Canonical puts Zephyr on an Ubuntu-style clock
Canonical will sell enterprise support for Zephyr 26.04 LTS, promising up to 15 years of security maintenance for the microcontroller devices covered by the EU's Cyber Resilience Act.

Fifteen years of patches for a microcontroller
Canonical has announced Zephyr 26.04 LTS, an enterprise-ready distribution of the Zephyr real-time operating system that promises up to 15 years of security maintenance for microcontroller-class devices. The announcement landed on 21 September, the day before Embedded World North America opens at the Anaheim Convention Center, and the product is sold as part of an Ubuntu Pro for Devices subscription rather than given away.
The target is the companies that design microcontrollers into products and then have to keep them patched for a decade: silicon vendors and the ODMs and OEMs building MCU-grade hardware. Canonical says the distribution covers both the core RTOS and a wider universe of microcontroller components, and that it will follow the same cadence as the rest of its line-up, with a long-term support release every two years and an interim release every six months.
The Cyber Resilience Act is the reason this exists
Europe's Cyber Resilience Act has entered into force, and it obliges manufacturers to provide at least five years of security maintenance, patching and record keeping for the products they sell. Upstream Zephyr offers five years of standard support. Canonical is offering up to 15, and pairing that with a documented, predictable release cycle so that a device maker can point at a support commitment rather than an open-source project's good intentions. This is a compliance product as much as a technical one, and Canonical is selling it that way.
The commitment also reaches past the kernel. Canonical says the Zephyr 26.04 LTS promise covers essential tooling from the wider microcontroller ecosystem, including West, the meta-tool Zephyr developers use to manage repositories, build firmware and flash it to boards. Maintenance of the tools around an operating system is usually where long-lifecycle promises quietly come apart, so naming West is a meaningful detail rather than a footnote.
Over-the-air updates without building them yourself
Zephyr 26.04 LTS natively supports Golioth Cloud's software update capabilities. Golioth is an IoT cloud platform built to push secure updates to microcontrollers in the field, and Canonical says including its SDK out of the box gives device makers over-the-air updates, credential provisioning and remote device management without writing custom tooling - the delivery pipeline that the Cyber Resilience Act's field-update requirements effectively assume you already have.
For developers, Canonical is adding Zephyr LTS support to Canonical Workshop, its tool for repeatable containerised development environments. A Workshop SDK for Zephyr 26.04 LTS is meant to hand over a working Zephyr environment with build tools already in place, so a new engineer can run west build without first reconstructing someone else's toolchain from a wiki page.
Who is vouching for it
"Longer device lifecycles, rising customer expectations, and regulations like the EU Cyber Resilience Act make long-term support a necessity for device makers, not a luxury," said Jonathan Beri, head of product for IoT at Canonical, who will present a session at the show titled Surviving the CRA: Architecting Zephyr for 15-Year Lifecycles and Long-Term Compliance. Kate Stewart, vice president of dependable embedded systems at the Linux Foundation and the Zephyr Project, called the offering a welcome addition that reinforces Zephyr as the real-time operating system of choice for production-grade embedded systems.
Two hardware partners are also quoted. Alex Iuorio, senior vice president for global supplier development at Avnet, said the distributor is expanding its work with Canonical beyond Ubuntu Pro to bring Zephyr 26.04 LTS to its customers, while Yoshio Sato, a director in Renesas Electronics' embedded processing strategy group, said pairing the chipmaker's long-lifecycle parts with Canonical's support gives customers the software stability and security maintenance a full product lifetime demands.
Our opinion
Regulation has quietly become the most effective sales force open source ever had. Nobody buys a fifteen-year patch promise out of enthusiasm; they buy it because a Brussels deadline turned firmware maintenance from a line item you can defer into a legal exposure you cannot, and Canonical has spotted that the cheapest way to win the microcontroller market is to be the vendor with a signature on the dotted line. The interesting question is what it does to the upstream project. When a commercial distributor starts guaranteeing a decade and a half on a five-year upstream cadence, either the vendor carries an increasingly large maintenance burden of its own, or it gains a strong incentive to steer the project towards whatever it can support cheaply. Canonical is a genuine contributor here, not a freeloader, and the Zephyr Project's endorsement reads as sincere. Keep an eye on pricing, though, because a support subscription nobody can quote for a three-person hardware startup is a compliance tax dressed as a product.