netsuite · release-notes · suitescript
NetSuite Release Timeline 2026.2 to 2028.2: What Breaks, and in Which Version
NetSuite has no single 2026.2 release date. Here is where your account's date lives and what changes for scripts and integrations in each release to 2028.2.
There is no 2026.2 release date, there is yours
Someone on the team searches for the NetSuite 2026.2 release date, finds partner posts and not one calendar day, and concludes the information is hidden. It is not hidden. It does not exist as a single date.
Oracle says it plainly on the Sneak Peeks page: enhancements "will not be available until your NetSuite account is upgraded to the new version. The date of your scheduled upgrade is displayed in the New Release Portlet in your account." The version you are on right now is printed at the bottom of the Home page. Accounts are upgraded on different days, and an administrator can move the date through Customer-Scheduled Maintenance. Even inside one company the dates differ: Oracle upgrades a sandbox within 7 days after its production account. A blog post quoting one date is quoting somebody's account.
What does not vary by account:
- NetSuite ships two scheduled version upgrades a year, 20XX.1 and 20XX.2. Between them, monthly minor releases add features without a version change.
- Release Preview is available twice a year, right before each release. An Administrator requests it at Setup > Company > Release Preview. It lives until your source account is upgraded, or until nobody logs in for 14 consecutive days, whichever comes first.
- If the New Release portlet is not on your Home page, add it: Personalize, then the Standard Content tab, then New Release.
The minor releases are why "we are on 2026.2" is not one state. REST web services support for saved searches and for File Cabinet records arrived in the September minor release of 2026.2, not in the version upgrade. So did the change that stopped custom tools built on the tool SDF object from deploying. Reading the 2026.2 notes as they stood on your upgrade day misses whatever the minor releases added after it.
The whole schedule on one page
Oracle publishes these milestones in at least four different places: the SuiteScript 2.1 transition guide, the authentication release notes, the SOAP removal FAQ and the SuiteCloud SDK notes. None of them puts the others side by side. This is that table, built only from those pages.
| Release | Scripts | Integrations and authentication | Tooling and security |
|---|---|---|---|
| 2026.2 | SuiteScript 2.1 becomes the standard for new and existing scripts. | SOAP endpoint 2019.2 disabled. REST saved search and File Cabinet REST added (September minor). | SuiteCloud CLI for Node.js 4.0 removes local validation. tool SDF objects can no longer be deployed (September minor). Passkeys for login. |
| 2027.1 | SuiteScript 1.0 enters end-of-life support, critical issues only. | NLAuth integrations stop working. No new TBA integrations, so no new SOAP integrations. PKCE required for new OAuth 2.0 authorization code integrations. SOAP endpoint 2020.1 disabled. | tool SDF objects stop executing. 2FA for All Employee Roles switched on automatically. SuiteCloud CLI for Java no longer downloadable. |
| 2027.2 | Only the newest SOAP endpoint (2025.2) is supported. Older ones stay available without support. 2020.2 disabled. | ||
| 2028.1 | 1.0 scripts cannot be deployed in new accounts. 2.0 and 2.x scripts run as 2.1 by default. | SOAP endpoint 2021.1 disabled. | |
| 2028.2 | All scripts must use 2.1. Legacy versions no longer run. | All SOAP endpoints disabled, SOAP integrations stop. TBA end of support, tentatively, excluding SuiteAnalytics Connect. |
Two of those cells carry a qualifier on Oracle's side, and the qualifier matters. The TBA date is described as "tentatively planned for the 2028.2 release". The SuiteScript guide says legacy versions are "expected to be removed in NetSuite 2028.2". The SOAP FAQ, by contrast, does not hedge: "With the 2028.2 NetSuite release, all endpoints will be disabled, and SOAP-based integrations will stop working."
2026.2: the part that already happened
If your account has been upgraded, these are not plans. They are current behaviour.
SuiteScript 2.1 is now the standard scripting model. Nothing stops running because of it, but Oracle's September notes added a useful mechanism for the conversion work: replace the file on a SuiteScript 1.0 script record with a compatible 2.1 file, and NetSuite updates the record's API version to 2.1. The replacement has to be the same script type. It works in the UI, through SDF and through SuiteBundler updates. We covered which scripts actually have to move and Oracle's AI upgrade assistant separately.
SuiteQL queries and Analytics datasets based on generic transactions now default to sorting by Transaction.tranDate instead of Transaction.tranDisplayName when no order is specified. Nothing errors. The rows just come back in a different sequence, which is its own kind of bug, covered in what the SuiteQL sort change breaks.
The ociConfig object is no longer supported in N/llm, N/documentCapture and N/task. Passing it does not throw. The values are simply ignored, so a script that relied on its own OCI configuration keeps running, and no error tells you the setting stopped applying.
The change most likely to surprise a development team is in the SuiteCloud CLI for Node.js 4.0. Local validation is gone. Validation happens on the server by default, and project:validate --server and project:deploy --validate now have no effect beyond printing a warning. Oracle also says the output format of validation, preview and deployment has changed, and tells you not to rely on it. If your pipeline parses CLI output to decide whether a deploy succeeded, that is the line to check first:
grep -rnE -- "--server|--validate|--dryrun" \
--include="*.yml" --include="*.yaml" --include="*.sh" --include="Jenkinsfile" .
Every hit is either a flag that now does nothing or a step whose output you may be parsing. The SuiteCloud CLI for Java has reached end of support at version 2025.2. It still downloads, but only until 2027.1.
On the login side, as of July 13, 2026 every user can sign in with a passkey instead of a password, and from 2026.2 a FIDO2-compliant passkey also works as the second factor. Since September 21, 2026 administrators can turn on 2FA for every Employee role.
The developer-facing list for this release, with each change mapped to what it touches in your scripts, is in NetSuite 2026.2 release notes for developers.
2027.1 is the deadline to plan against
Most planning conversations anchor on 2028.2, because that is where SuiteScript 1.0 and SOAP finally go away. That is the wrong anchor. The release that breaks working production code on the day of your upgrade is 2027.1, a year earlier.
Look at what changes there. Integrations that authenticate with NLAuth stop working. Oracle's wording is "all integrations that use NLAuth as an authentication method will stop working", with one carve-out for existing integrations that use the IssueToken endpoint. That is not a support status change. It is a login that fails. Custom tools built on the old tool SDF object stop executing, and since they already cannot be deployed, the only fix is moving them to toolset before your upgrade date, not after. And 2FA for All Employee Roles is switched on automatically. An administrator can disable it, which restores the previous setting, but a shared login that was never set up for 2FA finds out on upgrade day.
The rest of 2027.1 restricts new work rather than breaking old work:
- No new integrations with Token-Based Authentication, through either the IssueToken endpoint or the three-step authorization flow.
- No new SOAP integrations. Existing ones keep running, and their Integration Records can still be edited until SOAP is removed.
- PKCE becomes mandatory for all new integrations using the OAuth 2.0 authorization code grant, including private clients. Existing integrations without PKCE keep working.
- SuiteScript 1.0 drops to end-of-life support. Critical issues only. Anything else, Oracle asks you to convert the script to 2.1 first.
That last point is easy to underrate. From 2027.1, a support case about a 1.0 script that is not critical gets one answer: convert the script to 2.1 first. Your 1.0 code still runs for another year and a half, but the safety net under it is gone.
NLAuth is the item to search for now, because it leaves a recognisable header in the calling code, wherever that code lives:
grep -rniE "NLAuth|nlauth_signature" \
--include="*.js" --include="*.ts" --include="*.py" --include="*.java" --include="*.cs" --include="*.php" .
A hit in a connector's codebase is a hard deadline at your 2027.1 upgrade. The header format, and how it differs from TBA and OAuth 2.0, is in our SOAP and TBA migration piece.
2027.2 and 2028.1: the quiet releases
2027.2 is quiet on the scripting side and matters only for SOAP. From that release, Oracle supports exactly one SOAP endpoint, 2025.2, and fixes bugs only there. Older endpoints keep responding, without support, and the oldest one still available (2020.2) is disabled. An integration pinned to a 2023 or 2024 endpoint keeps working, but a defect you report against it is no longer Oracle's to fix.
2028.1 looks quiet and is not. SuiteScript 1.0 scripts can no longer be deployed in new accounts, though they stay deployable in existing ones. The line that affects customers is this one: "SuiteScript 2.0/2.x scripts run as SuiteScript 2.1 by default." Every 2.0 and 2.x script in the account switches runtime without anyone changing a file.
You can make that switch yourself today, and you should do it in a sandbox long before Oracle does it for you. Both controls live at Setup > Company > Preferences > General Preferences: Execute SuiteScript 2.x Server Scripts as 2.1, where you select 2.1, and the Execute SuiteScript 2.0 Server Scripts as 2.1 box. One detail from the help page catches people out. With the preferences on, a file annotated 2.0 or 2.x is still checked against 2.0 syntax rules when uploaded, and a file containing 2.1-only syntax returns a syntax error. The runtime changed, the syntax rules did not. For that you change the annotation itself.
To see how much sits behind each preference, count script records by version:
SELECT s.apiversion, COUNT(*) AS scripts
FROM script s
GROUP BY s.apiversion
apiversion comes back as 1.0, 2.0 or 2.1. There is no 2.x value: a file annotated @NApiVersion 2.x is stored on the record as 2.0, which we confirmed on a live account. If you need to know which preference governs which script, you have to read the annotation in the file.
2028.2: everything that was tentative becomes real
Three things land on the same release, and they are separate changes with separate owners.
Scripts first. The September 2026.2 notes put it without qualification: "All new and existing scripts must use SuiteScript 2.1. Legacy script versions will no longer run." That covers 1.0, 2.0, and anything annotated 2.0 or 2.x.
Then SOAP. Every endpoint is disabled and SOAP-based integrations stop working. The endpoint table in Oracle's FAQ shows 2025.2, the last planned endpoint, as supported right up to 2028.1 and gone in 2028.2. There is no endpoint you can upgrade to that survives.
Then TBA. Oracle currently describes end of support for existing TBA integrations as tentatively planned for 2028.2, with SuiteAnalytics Connect (ODBC/JDBC) excluded. The same help page said 2028.1 as recently as August 2026. A date that has moved once can move again, in either direction, so treat it as the release to be finished before, not the release to start in.
An integration that uses SOAP and TBA has to fix both. An integration that uses REST with TBA only has to fix authentication. The order of work for the SOAP side is in SOAP to REST migration: what to do and in what order.
What to do with this before your next upgrade
Find your date in the New Release portlet, then work backwards from 2027.1, not 2028.2. Before that upgrade, three searches should be closed: NLAuth in every calling system, tool objects in every SDF project, and roles or shared logins that will hit 2FA for the first time. The SuiteScript 2.1 work and the SOAP-to-REST work can run behind them, on the longer clock.
The SuiteQL above is the kind of check MokuBot runs from a side panel inside your account, under your own role. It runs SuiteQL, reads execution logs and writes SuiteScript, so the version count, the 1.0 inventory and the first conversions can happen in one place. If you would rather have someone else go through your scripts and integrations against everything on this list, write to sales@mokuhub.com.
The dates Oracle hedges are TBA and, mildly, the 2.1 cutover. The dates it does not hedge are NLAuth in 2027.1 and SOAP in 2028.2. Plan around the second pair.
Sources
NetSuite Sneak Peeks, Oracle NetSuite Help Center
NetSuite Version 2026.2 release index, Oracle NetSuite Help Center
Monthly Minor Release Notes, 2026.2, Oracle NetSuite Help Center
September Minor Release, NetSuite 2026.2, Oracle NetSuite Help Center
August Minor Release, NetSuite 2026.2, Oracle NetSuite Help Center
Transitioning To SuiteScript 2.1, Oracle NetSuite Help Center
Enabling SuiteScript 2.1 at the Account Level, Oracle NetSuite Help Center
Authentication changes in 2026.2, Oracle NetSuite Help Center
Preparing for Token-based Authentication (TBA) End of Support, Oracle NetSuite Help Center
SOAP Removal Plans FAQ, Oracle NetSuite Help Center
SuiteCloud SDK in 2026.2, Oracle NetSuite Help Center
Change to Default Sorting for SuiteQL Queries and Analytics Datasets, Oracle NetSuite Help Center
NetSuite Version Upgrade Maintenance, Oracle NetSuite Help Center
The Release Preview Account and Overview of Release Preview, Oracle NetSuite Help Center