Define every billable unit
| Potential meter | Definition to settle |
|---|---|
| Developer or user | Active, named, contributing or provisioned; service accounts included? |
| Repository / project / application / product | Monorepos, branches, variants, forks and retired projects counted how? |
| Scan / build / artifact / image | Retries, failed scans, layers, digests and repeated builds charged how? |
| SBOM / component | Revisions, duplicates, linked files and historical inventories counted how? |
| Supplier | A supplier company, product, version or upload? |
| API / enrichment | Requests, bulk jobs, lookups, refreshed matches or feed access? |
| Storage / retention | Raw files, indexes, logs, assessments and backups included? |
| Services / support | Implementation, integration, training, standards migration and support tier? |
These are possible quotation structures, not a claim about a specific vendor’s current model. Require a unit definition, included volume, measurement period, tier, overage rate, cap and reconciliation report for every applicable meter.
Four identical scenarios for every bidder
| Scenario | Illustrative usage assumption | What it reveals |
|---|---|---|
| Base | 50 applications; 12 release inventories per application/year; 1,000 supplier inventories/year | Ordinary operations at the initial scope. |
| Growth | 100 applications; 12 releases; 2,000 supplier inventories/year | How expansion crosses tiers or minimums. |
| High volume | 50 applications; 250 release inventories each/year; 1,000 supplier inventories | Build/scan/SBOM meters under frequent releases. |
| Supplier ingestion | 50 applications; 12 releases; 10,000 supplier inventories/year | Intake, enrichment and retention exposure. |
Counts are illustrative buyer assumptions. Add your historical retention, component counts, API traffic, support tier and deployment costs to each scenario. Ask vendors to explain which counts translate into their billable units and which events are excluded.
An indicative quote calculation
Use the calculator only when a quote explicitly charges a fixed annual fee, a per-application annual fee and a per-inventory fee. It assumes all counted inventories are chargeable, with no included allowance, tiers or minimums. For other quote structures, ask for scenario totals rather than forcing them into this model. Values remain in the browser and are not submitted.
Normalize total cost over the intended term
For each year, combine subscription charges, usage overages, enrichment, storage, support, infrastructure and internal operating effort. Add implementation and migration where they occur. Include expected exit or transition cost at the end. Keep recurring and one-time items separate.
Show assumptions and sensitivity rather than one unexplained total. If a vendor includes enrichment but charges historical storage, preserve that distinction. If custom integration is necessary, include both initial delivery and continuing maintenance.
Ask for a base/growth/high-volume/supplier scenario quote with all exclusions stated. Reconcile line items to totals and identify duplicated or inconsistent units. A cheaper subscription may be more expensive after operational gaps and services.
Negotiate predictability
- Complete definitions that survive renewal and cannot be changed unilaterally.
- Included volumes and overage rates, with measurement and notification rules.
- Price holds, renewal caps and tier transitions.
- Treatment of archived releases, corrected inventories and failed jobs.
- API, export, vulnerability-feed and standards-update charges.
- Support, integration and professional-services rates.
- Post-termination access period and transition pricing.
Ask what happens if a product moves from a monorepo to many repositories or a supplier increases update frequency. A contract should not turn an ordinary operating change into an undefined billing event.
Before approving the quote
Match every priced item to the evaluated capability and delivery responsibility. A feature that exists only through a partner may have a separate agreement and meter. A roadmap commitment may carry implementation risk even when no fee is listed.
Obtain a reconciliation example showing how observed usage becomes the invoice. Retain scenario assumptions with the award decision and check early invoices against them. Do not accept “unlimited” without the stated fair-use, scale, storage and support limitations.