Two managed firewall quotes for the same 100-user company, two sites, same requirement. One comes in at €140 a month. The other at €900. Neither provider is lying, and the difference is not margin — it is scope. The cheap quote covers uptime monitoring and firmware patching. The expensive one includes round-the-clock monitoring, the vendor security subscriptions, a defined number of rule changes and an SLA with credits attached.
Comparing managed firewall proposals means unbundling them, because the monthly figure on the front page tells you almost nothing on its own. This guide sets out what the market actually charges in Europe and North America, what the fee does and does not include, the lifecycle costs that appear in year four rather than year one, and the questions worth asking before you sign.
The five ways it gets priced
Per appliance, per month. The traditional model: a flat management fee per physical unit, scaled by throughput and site complexity. Predictable for one office, linear when you have eight.
Per user. Common when the firewall disappears into a broader managed IT agreement at roughly ≈€92–€230 ($100–$250) per user per month, covering helpdesk, endpoint protection and perimeter security together. Convenient to budget, impossible to benchmark.
By throughput. Tiered on provisioned bandwidth and inspection depth. Mostly seen in data centre and heavy WAN edge deployments.
Co-managed versus fully managed. Fully managed hands over monitoring, rule changes and patching entirely. Co-managed keeps policy authority in-house while the provider takes alert triage and maintenance, which typically reduces the monthly retainer by 20% to 35%.
Setup and onboarding. A one-off charge for scoping, rule translation, staging and cutover testing, generally ≈€415–€3,035 ($450–$3,300) per site — in practice two to three months of the recurring fee.
What the market charges
| Organisation size | Per-appliance monthly fee (North America) | One-off setup |
|---|---|---|
| 10–25 users | ≈€300 – €390 ($325 – $425) | ≈€415 – €645 ($450 – $700) |
| 26–50 users | ≈€485 – €665 ($525 – $725) | ≈€645 – €1,060 ($700 – $1,150) |
| 51–100 users | ≈€715 – €1,080 ($775 – $1,175) | ≈€1,060 – €1,750 ($1,150 – $1,900) |
| 100–500 users | ≈€1,080 – €1,355+ ($1,175 – $1,475+) | ≈€1,750 – €3,035 ($1,900 – $3,300) |
| European market reference points | Published entry price | Model |
|---|---|---|
| UK managed firewall providers | ≈€58 – €290 (£50 – £250) per site/month | Tiered per site, hardware included |
| Netherlands / Belgium | From €85 – €180 per month | Managed service retainer per device |
| Germany | From €49 – €99 per month | Per device base rate, plus setup |
| France | From €80 per month | Per gateway, excluding VAT and setup |
| Software-only firewall management (EU/UK) | ≈€207 (£179) per firewall/month | Flat per-firewall licence tier |
Converted from USD at ≈€0.92 and GBP at ≈€1.16 (August 2026); local pricing and VAT treatment differ by market. European entry prices are starting rates and typically exclude vendor security subscriptions.
Two things are worth noting before you use these as a target. European entry-level pricing looks dramatically cheaper than North American pricing largely because it is quoted differently: a €49 starting rate is a base management fee, while a $775 North American figure usually bundles monitoring and licensing. And the whole market has moved — managed firewall pricing rose 39% to 49% across size segments between 2022 and 2025, driven by compliance requirements and the cost of round-the-clock monitoring.
What the fee covers, and what it doesn’t
A standard agreement usually includes health and uptime monitoring, scheduled firmware and patch maintenance, a capped number of routine rule changes, and monthly reporting. That is a genuinely useful baseline, particularly since something between 95% and 99% of firewall breaches trace back to misconfiguration rather than a hardware flaw — policy governance is the actual product you are buying.
The exclusions are where quotes diverge:
- Vendor security subscriptions. Intrusion prevention, gateway antivirus, URL filtering, application control and sandboxing are sold by the hardware manufacturer at roughly ≈€920–€1,840 ($1,000–$2,000) per device per year, passed straight through to you. That is ≈€75–€150 ($80–$165) a month on top of the management fee, and it is the single most common reason two quotes differ.
- High availability. An active/passive pair doubles hardware and licensing and raises the management fee. Enterprise MSSP retainers for HA configurations run from ≈€1,380 ($1,500) to ≈€6,900 ($7,500) a month depending on throughput and network role.
- Emergency and out-of-hours work. Routine patching during business hours is standard. Deploying an emergency fix for an actively exploited vulnerability at 2am is usually billed separately.
- On-site hardware work. Replacing a failed power supply or chassis means dispatching an engineer, which falls outside remote management unless a hardware-as-a-service SLA says otherwise.
Out-of-scope labour is billed at roughly €59–€99 per hour in continental Europe, ≈€930–€1,160 (£800–£1,000) per engineer per day in the UK, and ≈€115–€207 ($125–$225) per hour in North America. Standard change requests typically carry a 24 to 48 hour turnaround; anything faster is a priority charge.
The cost that shows up in year four
Here is the line item that almost never appears in a quote: the appliance has an expiry date.
Manufacturers set end-of-sale and end-of-support milestones on a three-to-five year cycle. When a firewall passes end of support, firmware updates, security patches, signature feeds and hardware replacement all stop at once. That is not a theoretical schedule — it is a published one. The FortiGate 100E and 80E reached end of support on 17 August 2026, and the 60E follows on 29 December 2026, as documented in our FortiGate hardware end-of-life timeline. On the WatchGuard side, the T35, T55 and T70 went end of life on 31 December 2025 and the entire M270–M670 generation follows on 1 July 2028, set out in our WatchGuard Firebox end-of-life guide.
Vendors apply commercial pressure as those dates approach; WatchGuard added renewal surcharges of up to 16% on the retiring T35/T55/T70 generation in their final support phase. Meanwhile the risk of deferring the refresh is no longer abstract: the share of breaches involving exploitation of edge devices and VPNs jumped from 3% to 22% in a single year according to Verizon’s 2025 breach report, while the median time to patch an edge device stood at 32 days and only 54% of edge vulnerabilities were remediated within a year. An unsupported firewall also gives cyber insurers grounds to contest a claim and puts you outside what NIS2, ISO 27001 and PCI-DSS expect of a security control.
So the honest budget for a managed appliance includes a hardware refresh every three to five years, the migration labour that comes with it, and the emergency patch windows in between.
Three-year economics
For a 100-user organisation across two sites, over 36 months:
| Cost element | Managed physical appliances (two mid-range units) | Integrated flat-rate SASE platform |
|---|---|---|
| Initial hardware and setup | ≈€2,115 – €3,495 ($2,300 – $3,800) | ≈€0 – €920 ($0 – $1,000) cloud tenant setup |
| Management and service fees | ≈€25,670 – €38,915 ($27,900 – $42,300) | Flat platform subscription |
| Vendor security subscriptions | ≈€5,520 – €11,040 ($6,000 – $12,000) | Included in the platform |
| Out-of-scope change requests | ≈€1,955 – €3,280 ($2,124 – $3,564) | Self-service policy changes |
| Hardware refresh provision | ≈€2,760 – €5,520 ($3,000 – $6,000) | No edge hardware to replace |
| 36-month total | ≈€38,020 – €62,250 ($41,324 – $67,664) | Predictable operating expenditure |
Converted from USD at ≈€0.92 per US dollar (August 2026); local EUR pricing may differ. Platform subscription costs vary by provider and are deliberately not modelled as a single figure.
Where each model wins is fairly clear-cut. For a single static office, a managed appliance remains price-competitive at the entry point, and the difference only accumulates through change fees and the refresh provision. For five or more sites the appliance model deteriorates fast: hardware, setup, subscriptions and VPN mesh maintenance all multiply per location. And for hybrid workforces the appliance model quietly pays twice, once for the perimeter firewall and again for remote access infrastructure that inspects traffic somewhere else entirely.
One caution when comparing against cloud alternatives: appliance vendors moving into SASE often price in tiers that hide the real number. Published entry pricing of around ≈€83 ($90) per user per year can reach ≈€193–€230 ($210–$250) once multi-factor tokens, endpoint management, compute region access and bandwidth allocation are added — the pattern we documented in our breakdown of what FortiGate customers actually pay for FortiSASE and in single-vendor versus multi-vendor SASE cost. Ask any cloud provider for the all-in figure at your user count, not the entry tier.
Seven questions for any quote
| Ask | Warning sign | What good looks like |
|---|---|---|
| How many policy changes are included, and what is the rate beyond that? | “Unlimited changes” with no definition of out-of-scope | A stated monthly allowance and a published hourly rate |
| Who owns the hardware during and after the term? | Hardware markup bundled into the fee with no ownership stated | Explicit hardware-as-a-service lease including replacement |
| What happens when the appliance reaches end of support mid-contract? | The customer carries the full replacement cost | Refresh included at no additional capital cost |
| What is the SLA for patching an actively exploited vulnerability? | “Regular maintenance” with no timeframe | Critical patches within days; emergency fixes within 48 hours |
| What does exit cost, and will we get our configuration? | Extraction fees or refusal to export rule sets | 30-day notice and full configuration export at no charge |
| What service credits apply if availability targets are missed? | “Best effort” with no binding remedy | A defined availability target with proportional credits |
| Can we benchmark pricing mid-term? | Fixed pricing for 3–5 years with no adjustment mechanism | A formal review at month 18 against market rates |
When the classic managed appliance is still right
“A local appliance means local control and lower latency.” For east-west traffic between internal segments, genuinely true — local filtering avoids a round trip, which matters in industrial networks and media production. For everything else it works against you: most mid-market traffic goes to cloud applications, and hairpinning that through an on-premises box adds latency rather than protection.
“Our MSP knows our network.” That relationship has real value, and it is worth keeping. What it does not do is change a vendor’s end-of-support date or patch an edge vulnerability at the weekend — smaller providers often run business-hours engineering rather than a round-the-clock operations centre. This is not an either/or: many providers now keep the customer relationship while delivering security from a cloud platform, which is exactly the shift described in how MSPs deliver managed SASE without tool sprawl.
“The bundle is simpler and cheaper.” Simpler to approve, harder to evaluate. Bundling hides the hardware markup and the subscription pass-through, and the low first-year number is frequently recovered through change fees, annual licence increases and an unbudgeted refresh in year four.
There are environments where the physical appliance remains the correct answer regardless of the economics: isolated industrial and OT networks that must stay off public cloud routing paths, facilities with heavy local east-west traffic, and sectors under data residency rules that restrict routing control planes through multi-tenant infrastructure. Outside those, the decision usually comes down to how many sites you have and whether you want to repeat this procurement in four years.
Unbundle before you compare
Take every quote on your desk and split it into five numbers: management fee, vendor subscriptions, change-fee exposure, HA cost and the refresh provision. Quotes that looked three times apart usually converge — and the one that still looks cheap after the exercise is usually the one that excluded the most.
If that exercise makes the appliance treadmill look less attractive than it did, that is the point at which most mid-market teams look at doing it differently. Jimber delivers firewall-as-a-service alongside ZTNA network isolation, secure web gateway and SD-WAN from a single EU-sovereign platform at a predictable flat rate: no hardware to refresh, no per-change invoices, no end-of-support date on your calendar. Book a demo and bring your current quote — we will map it line by line. MSPs weighing the same shift can start with the partner model.
Frequently asked questions
How much does a managed firewall cost per month in 2026?
European providers advertise entry rates from around €49 to €180 per device per month, UK providers roughly ≈€58–€290 (£50–£250) per site, and North American providers ≈€300–€1,355 ($325–$1,475) depending on organisation size. Setup fees typically add the equivalent of two to three months of service.
What is included in a baseline managed firewall fee?
Usually uptime and health monitoring, scheduled firmware and patch maintenance, a capped number of routine rule changes, and monthly reporting. Vendor security subscriptions, high-availability pairs, emergency out-of-hours work and on-site hardware replacement are commonly excluded and billed separately.
What are the hidden costs of a managed physical firewall?
Four recur: a hardware refresh every three to five years when the appliance reaches end of support, vendor security subscriptions of roughly ≈€920–€1,840 ($1,000–$2,000) per device per year, out-of-scope change fees at €59–€125 per hour, and emergency patching labour for actively exploited edge vulnerabilities.
Why do quotes for the same company differ so much?
Scope, not margin. A low quote often covers monitoring and patching only, while a higher one includes round-the-clock security operations, vendor subscription pass-through, a defined change allowance and an SLA with credits. Unbundle each quote into management fee, subscriptions, change exposure, HA and refresh provision before comparing.
Is a managed firewall cheaper than managing it in-house?
For most mid-market organisations, yes — research puts the operational saving at 30% to 40%. Equivalent in-house capability requires certified engineers at roughly ≈€88,000–€106,000 ($96,000–$115,000) each plus tooling, and genuine round-the-clock coverage costs far more than any managed contract at this scale.
What is the difference between fully managed and co-managed?
Fully managed transfers monitoring, rule changes, patching and incident response to the provider. Co-managed splits it: the provider handles monitoring and maintenance while your team keeps policy authority and rule approvals. Co-managed typically reduces the monthly retainer by 20% to 35%.
Who pays when a managed firewall reaches end of support?
It depends entirely on the contract, which is why it belongs in your questions before signing. Under a hardware-as-a-service arrangement the provider carries replacement; where the customer bought the appliance, the refresh is a capital cost falling on the customer, often at an inconvenient point in the budget cycle.
Are firewall change request fees normal?
Yes. Most contracts include one or two routine changes per month in the base fee and bill anything beyond that hourly — €59 to €125 in Europe, higher for priority or out-of-hours execution. What matters is whether the allowance and the rate are written down, and what the provider counts as out of scope.