The AnyConnect to Secure Client upgrade costs nothing if you are already entitled, yet most buyers pay because eight entitlement traps convert a free version change into a new purchase before March 31, 2027
Cisco set two dates: software maintenance for AnyConnect 4.x ended March 31, 2024, and all support ends March 31, 2027. The version move itself carries no additive charge for any customer holding an active term license, an active support contract on perpetual, or indirect rights through Umbrella or Secure Access. The money leaks somewhere else, in tier reclassification from Plus to Premier, in unique-user counting, in VPN Only licenses that cannot be stacked, and in ordering mechanics that silently fail to generate PAKs. Fix the entitlement record before you accept a quote.
Prepared by Redress Compliance · September 4, 2026 · Cisco advisory practice. Secure Client and AnyConnect renewal engagements, 2024 to 2026.
Executive summary
The upgrade price is zero, and Cisco says so in writing in the May 30, 2023 end-of-life bulletin.
Every customer with a valid AnyConnect or Secure Client term license, or a perpetual license under an active support contract, is eligible to move to the current 5.x release at no charge, and any quote that prices the version change itself is a quote to reject on the vendor's own published terms.
Your patch window closed on March 31, 2024, which means every AnyConnect 4.x endpoint has been carrying unremediated code for over two years.
TAC will still take configuration calls from contract holders until March 31, 2027, but Cisco cannot ship a fix for any new CVE in the 4.x train, so the last maintenance build, 4.10.08029, is the permanent state of that software on your estate.
The real cost is tier drift, and it happens when Posture moves you from Advantage to Premier.
Advantage maps to the old Plus and Essentials entitlements, while Premier maps to Apex and is the only tier carrying endpoint Posture, ISE Posture, Network Visibility, Management VPN Tunnel, and Suite B encryption.
So a security team decision to enforce posture becomes a licensing event across the full user population, not a subset.
Eight documented entitlement traps sit between a free version change and a clean migration, and at least three of them are ordering mechanics rather than policy.
Counting unique users instead of concurrent sessions, the non-portable and non-stackable nature of VPN Only, PAK generation failing when you order Qty 2 on one line instead of two lines at Qty 1.
And the requirement to share the license into a Smart Account for FTD 6.2.1 and later each produce a real-world shortfall that a reseller will resolve by selling you more licenses.
How Secure Client licensing actually works: tiers, terms, and what maps to what
Cisco collapsed four legacy AnyConnect entitlements into two named tiers plus a survivor. Secure Client Advantage is the direct successor to AnyConnect Plus and Essentials: device and per-application VPN with third-party IKEv2 headend support, trusted network detection.
Basic device context collection, FIPS compliance, the Network Access Manager 802.1X supplicant, and the Umbrella Roaming module. Secure Client Premier is the old Apex, and it is the only tier that carries endpoint Posture (for Secure Firewall) or ISE Posture through Identity Services Engine.
Network Visibility, next-generation VPN encryption including Suite B, and the Management VPN Tunnel, on top of everything in Advantage. VPN Only is the third tier buyers forget until a quote arrives: it is concurrent endpoint-based, applied per individual physical ASA, non-portable.
And per Cisco's own FMC and cdFMC documentation it cannot be combined with Plus or Apex (and therefore not with Advantage or Premier).
If your estate mixes VPN Only on branch ASAs with Advantage everywhere else, you are running two counting models at once, and no reseller worksheet we have reviewed in the last three years has modeled that correctly on the first pass.
Terms are 1, 3, or 5 years, ordered through Cisco Commerce Workspace by selecting service tier and duration. Two mechanics matter more than the tier names.
First, support and software updates are baked into the license price: Cisco's Secure Client Features, Licenses, and OSs guide states plainly that these user-based licenses include access to support and software updates.
Any separate SASU or service line quoted against the client itself is a line you strike, not a line you negotiate. Second, licensing is headend-agnostic.
Cisco confirms the same license model applies across ASA, ISR, CSR, ASR, and non-VPN headends such as ISE, with no impact when headend migrations occur.
That single sentence is real leverage during a firewall refresh: an ASA to Firepower or ASA to Meraki MX move does not create a client relicensing event, whatever the account team's migration deck implies.
Use it, and pair it with the Cisco Secure licensing negotiation playbook for 2026 when the refresh and the client renewal land in the same quarter.
| Legacy license | New tier | Modules included | Counting basis | PAK applies to |
|---|---|---|---|---|
| AnyConnect Essentials | Secure Client Advantage | VPN (device and per-app), IKEv2 third-party headend, trusted network detection, basic device context, FIPS, NAM 802.1X, Umbrella Roaming | Unique users | Physical ASA only |
| AnyConnect Plus | Secure Client Advantage | Same as above | Unique users | Physical ASA only |
| AnyConnect Apex | Secure Client Premier | All Advantage, plus Posture (Secure Firewall), ISE Posture, Network Visibility, Suite B / next-gen VPN encryption, Management VPN Tunnel | Unique users | Physical ASA only |
| AnyConnect VPN Only | Secure Client VPN Only | VPN only, no posture, no NVM | Concurrent endpoints, per individual ASA | Physical ASA only, not portable |
| Umbrella / Secure Access bundled rights | Client rights included, module scope varies by SKU | VPN and SWG at minimum; ZTA and Duo Desktop on some packages only | Per the parent subscription | N/A |
The table's real message is in the last two columns, not the first two. The tier rename is cosmetic; the counting basis and the PAK boundary are where money moves.
Cisco's ordering guide restricts Advantage and Premier PAK registration to physical ASAs only: not ASAv, not Firepower NGFW appliances running ASA software, not routers, not ISE, not Meraki MX.
Buyers with virtualized or Meraki-terminated VPN who assume PAKs are the entitlement proof end up with quantities that reconcile to nothing.
The second message is the incompatibility line. VPN Only cannot be combined with Advantage or Premier, so a partial-estate VPN Only footprint is not a discount you carry forward, it is a segment you either keep isolated or convert wholesale.
Price both paths before you accept the conversion the reseller pre-modeled. In our experience negotiating these conversions, the reseller's default is wholesale conversion to Premier because it is the cleanest line item to quote, not because it is the cheapest outcome for the buyer.
The two dates that matter: March 31, 2024 and March 31, 2027
These are not two milestones on one runway.
They are two different events, and the earlier one has already cost you three years of patching. Software maintenance support for AnyConnect 4.x ended March 31, 2024.
And Cisco's Umbrella end-of-life documentation states that no patches or maintenance releases can be provided for 4.x releases after that date.
The final build of the train is 4.10.08029. That string, not "4.x", is your inventory scan target: anything at or below it has been frozen since Q1 2024.
March 31, 2027 is the separate date on which all support services end and the product becomes obsolete, per the EoS/EoL bulletin published May 30, 2023.
Understand what the remaining window actually buys. TAC will answer configuration questions for contract holders through March 31, 2027, and nothing more. It cannot ship code.
Any vulnerability disclosed against 4.x today stays open on every endpoint running it, with no vendor remedy and no compensating control beyond removal.
Cisco's own 4.10 release notes state the position without hedging: without upgrading to 5.1.x you cannot get support, new features, compliance module updates for HostScan, Secure Firewall Posture, or ISE, or updates for the latest operating systems.
Note also that support continuity was always conditional on entitlement, not just the calendar: the EoL bulletin ties software maintenance and application software support to an active term license or an active service contract on perpetual.
The practical failure mode is not a CVE. It is an operating system update that breaks an unpatchable client. Microsoft and Apple ship kernel, network stack, and driver signing changes on their own schedules, and a frozen 4.10 build has no path to accommodate them.
When that lands, you are not negotiating, you are doing an emergency deployment across the full endpoint estate with your account team holding the timeline.
Compliance module drift compounds it: posture checks that no longer recognize current OS builds fail open or fail closed, and neither outcome is one you want to explain.
Run the 4.10.08029 inventory now, size the deployment against your slowest device population (typically contractors, OT, and unmanaged BYOD in our experience), and finish the client rollout well before you touch the commercial conversation.
Cut your Cisco Secure licensing cost in 2026
How to cut Cisco Secure licensing cost in 2026 across Umbrella, Secure Endpoint, Duo, and XDR, with the bundle and contract levers that hold at renewal.
Get the white paper →Proving the no-charge entitlement before anyone quotes you
Cisco's own EoL bulletin from 30 May 2023 is the document you cite in the first meeting: all customers with valid AnyConnect / Secure Client term licenses or perpetual licenses with active support contracts are eligible to upgrade to the current release at no charge.
The Umbrella EoL page extends that further, stating there is no additive charge for any customer entitled to use the client directly or indirectly through another purchased Cisco service, including most Umbrella packages.
So there are three qualifying paths, and only three: an active term license, a perpetual license sitting under an active service contract, and indirect entitlement bundled into a Cisco service you already bought. Notice what governs the outcome.
The same bulletin says software maintenance and application software support requires an active term license or active service contract for perpetual licenses. Entitlement, not the calendar, is the gate.
A perpetual AnyConnect Plus estate whose SASU lapsed in 2022 is not covered by the free path, and Cisco is entitled to price that population as new business. That is precisely the gap resellers look for before they build a quote.
Assemble the evidence pack before you accept any pricing, because once a quote exists the conversation is about discount rather than entitlement. Pull four artifacts and reconcile them against each other, not against the reseller's spreadsheet.
In our experience, roughly a third of estates have at least one perpetual tranche with a lapsed contract that nobody has looked at since the last firewall refresh, and that tranche is where the entire uplift gets justified.
| Evidence artifact | Where it comes from | What it proves | Failure mode if missing |
|---|---|---|---|
| Service contract numbers with coverage dates | Cisco Service Contract Center, or your reseller's renewal file | Perpetual licenses sit under active support on the qualifying date | Perpetual tranche reclassified as new business |
| Smart Account entitlement export | Smart Software Manager, full CSV including sub-accounts | Term license quantities, tiers, and end dates of record | Quantities rebuilt from concentrator logs, always higher |
| PAK registration history | Cisco Licensing Portal, PAK-to-device mapping | Legacy Plus and Apex quantities that remain stackable | Renewal priced as a full replacement buy |
| SKU list with module coverage | Original POs plus the Secure Client ordering guide | Which modules (VPN, ZTA, SWG, Duo Desktop) are already bundled | Modules you own get quoted again as adders |
The table looks like an admin exercise. It is not: it is the boundary line between a version change and a purchase order.
Cisco's cross-product entitlement varies module by module, and the Cisco Community Security Licensing Guide (updated 12 August 2025) is explicit that some subscriptions entitle VPN, ZTA, SWG and the Duo Desktop app while others entitle only VPN and SWG.
Nobody in the account team is going to volunteer which of your existing SKUs already covers which module.
Build the pack yourself and date-stamp it.
Once you can put an entitlement export and a contract number list on the table, the discussion shifts from "what does the migration cost" to "which specific 400 users are genuinely uncovered", and that is a four-figure conversation instead of a six-figure one.
Our Cisco Secure licensing negotiation playbook for 2026 covers the same discipline applied across the wider Secure portfolio.
Advantage or Premier: the tier decision that sets your run rate for five years
The tier split is simple on paper and expensive in practice.
Cisco's Secure Client Ordering Guide describes Advantage as the successor to AnyConnect Plus and Essentials: device and per-application VPN with third-party IKEv2 headend support, trusted network detection, basic device context, FIPS, the Network Access Manager 802.1X supplicant.
And the Umbrella Roaming module.
Premier, the old Apex, adds endpoint Posture for Secure Firewall or ISE Posture via Identity Services Engine, network visibility, next-generation VPN encryption including Suite B, and the Management VPN Tunnel. Everything else is shared.
So the decision reduces to one question: do you actually enforce Posture, and on whom? If the answer is "on contractors and privileged admins", you do not need a Premier estate. You need a Premier subset.
| Population | Requirement driving the tier | Correct tier | Common oversell |
|---|---|---|---|
| Standard remote workforce | Tunnel, TND, FIPS, roaming module | Advantage | Premier applied to whole headcount |
| Contractors and BYOD | ISE Posture enforcement before access | Premier | Advantage plus a separate NAC adder |
| Privileged admin group | Suite B, Management VPN Tunnel | Premier | Premier for all admins' peers too |
| Site-to-site and appliance-terminated only | Concurrent tunnel capacity on one ASA | VPN Only | Advantage counted per named user |
| Legacy Plus and Apex holders | Existing term still running | Stack, do not replace | Full replacement quote |
Two budget realities get buried in the tier conversation. First, ISE Posture is not one line item.
It requires a Secure Client Premier license and an ISE Premier or Apex license, two separate contracts on two separate renewal clocks, and we routinely see the second one surface only after the first is signed. Model both before you commit, because the ISE side is frequently the larger of the two.
Second, Cisco explicitly permits stacking Advantage and Premier licenses and terms, including alongside valid legacy AnyConnect Plus and Apex entitlements. A mixed estate is a supported configuration, not an exception you have to argue for.
Push back hard on any quote that applies a single tier to the full user count, and be aware that stacking generates multiple PAKs to register against physical ASAs only, which is its own operational trap covered in our Cisco PAK to Smart Licensing migration risks analysis.
Counting users the way Cisco counts them, not the way your VPN concentrator does
The single largest source of overspend in this migration is not the tier decision, it is the quantity line, and the quantity line is where buyers hand Cisco a number generated by the wrong system.
Cisco's Secure Client Ordering Guide is explicit: the number of Advantage and Premier licenses is based on all possible unique users that may use any Cisco Secure Client service, with the exact count tied to the unique users requiring the specific services covered by each license type.
That is not your concurrent session peak. A 12,000-employee organization with a 3,000-user concurrent peak does not license 3,000 Advantage seats, and if a reseller quotes 3,000 you are looking at a quote that will fail the first entitlement review after the migration completes.
Equally, a firm that runs the reverse logic and simply hands over an HR headcount of 12,000 is overpaying, because "all possible unique users" means users who may use a Secure Client service, not every identity in Active Directory.
VPN Only behaves differently and buyers conflate the two constantly: it is concurrent endpoint-based, applied per individual physical ASA, not portable between headends, and per Cisco's own cdFMC documentation it cannot be combined with Plus or Apex (and therefore not with Advantage or Premier).
Two counting bases, two different denominators, one shared quote template.
In 25 years of these negotiations, the defensible method is a de-duplicated identity list built from the authentication source, not the concentrator, then reduced line by line with documented exclusions you can hand an auditor.
| Population | Counting basis | Include in Advantage/Premier count? |
|---|---|---|
| All AD/Entra identities | Directory object count | No. Not a licensing basis. |
| Employees with any Secure Client service enabled | Unique users | Yes |
| Contractors and seasonal staff | Unique users, active during term | Yes while provisioned, remove at offboarding |
| Service and machine accounts | Non-human | No |
| Decommissioned or disabled identities | Stale objects | No. Prove disablement date. |
| Users covered via Umbrella or Secure Access bundle | Indirect entitlement | No additive charge, exclude from new buy |
| Posture-scanned users only | Premier trigger | Yes, at Premier, count separately |
| VPN Only on a specific physical ASA | Concurrent endpoints, per ASA | Separate SKU, cannot stack with Advantage/Premier |
The table hides the arbitrage.
Advantage and Premier are counted by unique users but Posture is what forces the Premier tier, so the trimming exercise and the tier exercise are the same exercise: if only 4,200 of 11,000 users are subject to ISE or Secure Firewall Posture, you buy 4,200 Premier and the balance at Advantage.
And you refuse any quote that applies Premier uniformly across the estate.
Most reseller quotes apply the higher tier to the whole population because it is faster to build.
Build the exclusion evidence before you talk price. Pull the identity list, timestamp it, mark each excluded cohort with a reason and an owner, and keep the artifact.
That document is what stops a quantity dispute becoming an audit finding, and it is the same artifact you will want if the Smart Account reconciliation goes sideways, a risk covered in our Cisco PAK to Smart Licensing migration risks analysis.
Analysis: Cisco is not charging for the upgrade because the upgrade is the audit
Cisco gave the version change away, and the giveaway is not generosity, it is sequencing.
Moving AnyConnect 4.x to Secure Client 5.x costs Cisco effectively nothing in incremental revenue because the customers who would pay were already paying, either on a term license or on an active support contract against perpetual.
The EoL bulletin says so plainly: all customers with valid term licenses or perpetual licenses with active support contracts upgrade at no charge, and there is no additive charge for indirect entitlement through Umbrella or comparable services.
What Cisco buys with that concession is far more valuable than a one-time upgrade fee. It buys a forced reconciliation of every AnyConnect entitlement in the installed base against a Smart Account record, executed on Cisco's timetable rather than the customer's.
Understand what the PAK era actually looked like from Cisco's side. Product Authorization Keys were issued, registered against physical ASAs, and then largely disappeared into customer-managed spreadsheets. Cisco could see what was sold.
It could not reliably see what was deployed, who was using it, whether the quantity purchased in 2016 still matched the population connecting in 2024, or whether Plus licenses were quietly covering Apex-tier Posture use. That opacity worked in the buyer's favor for a decade.
Nobody was going to reconcile a 2016 PAK against a 2024 user base voluntarily.
Secure Client 5 changes the visibility model. Registering entitlement against a Smart Account, and the share requirements that come with Firepower Threat Defense and cloud-delivered FMC, pull deployment data into a system Cisco can query.
The reconciliation that was previously a customer-side spreadsheet becomes a vendor-side record.
That is not a conspiracy, it is the predictable consequence of a licensing architecture change, but buyers who treat the migration as a technical project rather than a commercial one will not have prepared for it.
The unique-user basis is the second lever, and it is the one that re-baselines quantities upward across most estates. Whatever quantity you bought under PAK, you bought it against the headcount and the concurrency assumptions of that year.
Since then most organizations have added staff, absorbed acquisitions, extended remote access to contractors, and pushed the client onto populations that were never in the original calculation.
Recount on Cisco's basis, all possible unique users who may use any Secure Client service, and the number goes up. It goes up before anyone has discussed a discount.
Posture adoption is the third lever, and it operates on tier rather than quantity. Premier is where endpoint Posture for Secure Firewall and ISE Posture live, alongside network visibility, Suite B encryption, and the Management VPN Tunnel.
Organizations that adopted posture checking for compliance reasons over the last five years, often without a licensing review at the time, are sitting on an Advantage-priced entitlement supporting a Premier-tier feature set.
The migration surfaces that gap in exactly the moment when the alternative to paying is losing support.
Which brings the March 31, 2027 date into focus as a commercial instrument, not a technical one. Software maintenance already ended in March 2024, so anything running 4.x today is unpatched.
The 2027 date removes the last remaining option to defer, because after it there is no TAC, no configuration support, no compliance module updates. A buyer with no ability to wait is a buyer with no leverage on quantity or tier.
The counter-move is unglamorous and entirely within your control: run your own reconciliation in 2026, on your own timetable, before Cisco's renewal cycle reaches you.
De-duplicate the identity list, document every exclusion, split the Posture population from the general population, catalog every legacy Plus and Apex PAK you can stack rather than replace, and confirm which users are already covered indirectly through Umbrella or Secure Access.
Then walk into the renewal with a defended number and the evidence behind it. Our Cisco Secure licensing negotiation playbook for 2026 sets out the sequence.
The difference between a self-run reconciliation and a vendor-run one is typically the difference between arguing over a discount and arguing over a shortfall.
Stacking, legacy licenses, and why a full replacement quote is usually wrong
The Secure Client Ordering Guide states plainly that Cisco permits stacking Advantage and Premier licenses and terms, including with valid legacy AnyConnect Plus and Apex licenses and terms, and that stacking generates multiple PAKs to register against your ASAs.
Read that sentence the way a reseller does not want you to read it: entitlement you already hold is additive to whatever you buy next.
So when a renewal quote arrives priced as a clean-sheet replacement for 8,000 users, and 3,200 of those users are already covered by perpetual Apex with an active service contract, the quote is overstated by 40 percent on quantity before anyone argues about tier or term.
In our experience across Cisco renewals, the clean-sheet quote is the default output of the reseller's configuration tool, not a considered position, and it is corrected without escalation once you present a netting schedule.
Build the netting schedule before you respond.
List every live entitlement source: perpetual Apex and Plus with support contracts current as of the quote date, in-term Advantage and Premier subscriptions with their end dates, VPN Only licenses (which sit outside the stack and cannot be combined with Plus or Apex, so count them separately).
And indirect rights through Umbrella or Secure Access packages.
Subtract that total from the quoted quantity and make Cisco price only the gap.
Perpetual Apex holders with live support sit in the strongest position of anyone in this transition: they own the Premier feature set in perpetuity, they are entitled to the version change at no additive charge, and their only recurring exposure is the support contract itself.
Nothing in the March 2027 date forces them onto a subscription. Treat any suggestion otherwise as a sales position, not a licensing fact, and test it against the same discipline you would apply during a PAK to Smart Licensing migration.
The netting exercise is where the negotiation actually happens, because quantity is harder for a seller to defend than discount. A 40 percent quantity reduction survives every downstream discussion, including the co-term reset that Cisco will propose to align your subscription end dates.
Discount concessions do not survive, they get clawed back at the next renewal.
One caution: stacking works only where the underlying legacy licenses are provably valid. If your Apex support lapsed in 2023 and was never reinstated, that quantity is not yours to net out, and asserting it invites a compliance conversation you did not need.
Verify contract status in your Smart Account and in the service contract record before you put numbers in front of the account team.
The ordering and PAK mechanics that silently break entitlement
Four mechanical failures convert a correctly negotiated deal into a broken entitlement record, and none of them throw an error at the time of order.
They surface months later, usually during a headend migration or an audit data request, when the license count on the device does not match the count on the purchase order. Each one is preventable with a single line on a pre-order checklist.
| Failure mode | What actually happens | Pre-order check |
|---|---|---|
| PAK scope | PAK registration applies only to physical ASAs. It does not apply to ASAv, Firepower NGFW running ASA software, Cisco routers, ISE, or Meraki MX. | Inventory your headends first. If none are physical ASAs, do not accept a PAK-based order structure. |
| Quantity on one PID | Ordering Qty 2 against a single top-level PID grants entitlement but generates no second PAK, leaving you unable to register the second license. | Two L-AC-PLS-P-G lines at Qty 1, never one line at Qty 2. Check the quote line by line. |
| FTD sharing | FTD 6.2.1 and later require the Secure Client license be shared with the Smart Account, per Section 6.0.4 of the ordering guide. | Confirm the Smart Account and Virtual Account on the order, and confirm the share is executed post-fulfilment. |
| Meraki MX | AnyConnect and Secure Client on MX is honor-system licensed. Nothing enforces the count until you open a TAC case. | Maintain your own unique-user count for MX. Do not treat silence as compliance. |
The Meraki MX row is the one that costs money later. Honor-system licensing feels like a gift until a TAC engineer asks for your entitlement position mid-incident, and you discover the VPN user population grew 60 percent since the last purchase.
Track it yourself, quarterly, against the unique-user definition Cisco applies, not against concurrent sessions on the dashboard. The same discipline applies across the wider Meraki licensing estate, where enforcement gaps and entitlement gaps are not the same thing.
Add one more control: require your reseller to send the fulfilment confirmation showing PAKs generated per line item, and reconcile that against the order within 30 days. Disputes are cheap inside the fulfilment window and expensive after it.
Bundled rights: Umbrella, Secure Access, and Duo Desktop module coverage
Indirect entitlement is real, it is written into Cisco's own end-of-life bulletin, and it is the single most underused lever in a Secure Client renewal.
Cisco states there is no additive charge to adopt the current version for any customer entitled to use AnyConnect either directly or indirectly through another purchased Cisco service that includes use of the client for that use case, and it names most Umbrella packages explicitly.
The trap is the phrase "for that use case." Coverage is granted module by module, not client by client.
Cisco's own security licensing guide on the Community site (updated 12 August 2025) confirms that some subscriptions entitle the VPN, ZTA and SWG modules plus the Duo Desktop app, while other packages entitle only VPN and SWG.
Secure Access is the sharpest example of the ambiguity: the Secure Access Subscription Ordering Guide says Secure Client is required for VPN, client-based Zero Trust Access, Internet Security features and Experience Insights.
Then separately notes that a client license is required and points the buyer back at the Secure Client ordering guide.
Required and included are not the same word.
Treat every posture, Network Visibility Module, and 802.1X supplicant use case as unentitled until your account team confirms it in writing against your specific SKU, because those are the capabilities that sit in Premier, and Premier is where the run rate lives.
The asymmetry here favors you if you move first. Cisco's field teams cannot reliably answer module coverage from memory, so the written answer you request becomes the document that governs the renewal. If the answer confirms bundled rights, you have removed a line item from the quote at zero cost.
If the answer is narrower than the account team implied verbally, you have caught the gap before you signed rather than during a true-up.
Do this before any quote arrives, not after.
Send one email listing your Umbrella, Secure Access and Duo SKUs, and ask for a module-by-module yes or no across VPN, client-based ZTA, SWG or Internet Security, Network Visibility, Posture (Secure Firewall and ISE), Network Access Manager, and Duo Desktop. Keep the reply.
In our experience it changes the tier mix on roughly a third of quotes, and it is the same evidence you will want if a licensing review lands later, a point we develop further in the Cisco Secure licensing negotiation playbook for 2026.
Negotiation position: what to ask for and where Cisco will actually move
Cisco will not discount the upgrade itself, because the upgrade is already free. Every dollar of movement available to you sits in quantity, tier mix, term length, and contract vehicle. Start with the lever Cisco has documented against its own interest: licensing is headend-agnostic.
The Secure Client 5.x features and licensing guide states that a consistent model is used regardless of headend, covering ASA, ISR, CSR, ASR and non-VPN headends such as ISE, so there is no impact when headend migrations occur. That sentence kills the most common upsell of 2026.
If you are refreshing from ASA to Firepower or moving termination into Secure Access, the client entitlement travels with you. A reseller who quotes a fresh client buy alongside a firewall refresh is quoting a repurchase of something you own.
Push back with the guide reference and the quantity drops.
Second, reject any separate SASU or support line attached to the client. Cisco's guide is explicit that these user-based licenses include access to support and software updates. Support on the client is not a separate purchase. Third, treat term length as a live trade rather than a default.
Cisco Commerce Workspace offers 1, 3 and 5 year terms, and the 5 year discount is real, but the SSE market is repricing quickly and a 5 year commitment on a per-user client locks your baseline while Secure Access and competing SSE vendors are still cutting bundle prices.
In our negotiations a 3 year term is the usual sweet spot: enough duration to earn most of the discount curve, short enough that you re-enter the market before the bundle economics shift again.
Fourth, be careful with the Enterprise Agreement. Folding Secure Client into an EA renewal is only worth it once your unique-user baseline is settled, because the EA locks that number as the floor for the whole term.
Sign an EA with an inflated count derived from concurrent sessions or stale directory objects and you have converted a one-time counting error into a multi-year annuity. Settle the count, prove your stacked legacy Plus and Apex entitlement, then decide whether the EA is worth it.
The moves that fail are predictable. Asking for a discount on the version upgrade fails because there is nothing to discount. Threatening to stay on 4.x fails because Cisco knows you cannot patch it after March 2024 and cannot support it after March 2027.
Escalating on price without a defensible user count fails because Cisco's counting definition is documented and yours usually is not.
The leverage that works is documentary: a written module-coverage answer, a defended unique-user number, and evidence of existing perpetual and term entitlement including PAK history, which is where the PAK to Smart Licensing migration risks intersect with this negotiation.
Bring those three artifacts and Cisco moves on quantity and tier mix, which is where the money actually is.
Evidence base and the patterns we see repeat
Everything above rests on Cisco's own published record, not on reseller interpretation.
The primary sources are the End-of-Sale and End-of-Life Announcement for AnyConnect 4.x, published May 30, 2023, which fixes both the March 31, 2024 software maintenance cutoff and the March 31, 2027 end of all support, and states plainly that customers with valid term licenses or perpetual licenses under active support contracts are eligible to upgrade at no charge.
The Cisco Secure Client Ordering Guide, which defines the Advantage and Premier feature splits, the unique-user counting basis, the stacking rule that includes legacy Plus and Apex terms, and the restriction of PAK registration to physical ASAs only.
The Secure Client Features, Licenses, and OSs guide for Release 5.x, which confirms headend-agnostic licensing across ASA, ISR, CSR, ASR, and ISE, plus the 1, 3, and 5 year term options and the fact that support and software updates are already inside the license price.
The Cisco Umbrella end-of-life documentation, which extends the no-additive-charge language to indirect entitlement through other purchased Cisco services.
The cdFMC and Meraki MX documentation (Meraki updated April 2, 2026), which establishes VPN Only as a separate, concurrent, non-combinable license.
And the Cisco Security Licensing Guide on Cisco Community, updated August 12, 2025, which flags that module coverage, including Duo Desktop, varies by SKU.
Cisco's own EoL bulletin grants the version move at no cost to every holder of an active term license or an active support contract on perpetual.
Software maintenance ended two years ago, so every 4.x endpoint carries unremediated CVEs regardless of contract status.
Across the engagements we run, four patterns repeat with enough regularity that we now screen for them in the first call.
First, entitlement was never reconciled after the PAK era, so the Smart Account shows a fraction of what the customer actually bought, and the reseller quotes against the visible fraction. Our analysis of PAK to Smart Licensing migration risks covers where those records go missing.
Second, blanket Premier, where the whole population is quoted at the higher tier because a subset needs ISE or Secure Firewall Posture.
Third, concurrent counting carried over from ASA habits, which either understates the buy and creates true-up exposure or, more often in our experience, gets corrected upward by the seller into a number nobody validated.
Fourth, quotes priced as replacement rather than net of existing stackable entitlement, despite the Ordering Guide explicitly permitting Advantage and Premier to stack with valid Plus and Apex terms.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
Your first five moves
Sequence matters. Do these in order, because each one produces the input the next one needs, and the whole chain has to close before you accept a quote.
Against a March 31, 2027 date, the practical deadline for finishing moves one through four is the quarter before your next renewal anniversary, not 2027.
- Inventory every 4.x build against 4.10.08029 by end of the current quarter, owner endpoint engineering, deliverable a machine-generated list of hostnames, versions, and headends, because anything below the final maintenance release has been unpatchable since March 31, 2024 and anything at all on 4.x loses TAC access on March 31, 2027.
- Export the full Smart Account and Cisco Commerce entitlement record within 30 days, owner licensing or procurement, deliverable a reconciled line-item list including legacy Plus, Apex, and any orphaned PAKs, since the Ordering Guide permits those terms to stack and the seller will not surface them for you.
- Decide the Posture population before you decide the tier, owner security architecture, deliverable a named user count that genuinely requires ISE Posture, Secure Firewall Posture, network visibility, Suite B, or Management VPN Tunnel, because that number, and only that number, justifies Premier while everyone else sits on Advantage.
- Build the unique-user number yourself from HR and identity data, not from concurrent session peaks, owner identity or IAM, deliverable an authoritative headcount of all possible unique users of any Secure Client service, since Cisco counts unique authorized users and your concentrator counts simultaneous tunnels, and the gap between the two is where the overbuy lives.
- Demand a quote priced net of existing entitlement with module coverage confirmed in writing, owner procurement, deliverable a signed statement naming which modules (VPN, ZTA, SWG, Duo Desktop) your Umbrella or Secure Access SKU already covers, and refuse any separate SASU line for the client itself because support and updates are already inside the license price.
The five moves work because they invert the normal order of a Cisco conversation. Sellers open with a tier recommendation and a user count, both of which arrive pre-inflated, then negotiate discount percentage off that inflated base. A 30% discount on a number that is 40% too large is still a loss.
By fixing the version inventory, the entitlement record, the Posture population, and the unique-user count before any quote exists, you change what is being discounted rather than how much.
Our Cisco Secure licensing negotiation playbook for 2026 sets out the wider account-level leverage, but the client transition is unusual: the vendor has already conceded the upgrade is free in writing.
Your entire job is preventing that concession from being converted into a new purchase through counting and classification. Hold the line on all five deliverables and the renewal should be flat or lower.
Frequently asked questions
When exactly does Cisco AnyConnect 4.x stop being supported?
All support services for AnyConnect 4.x end on March 31, 2027, after which Cisco treats the product as obsolete. The more urgent date already passed: software maintenance support ended March 31, 2024, so no patches or maintenance releases have been available for 4.x since then.
Support in the remaining window is limited to TAC configuration assistance for customers with an active contract, not code fixes.
Do I have to pay to upgrade from AnyConnect to Cisco Secure Client 5?
No. Cisco's end-of-life bulletin states that all customers with valid AnyConnect or Secure Client term licenses, or perpetual licenses with active support contracts, are eligible to upgrade to the current release at no charge.
There is also no additive charge for customers entitled indirectly through another purchased Cisco service, including most Umbrella packages. If a quote prices the version change itself, challenge it against the bulletin.
What is the difference between Secure Client Advantage and Premier?
Advantage corresponds to the legacy AnyConnect Plus and Essentials licenses and covers device and per-application VPN, third-party IKEv2 headend support, trusted network detection, basic device context, FIPS, the Network Access Manager 802.1X supplicant, and the Umbrella Roaming module.
Premier corresponds to the legacy Apex license and adds endpoint Posture for Secure Firewall or ISE Posture, network visibility, next-generation VPN encryption including Suite B, and the Management VPN Tunnel, plus everything in Advantage. If you enforce posture, you need Premier for those users.
Is Secure Client licensed by concurrent sessions or by user?
Advantage and Premier are licensed on unique users, specifically all possible unique users who may use any Cisco Secure Client service tied to that license type, not on simultaneous connections. VPN Only is the exception: it is concurrent endpoint-based and applied per individual ASA.
Buyers who carry over a concurrent-session count from their ASA configuration typically undercount Advantage and Premier by a wide margin.
Can I combine VPN Only licenses with Advantage or Premier?
No. VPN Only licenses are concurrent endpoint-based, applied per individual ASA, and are not portable. Cisco documentation for both the ordering guide and cdFMC confirms the VPN Only license cannot be used with Apex or Plus, and by extension not with Advantage or Premier.
Plan VPN Only as a separate, isolated entitlement rather than as part of a stackable pool.
Do my existing AnyConnect Plus and Apex licenses still count after migration?
Yes. Cisco permits stacking Advantage and Premier licenses and terms including with valid AnyConnect Plus and Apex licenses and terms, which generates multiple PAKs to register to ASAs.
This is the single most common place buyers overpay: a renewal quote priced as a full replacement buy ignores entitlement you already hold. Net your existing quantities out of any proposal before you sign.
Does buying Cisco Secure Access or Umbrella cover the Secure Client license?
Partially, and it varies by SKU and by module. Cisco's licensing guidance notes that some subscriptions entitle use of the Secure Client VPN, ZTA and SWG modules plus the Duo Desktop app, while others entitle only VPN and SWG.
The Secure Access ordering guide states the client is required for VPN, client-based Zero Trust Access, Internet Security features, and Experience Insights, while separately noting that a client license is required. Verify module-by-module against your exact SKU and get the confirmation in writing.