Join us live: How to Run a 24/7 SOC with AI

D3 Security / SOAR renewal / QRadar SOAR

QRadar SOAR after April 14, 2026: what ended, what continues, and where the workflows go.

The cloud editions of IBM QRadar SOAR reached end-of-life on April 14, 2026 under Palo Alto Networks ownership. On-premises QRadar SOAR stayed with IBM, is still supported, and has no announced end-of-life. The vendor-recommended successor is Cortex XSIAM, a cloud platform. For an on-prem or air-gapped SOC, Morpheus is the path that keeps QRadar SIEM, keeps the deployment boundary, and ports the workflows.

Bring your QRadar SOAR version and workflow count. We show the conversion on a workflow shaped like yours.

Screenshot of Morpheus's playbook generator

What happened to QRadar SOAR, with dates

Five dated facts. Everything on this page follows from them, and each one is sourced below.

Palo Alto Networks completes its acquisition of IBM’s QRadar SaaS assets. IBM’s divestiture notice covers the SaaS SOAR offering and states that “QRadar product support, for both SaaS and on-prem customers, will continue to be provided by IBM.”Source: IBM Support, QRadar Suite SOAR SaaS divestiture notification.
Palo Alto Networks announces End of Sale and End of Life for the acquired QRadar SaaS products. Existing customers may renew only for terms ending on or before the End of Life date.Source: Palo Alto Networks End-of-Sale announcements.
End-of-life for IBM Security QRadar Suite SOAR, IBM Security SOAR on Cloud, the SOAR portion of Cloud Pak for Security as a Service, QRadar on Cloud, Cloud-Native SIEM, Log Insights and Randori Recon. “These QRadar SaaS Products will no longer be available by the End-of-Life dates.”Source: Palo Alto Networks End-of-Life Policy.
End-of-life for QRadar Suite EDR and XDR, X-Force Threat Intelligence, Randori Attack and QRadar Advisor with Watson.Source: Palo Alto Networks End-of-Life Policy.
Standing
“This announcement does not affect any IBM QRadar on-premise products or SKUs.” IBM shipped QRadar SOAR Platform V51.0.9.2.21 for on-premises deployment on April 10, 2026. IBM’s on-premises SOAR lifecycle provides a minimum of twelve months of standard support from each version’s general availability.Source: Palo Alto Networks End-of-Life Summary; IBM QRadar SOAR release announcement; IBM QRadar SOAR Support Lifecycle.

Two customer groups came out of this. Cloud SOAR customers had a hard date and most have already moved, many to Cortex XSIAM through the no-cost migration services Palo Alto and IBM offer to qualified customers. On-premises customers had no date at all. They are running a supported product whose cloud sibling was sold and retired, and whose vendor-recommended future is a cloud platform from a different company. This page is for the second group.

What does the vendor-recommended path ask of an on-prem SOC?

A SIEM re-platform and a move to the cloud, delivered by people who do it well. The question is whether that is the change you wanted to make this year.

Palo Alto’s stated path for QRadar customers is Cortex XSIAM, and both companies say they will provide no-cost migration services to qualified customers who choose it. IBM Consulting runs those engagements, and there is nothing wrong with the work. For a SOC that runs QRadar SIEM on-premises for reasons of residency, air-gap or regulator preference, the path still means three things: the SIEM moves, the data moves to a SaaS tenant, and the SOAR workflows are rebuilt in a different product’s model along the way.

If those three changes are on your roadmap anyway, take the offer. If the SIEM is staying where it is and the boundary is staying where it is, the SOAR layer is the only thing that needs a decision, and it can be decided on its own.

Three paths for an on-premises QRadar SOAR estate, September 2026
Path SIEM Deployment boundary SOAR workflows What the vendor has said
Stay on on-prem QRadar SOAR QRadar stays Unchanged Unchanged IBM support continues; no announced end date; twelve months of standard support per version
Move to Cortex XSIAM Re-platform to XSIAM SaaS tenant Rebuilt in the XSIAM model No-cost migration services for qualified customers, per Palo Alto and IBM
Move the SOAR layer to Morpheus QRadar stays On-prem, hybrid, sovereign-region or air-gapped Ported by D3 with a diff per workflow Written 60-day plan; converted workflows start in Deterministic mode

Can the new SOAR layer stay inside the boundary?

Yes. Morpheus runs on-premises, hybrid, sovereign-region or air-gapped, and the AI inference runs where the data lives.

Residency was usually the reason a team chose on-prem QRadar in the first place. Morpheus was designed so that choice survives the SOAR change. In on-premises and air-gapped models, processing stays inside your environment, retention and location are customer-controlled, backups are customer-managed, and support access is granted by your team per session. Subprocessors are reduced or eliminated.

Attack Path Discovery investigates every alert to L2 depth before an analyst opens it, up to 95% in under two minutes per customer-reported production data, July 2026, and it is read-only in every mode. State-changing actions run through deterministic playbooks with approval gates your team sets. Every verdict is graded Confirmed, Inferred or Gap, and every incident produces one audit trail.

For regulated estates, that record is the oversight artefact. It supports the human-oversight expectations in EU AI Act Article 14 and maps to NIS2 Articles 21 and 23 and DORA Articles 5, 6 and 19. It is evidence for your reviewers, and your reviewers decide what it satisfies.

What ports from QRadar SOAR, and what your team reviews

The structure ports. The custom code comes back on a list with the source step attached.

QRadar SOAR porting coverage, D3 harness, September 2026
Artefact Ports automatically Returned for review
Workflows Workflow, phase and task structure; task ordering and dependencies; rule and condition logic Custom scripts attached to tasks; functions with no library equivalent
Notifications and reports Notification templates; report layout definitions; metric fields Templates that reference retired data sources
Integrations Actions that map to one of 800+ Morpheus connectors, including QRadar SIEM Integrations built in-house outside the D3 library
Incident history Imported to the scope agreed in discovery History beyond the agreed scope

This describes what the harness does. The hours your migration takes depend on how much of your automation lives in structured tasks and how much lives in custom scripts, which is what the readiness report measures before a scope is written. Resilient-era estates often carry years of custom functions, and the review list is where they get a deliberate decision: migrate, simplify or retire.

What does the 60-day plan look like?

Weeks 1 to 2Discovery. Inventory and readiness report. Every workflow tagged migrate, simplify, retire or agentic.
Weeks 3 to 4Conversion. Converted workflows with diffs. Notification templates and reports rebuilt to the KPIs your leadership already sees.
Weeks 5 to 6Replay and parallel run. Closed incidents replayed for a parity report, then live alerts on both platforms.
Week 7Validation. Parity confirmed against your criteria. Autonomy set per alert type, starting Deterministic.
Week 8Cutover. Production shifts by incident type on your sign-off. QRadar SOAR stays on until you switch it off.

Custom integrations outside the D3 library, incident history beyond the agreed scope and custom development are scoped in discovery. The plan, acceptance criteria and agentic-ready scope are attached to the order form.

faqs

Questions QRadar SOAR teams ask

Sources

  1. IBM Support, “IBM Security QRadar Suite – SOAR_SaaS – Divestiture notification”: September 5, 2024 announcement of the completed acquisition by Palo Alto Networks; statement that QRadar product support for SaaS and on-prem customers continues to be provided by IBM; April 14, 2025 end-of-life announcement reference. ibm.com/support/pages/ibm-security-qradar-suite-soarsaas-divestiture-notification
  2. Palo Alto Networks, End-of-Life Policy, section “For the QRadar SaaS products acquired from IBM”: April 14, 2026 and August 31, 2026 end-of-life product lists; no-cost migration services statement. paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-policy
  3. Palo Alto Networks, End-of-Sale Announcements: “Effective April 14, 2025, Palo Alto Networks announces the End of Sale and End of Life for the Threat Management (including QRadar) SaaS products acquired from IBM.” paloaltonetworks.com/services/support/end-of-life-announcements/end-of-sale
  4. Palo Alto Networks, End-of-Life Summary: “This announcement does not affect any IBM QRadar on-premise products or SKUs.” paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-summary
  5. IBM Support, “IBM Security QRadar SOAR Release Announcement V51.0.9.2”: V51.0.9.2.21 available for download, April 10, 2026. ibm.com/support/pages/ibm-security-qradar-soar-release-announcement-v51092
  6. IBM Support, “IBM Security QRadar SOAR Support Lifecycle”: on-premises offering provides a minimum of twelve full months of standard support from each version’s general availability. ibm.com/support/pages/ibm-security-qradar-soar-support-lifecycle

All sources retrieved September 14, 2026. Re-verify quarterly.

See a QRadar SOAR workflow land in Morpheus.

Thirty minutes. We convert a workflow shaped like one of yours, show the diff and the review list, and walk the 60-day plan against your deployment boundary.

Prefer to start with the inventory? The free migration assessment returns your tagged workflow list. No meeting required.

D3 Security builds Morpheus, the agentic SOC platform. Vancouver, Canada. IBM, QRadar and Resilient are trademarks of International Business Machines Corporation. Cortex, XSOAR and XSIAM are trademarks of Palo Alto Networks, Inc. D3 Security is not affiliated with IBM or Palo Alto Networks. Vendor facts reflect public documentation retrieved September 14, 2026 and may change.