Contents
Key takeawaysHow SecOps is licensedWhat SecOps costsHow connectors add costWho counts as a userBundles and add onsWhat we have seenNegotiating the renewalWhat to do nextFAQSecurity Incident Response and Threat Intelligence list at five figures per fulfilled user per year, yet the surprise on most bills is the connector count. Integrations above the edition allowance cost $20,000 to $40,000 each per year, checked at every renewal.
- Three modules, licensed separately. Security Incident Response and Threat Intelligence are priced per fulfilled user, current Vulnerability Response contracts count devices, and Now Assist for Security is a separate AI SKU.
- Connectors are the unbudgeted line. Standard includes three connectors, Professional six and Enterprise unlimited, and integration add ons made up 15 to 30 percent of the SecOps line in our engagements.
- Inventory connectors every quarter. Most excess connectors come from proofs of concept and tool trials, so decommissioning them before the renewal reconciliation costs nothing and removes the overage.
- Test each module before bundling. Security Incident Response is often quoted with Vulnerability Response when the SOC needs only one, and no bundle credit makes an unused module worth buying.
- Count users against the definition. Analysts, remediators and hunters count, reporting consumers do not, and a quarterly joiner, mover and leaver review keeps the baseline clean.
- Lock the platform clauses. Price protection across the term, a 15 to 20 percent reduction right and a written connector definition answer the renewal uplift and the audit.
How is ServiceNow SecOps licensed?
ServiceNow sells Security Operations as three modules that license independently: Vulnerability Response, Security Incident Response and Threat Intelligence. They come in Standard, Professional and Enterprise editions, with Threat Intelligence starting at Professional. Security Incident Response and Threat Intelligence are priced per fulfilled user per year, while current Vulnerability Response contracts count devices.
Now Assist for Security, the generative AI layer, is a separate per user SKU. Every module also carries a volume dimension and an allowance of integration connectors, and the connector count is the line buyers most often fail to estimate. The table shows how the pieces fit.
| Module | Primary metric | Typical integrations | Volume dimension |
|---|---|---|---|
| Vulnerability Response | Devices on current contracts; fulfilled users on older ones | 3 to 8 connectors: Tenable, Qualys, Rapid7, Defender | Vulnerability records |
| Security Incident Response | Fulfilled user, plus incident count | 4 to 12 connectors: Splunk, Sentinel, QRadar, CrowdStrike | Alert volume |
| Threat Intelligence | Fulfilled user, plus indicator count | 2 to 6 feeds: Mandiant, Recorded Future, MISP | IOC volume |
| Now Assist for Security | Fulfilled user with generative AI | Coupled to the base modules | Token and workflow assist consumption |
How does Vulnerability Response count devices?
Current contracts license Vulnerability Response by device, with order form lines such as "Security Operations Professional VR Devices". Usage counts the unique configuration items in the Discovered Items table that scanners such as Qualys, Tenable and Rapid7 reported in the past 90 days. Items marked CI Decommissioned drop out.
Running container instances are counted separately and averaged over the same window. A scanner that keeps reporting retired servers keeps them in your count, and so does the same server reported by two scanners until the records are merged. Older contracts sold the module per fulfilled user instead, so read your order form before you model anything.
- New names. ServiceNow now markets the module as Unified Security Exposure Management and Threat Intelligence as Threat Intelligence Security Center, so expect new SKU names on the next quote.
- New metering period. In January 2026 the licensing app moved subscription unit metering to a 30 day period. Ask which window your contract uses.
Where does Now Assist for Security fit?
It sits on top of the base modules, and ServiceNow's product page now calls it Now Assist for Security Operations. On SecOps quotes it has been priced per fulfilled user, while consumption follows the assist meter covered in our note on the Now Assist meter.
That may change at your next renewal. ServiceNow's April 2026 repackaging replaced the old tiers with Foundation, Advanced and Prime, folded Now Assist into them and ended sale of legacy SKUs on July 1, 2026. Ask the account team in writing whether your SecOps modules move to the new packaging and what happens to a separate AI line.
5 Ways to Win Your ServiceNow Renewal
What does ServiceNow SecOps cost per user?
At list, each SecOps module runs to five figures per fulfilled user per year. Security Incident Response lists at $11,500 to $24,500 across the editions and Threat Intelligence at $14,000 to $20,500. Vulnerability Response lists at $11,000 to $23,000 where it is sold per user. Now Assist for Security adds $4,500 to $6,500 per user.
| Module | Standard | Professional | Enterprise | Typical discount |
|---|---|---|---|---|
| Vulnerability Response | $11,000 | $16,500 | $23,000 | 20 to 40 percent |
| Security Incident Response | $11,500 | $17,500 | $24,500 | 20 to 40 percent |
| Threat Intelligence | Not offered | $14,000 | $20,500 | 15 to 35 percent |
| Now Assist for Security | Not offered | $4,500 | $6,500 | 10 to 25 percent |
ServiceNow does not publish these prices. They are the list benchmarks we see on quotes, so use them to test a proposal and read your own order form for the figures that bind you. On a device based Vulnerability Response contract, the per user row does not apply, and the price to test is the rate per device.
What discounts are realistic on each line?
Typical discounts run from 10 to 40 percent by line, with Now Assist topping out lower than the response modules. Two bundle credits can stack on top: 10 to 20 points for the three module SecOps bundle and 5 to 15 more for a cross bundle with ITSM and ITOM. Both pay only on modules you would have bought anyway.
Discount size tracks preparation. Buyers with clean counts, a connector inventory and a deployment plan per module reach the upper end of each range.
How much does the price rise at renewal?
Expect an opening uplift of 3 to 12 percent on the existing fulfilled user base. The answer is the same clause set you use on the wider platform: price protection for the full term and a reduction right on each anniversary. Our guide to the annual uplift covers the counter in detail.
ServiceNow 10 Step Renewal Toolkit
The entitlement pull, connector inventory, module fit test and contract terms for your SecOps renewal.
Get the white paper →How do SecOps connectors affect the bill?
Connectors are where SecOps bills outrun estimates. Each edition includes a connector allowance: three on Standard, six on Professional and unlimited on Enterprise. Every deployed connector above the allowance bills at $20,000 to $40,000 a year, and a bidirectional integration sometimes counts as two.
ServiceNow reconciles the deployed connector roster against the contract at every renewal and audit event. Any gap is repriced at the overage rate, so the renewal quote can arrive higher than the prior year even when your user count fell.
How do connectors pile up without a purchase order?
Engineers install them, and procurement never sees the change. The evaluation or hackathon ends and the integration keeps running, because switching it off was on no one's list. These are the usual sources.
- Proofs of concept. Integrations stood up to evaluate a scanner or EDR product and never removed after the decision.
- Parallel tools during migration. The old SIEM and the new one both feed Security Incident Response for months, and both count.
- Bidirectional sync. A two way integration with an EDR console that both reads alerts and pushes containment actions, which may count double.
- Extra threat feeds. Free or trial intelligence feeds added to Threat Intelligence alongside the paid ones.
The control costs nothing: a quarterly connector inventory, explicit decommissioning of what no one uses, and a reconciliation against your allowance before the renewal team runs its own.
Is Enterprise cheaper than Professional plus overages?
It can be on an integration heavy SOC. The hypothetical below uses the list prices above. Say you run Security Incident Response for 12 analysts on Professional, with nine connectors counted against the allowance of six.
| Option | Calculation | Annual list cost |
|---|---|---|
| Professional, 9 connectors | 12 x $17,500 = $210,000, plus 3 over allowance at $20,000 to $40,000 ($60,000 to $120,000) | $270,000 to $330,000 |
| Enterprise, unlimited connectors | 12 x $24,500 | $294,000 |
| Professional after cleanup, 7 connectors | $210,000 plus 1 over allowance ($20,000 to $40,000) | $230,000 to $250,000 |
The Enterprise premium is $7,000 per analyst, or $84,000 for the team, so Enterprise wins once the overage rate passes $28,000 per excess connector. Decommission two unused connectors, though, and Professional becomes cheaper by a wide margin. Do the cleanup first, then price the edition and the connector count together.
Who counts as a SecOps fulfilled user?
People who work security records count, and people who only read them do not. Active SOC analysts and threat hunters in the intelligence workspace are fulfilled users, and so are remediators who own patches and changes where Vulnerability Response is still licensed per user. View only reporting consumers are excluded, mirroring the platform's fulfiller and requester split.
- Contractors. They count against the tier like employees, so license contractor accounts deliberately.
- Service accounts. They stay out of the count only while they remain non interactive. An integration account someone uses to log in becomes a user.
- Analysts with SIR and VR access. On a per user Vulnerability Response contract, whether one person counts once or twice depends on the wording. Ask in writing whether a shared fulfilled user right applies before role overlap doubles the count.
How do you check your own counts?
- Read the order form. Note the edition, the fulfilled user quantity and any connector allowance for each module.
- Pull the allocation. In Subscription Management, list the users allocated to each SecOps subscription.
- Pull the roles. Export the sys_user_has_role table filtered to the licensed security roles, such as sn_si.analyst for Security Incident Response and sn_vul.remediation_owner on a per user Vulnerability Response contract. Flag anyone with no case, task or record activity in two quarters.
- Pull the device count. Install the Vulnerability Response Licensing and Usage app from the ServiceNow Store if it is missing, open its usage dashboard, and check the count for retired servers and assets reported by more than one scanner.
- List the connectors. Check installed integration apps in Application Manager, then the scheduled imports and integration runs, and mark each connector as live, idle or retired.
Run the joiner, mover and leaver review every quarter against that export, since analysts who change teams often keep their security roles. In our engagements, a clean baseline came in 10 to 20 percent below the count on the renewal quote.
Is the SecOps bundle worth buying?
Only when every module in the bundle will deploy. Each module owns a distinct workflow run by a distinct team: remediation for Vulnerability Response, case handling for Security Incident Response, hunting for Threat Intelligence. Test each module against the team that would own it before you let the bundle price the deal.
Why we would not take the three module bundle by default
The common advice is to buy the full suite because the bundle credit makes the extra modules cheap. We disagree, because a discounted module you will not run is still spend. In five of ten deals we scoped, Security Incident Response was quoted alongside Vulnerability Response when the buyer needed only one.
Take a hypothetical at list prices. You need Security Incident Response Professional for 12 analysts, or $210,000. The quote adds Threat Intelligence Professional for the same 12 people at $14,000 each, taking list to $378,000. With the top bundle credit of 20 points you pay $302,400, which is $92,400 more than the module you needed.
When should you add Now Assist for Security?
At the renewal. A mid term addition resets the discount on that line to current rates, so it costs more than the same SKU priced into the renewal. If the SOC wants to pilot it early, write the renewal discount into the mid term order.
What have we seen in recent SecOps negotiations?
Across roughly 25 to 35 ServiceNow engagements we scoped in 2024 and 2025, SecOps priced above the buyer's own estimate once connectors were added. Four patterns recurred often enough to plan for.
- Connectors drove the overrun. Integration add ons made up 15 to 30 percent of the SecOps line, mostly deployed without a contract update and captured at the renewal audit.
- Modules no one needed. In half the deals, one of the quoted modules had no team ready to run it.
- User counts ran high. Over counted fulfilled users inflated the line against a clean entitlement baseline.
- Uplift arrived as standard. Renewal quotes carried 3 to 12 percent on the existing base unless the prior contract capped it.
A connector stood up for a two week proof of concept keeps counting until someone switches it off.
The module test comes first, because no clause protects spend that should not exist. The count reviews and renewal calendar in our ServiceNow renewal guide then apply as they do across the platform.
How should you negotiate SecOps at renewal?
Negotiate SecOps inside the platform renewal, with your counts and connector inventory finished before the first quote. The clauses mirror the platform standard.
What will the account team say, and how should you answer?
- "The full SecOps bundle earns you another 10 to 20 points." Ask for each module priced alone at the same base discount, and share the deployment plan per module. Buy the bundle only if every module has an owner.
- "Your deployed connectors exceed the tier, so we have added them to the renewal." Ask for the roster they counted and match it to your inventory. Decommission idle connectors before the reconciliation date. Then ask for Enterprise priced as an alternative.
- "Everyone with a security role needs a fulfilled user license." Point to the definition: reporting consumers are excluded and non interactive service accounts stay out. Ask for the shared fulfilled user position in writing.
- "Your Vulnerability Response device count is above entitlement, so the renewal includes a larger device block." Ask for the usage report behind the number. Mark retired servers as CI Decommissioned, merge assets reported by two scanners, and let the count settle before you agree a quantity.
Which contract terms should you ask for?
- A written connector definition. State what counts as one connector, how bidirectional integrations count, and whether sub production instances count, so the tier cannot be reinterpreted at audit.
- A cure period on connector overages. The right to decommission excess connectors within a set window before any overage is billed.
- Zero uplift price protection. Fixed unit prices, per user and per device, across the whole multi year term.
- A reduction right of 15 to 20 percent. The right to cut fulfilled users by that share on each anniversary, so a smaller SOC does not keep paying for its old size.
- An edition upgrade price. A stated per user price to move from Professional to Enterprise during the term, in case integrations grow.
- Auto renewal notice. A notice window you control, since the auto renewal clause decides whether you get to negotiate at all.
How does this differ for a small SOC and a large one?
For a SOC of eight analysts, the choice turns on connectors. The Enterprise premium on Security Incident Response is $56,000 at list for eight people, about two excess connectors at overage rates, so clean up the connector list before you run the break even test.
In a large enterprise, the Vulnerability Response device count and the analyst count dominate the bill, so scanner cleanup and the quarterly role review return more than connector work. On a first purchase, settle the connector definition and the shared user right before any count exists. Our edition comparison covers the wider platform choice.
What to do next
- Every quarter, inventory connectors. List every deployed integration per module, decommission the unused ones, and compare the rest with your edition's allowance.
- 12 months out, test module fit. Name the team and workflow that owns each quoted module, and drop any module without one.
- 9 months out, clean the counts. Audit the fulfilled user list against the definition, with analysts and hunters in, reporting consumers out and shared access confirmed in writing. Clean the Vulnerability Response device count the same month.
- 6 months out, price editions against connectors. Compare Professional plus overages with Enterprise for each module, using your cleaned connector count.
- 3 months out, send your numbers first. Give the account team your user baseline, connector roster and module list before the renewal quote arrives.
- At signature, lock the terms. Price protection, the reduction right, the written connector definition and Now Assist priced at renewal rates. The ServiceNow negotiation practice can run the SecOps line with you.
Want a second opinion on your ServiceNow licensing? Our ServiceNow licensing consultants work only for buyers, with no partner income.
Frequently asked questions
How is ServiceNow SecOps licensed?
As three modules you can buy separately, each in tiered editions. Security Incident Response and Threat Intelligence are priced per fulfilled user per year, and Vulnerability Response counts scanned devices on current contracts. Connector allowances sit on top, and Now Assist for Security is a separate per user SKU that requires the base modules.
What does ServiceNow SecOps cost?
List benchmarks run from $11,500 per user for Standard Security Incident Response to $24,500 for Enterprise, with Threat Intelligence at $14,000 to $20,500. ServiceNow publishes no price list, so treat these as a test for your quote, and expect the first proposal to sit well above what a prepared buyer signs.
How do SecOps connectors affect the bill?
Each edition carries a connector allowance, and every connector above it bills at an annual overage rate, with some bidirectional integrations counted twice. The count grows with engineering work rather than purchasing, so it drifts furthest from the original estimate. Ask for the roster ServiceNow counted before you accept any overage.
Who counts as a SecOps fulfilled user?
Anyone who works security records: SOC analysts on cases, remediators who own patches and changes, and threat hunters in the intelligence workspace. Read only report viewers are excluded. Contractors count against the tier, and service accounts stay out only while no person logs in with them.
Should SecOps modules be bought as a bundle?
Only if a named team will run every module in it. The bundle credit lowers the price of each module but raises the total when one of them sits unused. Ask for single module pricing at the same base discount, compare the two totals, and let deployment plans decide.
What is the biggest SecOps audit risk?
Connectors deployed during trials and never contracted, priced at overage rates when ServiceNow compares the deployed roster with your allowance at renewal. On device based Vulnerability Response contracts, a stale scanner feed that inflates the device count is the second risk.
Does Vulnerability Response count devices or users?
Devices, on contracts signed in recent years. Usage counts unique scanned assets in the Discovered Items table over a 90 day window, with running containers measured separately. Older contracts licensed the module per fulfilled user, so the unit on your order form decides which count ServiceNow will check at renewal.