Cambium Networks has entered administration, and the practical consequence for UK businesses arrives on 1 October 2026 — nine days from today. The company has confirmed that cnMaestro Cloud, the hosted platform used to manage its enterprise Wi–Fi access points, cnMatrix switches and NSE firewalls, “may not support Enterprise devices post October 1st, 2026”. Its guidance to customers is to install the on–premise version of cnMaestro as soon as possible. Administrators have ended production of the enterprise hardware lines; 260 staff, 53.6% of the workforce, were let go in September without severance payments.
Here is the part that makes this urgent rather than merely unfortunate. The hardware does not stop working on 1 October. A Cambium access point will keep passing traffic on 2 October exactly as it did on 30 September. What goes away is the ability to manage it — to push a configuration change, onboard a replacement unit, update firmware, or see what the estate is doing. That is a slow failure rather than an outage, which is precisely why it gets deprioritised, and precisely why it is dangerous: a network you cannot change is a network that degrades quietly until the first time you urgently need to change it. And there is a second deadline behind the first. Customers who move to on–premise cnMaestro in time receive only a 90–day trial licence, after which the software loses functionality unless a buyer for the enterprise business emerges to extend or replace it. Migrate this week and you have bought yourself until roughly the turn of the year.
What has actually happened to Cambium
The collapse did not arrive without warning, and the sequence is a fairly textbook one. In August 2025, Cambium admitted that its financial reports for 2022, 2023 and six subsequent quarters were unreliable due to errors. NASDAQ delisted the company once the accounting issues came to light, and a later attempt to rejoin the exchange was unsuccessful. A May 2026 regulatory filing then disclosed that the company’s officers had “substantial doubt about our ability to continue as a going concern” — language with a specific technical meaning in financial reporting, and about as direct a signal as a listed company is capable of sending.
In September 2026 the position resolved. 260 staff were laid off, administrators were appointed, and production ended on the Wi–Fi access points, NSE firewalls and cnMatrix switches. The picture is not uniform across the business: Cambium’s fixed wireless broadband operation is expected to largely resume after a short pause, and it is the enterprise hardware lines — Wi–Fi, switching and firewalls — that are being wound down. If you are a wireless ISP using Cambium point–to–point and point–to–multipoint equipment, your position is different, and better, than that of a business running Cambium kit inside an office.
For enterprise customers, the cnMaestro guidance is the operative item. The company’s knowledge base advises installing the on–premise version of cnMaestro as soon as possible, because the cloud platform may not support Enterprise devices after 1 October 2026. That is an unusually candid instruction from a vendor in administration, and it deserves to be read as what it is: a company telling its customers, with limited time and limited staff, to get themselves onto something it does not have to keep running.
It is worth separating the two failures in this story, because businesses will draw the wrong lesson otherwise. The first is a company–specific failure — accounting errors, a delisting, a going–concern warning, administration. Those are idiosyncratic and, with hindsight, were visible in public filings for more than a year. The second is architectural and applies to a great many vendors that are in no financial difficulty at all: when the management plane for hardware you own lives in a vendor’s cloud, the continued manageability of your own equipment is contingent on that vendor continuing to operate the service. Cambium is the illustration. It is not the only place the pattern exists.
The failure mode here is not an outage, and expecting one will cause businesses to under–react. Your Cambium access points, switches and firewalls will continue forwarding traffic after the cloud portal stops supporting them. What you lose is control: no configuration changes, no adding or replacing devices, no firmware updates, no centralised visibility of what the estate is doing. The consequences arrive later and individually. A failed access point cannot be swapped in because nothing can adopt the replacement. A new office layout cannot be reflected in the wireless configuration. A firewall running an NSE appliance stops receiving updates, which turns a security device into an ageing, unpatchable one sitting at your network boundary — the single worst place in the estate to have equipment you cannot change. None of that announces itself. It surfaces the first time you urgently need to alter something and discover that you cannot.
Thirteen months from an accounting admission to administration
The chronology is worth setting out in full, because the most useful thing a business can take from it is not the ending but how visible the trajectory was. Every item below was public at the time.
The uncomfortable observation in that timeline is that the information was available and the signal was strong. A going–concern warning in a public filing is about as explicit as corporate disclosure gets, and it arrived four months before administration. Almost no UK SME monitors the financial filings of its networking vendor, and it would be unreasonable to suggest they all should. But the gap between “nobody could have known” and “nobody was looking” is worth being honest about, because only one of those is fixable.
How exposed are you if a hardware vendor disappears?
The answer depends almost entirely on where the management plane lives and what happens to it when the vendor stops. The chart below is an indicative planning model — not measured data — ranking how much control you retain over hardware you own when the company that sold it to you ceases to operate.
Cambium’s enterprise customers are currently being moved from the top of that chart to the middle of it, which is genuinely useful and explains why the advice is to install on–premise cnMaestro immediately. But note where the middle sits: an on–premise controller on a 90–day trial licence is the fourth bar, not the fifth. The distinction between a time–limited licence and a perpetual one is the whole difference between having solved the problem and having deferred it by a quarter.
The bottom two bars describe the position most affected businesses are in today, and they are worth distinguishing. “No local management path” means that if the portal goes, the device is effectively frozen in its current configuration. “Limited local fallback” means there is some way in — a local web interface, a console port, a factory–reset–and–configure–standalone mode — but it is per–device, manual, and often loses the centralised features the estate was designed around. Neither is a good place to be; the second is at least recoverable with enough labour.
The number that tells you how much help is left
When assessing how much vendor assistance will realistically be available during a migration like this, the redundancy figure is a more useful indicator than any corporate statement.
That figure should shape expectations about what the next nine days will feel like. Cambium has said it will provide further communication and direction, and there is no reason to doubt the intention. But a company that has lost more than half its people, is in administration, and is simultaneously supporting a customer base trying to migrate en masse before a fixed date has a capacity problem that goodwill does not solve. Support queues will be long. Documentation may not be updated. Edge cases specific to your deployment may go unanswered.
The practical implication is to treat this as a self–service migration and be pleasantly surprised if it is not. Download what you need now rather than assuming it will be available later — the on–premise cnMaestro installer, current firmware images for every device model you run, documentation, licence files and a full configuration export. Portals and download servers are operating costs, and operating costs in an administration are reviewed. The material you have locally is the material you can rely on.
There is also a reasonable case for optimism that should be stated alongside the caution. The fixed wireless broadband business is expected to largely resume after a short pause, which indicates the administrators see value worth preserving. Enterprise networking product lines with a substantial installed base are exactly the kind of asset that gets acquired in an administration, and a buyer would have a strong commercial incentive to extend or replace the trial licence and keep the installed base intact. That outcome is plausible. It is simply not something to plan around, because the timescale of an acquisition is not within anyone’s control and the licence clock is.
Where this exposure hides in a UK SME estate
Cambium is today’s example, but the pattern — hardware you own, dependent on a management service you do not — is now the default architecture across a great deal of business equipment. The rows below reflect where it typically sits, with badges indicating how much attention each usually needs.
The first row is the one that turns an inconvenience into a security problem. An access point that cannot be reconfigured is annoying. A firewall at the network boundary that can no longer receive firmware updates is something else entirely: it is a device whose entire purpose is to resist attack, ageing in place, accumulating unpatched vulnerabilities, in the position of maximum exposure. Any business running NSE firewalls should treat those specifically as the highest priority in this migration, ahead of the wireless estate, because the consequence of leaving them unmanageable compounds rather than merely persists.
The second row is the cheapest insurance available and almost nobody has it. A current export of your device configurations, held somewhere that is not the vendor’s platform, is what converts a vendor failure from a crisis into an inconvenience — it is the document that lets you rebuild the same network on different hardware without reverse–engineering it from a live system you can no longer read. It costs minutes per device and it is worth doing before 1 October regardless of which management path you end up on, because configuration exports are a portal feature and portals in administration are not guaranteed.
What responding to this costs
The bands below are indicative planning figures for UK businesses, covering the immediate migration to on–premise management and, where relevant, the eventual hardware replacement once the trial licence position becomes clear. They are not quotes, and the largest variable is the number of sites rather than the number of staff.
| Situation | Typical scope | Indicative cost | What you get for it |
|---|---|---|---|
| Small single–site estate, a handful of Cambium access points | Configuration and firmware export, on–premise cnMaestro installed on an existing server or VM, devices re–adopted, documented local access to each unit | £600 – £2,000 | Management restored before the deadline, with the estate documented well enough to rebuild on other hardware if needed |
| Single site including NSE firewalls or cnMatrix switches | As above, plus priority treatment of the security devices, firmware brought current while updates are still obtainable, boundary configuration documented in full | £1,500 – £5,000 | The highest–risk devices patched and documented while that is still possible, rather than frozen at whatever version they are on |
| Multi–site business, 3 – 10 locations | Central on–premise controller with per–site re–adoption, remote access design, full estate inventory, contingency plan for the 90–day licence expiry | £5,000 – £18,000 | A single managed estate again, plus a decision–ready plan for what happens at the end of the trial period rather than a scramble in December |
| Planned replacement onto a financially stable platform | Requirements review, vendor selection with viability as an explicit criterion, phased hardware replacement, migration of configuration and policy, disposal of the old estate | £8,000 – £45,000 | An exit from the problem rather than an extension of it, executed on a schedule you choose instead of one set by a licence timer |
| Any business, preventative | Hardware and management–plane inventory, exported configurations held independently, licence terms reviewed for vendor–failure provisions, a named owner and review date | £0 – £3,000 | The ability to answer, for every device you own, the question this story poses: if the vendor vanished tomorrow, could you still manage it? |
The comparison worth making is between the third row and the fourth. Migrating to on–premise cnMaestro is much cheaper than replacing the estate, and it is unquestionably the right immediate action given nine days. But it buys ninety days, and it buys them on the assumption that a buyer materialises. A business with a substantial Cambium deployment should be doing the cheap thing this week and starting the expensive conversation at the same time, because the worst position is arriving at the end of December having done the first and not begun the second.
Two ways to own network hardware
Reactive posture
What most UK SMEs have today
- Hardware selected on price, features and a reseller recommendation, with vendor viability never considered
- Device configurations existing only inside the vendor’s cloud portal, with no export held anywhere else
- Firmware always pulled on demand from the vendor, on the assumption the download service will always be there
- No idea whether any given device can be managed locally if the portal becomes unavailable
- Licence terms unread, so what happens to functionality on vendor failure is discovered during the failure
- A single vendor across wireless, switching and security, so one corporate event affects the entire estate at once
- Nobody owns hardware lifecycle, so a going–concern warning in a public filing reaches no one who acts on it
Proactive posture
Where Cloudswitched cloud networking takes you
- Vendor financial viability treated as a selection criterion alongside throughput and price, because infrastructure outlives procurement cycles
- Current configuration exports held independently of the vendor platform, sufficient to rebuild the network elsewhere
- Firmware images retained locally for every model in the estate, so updating never depends on a portal still existing
- A documented local management path for every device, tested rather than assumed
- Licence terms reviewed at purchase for what survives vendor failure — perpetual, subscription, or contingent on a service
- Deliberate decisions about vendor concentration, so the security boundary and the wireless estate do not share a single corporate risk
- A named owner for hardware lifecycle with a scheduled review, so supplier distress is noticed while options remain
It would be easy to read this story as an argument against cloud–managed networking generally, and that would be the wrong conclusion. Cloud management delivers real benefits that on–premise controllers do not — zero–touch provisioning, multi–site visibility from one place, no controller to patch or back up, and support engineers who can see the estate when you call. Most UK SMEs are better served by it. The lesson is narrower and more useful: the management plane is a dependency like any other, and dependencies deserve the questions you would ask of any supplier — is this company sound, what do I keep if it is not, and how would I get out. Cambium’s customers are not in difficulty because they chose cloud management. They are in difficulty because the company behind it was in public financial distress for thirteen months and almost nobody was watching.
Regardless of which management path you choose, the material worth having locally is the same, and it is only obtainable while cnMaestro Cloud is still serving it. Export a full configuration for every device, in whatever format the platform offers, and store it somewhere that is not the vendor’s platform. Download current firmware images for every model you run, including spares sitting in a cupboard. Take the on–premise cnMaestro installer and its documentation now rather than when you are ready to use it. Capture your device inventory — model, serial, MAC, site, location, current firmware version — because that list is tedious to reconstruct from physical inspection and trivial to export today. And note your licence entitlements and any keys. Portals and download servers are operating costs, and operating costs get reviewed in an administration. Nothing on that list requires a decision about your long–term direction, which is exactly why it should happen before the decision is made rather than after.
The security dimension, and why the firewalls come first
If a business running Cambium equipment can only act on one thing in the next nine days, it should be the NSE firewalls. The reasoning is about where consequences compound. An unmanageable access point has a static configuration and a fixed risk; it is a nuisance that stays roughly constant. An unmanageable firewall sits at the network boundary, is directly reachable from the internet by design, and accumulates risk continuously as new vulnerabilities are disclosed against whatever firmware version it is frozen on. The difference is not one of degree.
This has a direct bearing on Cyber Essentials. The scheme requires that software and firmware on in–scope devices is supported and kept up to date, and boundary firewalls are squarely in scope. A firewall that can no longer receive updates is heading towards being unsupported by definition, which becomes a certification problem at the next assessment as well as a security problem immediately. Businesses certified or seeking certification should raise this with their assessor early rather than discovering it during an assessment, and should document what they have done in the interim.
There is a continuity argument too, and it connects to the backup question more closely than it first appears. Most organisations think of backup as protecting data. The equivalent for infrastructure is protecting the ability to rebuild — the configurations, the firmware, the inventory, the documentation of how the network is actually put together. A business with current configuration exports can replace failed Cambium hardware with another vendor’s equipment in days, because it knows precisely what the network is supposed to do. A business without them is reverse–engineering a live system under pressure, which takes far longer and reliably misses something.
Finally, the concentration point deserves stating plainly for anyone specifying a replacement. Cambium’s enterprise customers were affected across wireless, switching and security simultaneously, because a single vendor supplied all three. That is an efficient way to buy and a poor way to distribute risk. It does not follow that every business should split its estate across three vendors — the operational cost of that is real. It does follow that the decision should be made knowingly, with someone having asked what a single corporate failure would take out, rather than arrived at by default because one reseller quoted the whole package.
The story at a glance
| Item | Detail |
|---|---|
| What happened | Cambium Networks has entered administration after months of financial trouble |
| The immediate deadline | 1 October 2026 — nine days from 22 September — after which cnMaestro Cloud “may not support Enterprise devices” |
| Cambium’s advice | Install the on–premise version of cnMaestro as soon as possible |
| The second deadline | On–premise cnMaestro comes with a 90–day trial licence, after which it loses functionality unless a buyer extends or replaces it |
| Affected product lines | Enterprise Wi–Fi access points, cnMatrix switches and NSE firewalls — production ended |
| Not affected in the same way | The fixed wireless broadband business is expected to largely resume after a short pause |
| Redundancies | 260 staff — 53.6% of the workforce — let go in September 2026 without severance payments |
| Accounting problems | In August 2025 the company admitted reports for 2022, 2023 and six subsequent quarters were unreliable due to errors |
| Market consequence | NASDAQ delisted the stock; a later attempt to rejoin the exchange was unsuccessful |
| The formal warning | A May 2026 filing disclosed “substantial doubt about our ability to continue as a going concern” |
| What still works | The hardware itself — devices continue forwarding traffic after 1 October |
| What is at risk | Configuration changes, device onboarding and replacement, firmware updates, and centralised visibility of the estate |
| Highest priority device | The NSE firewalls — a boundary security device that cannot be updated accumulates risk continuously |
| Cyber Essentials impact | In–scope firmware must be supported and up to date; an unpatchable boundary firewall becomes a certification issue as well as a security one |
| The general lesson | When the management plane for hardware you own lives in a vendor’s cloud, your ability to manage your own equipment depends on that vendor continuing to operate |
| Free first step | Export every device configuration, download firmware and the on–premise installer, and capture the inventory — while the portal is still serving them |
This story connects to several we have covered recently, and the common thread is dependency — on a supplier, a platform or a jurisdiction — that was reasonable when it was chosen and was never revisited. The reporting on UK police data held on Microsoft Azure is the same governance failure at a vastly larger scale: a risk documented, accepted, and then left unexamined for nine years while the dependency grew. The PSTN switch–off with months left to run is the physical–infrastructure version, where a deferred decision narrows until only one option remains. The BT email password reset flood shows what an escalation route looks like when you are a small customer of a very large supplier — a question worth asking of a supplier in administration too. LINX’s LON2 fabric passing 1Tbps makes the concentration argument directly: a second path is only worth having if it does not share a failure mode with the first, which applies to vendor risk as squarely as to circuits. And the Gemini autonomous hacking research and the NCSC’s adversary simulation work is a reminder of why an unpatchable boundary firewall is a worse proposition this year than it would have been five years ago.
Running Cambium kit? The next nine days matter more than the next nine months
Cloudswitched designs and manages business networks for UK organisations — and right now that includes getting Cambium estates onto on–premise management before 1 October, with the configurations, firmware and inventory captured while the portal is still serving them. We will also tell you honestly whether your estate needs replacing or can sit on on–premise cnMaestro and wait to see whether a buyer emerges. Those are different answers for different businesses, and the firewalls usually decide it.
Talk to us about Cloud NetworkingFrequently asked questions
The hardware still works. Make sure you can still manage it.
Cloudswitched provides network administration and cloud networking services to UK businesses — migrating Cambium estates onto on–premise management before the 1 October deadline, capturing the configurations and firmware while they remain available, prioritising the boundary security devices, and planning what happens when the 90–day licence runs out. If you are not sure how much Cambium equipment you have or what would still be manageable next month, that inventory is the place to start and it is quick to produce.
Talk to us about Cloud Networking


