I don't think there is real documentation.
I know for IPS if you enable it, run it with trial and let it expire you will get of course warnings.
After the warnings the IPS updates stop and IPS also. Only the 'core' protections will stay active. They come from the box it self (after installation of the software) They do not require license. But this is just a small part of IPS.
For app blade and URL blade I am not 100% sure I think it also depens on the fail-open, fail-closed setting in Smart Console. Also I would expect that the rules that contain application control objects will stop working.
You can buy a new firewall and it will include: 1 Year SNBT Subscription Builtin. Even if you select a 2 year service plan. So after the one year you either have to renew SNBT or go back to NGTP or NGFW.
BUT NGFW contain default IPS and application blade. So the question you ask depends on what type of blades. If it is specific IPS and application control you have to follow Phoneboy. Other blades will not be included. And what will happen depends on the blade that will expire and is enabled.
So it is a valid question and one SK that could explain this would be great. I get this question A LOT from customers and I never can share something official.
-------
If you like this post please give a thumbs up(kudo)! 🙂