D3 Security / SOAR renewal / QRadar SOAR
QRadar SOAR after April 14, 2026: what ended, what continues, and where the workflows go.
The cloud editions of IBM QRadar SOAR reached end-of-life on April 14, 2026 under Palo Alto Networks ownership. On-premises QRadar SOAR stayed with IBM, is still supported, and has no announced end-of-life. The vendor-recommended successor is Cortex XSIAM, a cloud platform. For an on-prem or air-gapped SOC, Morpheus is the path that keeps QRadar SIEM, keeps the deployment boundary, and ports the workflows.
Bring your QRadar SOAR version and workflow count. We show the conversion on a workflow shaped like yours.
What happened to QRadar SOAR, with dates
Five dated facts. Everything on this page follows from them, and each one is sourced below.
Two customer groups came out of this. Cloud SOAR customers had a hard date and most have already moved, many to Cortex XSIAM through the no-cost migration services Palo Alto and IBM offer to qualified customers. On-premises customers had no date at all. They are running a supported product whose cloud sibling was sold and retired, and whose vendor-recommended future is a cloud platform from a different company. This page is for the second group.
What does the vendor-recommended path ask of an on-prem SOC?
A SIEM re-platform and a move to the cloud, delivered by people who do it well. The question is whether that is the change you wanted to make this year.
Palo Alto’s stated path for QRadar customers is Cortex XSIAM, and both companies say they will provide no-cost migration services to qualified customers who choose it. IBM Consulting runs those engagements, and there is nothing wrong with the work. For a SOC that runs QRadar SIEM on-premises for reasons of residency, air-gap or regulator preference, the path still means three things: the SIEM moves, the data moves to a SaaS tenant, and the SOAR workflows are rebuilt in a different product’s model along the way.
If those three changes are on your roadmap anyway, take the offer. If the SIEM is staying where it is and the boundary is staying where it is, the SOAR layer is the only thing that needs a decision, and it can be decided on its own.
| Path | SIEM | Deployment boundary | SOAR workflows | What the vendor has said |
|---|---|---|---|---|
| Stay on on-prem QRadar SOAR | QRadar stays | Unchanged | Unchanged | IBM support continues; no announced end date; twelve months of standard support per version |
| Move to Cortex XSIAM | Re-platform to XSIAM | SaaS tenant | Rebuilt in the XSIAM model | No-cost migration services for qualified customers, per Palo Alto and IBM |
| Move the SOAR layer to Morpheus | QRadar stays | On-prem, hybrid, sovereign-region or air-gapped | Ported by D3 with a diff per workflow | Written 60-day plan; converted workflows start in Deterministic mode |
Can the new SOAR layer stay inside the boundary?
Yes. Morpheus runs on-premises, hybrid, sovereign-region or air-gapped, and the AI inference runs where the data lives.
Residency was usually the reason a team chose on-prem QRadar in the first place. Morpheus was designed so that choice survives the SOAR change. In on-premises and air-gapped models, processing stays inside your environment, retention and location are customer-controlled, backups are customer-managed, and support access is granted by your team per session. Subprocessors are reduced or eliminated.
Attack Path Discovery investigates every alert to L2 depth before an analyst opens it, up to 95% in under two minutes per customer-reported production data, July 2026, and it is read-only in every mode. State-changing actions run through deterministic playbooks with approval gates your team sets. Every verdict is graded Confirmed, Inferred or Gap, and every incident produces one audit trail.
For regulated estates, that record is the oversight artefact. It supports the human-oversight expectations in EU AI Act Article 14 and maps to NIS2 Articles 21 and 23 and DORA Articles 5, 6 and 19. It is evidence for your reviewers, and your reviewers decide what it satisfies.
What ports from QRadar SOAR, and what your team reviews
The structure ports. The custom code comes back on a list with the source step attached.
| Artefact | Ports automatically | Returned for review |
|---|---|---|
| Workflows | Workflow, phase and task structure; task ordering and dependencies; rule and condition logic | Custom scripts attached to tasks; functions with no library equivalent |
| Notifications and reports | Notification templates; report layout definitions; metric fields | Templates that reference retired data sources |
| Integrations | Actions that map to one of 800+ Morpheus connectors, including QRadar SIEM | Integrations built in-house outside the D3 library |
| Incident history | Imported to the scope agreed in discovery | History beyond the agreed scope |
This describes what the harness does. The hours your migration takes depend on how much of your automation lives in structured tasks and how much lives in custom scripts, which is what the readiness report measures before a scope is written. Resilient-era estates often carry years of custom functions, and the review list is where they get a deliberate decision: migrate, simplify or retire.
What does the 60-day plan look like?
Custom integrations outside the D3 library, incident history beyond the agreed scope and custom development are scoped in discovery. The plan, acceptance criteria and agentic-ready scope are attached to the order form.
faqs
Questions QRadar SOAR teams ask
Is QRadar SOAR end of life?
The cloud editions are. IBM Security QRadar Suite SOAR and IBM Security SOAR on Cloud reached end-of-life on April 14, 2026 under Palo Alto Networks ownership. On-premises QRadar SOAR is a different case: it stayed with IBM, IBM continues to support it, and there is no announced end-of-life date as of September 14, 2026.
What are my options after QRadar SOAR end of life?
Three. Stay on on-premises QRadar SOAR under IBM support with no announced end date. Take the vendor-recommended path to Cortex XSIAM, which Palo Alto and IBM support with no-cost migration services for qualified customers and which is a cloud SIEM re-platform. Or move the SOAR layer to Morpheus, which runs on-premises or air-gapped, keeps your QRadar SIEM, and ports your workflows on a 60-day plan.
What happens to my QRadar SOAR playbooks and workflows?
D3 porting scripts read the exported workflow, phase and task structure, task ordering and dependencies, rule and condition logic, notification templates and report layouts, and rebuild them as Morpheus playbooks. Custom scripts attached to tasks and functions with no library equivalent come back on a review list. Your team signs off on each converted workflow against a side-by-side diff.
What is the best IBM Resilient replacement for an on-prem SOC?
For a team that must stay on-premises or air-gapped, the replacement has to run inside that boundary. Morpheus deploys on-premises, hybrid, sovereign-region or air-gapped, with data and AI inference kept inside the boundary you choose, and connects to QRadar SIEM and 800+ other tools through self-healing integrations. It carries a full SOAR and case management, so Resilient-era workflows land in the same product that investigates the alerts.
Do I have to leave QRadar SIEM to leave QRadar SOAR?
No. Morpheus swaps only the orchestration and investigation layer. QRadar SIEM stays as the log source and detection engine. IBM continues to provide QRadar support to on-premises customers, and the SOAR change does not touch that relationship.
Can Morpheus run air-gapped?
Yes. Air-gapped is one of five deployment models, alongside EU cloud, on-premises, hybrid and sovereign-region. In air-gapped and on-premises models, processing stays inside your environment, backups are customer-managed, and support access is granted by your team per session.
What does a QRadar SOAR migration to Morpheus involve?
A written 60-day plan. Weeks one and two: inventory and readiness report, every workflow tagged migrate, simplify, retire or agentic. Weeks three and four: conversion with a diff per workflow. Weeks five and six: replay of closed incidents for a parity report, then parallel run on live alerts. Week seven: validation against your acceptance criteria. Week eight: cutover on your sign-off. Converted workflows start in Deterministic mode.
Sources
- IBM Support, “IBM Security QRadar Suite – SOAR_SaaS – Divestiture notification”: September 5, 2024 announcement of the completed acquisition by Palo Alto Networks; statement that QRadar product support for SaaS and on-prem customers continues to be provided by IBM; April 14, 2025 end-of-life announcement reference. ibm.com/support/pages/ibm-security-qradar-suite-soarsaas-divestiture-notification
- Palo Alto Networks, End-of-Life Policy, section “For the QRadar SaaS products acquired from IBM”: April 14, 2026 and August 31, 2026 end-of-life product lists; no-cost migration services statement. paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-policy
- Palo Alto Networks, End-of-Sale Announcements: “Effective April 14, 2025, Palo Alto Networks announces the End of Sale and End of Life for the Threat Management (including QRadar) SaaS products acquired from IBM.” paloaltonetworks.com/services/support/end-of-life-announcements/end-of-sale
- Palo Alto Networks, End-of-Life Summary: “This announcement does not affect any IBM QRadar on-premise products or SKUs.” paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-summary
- IBM Support, “IBM Security QRadar SOAR Release Announcement V51.0.9.2”: V51.0.9.2.21 available for download, April 10, 2026. ibm.com/support/pages/ibm-security-qradar-soar-release-announcement-v51092
- IBM Support, “IBM Security QRadar SOAR Support Lifecycle”: on-premises offering provides a minimum of twelve full months of standard support from each version’s general availability. ibm.com/support/pages/ibm-security-qradar-soar-support-lifecycle
All sources retrieved September 14, 2026. Re-verify quarterly.
See a QRadar SOAR workflow land in Morpheus.
Thirty minutes. We convert a workflow shaped like one of yours, show the diff and the review list, and walk the 60-day plan against your deployment boundary.
Prefer to start with the inventory? The free migration assessment returns your tagged workflow list. No meeting required.
D3 Security builds Morpheus, the agentic SOC platform. Vancouver, Canada. IBM, QRadar and Resilient are trademarks of International Business Machines Corporation. Cortex, XSOAR and XSIAM are trademarks of Palo Alto Networks, Inc. D3 Security is not affiliated with IBM or Palo Alto Networks. Vendor facts reflect public documentation retrieved September 14, 2026 and may change.
