them. If your SQL Server 2016 ran on Amazon RDS, AWS stopped allowing new 2016 instances on January 15 and began upgrading the remaining ones to SQL Server 2019 on July 14, inside maintenance windows at first and then, from September 8, regardless of them. Those databases are on a supported version now. Was anything on top of them tested first? Different question.
A Year of Extended Security Updates Costs About 85 Percent of a New License
Extended Security Updates are narrower than the name suggests. Microsoft’s description of the program says an update is released “if needed” once a vulnerability is discovered and rated Critical, and that there is “no regular release cadence.” No new features. No fixes on request. Support covers the update itself and nothing else about the product.
Here is what that costs, next to what a current license costs. The ESU rates are from the Azure Arc pricing page. The license and pay-as-you-go rates are from Microsoft’s SQL Server 2025 pricing sheet.
| Per two-core pack | Standard | Enterprise |
|---|---|---|
| SQL Server 2016 ESU, per month | $278 | $1,081 |
| SQL Server 2016 ESU, per year | $3,336 | $12,972 |
| New SQL Server 2025 license, paid once | $3,945 | $15,123 |
| One year of ESU as a share of that license | 85% | 86% |
| SQL Server 2025 pay-as-you-go, per month | $146 | $548 |
The bottom row and the top row belong next to each other. Renting SQL Server 2025 Standard through the same Azure Arc billing runs $146 a month for two cores. Security patches alone for the 2016 version run $278. Nearly double. For less.
The quote grows from there, and the rules that grow it are spread across three Microsoft pages. Every virtual machine is billed for at least four cores, so the smallest Standard server costs $556 a month, or $6,672 a year. The Dayton distributor’s five servers add up to 32 cores, which is 16 packs, which is the $53,376 on his quote. Then there is the calendar. Billing started at midnight UTC on July 15 for everyone, and a company that subscribes later gets what Microsoft calls a one-time bill-back charge to the first day of the term. Sign up in the middle of October and the first invoice carries three months you had no coverage for. On those five servers that is a little over $13,000.
Software Assurance decides whether you can buy it at all. A license bought outright years ago, with the assurance left to lapse? It does not qualify. The way in for that server is to switch it to pay-as-you-go licensing first and add the updates on top, which for one eight-core Standard server comes to $584 plus $1,112, or $1,696 a month. Moving to Azure does not change the bill either. The program page says in so many words that migrating to SQL Server on Azure VMs “no longer provides free access to ESUs for SQL Server 2016.”
Express, Web, and Developer editions cannot buy the updates at any price. That matters more than it sounds. Express is free, and it gets installed quietly under timeclock software, badge readers, and label printers. A packing plant in Fresno, California found four Express instances this summer that nobody in IT knew the company owned. One sat under the timeclock system. The fix cost a call to the vendor and a Saturday. Express is free on every version.
One number is missing. Microsoft’s page lists a single rate. It does not say whether that rate holds in the second and third years. Ask your reseller to put that answer in writing before you budget past next July.
So when is this the right path? In a narrower set of cases than the quote implies. A vendor application certified only on 2016, with recertification promised for next spring. A system already scheduled for retirement in eight months. A migration that is under way and running late. In each of those you are buying months. You know how many.
It also needs nobody new. Someone on the current team connects the servers to Azure Arc, installs and tests the latest cumulative update, and turns the subscription on. A day or two of work. Easy. That is the trouble with it. Extended Security Updates buy calendar time and nobody’s attention, and I watched more than one client on the 2012 version buy a single year as a bridge and still be paying in the third, because nothing ever forced a project to start.

An Upgrade Is a Three-Month Contract, Not a Permanent Hire
Microsoft supports a direct upgrade from SQL Server 2016 with Service Pack 3 to either SQL Server 2022 or SQL Server 2025. The supported upgrade paths for 2025 list it by name. SQL Server 2022 is supported until January 11, 2033. SQL Server 2025 runs to January 6, 2036, and its Standard edition now uses up to 32 cores and 256 GB of memory, where earlier versions stopped at 24 cores. Most mid-market companies I talk to pick 2022 anyway. One reason. Their ERP vendor has certified it and has not certified 2025 yet.
The detail that makes this path cheaper than people expect is the compatibility level. A database moved to a newer engine keeps the level it had, which for 2016 is 130. Microsoft’s compatibility certification says that for an application already certified on a given level, you upgrade the engine, keep the level, and “there’s no need to recertify an application in this scenario.” The engine changes. The query behavior the application was tested against stays put.
What breaks is around the database, not in it. On SQL Server 2025, Microsoft’s list of breaking changes opens with linked server connections that can fail after an upgrade, because the new driver changes the encryption default. Replication with a remote distributor can fail for the same reason. Full-text indexes need rebuilding before their queries work again. Reporting Services is the big one. There is no 2025 version of it at all. Microsoft’s reporting consolidation notice says no new versions of SSRS will be released and that Power BI Report Server takes its place, so a server with 200 SSRS reports has a reporting project attached to its database project. The report files themselves carry over. The server they run on does not. Master Data Services is gone. Data Quality Services too. The application code that calls these databases ages on a schedule of its own, and that upkeep is a separate seat, usually contract maintenance engineers.
Then there is the operating system. A true in-place upgrade on a Windows Server 2016 machine leaves a supported database on an operating system that has until January. So most of these upgrades are really side-by-side moves. New server, current Windows, new SQL Server, restore, test, cut over, and keep the old machine powered on for two weeks. Just in case.
Who does it? One contract SQL Server DBA who has made this exact jump before, for about three months. Add a few hours a week from whoever owns the application, for testing. Add a report developer if SSRS is involved. Contract DBAs on a W-2 run $65 to $110 an hour, the same band we publish on the DBA staffing page, so thirteen weeks at forty hours comes to somewhere between $33,800 and $57,200. Our average time to hire on IT searches is 17 days, which matters when a meter is running by the hour.
Why not hire someone permanently? The upgrade ends. A senior DBA brought on full time to run it is looking at five quiet servers by spring, and good ones do not stay for quiet. Run it through our contract staffing desk, see what the databases actually need once they are current, and decide then. If you would rather screen candidates yourself, our DBA interview questions include a walk-through of the candidate’s last migration. Listen for the rollback plan. That is the one I would not skip.
Azure SQL Ends the Version Clock and Changes the Job
Azure SQL Managed Instance is the option Microsoft would most like you to choose, and for a fair number of companies it is a good one. Microsoft describes it as “nearly 100% compatibility with SQL Server on-premises” and as a “version-less experience.” No more end-of-life dates. The engine is patched and upgraded underneath you.
Be clear about what this path is not. SQL Server 2016 on an Azure virtual machine is still SQL Server 2016. It needs the same paid updates and the same upgrade later. Same problem. Different building.
Managed Instance has its own list of things it will not do, and a server that has run since 2016 tends to use several of them. Microsoft’s page of differences is long. Four entries cause most of the trouble I hear about. xp_cmdshell is not supported. FILESTREAM and FileTable are not supported. Linked servers reach only other SQL Server and Azure SQL targets, so the one pointing at Oracle or at a spreadsheet on a file share stops working. Agent jobs that run command-shell steps do not run. Each one is a small rewrite. A nine-year-old server usually has a dozen of them.
The cutover has a catch that is specific to this version. The Managed Instance link, which replicates a live database into Azure, works from SQL Server 2016 in one direction only, and the documentation says plainly that failing back is not supported. Once you cut over, the way home is a restore and an outage. Rehearse it first.
Three seats, usually. A DBA with real Managed Instance time, not just Azure on a resume. A cloud engineer for the network, because Managed Instance wants its own subnet and private connectivity back to your offices. A developer for the rewrites. Plan for the middle of the three-to-nine-month range our DBA contracts usually fall in, and if several applications are moving at once, staff it as a cloud migration project team with one person accountable for the date.
The job that is left afterward is smaller and different. Nobody owns patch night anymore. Somebody still owns slow queries, access, and a bill that now arrives monthly instead of once.

PostgreSQL Removes the License and Rewrites the Code
The pull is easy to understand. Stack Overflow’s 2025 developer survey had PostgreSQL at 55.6 percent of respondents. Microsoft SQL Server, 30.1. Developers already like it. Finance likes any line that goes to zero.
The license is the small part, though. So is the data. A database moves in a weekend. What does not move is everything written in Microsoft’s dialect, meaning T-SQL stored procedures, SSIS packages, Agent jobs, and SSRS reports. None of it runs on PostgreSQL. All of it gets rewritten, tested, and reconciled against the old system, one object at a time.
Amazon’s answer to that is Babelfish for Aurora PostgreSQL, which lets the database accept connections from SQL Server clients and understand commonly used SQL Server statements. The same page says it runs T-SQL “with some differences.” Those last three words are where the project lives.
A healthcare billing company in Lexington, Kentucky, started this move in 2025 with a six-month budget. Their main database had about 1,100 stored procedures. Conversion tooling handled roughly three quarters of them. Good news, mostly. The other 270 or so had to be rewritten by hand, and those were the long ones, the ones with cursors and temp tables and business rules nobody had documented. Three contract SQL developers spent five months on that alone. The whole project took fourteen months. Not six. They bought a year of Extended Security Updates halfway through, which is the scenario that program is honestly good for.
PostgreSQL also has a clock of its own. The project supports each major version for five years. Leaving Microsoft does not end version upgrades. It ends the invoice for them.
This is the only path where the contract team is larger than the permanent one. A migration lead who has finished one of these. Not started one. Finished. Two to four developers who read T-SQL and write PL/pgSQL, which is where our SQL developer staffing desk comes in. A tester whose whole job is proving the new numbers match the old ones. And a PostgreSQL DBA, the one seat worth making permanent, often through contract-to-hire so the migration doubles as the interview. How long? Nine months is the short version. Tom Kenaley’s piece on a data warehouse migration walks through the same kind of team phase by phase, and the staffing logic carries over almost unchanged.
Four Paths and the Seats Each One Needs
All four, in one table.
| Path | What it buys | Seats to add | Typical length | Where it goes wrong |
|---|---|---|---|---|
| Extended Security Updates | Critical patches until July 17, 2029 | None | A day or two to switch on | The bridge becomes the plan |
| Upgrade to SQL Server 2022 or 2025 | Support into 2033 or 2036 | One contract SQL Server DBA, plus a report developer if SSRS is in use | About three months | Windows Server 2016 underneath, linked servers, reports |
| Azure SQL Managed Instance | No more engine versions to track | Cloud DBA, cloud engineer, a developer for rewrites | Four to six months | xp_cmdshell, FILESTREAM, file shares, no failing back from 2016 |
| PostgreSQL | No SQL Server license | Migration lead, two to four SQL developers, a tester, a PostgreSQL DBA | Nine months or more | Stored procedures, SSIS, Agent jobs, the schedule |
Most companies end up on two rows at once. That is normal. It is not indecision.
Sorting Your Servers Into Paths
The decision is per server. Not per company. A plain inventory with five columns gets most of the way there, and the columns are edition, cores, the Windows version underneath, what application sits on top, and whether Software Assurance is current.
- Express edition anywhere? It cannot buy the updates and it is free on every version. Call the application vendor and upgrade it.
- A vendor application certified only on 2016 goes on Extended Security Updates, with an end date written next to the cost.
- Anything on Windows Server 2016 is a side-by-side move, because the operating system has until January 12, 2027.
- Servers running SSRS need a reporting decision before they need a database one.
- If a server uses xp_cmdshell, FILESTREAM, or linked servers to something that is not SQL Server, Managed Instance will cost more than the brochure suggests. Upgrade that one where it sits.
- No Software Assurance and no appetite for new licenses? That is the server where PostgreSQL, or pay-as-you-go, deserves a real look.
- Whatever is left, which is usually most of them, is a version upgrade and a three-month contract.
Loose Ends From the First Planning Meeting
Will a SQL Server 2016 database stop working now?
No, it keeps running exactly as it did on July 13, with the same license and the same features.
What ended is maintenance. The first Critical vulnerability published after July 14 stays open on your server unless you are paying for Extended Security Updates, and Microsoft will not take a support call about anything else.
Can we skip SQL Server 2022 and go straight to 2025?
Microsoft supports a direct upgrade from SQL Server 2016 Service Pack 3 to SQL Server 2025, so the engine allows it.
Your application vendor may not. Ask which versions they have certified before you pick, and read the 2025 breaking-changes list against your own linked servers, replication, and full-text indexes. If the vendor says 2022, take 2022. No shame in it. That version is supported until January 2033, and the same contractor can do the next jump in a fraction of the time because the hard part, the inventory, will already exist.
Is ESU still free on an Azure virtual machine?
Not for SQL Server 2016.
It was for SQL Server 2014, which is where the advice comes from. In March 2026 Microsoft published a pricing notice saying that Extended Security Updates released on or after April 1 would carry the same list price inside Azure and outside it. The SQL Server 2016 program falls under that rule.
Realistically, how long can we run 2016 with no ESU at all?
Until the first Critical vulnerability that affects it is published, and nobody can tell you when that will be.
SQL Server does not get a monthly patch the way Windows does. Fixes ship when a problem is found. The gap could be weeks. It could be most of a year. A reporting server with no route in from outside the building is a different risk than the database behind a customer portal. Have your security lead make that call in writing, server by server, instead of letting it happen by default.
SQL Server 2017 is next. When?
October 12, 2027 is the last day of extended support for SQL Server 2017, and SQL Server 2019 follows on January 8, 2030.
If you have 2017 instances, fold them into the same project. The contractor is already there.
Do we need a permanent DBA once the upgrade is done?
Often the contractor was enough for the project, and the real question afterward is how many hours a week the databases need.
Five well-behaved servers rarely fill a full-time seat. Twenty do. So does anything with an on-call expectation. The Bureau of Labor Statistics puts the median annual wage for database administrators at $104,620 as of May 2025, and our DBA salary guide breaks that out by specialization and city. The upgrade itself is the best evidence you will get. By week ten the contractor can tell you, with a list, what the databases need every week and what they need once a quarter.
The Meter Has Been Running Since July 15
Decide per server, and write a date next to each one. Extended Security Updates bill back to July 15 whether you subscribed that morning or will next month, and a server with no updates is running up a different kind of debt. The cheapest version of this project is the one that starts before the Windows Server 2016 deadline in January turns one problem into two.
If one of your rows says upgrade and nobody on the team has done one, bring the server list to a call with our team. We will tell you whether it looks like one contract DBA for a quarter, a migration team, or a server that should sit on paid updates until its vendor catches up. Some of those calls end with us telling you to keep your money. Fine by us. KORE1 has been placing database people since 2005. Across everyone we place, 92 percent stay past their first year, which is longer than any of these upgrades should take.

