Cortavo Blogs

HCL Domino End-of-Life: What It Really Means for Your Business

Written by Team Cortavo | Aug 3, 2026, 5:15:01 PM

If someone on your team has mentioned "Lotus Notes end of life" and it left you with a vague sense of unease, this guide is written for you. Not for your IT admin, but for the owner, operations lead, or office manager who ultimately signs off on risk and has to think about what keeps the business running next year and the year after.

The short version is this. HCL Domino, the platform many people still call Lotus Notes, still works. Your email still arrives, your databases still open, your approvals still route through the same screens they always have. So it is natural to assume there is nothing here that needs your attention. The reality in 2026 is more nuanced. Running Domino today is no longer simply a sign of older software. It quietly increases your exposure around security, stability, compliance, and business continuity, and it does so in ways that rarely announce themselves until they become urgent.

This article explains what "end of life" actually means in plain terms, why it matters more now than it did even a couple of years ago, the kind of business that tends to still be running it, and what a calm, sensible plan looks like. No jargon, no scare tactics, and no assumption that you should have dealt with this already.

 

Lotus Notes and Domino belong to a different era of work

HCL Domino began life as Lotus Notes decades ago, long before the cloud, before smartphones, and before cybersecurity"was a board-level topic. For its time it was genuinely excellent. It combined email, shared databases, and custom-built applications in a single system, and it let companies design their own workflows without buying a dozen separate products. Many organisations built the core of their daily operations on top of it, and it served them well for twenty or thirty years.

The platform itself has not stopped functioning. What has changed is the world around it. The support ecosystem is getting smaller every year. Fewer engineers know how to manage it, fewer new hires have ever seen it, and the security expectations for business software have moved on dramatically since these systems were first configured. Modern platforms assume constant patching, multi-factor authentication, cloud backup, and integration with everything else you use. A system designed in an earlier era was not built around those assumptions, and closing that gap gets harder the longer it is left.

None of this means the software is bad or that the decisions made years ago were wrong. It means the ground underneath a stable Domino environment is slowly shifting, and that ground is what your business is really depending on.

 

"End of life" is not just a date on a support page

When people hear "end of life," they picture a single switch-off date after which everything stops. That is not how it works, and honestly the calendar date is the least important part of the story.

In practice, end of life shows us as three connected pressures that build gradually:

  • Rising security risk. As a platform ages and official support winds down, newly discovered vulnerabilities are less likely to be patched quickly, if at all. Attackers actively look for unsupported software because they know the door is more likely to be left open. At the same time, cyber-insurance providers and larger clients increasingly ask direct questions about whether your systems are supported, and "no" is an expensive answer.
  • Shrinking internal knowledge. The people who originally built and understood your Domino setup tend to move on, retire, or simply forget the details of something they configured a decade ago. Documentation goes stale or was never written down. The confidence to make changes fades, so changes stop being made, which quietly makes the system more fragile.
  • Growing key-person dependency. More and more, the whole environment leans on one or two individuals who still understand how it fits together. That is perfectly manageable right up until one of them is on holiday, off sick, or leaves the company. Then a routine issue can turn into a stressful scramble.

Notice that none of these appears as a dramatic failure on a single day. They accumulate slowly, which is exactly why they are so easy to ignore. The system keeps working, so the risk stays invisible until something forces it into view.

 

Why this matters more now

You might reasonably ask why this is worth thinking about now, when it has been fine for years. A few things have shifted in a way that changes the calculation.

First, the talent pool has thinned considerably. The engineers who specialised in Notes and Domino are retiring, and almost nobody entering the industry is learning it. Scarce skills cost more and are slower to find, so the price and difficulty of getting help rises even if nothing about your system changes.

Second, the security environment has become more hostile and more automated. Attacks on smaller businesses are no longer rare or targeted by hand. Automated tools scan constantly for known weaknesses, and unsupported platforms are a natural target. What used to be a theoretical risk for an SMB is now a routine one.

Third, the expectations placed on you by others have hardened. Insurers, larger customers, and regulators increasingly want evidence that your systems are supported, patched, and defensible. Running end-of-life software can affect your ability to win contracts or renew cover on reasonable terms, quite apart from the direct risk.

None of this is a reason to panic. It is a reason to make sure the topic is on your radar rather than sitting in a blind spot.

If you want a scoped plan and a predictable path forward, contact Cortavo.

 

The pattern is almost always the same

Companies still running Domino tend to share a recognisable profile, and it is worth describing because it may sound familiar.

They are often older and well established, frequently in fields like law, manufacturing, construction, accountancy, engineering, or other document-heavy and process-driven industries. Their work depends on records, approvals, case files, job sheets, and internal processes that have been refined over many years. Precisely because those processes work, and because they are woven into how the business operates, nobody wants to disturb them.

So the system runs quietly in the background and gets left alone. Nobody wakes up in the morning wanting to think about the email and database platform. Over time the original builders move on, the documentation ages, and no one internally feels fully confident owning it end to end. The environment does not fail. It simply becomes something the business relies on heavily while nobody is genuinely in control of it. A common tell is that changes to the system are avoided rather than managed, because the fear of breaking something outweighs the appetite to improve it.

If that description feels close to home, you are not behind or negligent. You are in the same position as most organisations that inherited a Domino environment and never had a clear reason to question it.

 

What the risk looks like in real life

Abstract risk is easy to dismiss. Here is how it tends to show up in practice for a document-heavy SMB.

A firm relies on a Domino database to log and approve client work. The one person who understands how it is wired together leaves for a new job. A few months later something breaks in the approval flow, and suddenly there is no one who can fix it confidently. Work backs up while the business scrambles to find outside help for a platform very few people still support.

Or a manufacturer keeps decades of quality and compliance records inside Domino applications. During a client audit or a certification review, they are asked to demonstrate that the system holding those records is supported and secure. They cannot, and the conversation becomes uncomfortable at exactly the wrong moment.

Or an aging server running the environment finally fails. Because the platform is old and the knowledge around it has faded, restoring it takes far longer than anyone expected, and email and key databases are down while the business waits.

None of these requires bad luck or a sophisticated attack. They are the ordinary consequences of depending on an unmanaged legacy system, and they are the scenarios a sensible plan is designed to avoid.

 

Signs it is time to move this up your priority list

You do not need a technical audit to get a first read on your exposure. If several of the following are true, it is worth treating this as a near-term planning item rather than a someday problem:

  • Only one or two people really understand how your Domino environment works.
  • You avoid updating or changing it because you are worried something will break.
  • You are not confident you could restore it quickly if a server failed.
  • It still runs business-critical functions such as email, approvals, or key records.
  • You would struggle to answer "is this system supported and secure?" on a client or insurance questionnaire.
  • The documentation is out of date, or you are not sure it exists.

None of these means anything is wrong today. Together they indicate that the quiet risk has been building and deserves attention while you still have the luxury of planning calmly.

 

This is a planning problem, not a panic

Here is the reassuring part, and it is worth stating plainly. Recognising the risk does not mean you need to rush into anything, spend heavily this quarter, or shut systems down. It means the topic deserves a place on your planning list instead of living in a blind spot.

For most companies, the long-term destination is a modern workplace platform such as Microsoft 365 or Google Workspace. These are supported, patched continuously, backed up in the cloud, and built around the security expectations that now apply to every business. Moving your email across to one of them is usually the most straightforward part of the whole exercise.

The more important questions sit underneath that. What happens to the databases, approval workflows, archives, and custom applications that quietly run behind the inbox? Some can simply be retired, some can be replaced with modern tools, and a few that genuinely matter may need to be rebuilt. Working out which is which is the real substance of a plan, and it is far better done deliberately than under pressure.

And then there is the question most businesses underestimate entirely. A migration gets you off the old platform. It does not, by itself, give you a secure, well-run environment afterwards. Someone still has to manage users, security, backups, and access, and to keep improving things as your needs change. The real decision is not only where you move to, but who is responsible for running it well once you get there. For a lot of SMBs, that is exactly where a managed IT partner earns its place, turning an unpredictable, key-person-dependent setup into something supported, documented, and accountable.

 

The cost of doing nothing

It is tempting to treat "leave it alone" as the free option, because there is no invoice attached to inaction. In reality, doing nothing has a cost that simply arrives later and less predictably. Every year, the support talent gets scarcer and more expensive, the security exposure grows, and the key-person risk deepens as more knowledge walks out the door. The eventual move also tends to get harder, not easier, because more history accumulates inside the old system and the people who understand it become fewer.

Choosing to plan now is not about spending money you do not need to spend. It is about replacing an unpredictable future cost with a manageable, deliberate one, on your timeline rather than in the middle of a crisis.

If you would like a calm, scoped assessment of where your Domino environment stands and what a sensible path looks like for your business, contact Cortavo today!

 

Frequently Asked Questions

Is HCL Domino / Lotus Notes still supported in 2026?

It depends on the exact version you are running. Newer Domino releases remain actively supported by HCL, while several older versions have already passed their support dates. The practical takeaway is that "still supported" is not the same as "safe to leave alone indefinitely." Even a supported version sits inside a shrinking pool of expertise and rising security expectations, so it is worth confirming exactly which version you run and treating the platform as something to plan around rather than assume it will simply keep looking after itself.

What happens when HCL Domino reaches end of life?

Nothing switches off on a single day, which is the most common misunderstanding. What changes is that official security patches and vendor help wind down, the number of people who can support the platform keeps shrinking, and unsupported software becomes harder to defend during security, compliance, and insurance reviews. Your system keeps running, but the safety net underneath it gets thinner, and both the cost and the difficulty of fixing problems climb steadily over time.

Is it risky to keep running Lotus Notes?

The bigger the role Domino plays in your business, the higher the risk. If it only holds a handful of old archives that nobody actively uses, the exposure is limited. If it still powers your email, approvals, shared databases, or business-critical applications, then security gaps and key-person dependency become genuine continuity risks. The point is not that something is guaranteed to fail tomorrow, but that the risk quietly increases the longer the platform is left unmanaged, and that it tends to surface at the least convenient moment.

Do I have to migrate off Domino right now?

No. This is rarely an emergency, and rushing an unplanned migration creates its own problems, from broken workflows to frustrated staff. What matters is that you stop treating the platform as invisible. Confirm what you are running, understand what depends on it, and build a realistic plan for where you are heading and who will run the new environment. Many businesses take a measured approach over a number of months rather than a panic-driven move, and that is usually the right call.

What is the difference between Lotus Notes and HCL Domino?

In everyday conversation, people use the names interchangeably, and that is fine. Strictly speaking, Lotus Notes refers to the desktop program that users open on their computers, while Domino is the server platform running quietly behind it that stores the data and applications. HCL is the company that now owns and develops both. For the purposes of this article, the key point is that "the Notes and Domino stack" is a single ecosystem, and when people talk about its end of life they are talking about the support and security status of that whole environment.

Where do businesses usually move to when they leave Domino?

The two most common destinations are Microsoft 365 and Google Workspace. Both are modern, supported, cloud-based platforms that cover email, files, calendars, and collaboration, and both can host replacements for the workflows and applications that currently live in Domino. Which one fits best depends on how your team works and what you already use. The destination genuinely matters, but as noted above, the more decisive question is who will manage and support whichever platform you choose once the move is done.