Roughly half the estates licensed advanced NSX security on clusters where only basic switching and routing ran, and scoping the attach back cut that bill 25 to 45 percent
vDefend attach pricing follows host cores rather than firewall policy. That single fact makes cluster scoping a larger lever than any rate you can negotiate.
Prepared by Redress Compliance · August 19, 2026 · Broadcom VMware files with material NSX usage. 20 to 30 reviewed, 2024 to 2025.
Executive summary
Half the estates were over scoped. Across roughly 20 to 30 Broadcom VMware files with material NSX usage reviewed between 2024 and 2025, advanced security sat on clusters running only basic switching and routing.
Scoping the attach to security relevant clusters cut the attach bill 25 to 45 percent, without removing a single control from a cluster that needed one.
Flow level usage evidence moved Broadcom's position in 7 of 10 files. The manager plane already holds the evidence, and most estates never pull it before the commercial conversation.
A dense 64 core host pays the attach on all 64 cores even where the firewall policy on it is trivial, which is why attach scoping beats rate negotiation.
How is NSX packaged under Broadcom in 2026?
As the networking layer of VMware Cloud Foundation, with advanced security sold separately as vDefend attach SKUs. The freestanding NSX product line that existed before the acquisition has largely folded into that structure.
The packaging decision drives everything else. If you run VCF you already own core NSX networking, and the open question is the security attach.
If you run vSphere Foundation instead, NSX is an upgrade conversation. Broadcom documents the platform on the Cloud Foundation page.
Which capabilities sit in which package
- VCF included: virtual switching, routing, basic load balancing and the NSX manager plane.
- vDefend attach: distributed firewall, gateway firewall and advanced threat prevention, priced per core.
- Avi load balancing: advanced application delivery, licensed separately.
The wider bundle mechanics are set out in our VCF licensing guide and in how core licensing works.
What does NSX actually cost per core?
The cost follows the bundle. You pay VCF per core for the platform, then per core again for each vDefend attach on covered clusters, with a 16 core minimum per CPU.
The published structure sits on the Broadcom software portfolio pages, but street pricing is set deal by deal.
The compounding is what surprises buyers. A dense 64 core host pays the attach on all 64 cores even if the firewall policy on it is trivial.
The five drivers, and what to do about each
| Cost driver | Effect on the bill | Buyer response |
|---|---|---|
| Host core density | Attach cost scales with cores, not usage | Scope attaches to security relevant clusters |
| 16 core minimum per CPU | Small hosts pay phantom cores | Consolidate hosts before renewal |
| Enterprise wide attach scope | Pays for features most clusters never run | License by cluster, prove usage |
| Threat prevention tier | Highest rate in the attach family | Reserve for regulated or exposed segments |
| Renewal uplift | Compounds the whole stack annually | Cap increases in the order form |
Current platform pricing detail sits in our VCF pricing analysis for 2026.
- Your quote benchmarked against real closed Broadcom deals by estate size
- Every renewal clause flagged with the quote, the page, and replacement language
- The attach scope modelled by cluster, so the cut list is priced before the call
How do you rightsize an NSX heavy estate?
By cluster, not by estate. Map which clusters carry regulated workloads, exposed services or genuine microsegmentation policy, and license the security attach there only.
In our file that scoping cut attach spend 25 to 45 percent. Treat the rest of the estate as a candidate for native vSphere controls or third party tooling.
The point is not to rip NSX out. It is to stop paying advanced security rates on clusters running basic switching.
How to verify what actually runs
Pull distributed firewall rule counts, flow statistics and feature flags from the NSX manager before any commercial conversation. The technical documentation describes the operational reporting available, and that output is your negotiation evidence.
Three levers, in the order they work
- Scope reduction: present the cluster map and remove the attach from clusters without security policy.
- Core consolidation: retire or merge low density hosts so the 16 core minimum stops manufacturing phantom cores.
- Alternative pressure: price third party firewalls or native controls for the clusters Broadcom wants to defend.
Support commitments should be held to written terms rather than to assurances, and the support portal is where those terms are published.
The VMware bundle negotiation brief
Seven buyer side levers on a VCF or VVF bundle, the core minimum trap, and where the price actually moves.
Get the brief →What 20 to 30 NSX files showed
Across the Broadcom VMware files with material NSX usage reviewed between 2024 and 2025, NSX was consistently over scoped.
The three patterns that recurred
- Roughly half the estates licensed advanced NSX security features on clusters where only basic switching and routing ran.
- Scoping vDefend attach SKUs to security relevant clusters cut the attach bill 25 to 45 percent.
- Estates that produced flow level usage evidence at renewal moved Broadcom's NSX position in 7 of 10 files.
None of those three requires a change to how the estate runs. All three require evidence that the manager plane is already producing.
Research briefingThe VMware estate, and what Broadcom prices it onWhere core counts, bundle scope and attach SKUs meet, and which of them a buyer can still move at renewal.
Where the common advice on NSX licensing is wrong
The standard partner guidance is to license vDefend across the whole estate for consistency, on the theory that uniform coverage simplifies operations and audits. We disagree.
In roughly 12 of the files reviewed in 2024 to 2025, uniform coverage meant paying advanced security rates on a majority of cores that ran nothing beyond default policy. The simplification argument never survived contact with the invoice.
Cluster scoped licensing with documented flow evidence passed every true up we defended. Segment the estate by security requirement, license the attach where the requirement is real, and let the usage evidence carry the audit conversation.
vDefend attach pricing follows host cores rather than firewall policy, which makes cluster scoping the largest single NSX cost lever.
Without removing a control from any cluster that needed one.
Advanced features licensed where only switching and routing ran.
Flow level data from the manager plane, presented at renewal.
Should NSX ride the VCF renewal or stand alone?
Ride the VCF renewal. Bundling the attach decision into the platform negotiation gives you a bigger number to trade against.
Broadcom quarter end dynamics apply to the combined deal, and a standalone attach conversation forfeits that leverage entirely.
Where the wider negotiation sits
The full approach is covered in negotiating with Broadcom, and the 2026 specific position in our Broadcom negotiation guide.
Your first five moves
- Inventory NSX feature usage by cluster from the manager plane, before anybody quotes anything.
- Map clusters to real security requirements and regulated workloads, then build the cut list from that map.
- Rescope vDefend attaches to the clusters that justify them and leave the rest on native controls.
- Consolidate low density hosts ahead of the core count snapshot, so the 16 core minimum stops manufacturing phantom cores.
- Fold the NSX position into the VCF renewal at quarter end rather than negotiating the attach on its own.
Frequently asked questions
How is NSX packaged under Broadcom now?
As the networking layer of VMware Cloud Foundation, with advanced security sold separately as vDefend attach SKUs priced per core.
How over scoped were the estates reviewed?
Roughly half licensed advanced NSX security features on clusters where only basic switching and routing ran.
What does cluster scoping actually save?
Scoping vDefend attach SKUs to security relevant clusters cut the attach bill 25 to 45 percent across the files reviewed.
Why does host density matter so much?
Because the attach scales with cores rather than usage. A dense 64 core host pays the attach on all 64 cores even where the firewall policy is trivial.
What is the 16 core minimum?
A per CPU floor that makes small hosts pay phantom cores. Consolidating low density hosts before the core count snapshot removes that waste.
Does usage evidence really move the price?
It moved Broadcom's NSX position in 7 of 10 files. Flow level data from the manager plane is the evidence that does it.
Where do you pull that evidence from?
Distributed firewall rule counts, flow statistics and feature flags from the NSX manager, gathered before any commercial conversation opens.
Should vDefend cover the whole estate?
No. In roughly 12 of the files reviewed, uniform coverage meant paying advanced rates on a majority of cores running nothing beyond default policy.
Does cluster scoping survive a true up?
Cluster scoped licensing with documented flow evidence passed every true up we defended. The evidence is what carries it.
Should NSX be negotiated separately from VCF?
No. Ride the VCF renewal, because the combined deal gives you a bigger number to trade against and quarter end dynamics apply to it.