On this page
Short answer
A Broadcom subscription is the only path to vendor patches, current versions and new hosts; it is priced per core with minimums and it is the answer for anything that grows, gets audited or runs a regulated workload. Third-party support on a perpetual key is cheaper per year and keeps a frozen estate running competently, but it cannot patch from the vendor, add hosts beyond the key or move you to a current release. The hybrid — subscribe the clusters that matter, third-party the ones being retired — is what most mixed estates end up doing, and it is worth pricing explicitly rather than falling into.
Subscription, third-party support and the hybrid on the same criteria
| Broadcom subscription (via partner) | Third-party support on perpetual licences | Hybrid: subscribe critical, third-party the rest | |
|---|---|---|---|
| Security patches | Vendor patches for the term | Provider mitigations and workarounds; no vendor patches after support ended | Vendor patches on subscribed clusters only |
| Version upgrades | Current releases within the tier | None; the estate stays on the version the key covers | Only on subscribed clusters |
| Adding hosts or cores | New order, co-termed | Not beyond what the perpetual key already licenses | On subscribed clusters only |
| Audit and compliance posture | Current entitlement on record | Defensible only if the estate has not grown past the key; no current entitlement | Split: current on subscribed clusters, legacy on the rest |
| Cost shape | Per core per year, 16-core CPU floor, 72-core order minimum; term lowers the annual rate | Flat annual fee, typically a fraction of the subscription | Subscription on the subset that needs it; support fee on the remainder |
| Typical fit | Production, regulated, growing, or anything a cyber-insurer asks about | Frozen estate, small, being retired, no compliance regime | Mixed estate with a retirement plan for the legacy part |
| Exit path | Renew, re-size, or migrate at term end | Buy a subscription when the estate must change; migrate; or decommission | Shrink the third-party side to zero as clusters retire |
| Wins when | The estate must stay current or must grow | The estate is genuinely frozen and the clock on it is short | Some clusters are critical and some are on their way out |
What third-party support genuinely delivers
Break-fix on the versions you already run, configuration and performance help, and the provider's own mitigations for published vulnerabilities. The good providers employ engineers who have run large vSphere estates and are faster to answer than a vendor queue. For an estate that is not changing, that is most of what support ever did.
What they cannot deliver is anything that requires Broadcom: a vendor patch, a new release, or an entitlement for a host the perpetual key does not cover. Those are not gaps in the provider; they are the definition of the model.
Where the model breaks
Three events end it. The estate grows past the key, which puts you out of licence with no way to buy in short of a full subscription. A vulnerability lands that needs a vendor patch, and the mitigation is a workaround your security team will not accept. Or an auditor, a customer or an insurer asks for a current entitlement, and there is none to show. Estates on third-party support should know which of those three is likeliest and how far away it is, because that distance is the real length of the arrangement.
What the subscription buys that is easy to undervalue
Beyond patches and versions, it buys optionality: the right to add hosts, to change tier at renewal, and to be re-sized at each term end. It also buys the paperwork that regulated workloads and cyber-insurance questionnaires increasingly ask for. Against that sits the cost shape: per core, with a 16-core floor per CPU and 72 cores per order, so a very small estate pays for cores it does not have. That is the case where third-party support on a perpetual key is most defensible.
The hybrid, priced honestly
Most estates are not uniform. Some clusters run the workloads the business cannot lose; some are running out the clock on an application being retired. Subscribing the first group at the right tier and putting the second on third-party support with a fixed retirement date is a legitimate answer, and it is cheaper than subscribing everything. The mistakes are not writing the retirement date down, and letting a critical workload land on the legacy side because that is where it happened to be. Ask for the subscription quoted on the critical subset only, with the core count derived from those hosts, and compare that figure to the whole-estate number.
How to decide
- List every cluster with its workload, its growth expectation and its retirement date if it has one.
- Anything with a compliance obligation, a growth expectation or no retirement date goes on the subscription side.
- Price the subscription on that subset, at the right tier, on the one, three and five-year terms.
- Price third-party support on the remainder, with a written end date.
- If the remainder is empty, you have a subscription decision, not a support one. If the subscription side is empty, confirm with security and finance that the three exit events are genuinely distant.
Frequently asked questions
Can third-party VMware support provide security patches?
Not vendor patches. Independent providers issue their own mitigations and workarounds for published vulnerabilities on the versions you run. Only a current Broadcom subscription delivers Broadcom's patches and new releases.
Can I add hosts while on third-party support?
Only within what the perpetual key already licenses. Growing past it puts the estate out of licence, and the only way back in is a subscription.
Is it legal to run VMware on perpetual licences without Broadcom support?
A valid perpetual licence remains valid; support ending does not revoke it. What you lose is patches, upgrades and the ability to add entitlements, and an estate that has grown past the key is out of licence regardless of support.
Can I put part of my estate on a subscription and part on third-party support?
Yes, and mixed estates often should. Subscribe the clusters that must stay current or will grow, and put clusters with a fixed retirement date on third-party support. Price the subscription on that subset only so the comparison is honest.
Related
Where this gets done
Other VMware guides, comparisons and research
Recent VMware articles
- VMware Licensing Cost in 2026Sep 2026
- Broadcom VMware Licensing Changes: What Changed for RenewalsSep 2026
- vSphere Foundation vs VMware Cloud Foundation (VVF vs VCF)Sep 2026
- VMware License Renewal ProcessSep 2026
- How to Get a VMware Renewal Quote in 2026Sep 2026
- The 2027 VMware Renewal Wave: Why Timing MattersAug 2026