HomeBroadcom HubPost Acquisition Audit Risk
Broadcom  |  Audit Exposure Buyer Guide 2026

The metric changed underneath designs that were already built

The exposure in a post acquisition VMware estate is unusual because almost none of it was created by anyone doing anything wrong. Sizing decisions made correctly under a per socket model became expensive under a per core one, non production estates that were effectively free became licensable, and a bundle that raised the contracted floor did so without changing what anybody deployed.

Prepared by Redress Compliance · August 11, 2026 · Broadcom advisory. Based on 30 to 40 Broadcom VMware engagements, 2024 and 2025.

Executive summary

Core counts on high density hosts ran 20 to 40 percent above the licensed position because sizing was inherited from the per socket era. Under a per socket model, packing more cores into fewer sockets was free and therefore correct, so estates were deliberately built that way.

The move to a per core metric turned that engineering decision into a licensing gap without anybody touching the estate, which is why the gap is largest precisely where the previous optimisation was pursued hardest.

Disaster recovery and test estates were unlicensed or under licensed in roughly 6 of 10 reviews. These are the environments that carried favourable treatment or informal tolerance under the old arrangements, so nobody budgeted them and nobody tracked them.

They are also the easiest gap to close cheaply before an audit and the most expensive to argue about afterwards, because their existence is not in dispute, only their entitlement.

The bundle lifted the contracted floor by 25 to 50 percent against what the customer actually consumed.

That is a commercial exposure rather than a compliance one, and it compounds the other two: an estate arguing about core counts is arguing about the quantity, while the floor sets a minimum below which the quantity does not matter.

Both need addressing, and only one of them is negotiable at the audit table.

A buyer side review before the publisher arrives cut exposure by 30 to 50 percent. The reason is straightforward: dated core inventories settle most disputes in the buyer's favour, and they can be produced calmly in advance or hurriedly under a notice period.

Since the notice periods have tightened, the difference between those two conditions is now larger than it used to be.

20 to 40%
How far core counts on high density hosts ran above the licensed position, from per socket era sizing.
6 in 10
Reviews where disaster recovery and test estates were unlicensed or under licensed.
25 to 50%
How far the bundle lifted the contracted floor above what the customer actually consumed.
30 to 50%
Exposure removed by running a buyer side review before the publisher arrives.
1.

What changed, and what it did to existing estates

ChangeEffect on an existing estateNature of the exposure
Perpetual retiredEvery renewal becomes a re licensing eventCommercial, recurring
Cores replace socketsHigh density hosts sized under the old model are now shortCompliance, retroactive
Bundle packagingThe contracted floor rises above actual consumptionCommercial, structural
Channel restructuringPrior partner arrangements re examined under new rulesContractual, inherited

The distinction between the retroactive and the commercial exposures matters because they are answered with different evidence. A core count gap is a factual question settled by a dated inventory: how many cores were running, on which hosts, at which point in the licence period.

A raised contracted floor is not a factual dispute at all, it is a term, and no amount of inventory evidence changes it.

Estates that conflate the two arrive at the audit arguing entitlement when half their problem is commercial, or accepting a floor when half their problem was a countable gap they could have closed beforehand.

Separate them at the start: fix what evidence can fix, and negotiate what only a renewal can change. The metric mechanics sit in the VMware licensing comparison.

2.

The self audit that removes a third to a half

Free download

The audit defence kit library

Scope language, disclosure discipline, response templates, and the counter positions that hold at settlement.

Get the kits →
3.

Non compliance that nobody created

It is worth being precise about the moral shape of this exposure, because it changes how the conversation should be run. In most audit situations there is at least an implicit suggestion that something was managed badly: a count drifted, a control lapsed, a deployment outran its entitlement.

Here the dominant gap was produced by the metric changing underneath designs that were correct when they were made.

Consolidating workloads onto fewer, denser hosts was the right answer under a per socket model, where additional cores cost nothing in licensing terms, and every serious infrastructure team pursued it.

The move to per core pricing converted that discipline into a shortfall of 20 to 40 percent on exactly the hosts where the discipline was strongest.

The same logic covers the non production estates: disaster recovery and test environments were treated favourably or tolerated informally under the previous arrangements, so nobody built a tracking habit for them, and in 6 of 10 reviews they turned up unlicensed or under licensed.

None of that is a management failure and framing it as one leads buyers to concede more than the facts require.

The practical consequence is that the self audit is not a confession, it is a measurement, and it removed 30 to 50 percent of exposure in our engagements precisely because most of what it finds is correctable rather than culpable.

Run it before the notice arrives, close what can be closed, document the rest with dates, and separate the countable gaps from the commercial floor so that each is answered with the right instrument.

The tightened notice periods make the timing question sharper than it was: the same work produces a materially better outcome when it is done calmly in advance than when it is compressed into a response window. The wider exposure discipline sits in the multi vendor audit response playbook.

Try Vera AI · free 30 day trial
Vera verifies core counts before the publisher rounds them up, models the renewal exposure over the term, and flags every clause in the new paper with replacement language.
  • Percentile standing for your exact deal size and industry, from real closed transactions
  • Scenario simulation before the call: test alternative terms and see the financial impact of each
  • A negotiation playbook, talking points, and a two page executive brief on day one
Start the free Vera AI trial →30 days free · no credit card · cancel anytime
4.

What we saw across Broadcom VMware engagements, 2024 and 2025

Across roughly 30 to 40 Broadcom VMware engagements run between 2024 and 2025, audit exposure clustered in a few predictable places after the move to subscription, and the pattern is consistent enough to be worth planning against:

20 to 40%
Inherited sizing gap

How far core counts on high density hosts exceeded the licensed position, because the sizing logic was correct under the previous metric.

30 to 50%
Removed by self audit

Exposure closed by running a buyer side review before the publisher arrived, largely by producing dated core inventories in advance.

Three patterns recurred: core counts on high density hosts running 20 to 40 percent above the licensed position because sizing was inherited from the per socket era, disaster recovery and test estates unlicensed or under licensed in roughly 6 of 10 reviews.

And bundle packaging lifting the contracted floor 25 to 50 percent above actual consumption.

The buyer side move is to self audit first, separate the countable compliance gaps from the commercial floor, and produce dated core inventories before a notice period compresses the work. The wider library sits in the Broadcom practice.

5.

Your first five moves

  1. Produce a dated core inventory per host now, because it settles most disputes in your favour and it cannot be reconstructed once a notice period has started.
  2. Check the high density hosts first, since the shortfall concentrates where per socket era consolidation was pursued hardest and runs 20 to 40 percent above the licensed position.
  3. Inventory and license the disaster recovery and test estates, which were short in 6 of 10 reviews and are cheap to close beforehand and expensive to argue about afterwards.
  4. Separate the countable gaps from the contracted floor, because evidence fixes the first and only a renewal negotiation changes the second.
  5. Run the self audit before the publisher arrives, which removed 30 to 50 percent of exposure, and treat it as a measurement rather than a confession. The Broadcom practice runs it with you.
6.

Frequently asked questions

Why did the audit exposure rise after the acquisition?

Because the metric changed underneath estates that were already built. Perpetual licensing was retired so every renewal became a re licensing event, and cores replaced sockets as the unit, which turned correct per socket era sizing decisions into shortfalls without anybody touching the estate.

Where does the core count gap concentrate?

On high density hosts, at 20 to 40 percent above the licensed position. Under a per socket model, packing more cores into fewer sockets cost nothing in licensing, so it was the right engineering answer and it was pursued hardest by the best run estates. The per core metric inverted that.

What about disaster recovery and test environments?

They were unlicensed or under licensed in roughly 6 of 10 reviews. Those environments carried favourable treatment or informal tolerance under the previous arrangements, so no tracking habit was ever built.

Their existence is never disputed in an audit, only their entitlement, which makes them cheap to close in advance.

Is the raised contracted floor a compliance problem?

No, and treating it as one wastes effort. A floor 25 to 50 percent above actual consumption is a commercial term rather than a factual dispute, so no amount of inventory evidence changes it. It needs a renewal negotiation, while the core count gaps need evidence. Separate the two at the start.

How much does a self audit actually save?

Between 30 and 50 percent of exposure in our engagements. Most of what it finds is correctable rather than culpable, and dated core inventories settle the majority of disputes in the buyer's favour.

The saving comes from producing that evidence calmly in advance rather than under a compressed notice period.

Have the notice periods changed?

They have tightened, which raises the value of preparation.

The same self audit work produces a materially better outcome done in advance than compressed into a response window, because inventories have to be dated and historical, and a short notice period does not leave time to reconstruct records that were never kept.

Is this a failure of licence management?

Mostly not, and framing it that way leads buyers to concede more than the facts require. The dominant gaps were created by a metric change applied to designs that were correct when they were made and by environments that were previously treated favourably.

That is a measurement problem to fix, not a governance failure to apologise for.

Watch the briefingResearch briefing · 4:44

The VMware VCF Renewal: How to Prepare Before Broadcom Names the Price

Renewal quotes land at 2 to 3x the old support cost, sometimes 5 to 10x. The core inventory and the 16-core minimum, right-sizing the forced bundle, costing an exit for the portable slice, the paper that outlives the discount, and running the clock toward late October.

© 2026 Redress Compliance · Independent, buyer sideredresscompliance.com
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent
Audit Defence Kits

The full audit defence kit library from the advisory practice.

Scope language, disclosure discipline, response templates, and the counter positions that hold at settlement.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
Independent, buyer side. We never share your details with vendors.
Model the repriced renewal with the Broadcom per core subscription calculator.
Open the Calculator → Broadcom Practice →
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Stay ahead of VMware pricing and contract moves.

One buyer side briefing a week. Renewal signals, discount bands, and the levers that work. No vendor spin.