The SSO tax, priced and scored

Single sign-on regularly costs 2x to 4x the base plan, and one vendor wants 41x. What the wall of shame documents, and how to score it in procurement.

The bench2 min readCosts

You want SAML single sign-on because your security team is right. The vendor knows this, which is why SSO lives in the enterprise tier next to features you will never use, at a price that would embarrass a casino.

The SSO Wall of Shame has documented this pattern for years: vendor by vendor, the base price next to the price with SSO, with the multiple printed in a column that reads like a police blotter. Multiples of 2x to 4x are the ordinary case. The record holders reach past 40x base price for the privilege of logging in through the identity provider you already pay for.

The vendors' defense, when they bother with one, is that SSO buyers are enterprises and enterprises can pay. This is price discrimination with a security feature as the fence, and the wall of shame's core argument is the right one: making the secure login path the expensive one means small teams run on shared passwords in a spreadsheet. Charging for security features is charging to not have the incident.

how we score it

Starting with this review cycle, the SSO tax is a scored line item in every ranking we publish, weighted inside the cost criterion:

  1. SSO in every paid tier: full marks. It exists and we salute it.
  2. SSO one tier up, under 1.5x: acceptable, noted, forgiven.
  3. SSO at 2x to 4x: scored as the price it is. The "cost at modest scale" number in our tables uses the SSO tier for any tool a team of ten would deploy company-wide.
  4. SSO behind "contact sales": scored at 4x, because that is what the quotes come back as, and we have the quotes.

Check the wall before every renewal. It is community-maintained, it names names, and it has done more for honest security pricing than any analyst report we have read.

The move that works: put SSO parity in the security questionnaire, not the negotiation. Vendors expect to haggle about the tax; they do not expect it to be a compliance failure. One of our readers reports their procurement team rejects any tool whose secure login costs extra, full stop, and the exception process requires a director's signature. Adoption of that policy is our actual recommendation.

Skip the tier. If the vendor will not sell you security at a sane multiple, that is a review with one sentence in it.