The twenty most active software auditors, and the wave behind them
We asked 500 enterprise clients and contacts one question: which software vendors have audited you in the last three years? 118 answered, and the league table they returned no longer looks like the 2010s. Broadcom leads at 33 percent, Autodesk follows at 29, and the two names that defined the audit era for two decades, IBM and Oracle's core licensing teams, now sit sixth and seventh. The audit letter has become the enforcement arm of the subscription pivot, and not one pure SaaS vendor made the list.
Prepared by Redress Compliance · August 8, 2026 · Advisory research. Survey of 118 enterprises, March to May 2026, plus roughly 220 audit defenses run 2024 to 2025.
Executive summary
The top of the table belongs to vendors running model transitions, not the old database names.
Broadcom is the most active software auditor in the market, named by 33 percent of the 118 responding enterprises, followed by Autodesk at 29 percent, Microsoft at 27, Oracle's Java organization at 25 and SAP at 22.
Each of the top five audited more than a fifth of respondents inside a three year window, and each runs a recognizable commercial script: Broadcom collecting the VMware repricing, Autodesk enforcing incomplete named user transitions with telemetry.
Microsoft timing SAM engagements ahead of Enterprise Agreement renewals, Oracle monetizing the Java employee metric off download records, and SAP calibrating measurement findings to the 2027 ECC deadline.
The soft audit is now the opening move, and the first reply decides the outcome.
Compliance reviews, license verification requests and friendly usage inquiries that never invoke the audit clause preceded formal contact in roughly 7 of 10 matters we defended, and the first informal reply did more damage than any later data submission.
A soft audit carries no contractual obligations, which is exactly why the casual answer is so costly: the classification decides the behavior, and the behavior decides the settlement.
Estates caught mid transition, VMware perpetual holders, incomplete Autodesk moves and confirmed Java usage, were 2 to 3 times more likely to receive contact than steady state estates.
Not one pure SaaS vendor appears in the top twenty, and that absence is the most instructive line in the data.
Salesforce, ServiceNow and Workday barely registered with respondents, not because they leave money on the table but because a SaaS vendor meters usage on its own infrastructure and enforces at renewal, where overage, repackaging and price uplift do the work an audit used to do.
Meanwhile engineering software vendors, Autodesk, Siemens, Dassault Systemes, PTC and MathWorks, hold five of the twenty positions, far above their share of IT spend, because design tool estates are easy to scan, hard to govern and historically under licensed.
The audit is a sales motion, and managing it like one moved settlements 30 to 60 percent. Across roughly 220 audits defended or supported in 2024 and 2025, speed of cooperation had almost no correlation with outcome, and full early disclosure reliably anchored the claim at the vendor's number.
Findings folded into a renewal or migration negotiation settled 30 to 60 percent below the vendor opening claim; standalone settlements rarely got below 20 percent.
The buyer side move is to slow the process down at the start, baseline first, control the data flow, and land every finding inside a negotiation you control.
The league table, and what drives each name
| Rank | Vendor | Share audited | What drives the audits |
|---|---|---|---|
| 1 | Broadcom (VMware, CA, Symantec) | 33% | Subscription bundle enforcement on perpetual VMware estates |
| 2 | Autodesk | 29% | Telemetry driven compliance on incomplete named user transitions |
| 3 | Microsoft | 27% | SAM engagements and reviews timed ahead of EA renewals |
| 4 | Oracle, Java | 25% | Employee metric monetization backed by download records |
| 5 | SAP | 22% | Annual measurement, indirect access, and the 2027 ECC deadline |
| 6 | IBM | 20% | Sub capacity and ILMT compliance at industrial scale |
| 7 | Oracle, database and middleware | 18% | Processor metrics, virtualization counting and ULA positions |
| 8 to 14 | Quest 15%, OpenText 13%, Adobe 12%, Citrix 11%, Siemens 10%, Dassault 9%, Red Hat 8% | 4 to 15% | Acquired portfolio enforcement and engineering estate scans |
| 15 to 20 | PTC 8%, Veritas 7%, MathWorks 6%, Splunk 6%, Anaconda 5%, Software AG 4% | 4 to 8% | Usage reviews, ingest metrics, and commercial use enforcement |
Oracle is counted twice deliberately. The Java compliance motion at 25 percent operates separately from database and middleware audits at 18 percent, with its own teams, its own data sources and its own commercial script, and respondents experience them as two distinct enforcement machines.
Counted as one company, Oracle rivals Broadcom for the top spot, and increasingly the Java machine writes first: industry analysts predict one in five Java users will face an Oracle audit by 2026, and our data supports it. The Oracle Java audit guide sets out the response protocol.
The five scripts at the top
- Broadcom, the acquisition enforcement playbook: after ending perpetual VMware sales, Broadcom escalated through 2025 from cease and desist letters to formal audit notices against holders who declined its bundles, in some cases within days of a support lapse. The audit establishes that patches or support were consumed beyond entitlement, then resolves the exposure through a bundle subscription; the Broadcom VMware audit defense guide covers the counter positions.
- Autodesk, telemetry does the targeting: products report installation and usage data home, so Autodesk frequently knows about over installed or lapsed deployments before it writes, and letters arrive with machine level findings. Estates that never completed the named user move are the prime target; the Autodesk audit defense guide walks the response sequence.
- Microsoft, the polite audit: it opens with a SAM engagement or licensing review through a partner, framed as helpful and timed ahead of the EA renewal, and the resolution on offer is rarely a penalty. It is Azure commitment, M365 uplift or Copilot; the Microsoft audit defense playbook covers the remediation sequence.
- Oracle Java, a compliance campaign at mass scale: friendly emails about your Java usage, backed by download and update server records Oracle has retained for years, with the employee metric turning any confirmed usage into an enterprise wide bill.
- SAP, the measurement that precedes the migration: the annual system measurement gives SAP a standing audit instrument most vendors lack, and findings surface in proximity to S/4HANA and RISE proposals, where they function as pricing pressure. The audit and the migration quote are one conversation, whichever order they arrive in.
The software audit defense playbook
Turn an audit notice into a controlled negotiation: control scope, build your ELP, and compress the opening claim.
Get the white paper →The system underneath the list
Four threads connect the whole table, and together they describe audits working as a system rather than as isolated events. Audits are a structured revenue motion, planned against quotas and fiscal calendars and timed to land where they create commercial leverage.
The soft audit is the standard opening, precisely because it carries no contractual obligations and invites the casual reply.
Acquisition is an audit trigger: Broadcom proved an acquired base can be audited into a new commercial model at speed, and Quest, OpenText with Micro Focus, Cloud Software Group with Citrix, Splunk under Cisco and Veritas follow the same logic.
Usually within 18 months of the deal and usually toward enforcement.
And targeting is data driven: download records, telemetry and expired support dates select recipients before any human writes. Exposure follows estate composition, not size.
VMware perpetual licenses on lapsed support are the single strongest audit predictor in the dataset, followed by engineering estates, unmanaged Microsoft server and hybrid positions, Java anywhere, and SAP at the 2027 crossroads.
Most respondents sat between 2,000 and 50,000 employees, large enough to carry every profile at once, and the smaller estate is not exempt: the targeting cost per letter is close to zero, so the small estate gets the automated letter while the large one gets the account team.
The audit frequency and cost report quantifies the cadence, and the cost of audit defense report prices the response.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
What we saw across 220 audit defenses, 2024 to 2025
Across roughly 220 software audits Fredrik Filipsson and the Redress advisory team defended or supported between 2024 and 2025, the survey ranking matches the casework almost vendor for vendor, and the standard advice fails the same way each time.
The standard advice says keep clean SAM records, cooperate fully, and the audit closes quickly. We disagree:
Below the opening claim, where the buyer baselined first and moved the finding into a negotiation. Standalone settlements rarely got below 20 percent.
How much more likely mid transition estates were to receive vendor contact than steady state estates.
Speed of cooperation had almost no correlation with outcome, and full early data disclosure reliably anchored the claim at the vendor's number. The matters that settled worst were almost always the ones where substantive information left the building before anyone classified the contact as an audit.
Two years ago the league table still read like the 2010s: Oracle, IBM, Microsoft and SAP at the top, engineering vendors in the tail. The 2025 to 2026 data shows three structural breaks. Broadcom went from barely registering to first place in under two years.
Oracle's Java motion now writes more letters than its database organization, a reversal unthinkable in 2020. And soft audits displaced formal ones as the default opening, which moved the decisive moment from the data room to the first reply.
None of these breaks reverse on their own: each transition hands the next acquirer a proven enforcement template, and the targeting data only accumulates. Cooperation is a posture. Control is a strategy.
The five moves, in priority order
- Treat every soft contact as the audit it is: route the friendly Java email, the SAM offer and the license review to one accountable owner, respond deliberately, and volunteer nothing. The first 48 hours checklist covers the immediate sequence.
- Baseline the top five before they write: VMware on lapsed support, incomplete Autodesk subscriptions, unmanaged SQL Server, Java anywhere, or SAP with indirect access puts you on a targeting list already. An internal baseline under your control turns a vendor's number into a negotiation instead of a verdict.
- Never settle an audit as an audit: every finding has more value inside a commercial negotiation, which is why audits arrive before renewals. Fold the resolution into the larger deal and take a written release of all historic claims as part of it.
- Control the data flow, including the automated kind: telemetry, update pings and download activity are doing the targeting, so govern what your estate reports home and run measurement scripts only on your terms, reviewed, never blind.
- Budget for it like the recurring event it now is: with the top vendor reaching a third of large estates over three years, audit response is an operating capability, not an emergency. The readiness checklist is the place to start.
Frequently asked questions
Which software vendor audits the most in 2025 and 2026?
Broadcom is the most active software auditor of 2025 and 2026, named by 33 percent of the 118 enterprises in our survey, followed by Autodesk at 29 percent, Microsoft at 27, Oracle's Java organization at 25 and SAP at 22.
The database era leaders, IBM at 20 percent and Oracle's core licensing teams at 18, now sit behind the vendors enforcing subscription transitions, overtaken in frequency though not in severity.
What is a soft audit and does it count as a real audit?
A soft audit is a compliance review, license verification request or usage inquiry that arrives without invoking the contractual audit clause, and it should be treated exactly like a formal audit.
Soft contact preceded formal invocation in roughly 7 of 10 matters we defended, and the casual first reply is where most organizations concede the information that decides the outcome. The classification decides the behavior, and the behavior decides the settlement.
Why are Salesforce, ServiceNow and Workday not in the top twenty?
Pure SaaS vendors do not need an audit clause, so they barely register in audit surveys. A SaaS vendor meters your usage on its own infrastructure and enforces at renewal, where overage, repackaging and price uplift do the work an audit used to do.
SaaS heavy organizations report fewer audits but not lower enforcement cost; the pressure simply arrives as a usage report attached to an uplift proposal, and it deserves audit grade scrutiny.
Why is Broadcom auditing VMware customers?
Because the audit is the collection mechanism for the VMware repricing.
After ending perpetual license sales, Broadcom escalated through 2025 from cease and desist letters to formal audit notices against perpetual holders who declined its subscription bundles, in some cases within days of a support contract lapsing.
The script establishes that patches or support were consumed beyond entitlement, then resolves the exposure through a bundle subscription, and the CA and Symantec estates follow the same pattern.
What triggers a software audit in 2026?
Data selects the targets before any human writes: download records, product telemetry, expired support dates and incomplete model transitions.
The strongest triggers are VMware perpetual licenses on lapsed support, the single best audit predictor in our dataset, incomplete Autodesk named user transitions, unmanaged SQL Server, confirmed Oracle Java usage, and SAP estates approaching the 2027 ECC decision.
Mid transition estates were 2 to 3 times more likely to receive contact than steady state estates.
Should audit findings be settled inside the renewal negotiation?
Yes. In roughly 220 audits we defended or supported in 2024 and 2025, findings folded into a renewal or migration negotiation settled 30 to 60 percent below the vendor opening claim, while standalone settlements rarely got below 20 percent.
Vendors time audits ahead of renewals for exactly this reason. Fold the resolution into the larger deal and take a written release of all historic claims as part of it.