HomeCisco PracticeSecurity Licensing
Cisco  |  Security Meters Estate Brief 2026

The meter rather than the product drove the overspend, and sizing the gateway on total users instead of active ones inflated the count by 15 to 30 percent

Three pillars, three different meters. The tier conversation is loud and the counting conversation is where the money actually sits.

Prepared by Redress Compliance · August 19, 2026 · Cisco security renewals. 25 to 35 renewals benchmarked, 2024 to 2025.

Executive summary

The secure gateway was sized on total users rather than active users, inflating the count by 15 to 30 percent. Nothing about the product changed; the denominator did.

Access tiers were over specified. Buyers bought multi factor plus access where multi factor alone covered the stated requirement.

Monitored asset counts crept upward as inventory tools double counted endpoints and cloud instances. The asset count is the bill on that pillar.

Security now runs 25 to 45 percent of total Cisco subscription spend, and suite consolidation compressed the tier level leverage that used to sit in the SKU list.

15 to 30%
Count inflation from sizing on total rather than active users.
22%
Median count inflation removed across the reviews.
28%
Median renewal reduction negotiated.
25 to 35
Cisco security renewals benchmarked, 2024 to 2025.
1.

Why does the meter matter more than the tier?

Because the portfolio shift from point products to suites compressed the tier level leverage. What is left sits inside the count and the bundle math.

Three shifts that moved the leverage

The line is now large enough to matter

Security spend runs 25 to 45 percent of total Cisco subscription spend in most enterprise accounts. It is no longer a rounding error attached to the networking conversation. The buying programs are described on the enterprise buying programs page.

2.

How do the secure gateway tiers price?

Per user per year, split between DNS layer tiers and full secure internet gateway tiers. The tier ladder is steep and most estates start one rung too high.

TierScopeList per user per yearBest fit
DNS EssentialsDNS security, basic filtering$24Smaller or branch coverage
DNS AdvantageDNS plus advanced filtering and intelligence$36Mid market enterprise
SIG EssentialsDNS plus gateway plus cloud access plus firewall$72Hybrid workforce
SIG AdvantageFull gateway plus data loss prevention and isolation$120Regulated industries

The gateway tier trap

Most enterprise buyers default to the first gateway tier on the account team recommendation. That tier carries about 70 percent more capability than most customers actually deploy in year one.

Stage the tier to the deployment

A staged approach starts one rung lower and moves up at the renewal, when the gateway and cloud access deployment is genuinely ready. The product scope sits on the Umbrella product page.

Free white paper

The Cisco enterprise agreement guide

How the agreement prices, where the security line sits inside it, and the buyer side moves before the commitment.

Get the brief →
3.

What 25 to 35 Cisco security renewals showed

Across roughly 25 to 35 Cisco security renewals benchmarked in 2024 and 2025, the meter, not the product, drove the overspend. Three patterns recur.

Removing the count inflation was worth a median 22 percent before any tier or rate conversation started.

Try Vera AI · free 30 day trial
Before the auditor finds it, Vera already has.
  • Every risky clause flagged with the verbatim quote and page anchor
  • Entitlements, caps and protections verified across your whole contract portfolio
  • Paste ready replacement language and an evidence trail for the response
Start the free Vera AI trial →30 days free · no credit card · cancel anytime
4.

Which access tier does the requirement actually need?

Usually one below the one on the quote. The four tier ladder runs from a free tier for pilots to a full zero trust tier, and the middle is where most estates belong.

TierScopeList per user per yearBest fit
FreeMulti factor for up to ten users$0Pilots and small teams
EssentialsMulti factor plus sign on plus device insight$36Basic enterprise multi factor
AdvantageEssentials plus device trust plus risk based access$72Hybrid workforce
PremierAdvantage plus remote access plus passwordless$108Zero trust adoption

Three asks that hold at the table

The published ladder sits on the access pricing page, and the overlap question is the one most likely to remove a whole line rather than discount it.

5.

Why does the monitored asset count drift?

Because the detection pillar bills on monitored assets rather than users, and the asset count includes endpoints, servers, network devices and cloud workloads.

TierScopeList per asset per yearBest fit
XDR EssentialsDetection and response across endpoint and network$36Mid market operations
XDR AdvantageEssentials plus cloud and email telemetry$60Full operations centre
XDR PremierAdvantage plus managed detection and response$120Managed partnership

Double counting is the default, not the exception

Inventory tools double count endpoints and cloud instances, so the number rises without anybody deploying anything. Reconciling the asset list is the single cheapest move on this pillar. The scope is set out on the detection product page.

Cisco 2026 negotiation briefing on the tactics buyers should expectWatch the briefing · 4:55Cisco Negotiations in 2026: How to Prepare, and the Tactics You Will FaceThe four tactics to expect, the consumption baseline, and spending capital on mechanics rather than headlines.
6.

Where the common advice on Cisco security is wrong

The standard advice is to consolidate onto the suites and negotiate the headline discount hard. We disagree.

The discount applies to a count nobody checked

Across the renewals benchmarked, removing count inflation was worth a median 22 percent, and it came before any rate conversation. A better percentage on an inflated count is still an inflated bill.

The buyer side move is to reconcile active users, reconcile monitored assets, and match each tier to the deployed capability, then negotiate. Median renewal reduction across the file was 28 percent. The wider agreement mechanics sit in the enterprise agreement guide.

7.

What the renewals measured, 2024 to 2025

Two cuts of the benchmark file, and the first produces the second.

22%
Median count inflation removed

From reconciling active users against total users and de duplicating the monitored asset list, before any rate discussion.

28%
Median renewal reduction negotiated

Across the benchmarked renewals, once the counts were corrected and the tiers matched to deployed capability.

The gap between the two is the part a discount contributed. The larger share came from counting.

8.

Your first five moves

  1. Reconcile active users against the total user count, because sizing on the total inflated the gateway count by 15 to 30 percent.
  2. De duplicate the monitored asset list across inventory tools, since double counted endpoints and cloud instances drift the count upward on their own.
  3. Match each tier to the capability actually deployed, as the first gateway tier carries about 70 percent more than most estates use in year one.
  4. Check whether the identity platform you already own covers multi factor, which removes a line rather than discounting one.
  5. Only then negotiate the rate and the bundle. The Cisco practice and the spend health check run the count before the quote arrives.
9.

Frequently asked questions

What actually drives Cisco security overspend?

The meter rather than the product. Sizing the secure gateway on total users instead of active users inflated the count by 15 to 30 percent on its own.

How large is the security line now?

Between 25 and 45 percent of total Cisco subscription spend in most enterprise accounts, which is why it no longer rides along with the networking conversation.

Why has tier leverage shrunk?

Suite consolidation replaced fifteen plus standalone items with three suites and compressed each pillar to three or four tiers, so the SKU list holds less room.

What is the gateway tier trap?

Defaulting to the first full gateway tier on the account team recommendation. It carries about 70 percent more capability than most customers deploy in year one.

Which access tier fits most estates?

The third rung rather than the fourth. Buyers routinely bought multi factor plus access where multi factor alone covered the stated requirement.

Can an existing identity platform cover it?

Often yes. Checking for multi factor overlap with the identity platform you already own is the one move that removes a line instead of discounting it.

Why does the asset count drift?

Because inventory tools double count endpoints and cloud instances. The number rises without anybody deploying anything new, and the asset count is the bill.

How much does correcting counts recover?

A median 22 percent across the benchmarked renewals, entirely before any rate conversation started.

What was the median renewal reduction?

28 percent. The gap between that and the 22 percent from counts is roughly what the rate negotiation itself contributed.

What order should the work run in?

Counts first, tiers second, rate last. A better percentage applied to an inflated count is still an inflated bill.

© 2026 Redress Compliance · Independent, buyer sideredresscompliance.com
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent
Score your software spend across Cisco and the broader portfolio in under five minutes.
Open the Software Spend Health Check →
White Paper · Cisco

Download the Cisco ELA Guide 2026.

A buyer side framework for the next Cisco ELA negotiation. Security tier benchmarks, Umbrella and Duo tier maps, XDR asset count rules, True Forward control language, and the bundle math that Cisco does not volunteer.

Used across five hundred plus enterprise clients. Independent. Buyer side. Built for enterprise customers running Cisco security at scale across Umbrella, Duo, XDR, and Secure Endpoint.

Cisco ELA Guide 2026

Open the white paper in your browser. Corporate email only.

Open the Paper →
20 to 35%
Security line recovery
3 pillars
Umbrella, Duo, XDR
3 suites
User, Cloud, Breach
500+
Enterprise clients
100%
Buyer side

We audited the Cisco security footprint, dropped two Duo Premier tiers down to Advantage where device trust was the actual requirement, swapped SIG Advantage for SIG Essentials on 6,400 users, capped the XDR asset count drift at five percent, and recovered 28 percent on the security line at the ELA renewal.

Director of Security Architecture
European banking group
Editorial photograph of enterprise contract negotiation strategy

Your Cisco security spend is your envelope.

We have run 500+ enterprise clients across 11 publishers. Every engagement starts with one conversation.

Cisco licensing intelligence, monthly.

Umbrella, Duo, and XDR tier movements, suite bundle pricing patterns, True Forward enforcement signals, and the wider Cisco commercial trends across every ELA cycle.