Research Note · Strategy · Support

Dropping vendor support: risks and how to manage them.

Annual vendor maintenance runs 20–22% of net licence fees, and moving to third-party support typically cuts that bill by 50–60%. The savings are real and well documented — but so are the exposures. This note prices what you lose (patches, upgrade rights, escalation), the reinstatement trap that makes the move hard to reverse, and how to segment the estate so the saving arrives without the risk.

By James Hill-WoodUpdated Feb 20248 min readSupport strategy cluster
Bottom line

Dropping vendor support is a legitimate way to cut a large, low-value cost — but it is a workload-level decision, not an all-or-nothing one. Keep maintenance where unpatched vulnerabilities or a future upgrade would hurt; drop it where compensating controls cover the risk and the version is stable. In every case, model the reinstatement penalty and clean up your compliance position before you act.

01 Key findings

  1. The saving is real, and so is the exposure. Maintenance is near-pure vendor margin; third-party providers undercut it by 50% or more. Buyers who get burned counted the saving without pricing the loss of patches, upgrade rights and audit cover.

  2. Security patching should drive the decision. An unpatched, internet-facing system in a regulated environment is a risk no support saving justifies. For an isolated, internal, stable system, the same loss is close to immaterial — so the choice is workload by workload.

  3. The move is hard to reverse. Returning to the vendor typically triggers back maintenance plus a penalty of around 150% of lapsed fees. That single payment can erase years of third-party savings, so treat leaving as a one-way door on any given workload.

  4. Cancellation invites an audit. Vendors often respond to a maintenance cancellation with a compliance audit on the theory that a departing customer is a likely settlement. Disorganised entitlement records turn that audit into a bill.

  5. The hybrid is the strongest position. Keep full maintenance on internet-facing, regulated or upgrade-bound workloads; move stable, internal, end-of-roadmap systems to third-party support. This captures most of the saving while containing the risk.

02 Why buyers drop support

Maintenance is the most profitable line a software vendor sells: near-pure margin on software that is already built, rising every year while the value delivered often does not. A buyer running stable, mature software that needs no new features is paying a fifth of the licence cost annually for the right to patches they rarely apply and upgrades they do not want.

Third-party support providers undercut this by 50% or more and frequently offer faster response and support for customised code the vendor will not touch. For a stable, end-of-roadmap product, the economics can be compelling — which is why the question comes up most on mature ERP and database estates. The same margin dynamic is why vendors defend maintenance so aggressively, a pattern covered in our discount erosion at renewal guide.

03 Risk & mitigation matrix

Four exposures matter, and they are not equal. The matrix separates the real risks from the ones vendors overstate, and pairs each with the control that contains it.

RiskSeverityWho it hits hardestPrimary mitigation
Loss of security patchesHighInternet-facing, regulated workloadsVirtual patching & compensating controls; keep maintenance where core fixes are essential
Loss of upgrade rightsMediumEstates planning a major version moveOnly leave workloads you will run to end of life; retain rights where an upgrade is plausible
Reinstatement penalty to returnHighAnyone who may go back to the vendorModel the ~150% back-maintenance cost up front; treat the move as irreversible
Audit & compliance exposureMediumBuyers with messy entitlement recordsEstablish a clean effective licence position before cancelling

Loss of security patches is the exposure that should drive the decision. For an isolated, internal, stable system the same loss is close to immaterial, which is why the assessment is workload by workload rather than a single estate-wide choice.

04 The security question, answered honestly

The vendor's strongest argument against dropping support is security: without vendor maintenance you lose access to official patches, and for a vulnerability in the core product there may be no fix you can apply. This is a genuine risk and the one to take seriously.

Third-party providers mitigate it with virtual patching and compensating controls, which protect the application at the network and configuration layer rather than in the code — and for many workloads this is sufficient. But virtual patching is not the same as a vendor fix. For systems exposed to the internet or subject to strict regulatory patching requirements, the gap can be unacceptable. The honest rule: keep vendor maintenance on the workloads where an unpatched core vulnerability would be a serious incident, and drop it where compensating controls genuinely cover the exposure.

05 Reinstatement and back-maintenance exposure

Dropping maintenance also ends your right to new versions: the version you run when you leave is the version you keep. For an estate at the end of its roadmap that is fine. For an estate that may need a major upgrade within a few years, it is a problem — because returning to the vendor to regain upgrade rights triggers the reinstatement penalty. Mapping the roadmap honestly is part of the discipline in our software licence management guide.

The reinstatement trap

If you drop maintenance and later want to return, most vendors charge back the fees you skipped plus a penalty — often 150% of the lapsed maintenance — before they will reinstate you. This back maintenance charge can erase years of third-party savings in a single payment, so treat the move as difficult to reverse. Model the reinstatement cost before you leave, and only drop support on workloads you are confident you will not bring back. The mechanics are covered in our back maintenance charges guide, which explains how the reinstatement penalty and the audit threat work together to keep buyers on maintenance.

Leaving support does not end your licence obligations, and vendors sometimes respond to a cancellation with a compliance audit. A buyer who drops support with disorganised entitlement records invites exactly this. Before cancelling, establish a clean effective licence position so any audit triggered by the move finds you compliant — the exposure our vendor negotiation practice manages alongside the commercial move.

06 Decision framework

Four considerations decide whether a given workload should leave vendor maintenance. Weight them per workload, not per estate.

Factor 01

Exposure profile

Internet-facing or regulated workloads need core security patches; the loss of official fixes is the decisive risk. Isolated, internal systems carry almost none of it.

Factor 02

Version roadmap

Drop support when you intend to run the current version to end of life. Keep it when a major upgrade is plausibly in your future, since returning triggers the penalty.

Factor 03

Reversibility & reinstatement

Price the ~150% back-maintenance cost of returning. If the workload might come back to the vendor within two years, the penalty can wipe out the saving entirely.

Factor 04

Compliance readiness

A clean effective licence position is the precondition for a safe exit. Messy entitlement records turn a cancellation-triggered audit into a settlement.

07 The hybrid model most buyers should run

The decision is rarely all vendor support or all third-party, and the strongest position for most estates is a deliberate hybrid. Keep full vendor maintenance on the workloads that are internet-facing, regulated, or heading for a major upgrade, where patches and version rights are worth the premium. Move stable, internal, end-of-roadmap systems to third-party support, where the saving is real and the risk is contained.

This split captures most of the available savings while keeping the vendor relationship intact where it matters — which also preserves negotiating goodwill for the contracts you still hold. A blanket cancellation, by contrast, can sour the whole relationship and invite the audit and reinstatement pressure described above. The hybrid is harder to administer because it requires knowing exactly which workload sits in which category, but that knowledge is precisely the effective licence position every well-run estate should already maintain.

Vetting a third-party provider is part of the same discipline. Ask four concrete questions in writing: the guaranteed response time for a severity-one issue, who actually delivers the support and their depth on your specific products, how they handle security through virtual patching and compensating controls, and what indemnification they offer if their advice causes a problem. A serious provider answers all four and supplies reference customers; a weak one sells the price and is vague on the rest.

08 Our recommendation

Keep maintenance
When exposure is high

Internet-facing, regulated, or upgrade-bound workloads stay on full vendor support. An unpatched core vulnerability or a lost version right costs far more than the maintenance premium saves.

Move to third-party
When stable & internal

Stable, internal, end-of-roadmap systems capture the 50–60% saving with compensating controls covering the risk — provided you have modelled the reinstatement penalty and confirmed you will not return.

Run the hybrid
The default answer

For most estates, segment workload by workload. Keep what protects you, drop what does not, and preserve vendor goodwill on the contracts you retain. Decide with the reinstatement and security exposures both priced in.

09 A worked savings-versus-risk calculation

The decision becomes concrete once the numbers are on the page. Take an estate with $5,000,000 in net licence value paying 22% annual maintenance — a $1,100,000 yearly bill. Moving the stable, internal two-thirds of that estate to third-party support at roughly half the rate saves about $363,000 a year, while the remaining third stays on vendor maintenance because it is internet-facing or heading for an upgrade.

Against that annual saving, weigh the one-time reinstatement exposure if you ever return — at 150% of lapsed fees on the moved portion, potentially several hundred thousand dollars — and the cost of the compensating security controls the moved workloads now need. For an estate genuinely at the end of its roadmap, the saving compounds year after year while the reinstatement risk stays hypothetical, so the move pays for itself quickly. For an estate likely to return within two years, the penalty can erase the saving entirely, which is why the version-roadmap question decides the calculation as much as the headline rate. Run that segmentation honestly and the maintenance line stops being a fixed cost you accept and becomes a portfolio you manage.

Decide on support with the numbers in front of you

We model the savings, map the risks, and structure the move to third-party support so it survives an audit.

Talk to an advisor →

The Licensing Edge

Weekly vendor and licensing intelligence for enterprise IT leaders. 3,000+ subscribers.