Skip to content

Report · Price Index · 2026

Security Tooling Price Index 2026: What Each Control Actually Costs

By SecurityBudget Research Team · published Jun 20, 2026 · updated Jun 24, 2026

Vendor-neutral 2026 unit pricing for endpoint, identity, email, SIEM, MDR, cloud, PAM, DLP, compliance, and pentest controls.

Methodology
Key findings
  • Core per-user controls (endpoint, identity, email) typically run $9–$40 per user per month combined.
  • Negotiated pricing commonly lands 20–40% below published list rates on multi-year deals.
  • SIEM and MDR are the line items most likely to surprise, scaling with data volume and endpoint count.
  • Compliance program costs range from about $15K (HIPAA) to $60K (GDPR) per year, separate from tooling.

Most security budgets are assembled control by control, yet published vendor pricing rarely tells the whole story — and rarely tells it in comparable units. This price index normalizes the major control categories into the units buyers actually negotiate (per user, per endpoint, per workload, per engagement, per year) using vendor list pricing cross-checked against Vendr buyer data, all verified in June 2026. Treat every figure as a planning range, not a quote.

How to read these numbers

Unit pricing varies by tier, commitment length, and bundle. A “typical” figure here is the rate a mid-market buyer commonly lands at, not the cheapest entry tier or the enterprise ceiling. Per-user controls scale with headcount; per-endpoint controls scale with device count, which often exceeds headcount once servers and cloud instances are included; and volume-based controls like SIEM scale with data, which is the hardest input to estimate in advance.

The most expensive surprises are almost never the per-user tools. They are the volume-scaled line items — SIEM ingest and MDR endpoint counts — where the meter runs faster than headcount.

Per-user and per-endpoint controls

These are the recurring subscriptions that form the backbone of most programs. Endpoint protection (EDR/XDR), identity (MFA/SSO and lightweight PAM), and email security are the three most common starting points.

ControlUnitRangeTypical
Endpoint (EDR/XDR)per user / mo$3–$20~$8
Identity (MFA/SSO/PAM-lite)per user / mo$3–$12~$7
Email securityper user / mo$2–$8~$4
DLPper user / mo$3–$15~$5
MDRper endpoint / mo$3–$45~$6

Combined, the three core per-user controls typically run $9 to $40 per user per month, with most mid-market buyers landing near the lower-middle of that band. MDR is priced per endpoint rather than per user, so a fleet with many servers and shared devices can cost more than a headcount-based estimate suggests.

Volume-scaled and per-asset controls

These categories do not track headcount cleanly, which makes them the most common source of budget variance.

ControlUnitRangeTypical
SIEMper year (ingest-based)$30K–$150K~$70K
Cloud security (CSPM/CNAPP)per workload / yr$60–$1,200full CNAPP ~$30K–$60K/yr
PAMper privileged user / yr$300–$8,000privileged ≈ 10% of staff
Vuln managementper asset / yr$17–$42~$30

SIEM pricing is driven by data ingested, not seats, so two organizations of identical size can see very different bills depending on log volume and retention. Cloud security follows a similar pattern: a mid-market estate of around 40 workloads commonly lands at $30K–$60K per year for a full CNAPP, but the per-workload rate spans a wide $60–$1,200 depending on depth (posture-only versus runtime). PAM is best estimated by counting privileged users — roughly 10% of staff is a reasonable planning assumption — rather than total headcount.

Project-based and program costs

Not every control is a subscription. Penetration tests are bought per engagement, and compliance is an ongoing program cost that sits alongside, not inside, tooling.

ItemUnitRangeTypical
Penetration testper engagement$5K–$50K~$18K
Compliance — HIPAAper year~$15K
Compliance — PCI DSSper year~$20K
Compliance — SOC 2per year~$40K
Compliance — ISO 27001per year~$40K
Compliance — GDPRper year~$60K

Compliance figures represent annualized program cost — audits, tooling overhead, and internal effort — and exclude the security controls themselves, which are budgeted separately above. A penetration test at the high end of the range typically reflects a larger scope or a specialized environment rather than a premium for the same work.

List price versus negotiated price

Published pricing is the starting point of a negotiation, not its conclusion. Across the categories in this index, Vendr buyer data shows negotiated deals commonly landing 20–40% below list, with the larger discounts concentrated in multi-year commitments, multi-product bundles, and end-of-quarter timing. Per-user tools tend to discount on the lower end of that band; larger annual contracts like SIEM and PAM tend toward the higher end. Build budgets against list price for safety, then treat the negotiated savings as upside rather than assumed. No tool or bundle eliminates risk on its own, so resist letting a discount drive which controls you adopt.

How to use this

These unit prices are planning ranges meant to be combined against your real environment — headcount, endpoint count, workload count, and privileged-user count. To assemble them into a full program estimate and compare it against spend benchmarks, run the cybersecurity budget calculator, then use these ranges as a checklist when reviewing vendor quotes line by line.

Sources

Figures are based on public pricing, industry benchmarks, and security frameworks. For planning only — not professional, financial, or legal advice.

See it for your organization

Turn these benchmarks into a budget tailored to your risk profile — free and ungated.

Open the calculator