Skip to content

Procurement

DDoS Appliance Licensing Models Explained

Last updated: August 2026 · What renews, what expires, what stops · Reading time ~13 min

Four identical stone jars in a row, each closed differently — a hinged clasp, a poured wax seal, a tied cord band and a hasp with a pin — with four separate amber threads running from the closures off to one side.

Licensing decides what a DDoS appliance costs over its life and, in some designs, whether it keeps working. Three questions separate suppliers more than any other: what happens at the end of a support term, whether the next capacity step is a licence change or a hardware change, and whether a failed licence check can stop enforcement. All three are answerable in writing and rarely volunteered.

Licensing is treated as the commercial team’s problem and evaluated after the technical decision is made. That sequence is backwards for this category, because several licensing mechanisms are technical properties wearing commercial clothes — they determine capacity, availability and failure behaviour, not merely price.

At a glance

ApplianceMechanismWhat it metersThe question it raises
Throughput or packet-rate tierA ceiling below the hardware's capabilityWhat is the step cost, and how fast can it be applied?
Feature licenceWhich countermeasures are enabledIs anything you evaluated separately licensed?
Protected-object or tenant countHow many zones, addresses or customersWhat happens when you exceed it — refuse, or bill?
Subscription termThe right to run the software at allWhat is the behaviour after expiry?
Support and maintenanceUpdates, TAC access, hardware replacementDoes lapsing stop updates only, or protection?

The five mechanisms combine differently in every product. What matters is not which combination is used but which of them can interrupt enforcement.

Capacity licensing, and the number you were quoted

The most common arrangement in this category is one hardware platform sold at several capacities, with a licence setting the ceiling.

This is sound engineering economics and a genuine convenience: growth becomes a licence transaction instead of a replacement, and the manufacturing volume of a single platform lowers cost for everyone. It also means a specification sheet and a quotation can describe the same box and different capabilities, which is the gap discussed in how to read a datasheet.

Three things to establish, all in writing:

Which ceiling is licensed and which is physical. They are different numbers and only one is usually printed.

The cost and mechanics of the next step. A licence key applied in minutes and a hardware exchange requiring a maintenance window are the same line item on a roadmap and entirely different events in practice.

Whether an emergency uplift exists. Capacity ceilings are reached during attacks. Whether a temporary increase can be authorised out of hours, by whom, and how long it takes to apply, is a question with a factual answer that nobody asks until the night it matters.

Feature licensing

Some products license countermeasures separately: application-layer inspection, particular protocol protections, reporting depth, tenancy.

The evaluation risk is specific and easy to fall into. A proof of concept is typically run on a fully enabled unit, because the supplier wants the product to show well and has no reason to cripple it. If the quotation then licenses a subset, the thing that was measured is not the thing being bought.

The defence costs one line in the tender: state which of the capabilities demonstrated during evaluation are separately licensed, and price them. Ask it before the demonstration rather than after.

Subscription, perpetual, and what the words mean here

The distinction is less clean in this category than in software generally.

A perpetual licence conveys the right to run the version you have, indefinitely. What it does not convey is updates, support, or — in some designs — the continued validation that lets the software start.

A subscription conveys the right to run for a term, with updates and support usually included. The behaviour at term end is a design decision, and it varies.

The important question is not which word the supplier uses. It is: on the day the term ends and nothing is renewed, what does the appliance do? The answers across this category range from continuing indefinitely without updates, through a documented grace period, to ceasing enforcement. The last is compatible with a subscription business model and is incompatible with a defence, unless the grace period is long enough to survive an ordinary procurement delay.

That behaviour belongs in the contract with a number attached, for the reasons set out in fail-operational requirements — where the same mechanism appears as an availability risk rather than a commercial term.

Support and maintenance renewal

Support renewal is where the five-year cost quietly accumulates, and where the largest divergence between suppliers sits.

Establish the annual percentage and whether it is calculated on list or on the price actually paid — the difference compounds substantially over five years. Establish whether renewal pricing is capped by the contract or reset at the supplier’s discretion. And establish the reinstatement cost of a lapsed agreement, which is frequently punitive and is the mechanism by which a lapse becomes expensive rather than merely inconvenient.

Ask what lapsing actually stops. If it stops updates, that is a manageable, dated risk. If it stops enforcement, support renewal is not a maintenance decision at all.

Counted objects

Some products meter protected addresses, zones, or tenants rather than throughput.

This aligns cost with what is being protected, which is reasonable. The question is the behaviour at the ceiling: does the product refuse to protect the next object, or protect it and generate a commercial conversation later? Both exist, and the first is an outage waiting for the day someone adds a service.

For service providers this interacts with tenancy in a way worth modelling explicitly, since per-tenant licensing turns the resale margin into a function of the licence structure rather than of the hardware.

Where to put each question

The behavioural questions belong in the technical specification, because technical evaluators are the ones who understand why they matter:

  • Expiry behaviour and grace period, with a number.
  • Whether a licence check sits in the enforcement path, and its failure mode.
  • Which capabilities demonstrated in evaluation are separately licensed.
  • Behaviour at a counted-object ceiling.
  • Emergency capacity uplift: whether, who, how long.

The financial questions belong in the commercial annex, where a five-year table with support renewal, one capacity step and no hidden reinstatement clause is the deliverable. The five-year cost model provides the structure with every line item visible and no supplier-supplied defaults.

Which of the two structures — capital purchase or continuing subscription — suits a given balance sheet and a given risk appetite is a separate argument, worked through in CapEx or subscription.

Frequently asked questions

Is a licence ceiling below hardware capability dishonest?
No, and treating it as such misreads the economics. One manufactured platform serving several price points lowers unit cost for everyone and lets a customer grow without a forklift. The problem is not the mechanism; it is a datasheet that prints the hardware figure while the quotation licenses a fraction of it, and a buyer who never asks which number they are being sold.
What is the single most valuable question here?
What happens on the day support lapses. Across this category the answers range from "updates stop and everything else continues" to "protection ceases", and the difference is worth more than most technical differentiators. It also predicts renewal negotiations for the rest of the relationship, because a supplier whose product stops has considerably more leverage than one whose product merely ages.
How does licensing interact with an incident?
Badly, if a ceiling is reached during one. A throughput tier hit under attack behaves like a capacity limit, and raising it takes a purchase decision, a licence issue and an application step — none of which fit inside an incident. Establish the emergency path before signing: whether a temporary uplift exists, who can authorise it out of hours, and how long applying it takes.
Should licensing terms appear in the technical specification?
The behavioural parts should. Expiry behaviour, grace periods and whether a licence check sits in the enforcement path are technical properties with commercial packaging, and leaving them to the commercial annex means the technical evaluators never see them and the commercial team does not know they matter.

Sources

  1. Regulation (EU) 2022/2554 (DORA)

    EUR-Lex · 2022-12-14 · regulator · accessed 2026-08-16

    Contractual requirements for ICT third-party arrangements, including exit and termination terms.

  2. Directive (EU) 2022/2555 (NIS2)

    EUR-Lex · 2022-12-14 · regulator · accessed 2026-08-16

Published: August 2026 · Last reviewed: August 2026

Reviewed means the sources above were re-read on that date; the text is only reissued when something material changed.

This guide is updated as vendors release new models and pricing. How we compare vendors