Cisco's no-charge AnyConnect to Secure Client 5.1.x upgrade is guaranteed only while your term license or perpetual support contract is active, and lapses of 90 days or more trigger reinstatement fees before the free upgrade unlocks
Cisco's 30 May 2023 end-of-life bulletin states there is no additive charge to move to Secure Client for any customer entitled to AnyConnect directly or indirectly, including through most Umbrella packages. The entitlement is conditioned on an active term license or an active service contract behind a perpetual license, and 4.x maintenance already stopped on 31 March 2024. Verify the support status of every line item now, because a lapsed contract converts a free upgrade into a purchase conversation with a reinstatement fee attached.
Prepared by Redress Compliance · September 4, 2026 · Cisco advisory. Secure Client migration and Smart Account entitlement reviews, 2024 to 2026.
Executive summary
The no-charge upgrade is documented Cisco policy, not a sales concession, and it covers direct and indirect entitlement including most Cisco Umbrella packages.
The 30 May 2023 end-of-sale bulletin and the AnyConnect 4.10 release notes both state that eligible customers may move to the current Secure Client 5.1.x release at no additive charge, so any quote that prices the upgrade itself should be rejected on the spot.
Eligibility turns on one binary test: an active term license, or a perpetual license with an active service contract, per the Secure Client Data Sheet.
Perpetual customers who let SWSS lapse still own the right to run 4.x forever, but they lose the right to the 5.1.x code, and Cisco treats reinstatement of contracts lapsed 90 days or more as a fee event.
The clock has two dates and only one of them is 2027: maintenance for 4.x ended 31 March 2024 and the last build shipped was 4.10.08029, with full obsolescence on 31 March 2027.
That means you have already run more than two years without security patches on 4.x, and TAC will answer configuration questions for contract holders but cannot patch code.
Most entitlement disputes we see are counting errors, not policy disputes, and the recurring cause is mixing unique-user tiers with concurrent-connection tiers.
Advantage and Premier are licensed by unique users while VPN Only is by concurrent connections, and PAK-based verification only applies to physical ASAs, not ASAv, FTD, ISE, routers, or Meraki MX.
The entitlement rule, line by line: what Cisco actually promises
Cisco's 30 May 2023 end-of-sale and end-of-life bulletin for AnyConnect Secure Mobility Client 4.x contains the only sentence that matters commercially: there is no additive charge to adopt the current version of Cisco Secure Client for any customer entitled to use AnyConnect either directly.
Or indirectly through another purchased Cisco service that includes use of the client for that use case.
The AnyConnect 4.10 release notes repeat that promise in all caps and name the destination explicitly, Secure Client 5.1.x. But the entitlement is not unconditional.
The Secure Client data sheet states the precondition in licensing language rather than courtesy language: software maintenance and application software support requires an active term license, or an active service contract behind a perpetual license.
That single dependency is where every customer we have defended has lost the argument. The bulletin gives you the free upgrade; the data sheet takes it back the moment the contract line goes dark.
Read those two documents together, not separately, because your reseller will only quote you the second one. There are exactly three doors into no-charge eligibility, and each one is proved by a different artifact.
| Entitlement path | License family | Verification artifact | Target train | What breaks if the condition fails |
|---|---|---|---|---|
| Active term license | Advantage or Premier subscription (formerly Plus / Apex subscription) | Smart Account > Inventory > Virtual Account, license name row, Balance not negative | Secure Client 5.1.x | Term lapse ends maintenance and support entitlement immediately; upgrade becomes a new purchase |
| Perpetual plus active service contract | Advantage perpetual, Premier perpetual, VPN Only perpetual (concurrent connections) | Contract number with active coverage dates, plus PAK fulfilment record at the License Registration Portal for L-AC-PLS-LIC= / L-AC-APX-LIC= | Secure Client 5.1.x | Perpetual right to run 4.x survives, but the free 5.1.x upgrade and TAC access do not; reinstatement is quoted first |
| Indirect entitlement via another Cisco service | Most Cisco Umbrella packages, and other services that include client use for that use case | Active Umbrella support contract, plus Umbrella module entitlement confirmed in the Umbrella dashboard | Secure Client 5.1.x with Umbrella module | Umbrella support lapse removes the indirect path; the VPN module still installs but the entitlement argument is gone |
The operative phrase is "no additive charge," not "free." Cisco is not gifting you software. It is confirming that the upgrade carries no separate SKU, no uplift line, and no per-seat conversion fee for anyone already inside an entitlement.
That wording is your defense against a reseller quoting a migration or upgrade part number, because no such part number legitimately exists for an entitled customer. Send the bulletin paragraph back with the quote attached and ask which SKU the additive charge is being applied under.
What the wording does not do is protect you from the support dependency underneath it. Non-additive applies to the upgrade, not to the contract that makes you eligible for it.
A customer with 4,000 lapsed perpetual Plus seats is quoted reinstatement, not an upgrade fee, and the reinstatement is entirely legitimate under Cisco's own terms. Fix the contract, and the upgrade genuinely costs nothing. Argue about the upgrade, and you lose twice.
Run the verification: Smart Account, PAK portal, and the paper-license blind spot
Do not accept a reseller entitlement summary as evidence. Build the position yourself in three passes. Start in Cisco Software Central: Smart Account > Inventory > [Virtual Account Name], then filter by license name across every virtual account, not just the one your network team uses.
The column that decides the argument is Balance, which Cisco defines as the offset between purchased and in-use.
A negative balance drives an Out-of-Compliance state, and per Cisco's Secure Client documentation the RA VPN configuration cannot be deployed at all if a device lacks entitlement for at least one Secure Client license type. Export every row with purchase date, term end date, and quantity.
Second pass: legacy PAK-based licenses (typically L-AC-PLS-LIC= and L-AC-APX-LIC=) do not appear as consumed entitlements until fulfilled. Go to the License Registration Portal under Traditional Licenses, enter each PAK, and click Fulfill.
Remember Cisco's own constraint here: Advantage and Premier PAKs apply only to physical ASAs, not to ASAv, Firepower NGFW appliances running ASA software, routers, ISE, or Meraki MX. Counting PAKs against a virtual headend produces a number your reseller will happily use against you.
Third pass covers the two blind spots that produce most of the false shortfalls we see in Secure Client migration and licensing reviews. If your headends run FTD 6.2.1 or later, entitlement is not automatic and does not self-populate.
You must open a case with Cisco Global Licensing Operations through Support Case Manager, selecting Software Licensing > Security Related Licensing > Cisco Secure Client; once GLO validates the entitlement it is pushed into your Smart Account.
Until that case closes, your inventory understates what you own. The harder blind spot is paper.
Right-to-use licenses issued as PDF or printed certificates never appear in Smart Account inventory at all, and in our audit-defense experience these are disproportionately the oldest and largest Plus and Apex blocks, sitting in a procurement folder rather than a licensing tool.
Reconcile purchase orders back to 2016 before you conclude you are short, then confirm which tier those entitlements actually map to using our Advantage versus Premier tier comparison, because Advantage and Premier count unique users while VPN Only counts concurrent connections.
Cut your Cisco Secure licensing cost in 2026
How to cut Cisco Secure licensing cost in 2026 across Umbrella, Secure Endpoint, Duo, and XDR, with the bundle and contract levers that hold at renewal.
Get the white paper →Map old SKUs to new tiers before you count anything
Before you count a single entitlement, resolve the naming layer, because Cisco renamed the tiers without renaming the underlying rights, and every quote you receive will mix the old and new vocabulary in the same document.
Per the Cisco Secure Client Ordering Guide, Advantage subscription is the former AnyConnect Plus subscription, Advantage perpetual is the former Plus perpetual, Premier subscription is the former Apex subscription.
And VPN Only perpetual (licensed by concurrent connections) is the former AnyConnect VPN Only perpetual.
If your asset register still says "Plus 3YR" and the renewal quote says "Advantage 3YR," those are the same right, not an upgrade, and you should reject any line item that prices the rename as a change of tier.
| Legacy name on your contract | Current Cisco name | Metric | Counting trap to check |
|---|---|---|---|
| AnyConnect Plus subscription | Secure Client Advantage subscription | Unique users | Users, not devices; one user with laptop plus phone is one license |
| AnyConnect Plus perpetual | Secure Client Advantage perpetual | Unique users | Needs an active service contract for the free 5.1.x move |
| AnyConnect Apex subscription | Secure Client Premier subscription | Unique users | Only tier that carries ISE posture rights |
| AnyConnect VPN Only perpetual | Secure Client VPN Only perpetual | Concurrent connections | Cannot be combined with Plus or Apex |
The metric split is where counts break. Advantage and Premier are licensed by unique users; VPN Only is licensed by concurrent connections.
Teams that historically sized VPN Only against a peak concurrency figure and then convert that same number into an Advantage user count either over-buy by a wide margin or, more often in our casework, under-declare and land out of compliance in the Smart Account balance view.
Count each metric separately, from separate sources: identity directory for users, headend concurrency reports for connections.
Two structural rules protect you during consolidation. Legacy and current licenses stack: valid Plus and Apex terms coexist with Advantage and Premier terms and generate multiple PAKs to register against physical ASAs, so you do not need to retire legacy quantity to add new.
But VPN Only cannot be combined with Plus or Apex on the same footprint, so a "simplification" that folds VPN Only volume into Advantage is a purchase, not a merge.
And if posture is the actual requirement, ISE-based posture assessment needs Secure Client Premier plus an ISE Premier license, a two-license dependency covered in our Advantage versus Premier tier analysis.
Establish the mapped, metric-correct baseline first; every later negotiation is arithmetic on top of it.
Why the free upgrade is Cisco's most effective upsell instrument
The no-charge guarantee is real.
At the code level, Cisco has not built a paywall between AnyConnect 4.x and Secure Client 5.1.x, and the 30 May 2023 bulletin language about no additive charge for anyone entitled directly or indirectly, including through most Umbrella packages, is about as unambiguous as vendor bulletins get.
Twenty-five years of reading Cisco EoL notices tells me that when the wording is this clean, the commercial mechanism sits elsewhere. It does. The upgrade is free; what the upgrade reveals is not.
Secure Client 5.1.x is a modular client. Migration forces every organization to enumerate which modules it actually deploys and which tier authorizes them.
Posture is the classic one: teams running HostScan under 4.x rebuild it as Secure Firewall Posture or move to ISE-based posture, and ISE posture requires Premier plus ISE Premier. Umbrella entitlement arrives free but only for the Umbrella module.
Network Visibility, Network Access Manager, export-controlled encryption behavior, and the ISE integration path each map to tier boundaries that most customers never audited under 4.x because the old client tolerated loose deployment while the license stayed nominally intact.
That is the engineered part. Cisco did not have to gate the binary, because the migration itself performs the entitlement audit that Cisco could never justify running as an audit.
Your engineers do the work, at their own cost, on Cisco's timetable, and the output is a list of functional gaps expressed in Cisco's tier vocabulary. Free migration, paid discovery.
The timing is the sharper edge. Gaps surface mid-project, when the pilot is running, the change window is booked, and the security team has already told the board that posture assessment will be live in the quarter. At that moment the buyer has no walk-away.
A Premier uplift quoted against an in-flight rollout prices very differently from the same uplift quoted eleven months before a renewal, when the alternative of descoping posture, deferring ISE, or reducing the covered population is still on the table.
Cisco's account teams know exactly which of those two conversations they are in, and they price accordingly.
In our negotiation work, mid-migration tier uplifts consistently land at weaker discount levels than the same uplift raised as a planned renewal line item; the delta is a function of timing, not of volume.
The second-order effect is worse. Once a gap is discovered under project pressure, it usually gets closed with the fastest instrument available, which is an add-on co-termed to the existing agreement.
Co-termed add-ons carry short remaining terms, they anniversary at full list-adjacent rates, and they quietly convert a clean two-tier estate into a mixed one that is harder to benchmark at the next renewal. You have then paid twice: once in uplift, once in lost comparability.
The counter is sequencing, and it is entirely within your control. Complete SKU mapping, metric reconciliation, and module-to-tier verification before you open any renewal or migration conversation, and before any pilot creates delivery commitments.
Produce your own written entitlement position, including the modules you intend to run and the tiers they require, and put it in front of Cisco as a finding rather than a question.
That single reordering moves the discovery to your side of the table and turns a mid-project uplift into a scheduled negotiation line, which is where the leverage described in our Secure Client migration licensing guide actually lives.
If a gap exists, you want to know about it in a spreadsheet, not in a change window.
When support has lapsed: reinstatement math and the alternatives
Cisco's language is deceptively clean: the no-additive-charge move to Secure Client 5.1.x is available to customers holding a valid term license or a perpetual license with an active service contract.
The word doing the work is "active." Once a contract lapses, you are not a customer with an upgrade right; you are a prospect with an expired one, and Cisco's standard reinstatement practice applies.
In my 25 years dealing with Cisco service contract restorations, the pattern is consistent: short gaps of roughly 30 days are commonly bridged as a straight backdated renewal, while gaps at or beyond 90 days trigger a reinstatement charge on top of the back-support owed for the uncovered months.
Treat those two thresholds as the operative deadlines on your calendar, not the license expiry date itself, because the expiry date only starts the clock that the reinstatement fee is measured against.
You have three realistic paths and they should be priced side by side, not chosen by default. First, pay back-support plus reinstatement to restore the perpetual entitlement, which preserves the asset you already own and reopens the free 5.1.x upgrade.
Second, abandon the perpetual line and convert to a Secure Client Advantage or Premier term subscription, which Cisco's sales team will push hard because it converts a one-time restoration into recurring revenue.
Check the tier boundaries in our Advantage versus Premier tier analysis before you accept the mapping they propose.
Third, ride 4.x unpatched to the 31 March 2027 last day of support.
Path three is the one buyers underestimate. AnyConnect 4.x software maintenance ended 31 March 2024. The last build is 4.10.08029, so you are running code that has received no security fixes and no bug fixes for two years and will receive none for another year.
You also get no operating system compatibility updates, meaning the next macOS or Windows feature release can break your remote access estate with no remedy, and no HostScan or Secure Firewall Posture module updates, which quietly degrades your posture policy accuracy.
TAC will take configuration questions from contract holders until 31 March 2027 but cannot ship you code. That is not a support path, it is a managed decay.
The reinstatement conversation is almost always cheaper than the conversion conversation, and Cisco knows it. Restoring a lapsed perpetual contract is a one-time, bounded number: uncovered months of support plus a reinstatement uplift.
Converting the same estate to Advantage or Premier subscription is unbounded, because you have surrendered the perpetual right and will pay again at every renewal for the rest of the estate's life.
Ask for the restoration quote in writing before you disclose that you are also evaluating subscription, and price both against a three-year total, not a first-year figure.
Do this now: pull every lapsed line item, calculate uncovered months per SKU, and demand a written restoration quote with the reinstatement component itemized separately from back-support. If the gap is under 30 days, escalate for a straight backdated renewal with no uplift, and expect to get it.
Sequence the work using our Secure Client migration and licensing guide.
Evidence base and the failure patterns we see repeatedly
This analysis rests on Cisco's own published record: the end-of-sale and end-of-life bulletin for AnyConnect 4.x dated 30 May 2023, the AnyConnect 4.10 release notes carrying the no-charge 5.1.x language, the Secure Client Ordering Guide for SKU mapping and licensing metrics.
The Secure Client Data Sheet for the active-contract precondition, the Secure Client Licensing FAQ (Doc ID 200191) for GLO and PAK registration mechanics, the cdFMC Secure Client licensing pages for tier incompatibilities, the FMC administration guidance on deployment blocking.
And the Umbrella migration document last updated 29 August 2025.
Every date and rule cited in this article traces to that set.
No security patch has shipped for AnyConnect 4.x since build 4.10.08029, so every day on 4.x is unremediated exposure.
Third-party EOL trackers show the same 2027-03-31 date across all 15 tracked 4.x part numbers, leaving no quiet extension to hope for.
Five failure patterns recur in the entitlement checks we run. Metric mismatch is the most expensive: Advantage and Premier count unique users while VPN Only counts concurrent connections.
And teams routinely compare a concurrent number against a per-user entitlement and conclude they are short by thousands. PAK applied to unsupported headends comes second: Advantage and Premier PAKs register only to physical ASAs, not ASAv, not Firepower NGFW running ASA software, not routers.
Not ISE, not Meraki MX, so a failed fulfilment is read as a lapsed entitlement when it is a platform mismatch. Export control not enabled blocks RA VPN deployment entirely.
And the resulting error looks identical to an entitlement failure. Evaluation-mode blockers generate the same licensing alerts and health events, which teams then escalate to procurement as a compliance gap.
Finally, paper right-to-use grants from pre-Smart-Account purchases never appear in Smart Account inventory at all, so entitlement you already own is invisible and gets bought twice. Reconcile against the purchase record, not the console.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
Your first five moves
- Export the full Smart Account inventory this week, pulling Smart Account > Inventory > [Virtual Account] filtered by license name, and record purchased quantity, in-use, Balance, and support contract end date for every AnyConnect and Secure Client line item, because a negative Balance is already an out-of-compliance flag and Cisco will read it before you do.
- Classify each entitlement into one of four buckets, active term license, perpetual with active service contract, perpetual lapsed, or indirect entitlement through Umbrella or another purchased Cisco service, since only the first two carry the 30 May 2023 no-additive-charge guarantee unconditionally and the third is where the reinstatement fee lands.
- Open the Global Licensing Operations case for every FTD headend before deployment work starts, using Support Case Manager under Software Licensing > Security Related Licensing > Cisco Secure Client, because entitlement on FTD 6.2.1 and later is not automatic, RA VPN configuration will not deploy without at least one validated Secure Client license type, and GLO turnaround is not something you want sitting on the critical path.
- Price reinstatement against term conversion for every lapsed line before a renewal quote arrives, not after, and check the tier boundary while you are there, since ISE-based posture needs Premier plus ISE Premier and our Advantage versus Premier tier analysis shows most estates over-buy that step.
- Put a written no-additive-charge statement into the renewal thread, quoting the 30 May 2023 end-of-life bulletin language on direct and indirect entitlement, and require the account team to confirm in writing which of your line items they consider ineligible and why, before you discuss quantity, tier, or discount on the Secure Client migration.
Frequently asked questions
Is the AnyConnect to Cisco Secure Client upgrade really free?
Yes, at the software level. Cisco's 30 May 2023 end-of-sale bulletin states there is no additive charge to adopt the current Secure Client release for any customer entitled to use AnyConnect, directly or indirectly.
The condition is an active term license, or a perpetual license backed by an active service contract. If a reseller quotes an upgrade SKU, ask them to reconcile it with that bulletin in writing.
What happens if my perpetual AnyConnect support contract has lapsed?
You keep the right to run the version you already own, but you lose the right to download and run Secure Client 5.1.x and you lose TAC and maintenance. Cisco may impose reinstatement fees where support was purchased more than 90 days after the product, or renewed more than 30 days late.
Price reinstatement against a term subscription conversion before you accept either, because the two often land within 15 percent of each other over three years.
Do Umbrella-only customers qualify for Secure Client at no charge?
Yes for the Umbrella module. Cisco's Umbrella migration documentation, updated 29 August 2025, states that customers with valid licenses and active Umbrella support contracts may migrate to Secure Client for the Umbrella module at no charge.
The VPN module installs as a core component regardless but can be hidden in the UI, and using it for remote access still requires a separate Secure Client entitlement.
Where do I check my Secure Client entitlement in the Smart Account?
Go to Smart Account, then Inventory, then the relevant Virtual Account, and filter by license name. The Balance column is purchased quantity minus in-use quantity, and a negative balance is what drives an Out-of-Compliance state.
Note that legacy paper licenses or RTUs never appear in this view, so a clean inventory does not prove you hold no additional entitlement.
Why does my FTD firewall show no Secure Client entitlement even though I bought licenses?
For FTD 6.2.1 and later, entitlement is not populated automatically. You must open a case with Cisco Global Licensing Operations through Support Case Manager, selecting Software Licensing, then Security Related Licensing, then Cisco Secure Client.
Once GLO validates your entitlement it is pushed into your Smart Account. Separately, confirm export-controlled strong encryption is enabled, because RA VPN will not deploy without it or while Smart Licensing is in evaluation mode.
When exactly does AnyConnect 4.x stop being supported?
Software maintenance ended 31 March 2024, and the last maintenance build was 4.10.08029. Application software support ends 31 March 2027, after which the product is obsolete and all services are unavailable.
Between those two dates TAC will answer configuration questions for contract holders but cannot ship code fixes, so you are already running unpatched if you remain on 4.x.
Does the free upgrade also give me posture assessment and ISE integration?
No. The no-charge rule covers the client software, not tier uplift. ISE-based posture assessment requires a Secure Client Premier license plus an ISE Premier or Apex license.
If you are on Advantage today, moving to Secure Client is free but enabling posture is a purchase, and that is where most migration budget surprises originate.