CPQ & quoting for Cybersecurity

Quoting for security vendors: per-endpoint pricing, multi-year terms and channel deals

How cybersecurity companies quote per-endpoint, per-identity and per-asset subscriptions in Bunny, with multi-year ramps, tiered volume pricing, approval workflows and e-signature that flow straight into billing.

What makes cpq & quoting different for cybersecurity SaaS

Security vendors selling per-endpoint, per-identity or per-asset subscriptions on multi-year terms, often through MSPs and resellers, to buyers who audit everything.

  • Per-unit pricing across large, moving counts

    Endpoints, identities, workloads, mailboxes — the quantity is in the thousands and changes as the customer's estate grows. Tiered and volume pricing on that count has to be right on the quote and on every invoice.

  • Multi-year is the default

    Three-year terms with annual uplift or stepped quantities are normal in security procurement. A quote tool that only understands one term at one price leaves the schedule in a spreadsheet.

  • Bundles, modules and add-ons

    A platform SKU plus detection, response, identity and email modules, each with its own pricing and eligibility. The catalog has to enforce which combinations are valid.

  • Discount control against long sales cycles

    Enterprise security deals close at quarter end under competitive pressure. Without approval gates on the quote, the discount finance sees is the one already signed.

How Bunny handles cpq & quoting for cybersecurity SaaS

  1. 01

    Quantity-based pricing with tiers and volume breaks

    Per-endpoint or per-identity charges use flat, tiered, volume or banded pricing from the catalog, so a 5,000-endpoint quote prices correctly without a rep working a spreadsheet.

    Volume pricing explained
  2. 02

    Multi-year ramps generated from the quote

    Annual uplifts and stepped quantities across a multi-year term are set as a ramp on the quote; Bunny generates the invoice schedule and revenue schedule for the full term.

    Multi-year contracts
  3. 03

    A catalog that enforces valid bundles

    Products, plans and add-ons are modelled with their dependencies in the product catalog, so a rep cannot quote a module the platform tier does not support.

    Product catalog
  4. 04

    Approval workflows before the customer sees it

    Discounts above policy route to the right approver inside the quote flow. Legal or security-review steps can be added as approval stages too.

    Approval workflows
  5. 05

    Order forms, e-signature and CRM

    Branded order forms go out for signature via Bunny e-signature, DocuSign, PandaDoc or Dropbox Sign, with Salesforce and HubSpot integration so the deal is tracked in the CRM.

    CPQ for Salesforce
  6. 06

    Signed quote becomes the subscription

    Acceptance creates the subscription, the multi-year invoice schedule and the ASC 606 revenue schedule. Finance does not rekey the contract.

    CPQ in Bunny

Security deals are renewals in disguise

The distinctive thing about quoting in cybersecurity is that the first quote sets up years of subsequent ones. A three-year contract will see at least two true-ups as the endpoint count grows, a renewal quote before year three ends, and probably a module upsell in between. Each of those quotes has to know exactly what the customer has today.

That is the argument for quoting and billing being one system. Bunny’s CPQ prices from the live subscription, so a mid-term true-up quote already knows the current quantity, the contracted rate and the remaining term, and prorates the difference. The renewals page covers what happens at the end of the term.

What to model before the first quote

  • The unit. Endpoints, identities and workloads are different charges, not different quantities of one charge. Keep them separate so tiering and reporting work per unit.
  • The platform-module hierarchy. Model which modules require which platform tier in the catalog rather than in rep training.
  • Uplift policy. Whether the annual uplift is a fixed percentage or a price-list change at renewal decides whether it belongs on the ramp or in the renewal quote.
Free trial

The RevOps expert your team never had.

Bunny's AI agent knows your entire book of business and acts on it — flagging at-risk renewals, chasing overdue invoices, and closing upgrades automatically.
  • Type "send upgrade quotes to all starter plan accounts" — done in seconds
  • At-risk renewals flagged, chased, and closed — before you know there's a problem
  • Overdue invoices collected automatically, without an awkward conversation
Try free for 30 days

No credit card required. Cancel anytime.

FAQ

Frequently asked questions

Can Bunny quote per-endpoint or per-identity pricing with volume tiers?
Yes. The endpoint or identity count is the quantity on a recurring charge, priced with flat, tiered, volume or banded pricing from the catalog, and the same pricing rates every invoice for the term.
How does Bunny handle a three-year security contract with a 5% annual uplift?
The uplift is configured as a ramp on the quote. Bunny generates the billing schedule for each year at the stepped price, and the revenue recognition schedule to match, when the quote is accepted.
Can we prevent reps quoting invalid module combinations?
Yes. Dependencies between platform tiers, modules and add-ons are modelled in the product catalog, so the quote can only contain combinations the catalog allows.
Does Bunny support quoting through resellers or MSPs?
Account hierarchies (part of the Advanced Billing add-on) let a reseller or MSP be the billed party for multiple end-customer accounts, each with its own subscription. Talk to us about your specific channel model in a demo.