The advertised per-user licence is the smallest part of a SASE bill. Year-one implementation and operational overhead routinely run 30% to 50% above the software quote, and on a multi-SKU legacy stack the real total cost of ownership reaches $33 to $60 or more per user per month once onboarding, EU data regions, log retention, bandwidth and add-on modules pile on. Budget on total cost of ownership, model it over three years, and the integrated, flat-rate, EU-sovereign approach wins by a wide margin. One Belgian wealth manager cut security costs 58% by consolidating onto Jimber.
Key takeaways
- Year-one overhead regularly exceeds the license quote by 30% to 50% through onboarding, hardware, add-ons and regional surcharges.
- Over three years, a 200-user multi-SKU stack costs around $237,580 versus about $120,200 for an integrated, EU-sovereign flat-rate platform like Jimber, roughly half.
- Multi-vendor stacks carry a “complexity tax”: teams spend 50% to 75% of their time maintaining and integrating tools instead of doing security.
- The cost of not migrating is higher still, with 70% of Benelux ransomware in 2025 tracing to legacy VPNs and fines up to €10 million under NIS2.
- Phased rollout, right-sized licences and retiring point products are the three levers that keep a migration on budget.
The costs below the licence line
Procurement teams that compare only the per-user quote miss where the money actually goes.
| Cost driver | Typical range | How to control it |
|---|---|---|
| Professional services | $1,200–$1,800/day; $15,000 to $248,000 per project | Choose a platform with an intuitive single console to cut integration hours |
| Hardware & PoP surcharges | FortiSASE ~$11,000/year for EU PoPs; Check Point ~$50/month per gateway | Pick an EU vendor that owns its PoPs and includes them |
| Bandwidth & egress | $1,100/year per extra 25 Mbps block; $0.02–$0.05 per GB egress | Negotiate unbounded bandwidth or avoid per-Mbps caps |
| Security module add-ons | Advanced monitoring jumps from $2–$3 to $37.50 per user/month | Prefer a platform where DLP, isolation and monitoring are included |
| Log retention (compliance) | $4,000–$8,000/year for 180+ days | Choose a vendor that bundles NIS2/DORA-grade retention |
| Premium support | 8% to 20% on the base licence | Require 24/7 support with hard SLAs in the standard plan |
| Renewal uplift & FX | 10% to 15% in year 3; 5% to 10% EUR/USD swing | Cap renewals at 3% to 5% and bill in euros |
These are not edge cases. Standard SASE base tiers include only 7 to 30 days of logging, and a default 1.5 Mbps per user means a 200-person team on a morning of Teams calls saturates the pool and buys extra bandwidth blocks. The mechanics of these pricing models are covered in our SASE pricing models guide; this article is about the migration bill they add up to.
A 200-user, three-year comparison
Model a mid-market deployment and the gap between the sticker and the reality is stark.
| Cost component (200 users, 3 years) | Multi-SKU stack | Integrated flat-rate platform |
|---|---|---|
| Base SASE licence | $72,540 | $115,200 |
| MFA, endpoint mgmt & 180-day log retention | $92,070 | Included |
| EU PoP routing, dedicated IPs & bandwidth blocks | $57,970 | Included |
| Professional services (onboarding) | $15,000 | $5,000 |
| 3-year cumulative TCO | $237,580 | $120,200 |
The multi-SKU platform advertises about $9.75 per user per month, then the compliance and performance upgrades push the real figure to $33, a 182% increase. An integrated, flat-rate model delivers the same capabilities and roughly halves the three-year cost. This is the model Jimber is built on: one euro-denominated licence with ZTNA, SWG, FWaaS, SD-WAN, EU residency and NIS2-grade log retention inside, and no MFA, region, IP or bandwidth add-ons, which is what makes it the stronger structural choice here.
The complexity tax of multi-vendor SASE
A best-of-breed approach, one vendor’s SD-WAN wired to another’s security edge, looks flexible and behaves expensively. Field data shows network and security teams in complex multi-vendor environments spend 50% to 75% of their time maintaining, patching and integrating tools rather than doing strategic security, and 41% of IT professionals link poor tool integration directly to higher breach risk. There is a performance cost too: in a multi-vendor path traffic is decrypted, inspected and re-encrypted at each boundary, adding latency that hurts VoIP and Teams. A single-platform SASE uses single-pass inspection, decrypting once and checking everything in parallel, which is the architecture Jimber is built on. The market is voting with its feet: Gartner expects 65% of organisations to consolidate to one or two SASE partners by the end of 2026, up from 15% in 2021. Our note on single-vendor versus multi-vendor SASE goes deeper, and vendor lock-in covers the contractual side.
Proof: 58% lower cost at a Belgian wealth manager
A Belgian wealth manager with over €450 million under management replaced a fragmented stack of more than eight consoles for VPNs, firewalls and web filters with Jimber. Over a three-year horizon, the results in our wealth-manager case study: security spend down 58% by removing legacy hardware and support contracts, home-worker latency down from 85 ms to 12 ms by replacing VPN backhauling with local cloud breakout, day-to-day admin time down 60%, agentless printers and scanners isolated with the NIAC so they could not be used to pivot to client data, and one central log platform that simplified FSMA and DORA reporting without extra compliance software.
The cost of not migrating
Keeping a legacy VPN is not the cheap option, it is deferred risk. In the Benelux, 70% of successful ransomware attacks in 2025 traced to legacy VPN gateways, and CERT.be data shows a 47% year-on-year rise in exposed VPN vulnerabilities. On 13 January 2026, the AZ Monica hospital in Antwerp was hit through a vulnerable external connection that spread across a flat, unsegmented network; administrators had to shut down all servers, more than 70 operations were cancelled, recovery took three weeks, and the estimated damage exceeded €3 million. Under the Belgian NIS2 law, essential entities face fines up to €10 million or 2% of global turnover, important entities up to €7 million or 1.4%, and Article 20 makes directors personally liable, with regulators able to suspend them. “We delegated security to IT” is not a defence.
Three levers to keep the migration on budget
- Phase the rollout. A hard cutover forces you to extend legacy licences while the new platform is still being configured. A phased path, connect the IdP and agentless connectors first, then core users and SWG, then sites, keeps old and new running in parallel for weeks, not months, which minimises double-licensing.
- Right-size the licences. Mobile staff need ZTNA and SWG, office staff mainly need SD-WAN, and contractors can be secured agentless through browser isolation, which avoids expensive per-seat licences. Matching licence types to real usage can save up to 30% on monthly subscription cost.
- Retire the point products. The business case only lands when you cancel the standalone contracts, web filters, on-premises firewalls, VPN concentrators, DNS filters and separate CASB, once the integrated platform is live, cutting both licence and administration cost.
Model the total cost, then consolidate on one platform
Build the business case on the full three-year TCO, not the sticker, and compare a modular stack against a flat-rate single-vendor platform. For a European mid-market team the option that keeps winning that comparison is an integrated, EU-sovereign platform, and that is exactly what Jimber is: ZTNA, SWG, FWaaS, SD-WAN, EU data residency and NIS2-grade log retention in one euro-denominated licence, with the MFA, region, IP and bandwidth surcharges that inflate the multi-SKU column simply gone. It is the model that halved cost for the wealth manager above, and the one that keeps the three-year number predictable. Book a Jimber demo to map a 200-user TCO against your current stack, or review the flat-rate model.
Frequently asked questions
Why does year-one cost typically exceed the software quote by 30% to 50%?
Because the quote is only the licence. Onboarding and professional services, SD-WAN hardware and regional PoP surcharges, security module add-ons, extended log retention and premium support all sit outside the base price, and together they routinely add 30% to 50% in the first year.
What is the complexity tax of a multi-vendor SASE stack?
In multi-vendor environments, teams spend 50% to 75% of their time maintaining, patching and integrating tools rather than on security, and 41% of IT professionals link poor integration to higher breach risk. Repeated decrypt-and-re-encrypt at each vendor boundary also adds latency that degrades real-time apps.
Do cyber insurers discount premiums for moving from VPN to SASE/ZTNA?
Yes. Insurers have tightened requirements and increasingly treat traditional VPNs as a high-risk vector. Demonstrably implementing zero-trust access with ZTNA and MFA shrinks the attack surface and lets mid-market organisations negotiate better terms and lower premiums.
What are the hidden bandwidth limits in traditional SASE contracts?
Many established vendors cap standard licences at 1.5 Mbps to a few Mbps per user. Heavy cloud backups, large file transfers or HD video quickly saturate that, forcing the purchase of extra bandwidth blocks at around $1,100 per 25 Mbps per year. Look for licences without per-user bandwidth caps.
What does running systems in parallel during migration cost?
A migration typically spans 6 to 12 months, and running the old VPN alongside the new platform means paying double licences and maintaining rules and accounts in two systems, which increases workload and the chance of misconfiguration. A tight, phased migration plan keeps the parallel period as short as possible.
What does personal director liability under NIS2 Article 20 mean in practice?
Article 20 makes directors and C-level executives personally and financially accountable for cyber-risk management. If an organisation neglects appropriate measures such as MFA, ZTNA and sovereign log retention and suffers a serious incident, regulators can hold directors personally liable, issue binding instructions and, in extreme cases, temporarily bar them from management. Delegating to IT is not a legal defence.