Managed Firewall Pricing 2026: What Mid-Market Teams Actually Pay

Managed firewall pricing benchmarks for Europe and North America, what the monthly fee hides, and the seven questions to ask before signing an MSP quote.
Business owner and IT consultant reviewing two printed service quotes side by side at a meeting table in a small office

Two managed firewall quotes for the same 100-user company, two sites, same requirement. One comes in at €140 a month. The other at €900. Neither provider is lying, and the difference is not margin — it is scope. The cheap quote covers uptime monitoring and firmware patching. The expensive one includes round-the-clock monitoring, the vendor security subscriptions, a defined number of rule changes and an SLA with credits attached.

Comparing managed firewall proposals means unbundling them, because the monthly figure on the front page tells you almost nothing on its own. This guide sets out what the market actually charges in Europe and North America, what the fee does and does not include, the lifecycle costs that appear in year four rather than year one, and the questions worth asking before you sign.

The five ways it gets priced

Per appliance, per month. The traditional model: a flat management fee per physical unit, scaled by throughput and site complexity. Predictable for one office, linear when you have eight.

Per user. Common when the firewall disappears into a broader managed IT agreement at roughly ≈€92–€230 ($100–$250) per user per month, covering helpdesk, endpoint protection and perimeter security together. Convenient to budget, impossible to benchmark.

By throughput. Tiered on provisioned bandwidth and inspection depth. Mostly seen in data centre and heavy WAN edge deployments.

Co-managed versus fully managed. Fully managed hands over monitoring, rule changes and patching entirely. Co-managed keeps policy authority in-house while the provider takes alert triage and maintenance, which typically reduces the monthly retainer by 20% to 35%.

Setup and onboarding. A one-off charge for scoping, rule translation, staging and cutover testing, generally ≈€415–€3,035 ($450–$3,300) per site — in practice two to three months of the recurring fee.

What the market charges

Organisation size Per-appliance monthly fee (North America) One-off setup
10–25 users ≈€300 – €390 ($325 – $425) ≈€415 – €645 ($450 – $700)
26–50 users ≈€485 – €665 ($525 – $725) ≈€645 – €1,060 ($700 – $1,150)
51–100 users ≈€715 – €1,080 ($775 – $1,175) ≈€1,060 – €1,750 ($1,150 – $1,900)
100–500 users ≈€1,080 – €1,355+ ($1,175 – $1,475+) ≈€1,750 – €3,035 ($1,900 – $3,300)
European market reference points Published entry price Model
UK managed firewall providers ≈€58 – €290 (£50 – £250) per site/month Tiered per site, hardware included
Netherlands / Belgium From €85 – €180 per month Managed service retainer per device
Germany From €49 – €99 per month Per device base rate, plus setup
France From €80 per month Per gateway, excluding VAT and setup
Software-only firewall management (EU/UK) ≈€207 (£179) per firewall/month Flat per-firewall licence tier

Converted from USD at ≈€0.92 and GBP at ≈€1.16 (August 2026); local pricing and VAT treatment differ by market. European entry prices are starting rates and typically exclude vendor security subscriptions.

Two things are worth noting before you use these as a target. European entry-level pricing looks dramatically cheaper than North American pricing largely because it is quoted differently: a €49 starting rate is a base management fee, while a $775 North American figure usually bundles monitoring and licensing. And the whole market has moved — managed firewall pricing rose 39% to 49% across size segments between 2022 and 2025, driven by compliance requirements and the cost of round-the-clock monitoring.

What the fee covers, and what it doesn’t

A standard agreement usually includes health and uptime monitoring, scheduled firmware and patch maintenance, a capped number of routine rule changes, and monthly reporting. That is a genuinely useful baseline, particularly since something between 95% and 99% of firewall breaches trace back to misconfiguration rather than a hardware flaw — policy governance is the actual product you are buying.

The exclusions are where quotes diverge:

  • Vendor security subscriptions. Intrusion prevention, gateway antivirus, URL filtering, application control and sandboxing are sold by the hardware manufacturer at roughly ≈€920–€1,840 ($1,000–$2,000) per device per year, passed straight through to you. That is ≈€75–€150 ($80–$165) a month on top of the management fee, and it is the single most common reason two quotes differ.
  • High availability. An active/passive pair doubles hardware and licensing and raises the management fee. Enterprise MSSP retainers for HA configurations run from ≈€1,380 ($1,500) to ≈€6,900 ($7,500) a month depending on throughput and network role.
  • Emergency and out-of-hours work. Routine patching during business hours is standard. Deploying an emergency fix for an actively exploited vulnerability at 2am is usually billed separately.
  • On-site hardware work. Replacing a failed power supply or chassis means dispatching an engineer, which falls outside remote management unless a hardware-as-a-service SLA says otherwise.

Out-of-scope labour is billed at roughly €59–€99 per hour in continental Europe, ≈€930–€1,160 (£800–£1,000) per engineer per day in the UK, and ≈€115–€207 ($125–$225) per hour in North America. Standard change requests typically carry a 24 to 48 hour turnaround; anything faster is a priority charge.

The cost that shows up in year four

Here is the line item that almost never appears in a quote: the appliance has an expiry date.

Manufacturers set end-of-sale and end-of-support milestones on a three-to-five year cycle. When a firewall passes end of support, firmware updates, security patches, signature feeds and hardware replacement all stop at once. That is not a theoretical schedule — it is a published one. The FortiGate 100E and 80E reached end of support on 17 August 2026, and the 60E follows on 29 December 2026, as documented in our FortiGate hardware end-of-life timeline. On the WatchGuard side, the T35, T55 and T70 went end of life on 31 December 2025 and the entire M270–M670 generation follows on 1 July 2028, set out in our WatchGuard Firebox end-of-life guide.

Vendors apply commercial pressure as those dates approach; WatchGuard added renewal surcharges of up to 16% on the retiring T35/T55/T70 generation in their final support phase. Meanwhile the risk of deferring the refresh is no longer abstract: the share of breaches involving exploitation of edge devices and VPNs jumped from 3% to 22% in a single year according to Verizon’s 2025 breach report, while the median time to patch an edge device stood at 32 days and only 54% of edge vulnerabilities were remediated within a year. An unsupported firewall also gives cyber insurers grounds to contest a claim and puts you outside what NIS2, ISO 27001 and PCI-DSS expect of a security control.

So the honest budget for a managed appliance includes a hardware refresh every three to five years, the migration labour that comes with it, and the emergency patch windows in between.

Three-year economics

For a 100-user organisation across two sites, over 36 months:

Cost element Managed physical appliances (two mid-range units) Integrated flat-rate SASE platform
Initial hardware and setup ≈€2,115 – €3,495 ($2,300 – $3,800) ≈€0 – €920 ($0 – $1,000) cloud tenant setup
Management and service fees ≈€25,670 – €38,915 ($27,900 – $42,300) Flat platform subscription
Vendor security subscriptions ≈€5,520 – €11,040 ($6,000 – $12,000) Included in the platform
Out-of-scope change requests ≈€1,955 – €3,280 ($2,124 – $3,564) Self-service policy changes
Hardware refresh provision ≈€2,760 – €5,520 ($3,000 – $6,000) No edge hardware to replace
36-month total ≈€38,020 – €62,250 ($41,324 – $67,664) Predictable operating expenditure

Converted from USD at ≈€0.92 per US dollar (August 2026); local EUR pricing may differ. Platform subscription costs vary by provider and are deliberately not modelled as a single figure.

Where each model wins is fairly clear-cut. For a single static office, a managed appliance remains price-competitive at the entry point, and the difference only accumulates through change fees and the refresh provision. For five or more sites the appliance model deteriorates fast: hardware, setup, subscriptions and VPN mesh maintenance all multiply per location. And for hybrid workforces the appliance model quietly pays twice, once for the perimeter firewall and again for remote access infrastructure that inspects traffic somewhere else entirely.

One caution when comparing against cloud alternatives: appliance vendors moving into SASE often price in tiers that hide the real number. Published entry pricing of around ≈€83 ($90) per user per year can reach ≈€193–€230 ($210–$250) once multi-factor tokens, endpoint management, compute region access and bandwidth allocation are added — the pattern we documented in our breakdown of what FortiGate customers actually pay for FortiSASE and in single-vendor versus multi-vendor SASE cost. Ask any cloud provider for the all-in figure at your user count, not the entry tier.

Seven questions for any quote

Ask Warning sign What good looks like
How many policy changes are included, and what is the rate beyond that? “Unlimited changes” with no definition of out-of-scope A stated monthly allowance and a published hourly rate
Who owns the hardware during and after the term? Hardware markup bundled into the fee with no ownership stated Explicit hardware-as-a-service lease including replacement
What happens when the appliance reaches end of support mid-contract? The customer carries the full replacement cost Refresh included at no additional capital cost
What is the SLA for patching an actively exploited vulnerability? “Regular maintenance” with no timeframe Critical patches within days; emergency fixes within 48 hours
What does exit cost, and will we get our configuration? Extraction fees or refusal to export rule sets 30-day notice and full configuration export at no charge
What service credits apply if availability targets are missed? “Best effort” with no binding remedy A defined availability target with proportional credits
Can we benchmark pricing mid-term? Fixed pricing for 3–5 years with no adjustment mechanism A formal review at month 18 against market rates

When the classic managed appliance is still right

“A local appliance means local control and lower latency.” For east-west traffic between internal segments, genuinely true — local filtering avoids a round trip, which matters in industrial networks and media production. For everything else it works against you: most mid-market traffic goes to cloud applications, and hairpinning that through an on-premises box adds latency rather than protection.

“Our MSP knows our network.” That relationship has real value, and it is worth keeping. What it does not do is change a vendor’s end-of-support date or patch an edge vulnerability at the weekend — smaller providers often run business-hours engineering rather than a round-the-clock operations centre. This is not an either/or: many providers now keep the customer relationship while delivering security from a cloud platform, which is exactly the shift described in how MSPs deliver managed SASE without tool sprawl.

“The bundle is simpler and cheaper.” Simpler to approve, harder to evaluate. Bundling hides the hardware markup and the subscription pass-through, and the low first-year number is frequently recovered through change fees, annual licence increases and an unbudgeted refresh in year four.

There are environments where the physical appliance remains the correct answer regardless of the economics: isolated industrial and OT networks that must stay off public cloud routing paths, facilities with heavy local east-west traffic, and sectors under data residency rules that restrict routing control planes through multi-tenant infrastructure. Outside those, the decision usually comes down to how many sites you have and whether you want to repeat this procurement in four years.

Unbundle before you compare

Take every quote on your desk and split it into five numbers: management fee, vendor subscriptions, change-fee exposure, HA cost and the refresh provision. Quotes that looked three times apart usually converge — and the one that still looks cheap after the exercise is usually the one that excluded the most.

If that exercise makes the appliance treadmill look less attractive than it did, that is the point at which most mid-market teams look at doing it differently. Jimber delivers firewall-as-a-service alongside ZTNA network isolation, secure web gateway and SD-WAN from a single EU-sovereign platform at a predictable flat rate: no hardware to refresh, no per-change invoices, no end-of-support date on your calendar. Book a demo and bring your current quote — we will map it line by line. MSPs weighing the same shift can start with the partner model.

Frequently asked questions

How much does a managed firewall cost per month in 2026?

European providers advertise entry rates from around €49 to €180 per device per month, UK providers roughly ≈€58–€290 (£50–£250) per site, and North American providers ≈€300–€1,355 ($325–$1,475) depending on organisation size. Setup fees typically add the equivalent of two to three months of service.

What is included in a baseline managed firewall fee?

Usually uptime and health monitoring, scheduled firmware and patch maintenance, a capped number of routine rule changes, and monthly reporting. Vendor security subscriptions, high-availability pairs, emergency out-of-hours work and on-site hardware replacement are commonly excluded and billed separately.

What are the hidden costs of a managed physical firewall?

Four recur: a hardware refresh every three to five years when the appliance reaches end of support, vendor security subscriptions of roughly ≈€920–€1,840 ($1,000–$2,000) per device per year, out-of-scope change fees at €59–€125 per hour, and emergency patching labour for actively exploited edge vulnerabilities.

Why do quotes for the same company differ so much?

Scope, not margin. A low quote often covers monitoring and patching only, while a higher one includes round-the-clock security operations, vendor subscription pass-through, a defined change allowance and an SLA with credits. Unbundle each quote into management fee, subscriptions, change exposure, HA and refresh provision before comparing.

Is a managed firewall cheaper than managing it in-house?

For most mid-market organisations, yes — research puts the operational saving at 30% to 40%. Equivalent in-house capability requires certified engineers at roughly ≈€88,000–€106,000 ($96,000–$115,000) each plus tooling, and genuine round-the-clock coverage costs far more than any managed contract at this scale.

What is the difference between fully managed and co-managed?

Fully managed transfers monitoring, rule changes, patching and incident response to the provider. Co-managed splits it: the provider handles monitoring and maintenance while your team keeps policy authority and rule approvals. Co-managed typically reduces the monthly retainer by 20% to 35%.

Who pays when a managed firewall reaches end of support?

It depends entirely on the contract, which is why it belongs in your questions before signing. Under a hardware-as-a-service arrangement the provider carries replacement; where the customer bought the appliance, the refresh is a capital cost falling on the customer, often at an inconvenient point in the budget cycle.

Are firewall change request fees normal?

Yes. Most contracts include one or two routine changes per month in the base fee and bill anything beyond that hourly — €59 to €125 in Europe, higher for priority or out-of-hours execution. What matters is whether the allowance and the rate are written down, and what the provider counts as out of scope.

Find out how we can protect your business

In our demo call we’ll show you how our technology works and how it can help you secure your data from cyber threats.

Cybersecurity
Are you an integrator or distributor?

Need an affordable cybersecurity solution for your customers?

We’d love to help you get your customers on board.

checkmark

White glove onboarding

checkmark

Team trainings

checkmark

Dedicated customer service rep

checkmark

Invoices for each client

checkmark

Security and Privacy guaranteed