Widening the eligible-spend definition in an AWS PPA retires 10 to 25 percent more commit than the discount band itself, which never exceeds 20 percent
AWS caps portfolio discounts at 5 to 20 percent and negotiates them in a narrow lane, so the real money in a three-year private pricing agreement sits in what your committed dollars are allowed to buy. Substitution rights across services, regions, account groups and Marketplace decide whether a re-architecture leaves you paying a shortfall on spend you actually made. Draft them before signature, because AWS will not reopen the eligible-spend definition mid-term.
Prepared by Redress Compliance · August 28, 2026 · AWS private pricing advisory. Benchmarked across 20 to 25 EDP and PPA negotiations, 2024 to 2026.
Executive summary
The discount band is nearly fixed at 5 to 20 percent, so portability of spend is where the remaining value sits.
Across 20 to 25 benchmarked negotiations, a $5M to $10M annual commit lands at 12 to 16 percent regardless of how hard the rate is pushed, while widening the eligible-spend definition has lifted commitment retirement by 10 to 25 percent in the same deals.
AWS's default eligible-spend definition excludes support, professional services, training and premium features, and that exclusion is the single most negotiable clause in the addendum.
Every dollar of Enterprise Support you pay but cannot retire is a dollar you must find again in infrastructure, on top of a commit AWS expects to rise year over year.
The 25 percent Marketplace contribution cap is a separate mechanism from the discount and moves independently, with negotiated outcomes at 30 to 35 percent.
AWS narrowed qualifying products in May 2025 to SaaS fully deployed on AWS, proving that eligibility lists change mid-term unless you lock a no-adverse-change clause at signature.
Service-specific PPAs can carve spend out of the portfolio band, turning a stacked discount into a substitution trap.
A CloudFront or Bedrock lane deal worth 8 to 15 percent extra can remove that same spend from portfolio retirement, so the inclusion language must be drafted before the lane deal is countersigned.
What a substitution right actually does inside the PPA document stack
A substitution right is the clause that decides whether your committed dollars follow your architecture or your architecture is held hostage by a definition written in 2024.
The private pricing addendum is a thin document sitting on top of the AWS Customer Agreement and the AWS Service Terms, and the terms that matter most to you (what counts as eligible spend, which services are excluded, which regions are covered.
How Marketplace retires commit) are defined by reference to documents AWS revises unilaterally.
The May 2025 Marketplace narrowing, which limited retirement to SaaS products fully deployed on AWS, is the live proof: buyers who had modeled a pass-through found the goalposts moved mid-term with no consent required. Two mechanics decide the size of the exposure.
First, measurement is on net spend, so a $2M gross month at a 10 percent discount produces roughly $1.8M of retirement, meaning your discount actively shrinks the pool that satisfies your own commit.
Second, a service-lane PPA (EC2 at 5 to 12 percent, Bedrock at 8 to 15 percent, S3 at 3 to 8 percent) can carve that service out of portfolio retirement entirely, which is how a buyer signs two discounts and ends up short on one commit.
AWS will not reopen the eligible-spend definition mid-term, so this is a pre-signature exercise, covered further in our AWS private pricing agreement clause redlines.
| Lever | AWS default | Negotiated range | What it moves on a $6M commit |
|---|---|---|---|
| Eligible spend definition | Standard service consumption only; support, ProServe, training excluded | All AWS services plus Enterprise Support, ProServe, Training and Certification | $600K to $1.5M of retirement without new infrastructure |
| Marketplace contribution cap | 25 percent of commit, SaaS deployed on AWS only | 25 to 35 percent; broader qualifying categories | Up to $600K of additional retirement at 35 percent |
| Service-lane PPA interaction | Carved out of portfolio retirement | Stacks, retirement preserved at gross or net | Prevents an unplanned 10 to 20 percent retirement gap |
| Region coverage | Silent or enumerated at signature | All current and future commercial regions | Removes shortfall risk on any relocation |
| Account-group portability | Payer account at signature | Acquired and divested entities added on notice | Protects retirement through M&A |
| Measurement basis | Net of discount | Gross where obtainable, else discount-neutral true-up | 5 to 20 percent swing in retirement per dollar spent |
Read the table as one continuous mechanism, not six clauses. AWS negotiates the discount band in a lane it controls (5 to 20 percent, stepped by threshold, never above 20), and every point it concedes there mechanically reduces the net spend retiring your commit.
The retirement scope levers are the opposite: each one expands the pool at zero cost to AWS revenue recognition, which is why account teams have materially more room on them than on the band.
Why the eligible-spend definition beats the discount rate on every deal above $3M
Run the arithmetic before the first call and the priority ordering becomes obvious.
On a $6M annual commit, moving from 12 to 15 percent is worth roughly $180K a year, and it is a fight, because the band steps by threshold and AWS will ask for more commit or a five-year term (typically 4 to 6 additional points) to get you there. Now price the other lever.
Pulling Enterprise Support, Professional Services, Training and Certification into eligible spend, and lifting the Marketplace contribution from 25 to 30 or 35 percent, retires 10 to 25 percent more of the same commit.
On $6M that is $600K to $1.5M of infrastructure you no longer have to buy purely to avoid a shortfall invoice. The retirement lever is worth three to eight times the discount lever, and it does not require you to spend a dollar more.
The negotiating consequence is behavioral. AWS wants the conversation on the discount percentage because that number is governed by internal approval matrices, is benchmarked against every peer deal, and is capped.
Retirement scope is drafted per deal, sits closer to the account team's discretion, and rarely surfaces in the executive summary the CFO reads. So the account team will happily trade you a point or two of band, then push a standard eligible-spend definition through on the addendum.
Expect them to argue Marketplace above 25 percent needs partner-level approval and that support spend is "not consumption." Both are positions, not policies.
A strong outcome on a $6M three-year deal looks like 12 to 16 percent band, support and training in scope, Marketplace at 30 percent minimum, and a clause freezing the eligibility list at signature values.
Our page on AWS EDP flexibility provisions covers the shortfall cure and step-down language that belongs in the same drafting session.
Protect your AWS EDP commit with 6 flexibility clauses
Six flexibility clauses protect an AWS EDP commit: rollover, carryforward, over commit caps, under commit relief, and clean exit ramps.
Get the white paper →The architecture-change problem: why non-decreasing commit makes portability structural
AWS underwrites a private pricing agreement on the assumption that your annual commitment steps up every year and never steps back. That expectation is not a courtesy clause buried in year three, it is the pricing model.
The 5 to 20 percent band exists because AWS is buying a rising floor from you, and the higher tiers in that band are reserved for buyers who commit to roughly 20 percent year over year growth.
The problem is asymmetric: the commit ratchets on a fixed schedule, the estate moves on an engineering schedule, and the two are governed by entirely different decision rights inside your company.
Nobody in the architecture review board asks whether refactoring reduces eligible spend under the payer account.
Run the scenarios that actually happen in a three-year term. A serverless migration replaces provisioned EC2 with Lambda and Fargate, cutting the bill 30 to 40 percent on the migrated workload while the commit floor for that year is already contractually fixed.
A region consolidation collapses six regions into three and strands the data transfer and replication spend that was quietly padding your retirement.
A pivot to Bedrock moves budget toward a service that may sit under a separate service-specific PPA, which, per AWS's own construction, can be excluded from portfolio discount treatment for the duration of that agreement.
A divestiture removes a business unit's accounts from the payer hierarchy, and unless portability is drafted, you keep the commit and lose the consumption.
A tooling strategy that buys observability, security and data platforms through Marketplace runs straight into the 25 percent contribution cap, which is a separate mechanism from the discount and does not expand just because your third-party spend did.
Each of these is a rational business decision that reduces eligible spend without reducing your obligation by a dollar. That is the structural point. You did not overspend, you did not under-consume, you spent the money somewhere the contract does not count it.
The shortfall true-up that follows is not a penalty for failure, it is a penalty for engineering.
The evidence that AWS will move the line under you mid-term is not theoretical.
In May 2025 AWS narrowed Marketplace retirement so that only SaaS products fully deployed on AWS qualify.
And the practical effect for buyers who had built a Marketplace pass-through plan around a wider definition was retroactive: the plan still worked operationally and stopped working contractually.
AWS's own Migrations Included Services List demonstrates the same behavior in public, with a dated changelog, blanket exclusions for data transfer and third-party software licenses, and services becoming eligible only after a stated date.
The eligibility list is a living document maintained by the vendor, and unless your agreement pins it, the vendor edits it.
This is why substitution rights are structural rather than cosmetic. A commit-size negotiation, ramp shape, step-down rights, a shortfall cure period of 30 to 90 days, all of it governs how many dollars you owe.
Only the eligible-spend definition governs whether the dollars you actually spent count against what you owe. Buyers routinely spend six weeks arguing two points of discount on a $30M commit, worth roughly $600K, while leaving the retirement scope on AWS default paper.
Our negotiation experience puts the value of widening retirement scope at 10 to 25 percent more commit retired, which on that same $30M is $3M to $7.5M of consumption that stops being at risk.
The conclusion is uncomfortable and worth saying plainly to your CFO. If you negotiate commit size without negotiating commit spendability, you have bought a floor with no ceiling on your own architecture.
Every future design decision now carries an unpriced contract cost, and the people making those decisions do not know it exists. Fix that in the paper, not in the quarterly forecast, and treat it as part of the same drafting pass as your other AWS private pricing agreement redlines.
Model language: service, region, account-group and new-service inclusion
Drafting positions, not principles. Bring these as redlines to the eligible-spend definition rather than as questions in a QBR, because AWS will not reopen retirement scope mid-term and the account team has no authority to reinterpret it after signature.
Anchor the enumeration approach on AWS's own MAP Included Services List: dated changelog, line-item granularity, blanket exclusions called out explicitly.
If AWS enumerates that precisely for its own programs, it can enumerate for yours, and refusing to do so is a negotiating posture, not a systems limitation.
| Clause | Buyer drafting position | AWS default if you stay silent |
|---|---|---|
| All current and future services | Eligible spend means net charges for all AWS services, current and future, including services introduced after the Effective Date, plus Enterprise Support, Professional Services, and Training and Certification | Standard service consumption only; support, ProServe, training excluded from retirement |
| No adverse mid-term change | The eligible services list as of the Effective Date governs for the full term; AWS may add but not remove categories | Eligibility follows AWS program rules as amended, including narrowings like May 2025 Marketplace |
| Region neutrality | Movement of a workload between AWS regions or Availability Zones does not change eligibility, discount rate, or retirement treatment | Silent; region-specific PPAs and exclusions can be applied by service lane |
| Account-group portability | Any account added to the payer organization by acquisition retires against commit from the date of addition; divested accounts trigger proportional commit reduction | Consolidation permitted case by case as a drawdown favor, not a right |
| Service-lane carve-out ban | Entering a later service-specific PPA does not remove that service's spend from portfolio retirement, only from double discounting | A service-specific PPA excludes that service from EDP discount for its duration |
| Marketplace | Retirement at 30 to 35 percent, categories fixed at Effective Date, deployment-location test disapplied for products already purchased | 25 percent cap, SaaS fully deployed on AWS only |
The row that pays for the whole redline session is no adverse mid-term change. Every other clause protects you against your own architecture decisions, which you control and can at least forecast.
That one protects you against AWS unilaterally editing the eligibility list under a signed three-year agreement, which you do not control and cannot forecast, and which the vendor has already done once inside the current contract generation.
Two mechanics decide whether this language holds. Pin the list as an exhibit with a version date, not by reference to a URL AWS maintains, because a referenced page is an amendment power you handed over for free.
And define eligible spend as net charges before discount, so that improving your own efficiency through Savings Plans or right-sizing does not shrink retirement twice. Both belong in the same pass as the rest of your AWS EDP flexibility provisions.
What AWS will concede, what it will trade, and what it will refuse
Sort the ask list by what the AWS deal desk can approve without escalation, because that ordering decides how many of your redlines survive the last two weeks.
Enterprise Support counting toward retirement and account-group consolidation under the payer are near-automatic concessions on anything above roughly $3M annual commit: neither costs AWS list revenue, and both make the commit easier to hit, which AWS wants.
Service and region portability inside the general eligible-spend definition is usually a drafting fight, not a pricing fight, and you win it by refusing to accept a named-service schedule at all. The trades sit in the middle.
Lifting the Marketplace contribution cap from the standard 25 percent toward 30 or 35 percent is available, but AWS will price it: expect a counter of a fifth year, a 20 percent year-over-year growth commitment, or a steeper back-loaded ramp. The refusals are consistent.
AWS will not write uncapped Marketplace retirement, and it will not sign blanket "all future AWS services" language without a carve-out for anything it later reclassifies, which is exactly the mechanism that narrowed Marketplace SaaS eligibility in May 2025.
Ask instead for a no-adverse-mid-term-change clause: whatever counts on the signature date keeps counting for the full term. That is a materially easier yes than perpetual forward inclusion, and it protects the same dollars.
The counter-asks are not equivalent in cost to you. A five-year term buys roughly 4 to 6 points of discount but locks your architecture for two extra years, which is precisely the risk substitution rights exist to cover, so paying for cap flexibility with term length is often self-defeating.
A 20 percent growth commitment is cheaper if your forecast already supports it. Cheapest of all: give AWS a public reference, an earlier signature date inside its quarter, or a named workload migration commitment.
Those cost you nothing in contractual freedom and AWS values them because the offer composition, credits versus discount, shifts every quarter and the desk is managing a quota, not a margin model. Concede the things that expire; never concede the things that bind for 36 months.
Evidence base and the patterns that repeat
Across 20 to 25 EDP and PPA negotiations from 2024 to 2026, pulling Marketplace into the retirement definition raised commitment drawdown by 10 to 25 percent.
Observed discounts run 8 to 12 percent at $1M to $3M annual commit and 10 to 16 percent at $3M to $10M, and never exceed 20 percent regardless of tier.
Three failure patterns recur often enough to treat as design defects rather than bad luck.
First, Marketplace pass-throughs planned at modeling time and refused at invoice time: the buyer assumed a third-party seller qualified, AWS applied the current program rules, and the spend landed outside retirement.
Confirm eligibility seller by seller before signature and name the sellers in the addendum.
Second, service-lane PPAs signed after the portfolio deal, typically for CloudFront, EC2 or Bedrock, where the carve-out language pulls that service out of the portfolio discount for the life of the lane deal.
The buyer gets a better unit rate on one service and loses retirement volume across the whole commit. Sequence the portfolio agreement first and require that any later service PPA be additive, never exclusionary.
Third, shortfall true-ups triggered by successful cost optimization: the FinOps team hits its savings target, consumption falls below the ramp, and the contract charges the difference.
That is a structural conflict between two internal mandates and it is fixable only in drafting, through breadth of eligible spend plus a 30 to 90 day cure period.
The breakpoint data explains why buyers overpay in the wrong place. Discount steps cluster at $1.5M, $2M and $5M annual spend, so a modest increase in commit can jump a band.
That tempts teams into over-committing for one or two points when the same negotiating capital, spent on the eligible-spend definition, retires more dollars with no additional exposure. Work the flexibility provisions and the clause redlines before you touch the commit number.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
Your first five moves
- Inventory non-eligible spend before you name a commit number. Pull twelve months of invoices and tag every dollar AWS excludes by default (Enterprise Support, Professional Services, Training, non-qualifying Marketplace, third-party licenses, and any service-lane PPA already carved out), then express it as a percentage of total AWS invoice: if it lands above 10 percent, that gap is worth more than the two extra discount points you were going to chase.
- Get gross versus net measurement confirmed in writing in the first week. Ask AWS to state, on paper, whether drawdown is measured on list-price consumption or post-discount net spend, because a 15 percent discount applied against a net-measured commit silently raises the consumption you must generate to retire it, and no verbal answer from a rep survives a mid-term true-up dispute.
- Put the inclusion list and the no-adverse-mid-term-change clause into the first paper exchange, not the third. The May 2025 Marketplace narrowing (only SaaS fully deployed on AWS qualifies) is the proof AWS will re-scope eligibility while you are inside the term. Model your enumerated list on the granularity AWS itself uses in the MAP Included Services List, and pair it with the broader clause redlines that decide your next three years.
- Price the Marketplace cap ask at 30 to 35 percent and trade it against term, not discount. The 25 percent cap is a separate mechanism from the discount band, so AWS can move it without touching the 5 to 20 percent lane. In our experience it concedes 30 percent on a three-year deal well before it concedes a nineteenth discount point.
- Hold signature until account-group portability names the subsidiaries. Generic "affiliates" language fails at the payer-account level. List the specific legal entities and pre-agree an add-on mechanic for acquisitions, using the flexibility provisions written into the contract as your template.
Frequently asked questions
Can I move committed AWS spend between services during a PPA term?
Only if the eligible-spend definition permits it. AWS's default addendum retires standard service consumption and excludes support, professional services, training and certain premium features, so movement is free within the eligible set and impossible outside it.
Negotiate an all-current-and-future-AWS-services formula at signature; AWS will not reopen the definition mid-term.
Does an AWS EDP or PPA discount count toward retiring my commitment?
No. Discounts are applied after the retirement calculation, so $2M of spend with $200K of benefit retires $1.8M against your commit.
Ask in writing whether the commit is measured on gross or net spend before you model the ramp, because the difference on a $10M commit is roughly $1M to $2M of additional buying you did not plan for.
How much of my AWS commitment can Marketplace purchases retire?
The standard cap is 25 percent of commitment, down from an earlier 50 percent, and it is a separate mechanism from the discount band. Negotiated outcomes run 20 to 35 percent depending on commit size and term.
Since May 2025 only SaaS fully deployed on AWS qualifies, so confirm eligibility per seller before signature.
Can a service-specific AWS PPA hurt my portfolio discount?
Yes. If you hold a PPA for a specific service such as CloudFront, that service is typically excluded from the portfolio discount for the life of the lane deal.
Lane discounts are real (5 to 12 percent extra on EC2, 8 to 15 percent on Bedrock), but you must model the carve-out before signing, and add language stating a later lane deal does not remove the spend from portfolio retirement.
What happens to my commit if I optimize costs and spend less than forecast?
You pay the shortfall, because AWS measures the commit, not the value delivered.
Negotiate a 30 to 90 day cure period before true-up, credit carry-forward so shortfall converts to future AWS credits rather than cash clawback, and a step-down right of 25 to 40 percent on M&A, divestiture or regulatory change. None of these can be added after signature.
Can I bring an acquired company's AWS accounts under my existing PPA?
Usually yes, by consolidating those accounts under the payer account covered by the agreement, and this is one of the fastest ways to close a retirement gap. Do not rely on it as a favor.
Name the entity classes in the contract so future subsidiaries qualify automatically rather than requiring an AWS approval each time.
Is EDP or PPA the right name to use in negotiation?
AWS now uses Private Pricing Agreement as the umbrella term for all negotiated enterprise discounts; EDP is legacy paper with the same commercial mechanics.
The distinction matters only for drafting, since PPA historically described service-specific pricing and EDP described organization-wide discounts. Make sure your inclusion language names both scopes explicitly.