FortiSIEM pricing in 2026: the EPS and device licensing model, and what it really costs
The independent FortiSIEM pricing reference. Fortinet does not publish a list price, so this page explains the events-per-second, device, GB/day and FortiSIEM Compute Unit licensing model, perpetual versus subscription, honestly-labelled indicative reseller figures, and where FortiSIEM fits, especially inside an existing Fortinet Security Fabric. Licensing model verified against Fortinet's ordering and licensing guides, August 2026.
Fortinet publishes no list price. The licensing model here is drawn from Fortinet's own FortiSIEM ordering guide and licensing guide. Dollar figures are indicative reseller and buyer-reported data points, clearly labelled as such, not an official Fortinet rate card. Always confirm against a real quote.
How FortiSIEM pricing actually works
The first thing to know is that Fortinet does not publish a FortiSIEM list price. There is no public rate card, so every genuine number comes through a quote. What is documented, in Fortinet's own ordering and licensing guides, is the model: FortiSIEM licenses primarily on events per second (EPS), the sustained rate of security events the platform is entitled to process. That is the meter to understand before anything else.
EPS is often bought indirectly through device and endpoint licences. A Device licence provides 10 EPS and an Endpoint licence provides 2 EPS, and Fortinet does not differentiate what kind of device, service, or application the licence monitors. Some subscription options are instead sized by GB per day, and the cloud deployment meters on FortiSIEM Compute Units, which fold EPS and storage into a single consumption unit. Across all of these, you can buy perpetual licences (a CAPEX purchase plus annual support) or subscription licences (OPEX).
On real numbers, honesty matters more than a confident figure. Buyers and resellers report small deployments starting around $29,000 per year, and some resellers publish packaged MSRP figures such as an all-in-one licence sized for several thousand devices priced in the mid-$40,000s. These are useful as order-of-magnitude anchors, but they are reseller and third-party data points, not Fortinet list pricing, and they vary widely by EPS, region, term, and bundle. We label them as indicative for exactly that reason.
The practical implication of the EPS meter is that cost tracks event rate, not raw bytes. Two environments with the same gigabytes per day can carry very different EPS depending on event size and verbosity, so FortiSIEM can be favourable for high-volume-but-large-event telemetry and less favourable for chatty, high-event-count sources. Filtering and aggregating at the collector, and sizing to sustained rather than peak EPS, are the levers that move the bill.
FortiSIEM licensing model
| Licence unit | What it means |
|---|---|
| Events per second (EPS) | The primary meter. Sustained EPS is the licensed capacity; overshoot is throttled or requires a bump. |
| Device / Endpoint | A Device licence provides 10 EPS, an Endpoint provides 2 EPS. Fortinet does not differentiate by device type. |
| GB/day (subscription) | Some OPEX subscriptions are sized by daily ingest volume instead of raw EPS. |
| FortiSIEM Compute Units (FCUs) | The cloud meter, combining EPS and storage into compute units for the hosted deployment. |
| Perpetual vs subscription | CAPEX perpetual licences (plus annual support) or OPEX subscription. Both scale with EPS/devices. |
Indicative FortiSIEM cost bands
| Scale | Profile | Indicative cost |
|---|---|---|
| Small (a few hundred EPS) | SMB / single site | ~$29K/yr floor (reseller-reported) |
| Mid-market (1,000-3,000 EPS) | Multi-site enterprise | Quote-only (rises with EPS) |
| 5,000-device all-in-one | Large enterprise / MSSP | Reseller MSRP packages ~$44K seen |
| High EPS / multi-tenant | MSSP, global SOC | Quote-only, negotiated |
Indicative only. These are reseller-listed and buyer-reported figures, not Fortinet list pricing, and vary widely by EPS, term, region, and bundle. Confirm against a quote.
Four FortiSIEM cost optimisations that genuinely work
Size EPS to sustained, not peak
Directly on licenceFortiSIEM licences on events per second, so the single biggest lever is sizing to sustained EPS with sensible headroom rather than to worst-case peak. Measure real EPS over a representative period, then license to the sustained rate plus a margin. Over-provisioning EPS is the most common way FortiSIEM deals come in higher than they need to.
Filter and aggregate before ingest
Reduces required EPSBecause the meter is events per second, dropping low-value events and aggregating repetitive ones at the collector reduces the EPS you must license. Verbose firewall accept logs, routine health checks, and duplicated telemetry are the usual candidates. Every event removed upstream is capacity you do not pay for.
Use the Security Fabric bundle if you are already Fortinet
Deal-dependentFortiSIEM's strongest commercial case is inside an existing Fortinet Security Fabric estate. Bundling FortiSIEM with FortiGate, FortiAnalyzer, and the wider fabric typically unlocks better commercial terms than buying it standalone, and the native integration reduces the engineering cost of onboarding Fortinet sources.
Weigh perpetual against subscription over the term
Deal-dependentFortinet offers both perpetual (CAPEX plus annual support) and subscription (OPEX) licensing. For a stable, long-lived deployment, perpetual plus support can undercut multi-year subscription totals; for a changing or growing estate, subscription keeps you flexible. Model both over your real horizon before signing.
When FortiSIEM is the right SIEM
FortiSIEM wins most clearly for organisations already standardised on the Fortinet Security Fabric. Bundled commercial terms, native integration with FortiGate and the wider fabric, and the built-in discovery, CMDB, and availability monitoring make it a natural fit when Fortinet is already the network and security backbone. It also suits MSSPs, thanks to its multi-tenant architecture, and IT teams that value having asset inventory and performance monitoring inside the same platform as security analytics.
FortiSIEM is less compelling where transparent, self-serve pricing is a requirement (there is no public rate card), where the team wants a cloud-native security data lake with detection-as-code, or where the estate is not Fortinet-centric and the bundle advantage disappears. In those cases per-GB and consumption-priced platforms (Splunk, Sentinel, Chronicle, Panther) are easier to evaluate and often a better architectural fit. The deciding question is usually simple: if you are a Fortinet shop, FortiSIEM deserves the shortlist; if you are not, weigh it against the event profile and the friction of quote-only pricing.