cisco onprem uc · published

Planning a Unified CM upgrade

Verified 2026-09-25 · 60 sources · tier 2

Planning an upgrade for Cisco Unified Communications Manager (Unified CM) requires validating virtualization prerequisites, adhering to supported target releases, and maintaining node sequencing across dependent components 59​42​29. Cisco treats an upgrade as complete only when every node has installed the inactive software version, switched active versions, rebooted, and finished database replication 57.

Supported upgrade paths and deployment requirements

There are no Direct Refresh Upgrade paths to Unified CM and IM and Presence Service Release 15 or later 36. Refresh upgrades from source releases earlier than 12.5.x to Release 15 or later are unsupported 35. Additionally, upgrading from Release 14SU4 to any destination lower than 15SU2 is unsupported 1. Any supported path using a PCD Upgrade Task or PCD Migration Task requires Prime Collaboration Deployment Release 15 37.

Release 15x supports only virtualized deployments and does not support bare-metal servers 59. A direct upgrade to Release 15 fails on any single-80GB-vDisk deployment, even when the virtual disk has been manually resized to 110 GB 2. Starting in Release 15SU3, ESXi virtual machines must utilize a CPU mode supporting AVX, requiring administrators to verify VMware Enhanced vMotion Compatibility (EVC) settings 4.

Version 12.5 on-premises calling applications (Unified CM, SME, IM and Presence, CER, Unity Connection, and Paging Server) reached End of Software Maintenance Releases on 31 August 2024 and Last Date of Support on 31 August 2025 22​21.

Pre-upgrade tasks and system preparations

Cisco strongly recommends running the Upgrade Readiness COP file prior to a Release 15 upgrade, though it is not mandatory 45. Any required COP file must be installed on every node across the cluster before starting the upgrade, regardless of whether PCD or Unified OS Administration is used 9.

The common partition requires at least 25 GB of free space before upgrading, although Cisco warns that an upgrade can still fail with an insufficient-space error even when 25 GB is free 8. Installing the Free Common Space COP file makes the inactive partition unusable, which permanently removes the option to switch back to the prior version 26.

Before beginning maintenance, perform the following tasks:

  • Take a fresh Disaster Recovery System (DRS) backup, as Cisco cautions that outdated backups risk data loss or unrecoverable states 27.
  • Add a virtual serial port to each virtual machine so installation logs can be dumped if failures occur, and remove it following the upgrade because it affects VM performance 51.
  • Record registered device counts (phones, gateways, media resources) in Cisco Unified Real-Time Monitoring Tool (RTMT) and assigned-user counts in IM and Presence to compare post-upgrade 46.
  • Take screenshots of IM and Presence and Unified CM enterprise parameters, as differing values can result in IM and Presence parameters being overwritten by Unified CM values 20.
  • Disable High Availability on each Presence Redundancy Group and stop the Cisco Sync Agent on IM and Presence 28.
  • On systems with Permanent License Reservation (PLR), return the license via license smart reservation return before upgrading to Release 15 39.
  • Suspend LDAP user synchronisation and enforce a strict configuration freeze; Cisco states that modifications made during the upgrade—including automated jobs, password adjustments, and LDAP syncs—are overwritten 34​55.

Endpoint and license planning

Phone hardware and firmware must be validated prior to target software installation:

  • Cisco Wireless IP Phone 8821 and 8821-EX models require firmware 11.0(5)SR3 or later before Unified CM is upgraded to Release 15 3.
  • Devices on Cisco's deprecated phone list stop operating following an upgrade to the current Unified CM release and must be replaced prior to upgrading 16.
  • End-of-Life phone models are not tested by Cisco with Unified CM Release 15x 23.

Following installation, Unified CM operates in a 90-day evaluation period, after which the creation of new users and devices is blocked until registration with Cisco Smart Software Manager (CSSM) or a CSSM satellite completes 53. Smart License authorizations remain valid for 90 days, renewing at least once every 30 days; expirations prevent new provisioning 52. Call Home is deprecated as a transport starting in Release 15SU2, making Smart Transport (introduced in 14SU4 and 15SU2) the preferred mechanism 6.

Phones maintain cluster security via an Initial Trust List (ITL) file containing the ITLRecovery certificate, TFTP CallManager certificate, CAPF certificate, and TVS certificates 32. Administrators should maintain an offline copy of the ITL Recovery key via file get tftp ITLRecovery.p12 alongside DRS backups, as it is required to recover phones that reach an untrusted state 33. If endpoint trust is lost, executing utils itl reset localkey or utils itl reset remotekey generates a new ITL recovery file to restore communication 31. Setting the enterprise parameter "Prepare Cluster for Rollback to pre-8.0" distributes an ITL with empty TVS and TFTP sections so phones accept unsigned configuration files and alternate ITLs 41.

Sequencing and node execution

Standard deployments mandate that Unified CM and IM and Presence run identical releases; mismatched versions are not supported, though centralized deployments may mix them 29. Cisco's Collaboration Systems Release (CSR) Compatibility Matrix identifies cross-product software compatibility for CSR 10.5 and onward for applications like Unity Connection, Cisco Emergency Responder, and Expressway 10.

Cluster node transitions must proceed in order:

  • The Unified CM publisher is upgraded and switched active first, followed by the subscriber nodes 42.
  • Version switching must be completed on all Unified CM nodes prior to switching versions on any IM and Presence node 56.
  • After the upgrade, re-enable High Availability on Presence Redundancy Groups, restart the Cisco Sync Agent, and resume LDAP user synchronisation 28​55.

When performing an L2 upgrade on a Cisco Unity Connection cluster, the publisher node is fully disabled while the subscriber continues handling traffic 12. Administrators must not switch versions or restart the Unity Connection publisher until the subscriber upgrade has completed 11. Unity Connection nodes are then switched active by switching the publisher first, followed by the subscriber 11.

Rollback and disaster recovery considerations

Version switching places new software onto an inactive disk partition, enabling rollback, which Cisco supports with most direct upgrades but not with migrations 58. WarmTransfer's reading of the sources is that a version-switch rollback window exists only while the prior release remains intact on the inactive partition; following a migration, data-import fresh install, or Free Common Space COP installation, reverting requires reinstalling the base release and restoring a matching DRS backup 30. For Unity Connection, rolling back to a previous version prevents subsequent forward switching to the newer partition and requires reinstalling the upgrade 13.

Disaster Recovery System restores cannot cross software versions and must be executed on the identical product version as the backup archive 19. DRS restores additionally require matching the host IP address, hostname, DNS setup, and deployment type against the parameters stored inside the backup 18. If the cluster security password was modified following the backup event, the restore operation fails unless the original password is known 17.

See also

Applicability

Applies to: Cisco Unified Communications Manager, Cisco Prime Collaboration Deployment, Cisco IM, Cisco Unified Communications Manager 12.5, Cisco Unity Connection, and Cisco Collaboration Systems Release. Deployments: on-premises. Sources checked 2026-09-25.

What remains uncertain

Whether specific hardware server models outside virtualized environments can run diagnostic rollback tools is not covered by the sources below.

See also

Referenced by

Sources

  1. 1
    Upgrading from Release 14SU4 to any Unified CM or IM and Presence destination lower than 15SU2 is not supported.
    Compatibility Matrix for Cisco Unified Communications Manager and the IM and Presence Service, Release 15x · Supported Upgrade Paths section, note on 14SU4 · Checked 2026-09-25
  2. 2
    A direct upgrade to Release 15 fails on any single-80GB-vDisk deployment, even if the disk was manually resized to 110 GB.
    Upgrade and Migration Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Planning the Upgrade · Planning the Upgrade > Requirements and Limitations > Virtual Machine Configuration · Checked 2026-09-25
  3. 3
    Before upgrading Unified CM to Release 15, Cisco Wireless IP Phone 8821 and 8821-EX handsets need firmware 11.0(5)SR3 or later.
  4. 4
    From Release 15SU3, ESXi virtual machines must use a CPU mode that supports AVX. Where VMware EVC is configured, its settings must be checked.
  5. 5
    After regenerating expired identity certificates during pre-upgrade cleanup, take a backup so the new certificates are preserved.
  6. 6
    From Release 15SU2, Call Home is deprecated as a Smart Licensing transport. Smart Transport, introduced in 14SU4 and 15SU2, is the preferred mode.
  7. 7
    Cluster-wide version switching is available only for Direct Standard Upgrades from 12.5(x) or later. Otherwise each node is switched individually, for example with utils system switch-version.
  8. 8
    The common partition needs at least 25 GB free before upgrading. Cisco warns that an upgrade can still fail with an insufficient-space error even with 25 GB free.
  9. 9
    Required COP files must be installed on every node before the upgrade starts, whether you use Unified OS Admin or Prime Collaboration Deployment.
  10. 10
    Cisco's Collaboration Systems Release Compatibility Matrix identifies compatible software versions across collaboration products for CSR 10.5 and onward. It is the cross-product check for Unity Connection, CER, Expressway and similar applications.
    Cisco Collaboration Systems Release Compatibility Matrix · Landing page introduction · Checked 2026-09-25
  11. 11
    In an L2 upgrade of a Unity Connection cluster, do not restart or switch version on the publisher until the subscriber upgrade is complete. After that, switch the publisher first and then the subscriber.
    Install, Upgrade and Maintenance Guide for Cisco Unity Connection Release 15 - Upgrading Cisco Unity Connection · Upgrading Cisco Unity Connection > Upgrading a Unity Connection Cluster · Checked 2026-09-25
  12. 12
    While a Unity Connection cluster upgrades, the publisher is fully disabled and the subscriber keeps serving users and callers.
    Install, Upgrade and Maintenance Guide for Cisco Unity Connection Release 15 - Upgrading Cisco Unity Connection · Upgrading Cisco Unity Connection > Upgrading a Unity Connection Cluster · Checked 2026-09-25
  13. 13
    After rolling Unity Connection back to the previous version, you cannot switch forward to the newer version again and must reinstall the upgrade.
    Install, Upgrade and Maintenance Guide for Cisco Unity Connection Release 15 - Upgrading Cisco Unity Connection · Upgrading Cisco Unity Connection > Rolling Back Unity Connection to the Previous Version · Checked 2026-09-25
  14. 14
    DRS backups do not include custom TFTP content: Ringlist.xml, List.xml, custom ringtones and background images. Back these up separately before upgrading.
  15. 15
    Before upgrading, check database health with a CURT Database Status Report and with utils dbreplication status and utils dbreplication runtimestate. The replication setup value should be 2 for every node.
    Upgrade and Migration Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Pre-Upgrade Tasks (Manual Process) · Pre-Upgrade Tasks > Check Network Health > Generate a Database Status Report; Check Database Replication · Checked 2026-09-25
  16. 16
    Phone models on Cisco's deprecated list stop working after an upgrade to the current Unified CM release, so they must be replaced beforehand.
  17. 17
    If the cluster security password has changed since the backup was taken, the restore fails unless you have a record of the old password.
    Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Restore the System · Restore the System > Restore Prerequisites · Checked 2026-09-25
  18. 18
    A DRS restore also requires the server's IP address, hostname, DNS configuration and deployment type to match those stored in the backup file.
    Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Restore the System · Restore the System > Restore Prerequisites · Checked 2026-09-25
  19. 19
    A DRS restore must run on the same product version as the backup, so a backup cannot be restored across versions.
    Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Restore the System · Restore the System > Restore Prerequisites / Restore Overview · Checked 2026-09-25
  20. 20
    The upgrade can overwrite IM and Presence enterprise parameters with Unified CM values when the two differ. Screenshot both sets beforehand.
  21. 21
    Cisco's Version 12.5 on-premises calling applications (Unified CM, SME, IM and Presence, CER, Unity Connection, Paging Server) reached Last Date of Support on 31 August 2025.
  22. 22
    End of software maintenance releases for Version 12.5 on-premises calling applications was 31 August 2024.
  23. 23
    Cisco does not test Unified CM Release 15x with phones that are End of Life.
  24. 24
    A FIPS-mode node cannot be upgraded while its IPsec policies use Diffie-Hellman groups 1, 2 or 5. Those policies must be reconfigured with groups 14 to 18 first, and groups 17 and 18 are unavailable from 15SU3.
  25. 25
    To upgrade a node in FIPS mode, the cluster security password must be at least 14 characters long.
  26. 26
    Installing the Free Common Space COP file makes the inactive partition unusable, so you can no longer switch back to the inactive (previous) version.
  27. 27
    Take a fresh DRS backup just before the upgrade. Cisco cautions that an outdated backup can lose data or leave the system unrestorable.
  28. 28
    Before upgrading, disable High Availability on each Presence Redundancy Group and stop the Cisco Sync Agent on IM and Presence. Re-enable both afterward.
    Upgrade and Migration Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Pre-Upgrade Tasks (Manual Process) · Pre-Upgrade Tasks > Disable High Availability on Presence Redundancy Groups; Stop the IM and Presence Sync Agent · Checked 2026-09-25
  29. 29
    In a standard deployment, IM and Presence must run the same release as Unified CM, and a mismatch is not supported. Centralized deployments may mix releases.
    Compatibility Matrix for Cisco Unified Communications Manager and the IM and Presence Service, Release 15x · Version compatibility between Unified CM and IM and Presence Service section · Checked 2026-09-25
  30. 30
    A version-switch rollback exists only while the previous release still sits intact on the inactive partition. After a migration, a fresh install with data import, or a Free Common Space COP install, the only documented way back is reinstalling the source release and restoring a same-version DRS backup.inferred
    Upgrade and Migration Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Planning the Upgrade · Planning the Upgrade > Version Switching; combined with Pre-Upgrade Tasks > Maximize Usable Disk Space and Restore the System > Restore Prerequisites · Checked 2026-09-25
  31. 31
    When phones lose trust in the cluster, utils itl reset localkey or utils itl reset remotekey generates a new ITL recovery file and re-establishes trust between phones and TFTP.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security · Default Security > ITL recovery / Bulk Reset of ITL · Checked 2026-09-25
  32. 32
    The ITL file holds the ITLRecovery certificate, the TFTP server's CallManager certificate, all TVS certificates and the CAPF certificate. Phones use it to authenticate configuration-file signatures and, through TVS, application servers.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security · Default Security > Initial Trust List · Checked 2026-09-25
  33. 33
    Recovering phones from an untrusted state requires the ITL Recovery key. Cisco's tech note says to keep a copy (file get tftp ITLRecovery.p12) in addition to DRS backups.
    Unified Communications Manager ITL Enhancements in Version 10.0(1) · ITL Recovery key / backup section · Checked 2026-09-25
  34. 34
    Make no configuration changes during the upgrade. Cisco says changes made then are overwritten, and that includes password changes, LDAP synchronisation and automated jobs.
  35. 35
    Refresh upgrades from a source release earlier than 12.5.x to Release 15 or later are not supported.
  36. 36
    There are no Direct Refresh Upgrade paths to Unified CM and IM and Presence Service Release 15 or later.
  37. 37
    Any supported path that uses a PCD Upgrade Task or PCD Migration Task must use Prime Collaboration Deployment Release 15.
    Upgrade and Migration Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Planning the Upgrade · Planning the Upgrade > Supported Upgrade and Migration Paths (note below table) · Checked 2026-09-25
  38. 38
    Cisco lists upgrading IP phone firmware through the TFTP server as an optional task before the Unified CM upgrade.
  39. 39
    On a system with Permanent License Reservation, return the license with license smart reservation return before upgrading to Release 15.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Smart Software Licensing · Smart Software Licensing > Upgrading Permanent License Reservation Enabled System to Version 15 · Checked 2026-09-25
  40. 40
    Sources from 10.5 through 12.0 have no direct upgrade to Release 15. They move by a PCD Migration or a fresh install with data import, and each path needs specific COP files.
    Upgrade and Migration Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Planning the Upgrade · Planning the Upgrade > Supported Upgrade and Migration Paths table, rows 10.5 through 12.0 · Checked 2026-09-25
  41. 41
    The enterprise parameter Prepare Cluster for Rollback to pre-8.0 gives phones an ITL with empty TVS and TFTP sections, so they accept unsigned configuration files and any new ITL. Cisco recommends it before moving phones between clusters.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security · Default Security > Migrate IP Phones Between Clusters / Prepare Cluster for Rollback · Checked 2026-09-25
  42. 42
    Within the Unified CM cluster, the publisher node is upgraded and switched first and the subscriber nodes after it.
  43. 43
    If the upgrade fails on the Unified CM publisher, recover by restoring the publisher from a DRS backup. If that is not possible, reinstall the entire cluster.
    Upgrade and Migration Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Troubleshooting · Troubleshooting > Troubleshooting Unified Communications Manager Upgrades > Upgrade Failure of Publisher Node · Checked 2026-09-25
  44. 44
    The pre-upgrade readiness COP checks for common problems such as low disk space, service status and expiring certificates. Cisco says to re-run it until it reports no errors.
  45. 46
    Before upgrading, record the registered device counts from RTMT (phones, gateways and media resources) and the IM and Presence assigned-user counts, then compare them after the upgrade.
    Upgrade and Migration Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Pre-Upgrade Tasks (Manual Process) · Pre-Upgrade Tasks > Record the Registered Device Count; Record the Number of Assigned Users · Checked 2026-09-25
  46. 47
    The upgrade changes the TFTP Maximum Serving Count service parameter. Record its value beforehand and reset it after the upgrade.
  47. 48
    For large clusters, raise the database replication timeout on the publisher with utils dbreplication setrepltimeout before upgrading, then restore the 300-second default afterward.
  48. 49
    Configuration changes made after the upgrade and before a revert are lost when you revert.
  49. 50
    To revert a cluster, switch the publisher back first, then all backup subscribers, then all primary subscribers, and then reset database replication with utils dbreplication reset all.
  50. 51
    Add a serial port to each VM before upgrading so install logs can be dumped if the upgrade fails. Remove it afterward because it affects VM performance.
  51. 52
    A Smart License authorization is valid for 90 days and renews at least once every 30 days. If it expires, new devices and users cannot be provisioned.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Smart Software Licensing · Smart Software Licensing > overview / license authorization · Checked 2026-09-25
  52. 53
    After installation, Unified CM runs under a 90-day evaluation period. When it ends, the system stops allowing new users or devices until it is registered with CSSM or a CSSM satellite.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Smart Software Licensing · Smart Software Licensing > Product Instance Evaluation Mode · Checked 2026-09-25
  53. 54
    If a Unified CM subscriber fails to upgrade, restore it from a DRS backup or re-run its upgrade. The node does not have to be removed from the publisher's Server page.
    Upgrade and Migration Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Troubleshooting · Troubleshooting > Troubleshooting Unified Communications Manager Upgrades > Upgrade Failure of Subscriber Node · Checked 2026-09-25
  54. 55
    Suspend LDAP user synchronisation for the upgrade and resume it only after the whole upgrade is complete.
  55. 56
    Switch versions on all Unified CM nodes before switching versions on any IM and Presence node.
    Upgrade and Migration Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Planning the Upgrade · Planning the Upgrade > Upgrade Sequence (Unified CM and IM and Presence) · Checked 2026-09-25
  56. 57
    Cisco counts an upgrade as complete only when every node has installed the inactive version, every node has switched version and rebooted, and database replication has finished.
  57. 58
    Version switching installs the new release on the inactive partition so an administrator can switch to it and later revert. Cisco supports it with most direct upgrades but not with migrations.
  58. 59
    Unified CM and IM and Presence Release 15x support only virtualized deployments. Bare-metal servers are not supported.
  59. 60
    If space is short, Cisco suggests temporarily lowering the RTMT log-partition low and high watermarks from their defaults (80 and 85) to 30 and 40, then restoring them after the upgrade.

Documents

tier 2 current vendor documentation

Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Restore the System

Cisco Systems · 2026-08-31 · accessed 2026-09-24

tier 2 current vendor documentation

Cisco Collaboration Systems Release Compatibility Matrix

Cisco Systems · 2025-01-10 · accessed 2026-09-25

tier 2 current vendor documentation

Compatibility Matrix for Cisco Unified Communications Manager and the IM and Presence Service, Release 15x

Cisco Systems · 2026-07-16 · accessed 2026-09-24

tier 2 current vendor documentation

Install, Upgrade and Maintenance Guide for Cisco Unity Connection Release 15 - Upgrading Cisco Unity Connection

Cisco Systems · 2025-12-02 · accessed 2026-09-25

tier 2 current vendor documentation

Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security

Cisco Systems · 2026-09-22 · accessed 2026-09-24

tier 2 current vendor documentation

System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Smart Software Licensing

Cisco Systems · 2026-09-22 · accessed 2026-09-24

tier 2 current vendor documentation

Unified Communications Manager ITL Enhancements in Version 10.0(1)

Cisco Systems · 2014-04-08 · accessed 2026-09-24

Cite this page

APA

WarmTransfer. (2026, September 25). Planning a Unified CM upgrade. WarmTransfer. https://warmtransfer.net/knowledge/cucm-upgrade-planning

BibTeX

@misc{warmtransfer-cucm-upgrade-planning,
  title  = {Planning a Unified CM upgrade},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/cucm-upgrade-planning},
  note   = {Verified 2026-09-25}
}