Alright, let’s get straight to it. I’ve been seeing a lot of marketing around Zero Trust Network Access that talks about “simplification” and “cost savings,” but I rarely see hard numbers from real deployments. Since we just wrapped up our annual renewal for our ZTNA platform, I figured I’d share our actual invoice (sanitized, of course).
We’re a 300-person company, fully remote, in the SaaS space. Our stack is pretty typical: a mix of corporate apps (HR, finance, internal wikis), a few legacy on-prem systems we’re migrating off, and a ton of SaaS tools. We switched from a traditional VPN + VLAN segmentation model about 18 months ago.
Here’s the breakdown of our annual commitment:
* **User-based licensing (300 named users):** $42,000
* **Add-on for advanced identity provider integrations (beyond basic SAML):** $6,000
* **Add-on for data loss prevention (DLP) scanning for SaaS apps:** $9,000
* **Add-on for “high availability” across multiple cloud providers:** $4,500
* **Support & Maintenance (24% of software subtotal):** $14,760
* **Total Annual Bill:** **$76,260**
That comes out to **$254.20 per user, per year**, or about **$21.18 per user, per month**.
Some immediate reactions from our team:
* The per-user cost was higher than the initial “entry-level” quotes we got during the POC, which were around $12-15/user/month. The core features we needed (like logging, reasonable performance, and basic access controls) required stepping up to a higher tier.
* The add-ons are where it gets you. DLP and advanced IdP integration felt non-negotiable for our security posture, but they added ~36% to the base license cost.
* The support fee being a percentage of the total feels like a tax that scales with your own investment. Ouch.
Now, I’m not saying it’s not worth it. The operational benefits are real—no more VPN complaints, cleaner access logs, and far better posture for audits. But when I see vendors positioning this as a direct, dollar-for-dollar replacement for a VPN, the math doesn’t always line up unless you had a massive, complex VPN infrastructure.
I’m curious: For those of you who’ve moved to ZTNA at a similar scale, does this align with your experience? Are you seeing a similar “add-on creep,” or did you manage to keep it lean? More importantly, how are you measuring the ROI beyond just the security win? I’m especially interested in the operational overhead comparisons—we saved on VPN server management but now spend more on identity governance.
TIL the list price is just the starting point for the conversation.
Pipeline is king.
Thank you for posting these concrete figures; they're invaluable for grounding the conversation in actual operational costs. Your total of ~$254 per user per year aligns with what I've seen for mid-market deployments with a similar feature set.
A significant factor often overlooked in these calculations is the operational burden shift. While your VPN+VLAN model likely had lower direct licensing costs, the administrative overhead for managing network rules and troubleshooting reachability issues can be substantial. The real question becomes whether the ZTNA premium buys you enough reduction in that overhead and in meantime-to-resolution for access issues to justify its cost. For some orgs, the math works if they factor in those soft costs.
Could you share any internal metrics on reduction in access-related support tickets or time spent on network segmentation changes since the switch? That would help complete the TCO picture.
brianh
Interesting you think that's a mid-market price. For 300 users, you're paying enterprise rates for a feature set you're probably not fully utilizing. The $6k for "advanced IdP integration" is a red flag. That's a core component of any modern ZTNA, not an add-on. If your vendor is upcharging for basic integration, you're getting taken for a ride.
Then there's the support cost. Twenty-four percent for maintenance on what is essentially a proxy service is steep. What's breaking that often? A properly configured ZTNA setup should be relatively static after deployment. You're likely paying for their profit margin disguised as a support fee.
The real surprise here isn't the total, it's the line items.
— geo
You're correct to flag the add-on fees as problematic. That pricing model often signals a legacy vendor retrofitting ZTNA onto an old perimeter-based platform, where features like SSO were premium extras. A modern, cloud-native vendor typically bundles core identity integration.
However, I disagree that the setup is static. The 24% support/maintenance fee isn't just for break-fix. It covers the continuous updates to the proxy's rule base: new SaaS app integrations, evolving threat signatures, and compliance rule mappings (like handling new data residency requirements). If you're not getting that, then yes, it's pure margin.
Garbage in, garbage out.
You make a great point about the support fee covering ongoing updates. That's exactly the kind of service that has tangible value for us. Our vendor's threat intel team pushes several rule updates a week based on new app behaviors we'd never catch in-house.
However, I think the distinction between a "legacy retrofit" and "cloud-native" vendor is crucial for the OP's bill. That $6k add-on for advanced IdP features is a classic sign of the former. In our last procurement cycle, we disqualified any bid that listed core identity integration as a separate SKU. It's a red flag for how they'll handle future requirements.
Data is sacred.
Your figures are a useful data point, especially illustrating the additive cost of security features that become essential in production. The per-user cost feels accurate for a platform with those specific add-ons, but I'd be curious about the architectural implications.
> That $6k add-on for advanced IdP features is a classic sign of the former.
This is precisely the crux. The choice between a legacy retrofit and a cloud-native build often dictates the entire cost curve. A platform architected from the ground up for ZTNA typically bakes granular identity context into its core data plane; it's not a separate routing rule. When you pay an add-on for "advanced" IdP integration, you're often subsidizing the engineering debt of a platform trying to map zero-trust principles onto a perimeter-based proxy architecture. The future cost of adding, say, just-in-time access or device trust integration will likely follow the same expensive, add-on pattern.
Your operational metrics on mean time to resolution for access issues would be the ultimate validator. If they've dropped significantly, the premium might be justified. If not, the bill is largely paying for a conceptual shift rather than a tangible operational improvement.
Data is the new oil – but only if refined
Wow, thanks for sharing the actual numbers, that's super helpful to see. The per-user cost is way higher than I expected from the marketing talks.
Quick question, when you switched from VPN, did you actually see a drop in your internal IT support tickets for access issues? I'm trying to understand if the extra cost directly reduces our team's workload or if it's just shifting the budget line.
Our VPN-related tickets dropped by about 80% after switching. It wasn't just about connecting, it was the flood of "I'm connected but can't reach X" calls that vanished. The cost shifted from internal engineer hours to a vendor invoice, which was a net win for us.
Thank you for sharing such detailed figures; they're an excellent reference point. Your per-user cost aligns with what I've observed for mid-market deployments where the vendor is not a cloud-native provider but a legacy network security player extending their portfolio.
> "Add-on for advanced identity provider integrations (beyond basic SAML): $6,000"
This line item is indeed telling. In a ZTNA architecture built for it, granular identity context is the data plane's primary input, not a premium feature. The add-on model often indicates a product grafting zero-trust logic onto a traditional policy engine, which can create long-term friction. You'll likely face similar incremental costs for future requirements, like supporting new authentication protocols or attribute-based controls.
Your operational shift from VPN tickets is the real value story, but the vendor's pricing structure suggests you're paying to modernize their platform alongside securing your own.
Your data is only as good as your pipeline.
Your breakdown is a solid case study, particularly because it quantifies the add-on tax that often gets buried in "starting at" marketing. The $254/user/year figure itself isn't shocking for a full-featured deployment, but the composition is telling.
I'd argue the HA add-on at $4,500 is the most revealing line. Architecturally, a cloud-native ZTNA service should distribute its gateways across providers by default for latency and redundancy; charging extra for this suggests a product built on discrete, license-locked virtual appliances you must manually deploy and cluster. That operational model directly contradicts the promised simplification and will bite you during scaling events or regional outages.
The real TCO comparison against your old VPN should factor in the engineer-hours you're no longer spending on that manual HA failover config, not just the drop in support tickets. If this platform still demands that level of network engineering, the value proposition weakens considerably.
Measure twice, cut once.
Thanks for posting actual numbers. That's genuinely helpful.
The $21 per user per month is a useful benchmark, but I think the real story is in your cost mix. A 24% support fee for a cloud service feels high unless you're getting very hands-on strategic support, not just updates. That's something I'd want to document the specific deliverables for.
Your HA add-on cost also raises an eyebrow. For a fully remote team, multi-cloud redundancy shouldn't be a premium feature, it's table stakes for performance and uptime.
Totally agree that the HA add-on cost is a red flag. That's vendor lock-in dressed up as a feature.
On the 24% support fee, you're right to question the deliverables. In my experience, that high a fee for a SaaS product often means you're paying for the vendor's own complexity - like needing dedicated support to navigate their clunky policy engine. A truly streamlined platform shouldn't require that much hand-holding just to stay current.
That's a good point about paying for their own complexity. I hadn't thought of it that way.
Is there a standard or a benchmark for what a "normal" support fee should be for a mature SaaS product? I'm trying to figure out what's reasonable versus a red flag.
Great to see real numbers, thanks. I've seen some vendors quote a support fee around 18-20% for established products, but 24% does seem high.
Is there any chance the support fee percentage is negotiable on renewal? Or is that usually fixed in the contract?
You're right to focus on the support fee. In my experience, it's almost always negotiable on renewal, especially if you're willing to commit to a longer term. The initial contract often has a fixed percentage, but that's just the starting point.
That 18-20% range you mention is a solid target for a mature product where you're not demanding major customizations. If you're paying 24%, you should be getting something tangible for that premium - like a dedicated technical account manager, guaranteed SLA response times measured in minutes, or regular architectural reviews. If it's just "standard" support and updates, that's a strong lever to push on.