Insights Business| SaaS| Technology VMware Licensing, Egress Fees and the Real Cost of Cloud Lock-In
Business
|
SaaS
|
Technology
Sep 22, 2026

VMware Licensing, Egress Fees and the Real Cost of Cloud Lock-In

AUTHOR

James A. Wondrasek James A. Wondrasek
VMware Licensing, Egress Fees and the Real Cost of Cloud Lock-In

Broadcom has turned a stable infrastructure cost into a boardroom line item. When VMware went subscription-only with per-core pricing and a 72-core minimum order, the renewal stopped being reflexive and became a P&L event. Industry analysis puts the average increase at 60 percent over seven years, with some rises of eight to fifteen times. Now egress fees apply on the way out, and the CFO asks the one question no single number can answer: what’s our strategy?

Neither path is free: licensing, egress, migration, staffing, hardware and resilience all carry cost, so any obvious answer is suspect. By the end you’ll be able to price both staying and leaving, and set a per-workload lock-in threshold that separates a genuine saving from a headline claim. It is one thread of the larger question of cloud repatriation and digital sovereignty, which weighs these economics against the regulatory and sovereignty overlay.

How does the VMware licensing reset actually change the economics of staying on-premises?

Broadcom abolished perpetual licences, cut the catalogue from 168 bundles to four, moved pricing from per-socket to per-core and made everything subscription-only. Every CPU counts as a minimum of 16 cores, every purchase carries a 72-core floor, and late renewals attract a flat 20 percent surcharge plus 180-day compliance reporting.

The detail that matters is the bundling. VMware Cloud Foundation now packs vSphere, vSAN, NSX, the Aria Suite, HCX and SDDC Manager into one SKU at roughly US$350 per core per year, so you pay for modules you never switch on.

The scale signal is Tesco, which is moving 40,000 server workloads off VMware after a proposal landed at US$23.5 million, a 175 percent jump over its 2021 agreement. Seventy-one percent of customers now say pricing has risen well beyond the broader software market.

But don’t model on-prem as free. DRAM contract prices rose 90 to 95 percent in a single quarter, and enterprise server prices climbed roughly 15 percent, so hardware refresh and depreciation have to be netted against whatever you save on the licence. That reset is driving the repatriation rethink.

How do cloud egress fees make data-intensive workloads structurally more expensive than they first appear?

The same pattern shows up at the cloud’s edge. Egress is priced as a designed switching cost, and it compounds exactly where your data gravity is highest.

Egress is a per-gigabyte charge on anything leaving a provider’s network: internet traffic, movement between regions or availability zones, and transfers back to your own racks. Ingress is free, while egress bills separately from compute and storage. The list price looks small, around US$0.09 per GB on AWS, but egress can run to 10 or 15 percent of total cloud spend, and more for data-heavy workloads.

Those free tiers of 100 to 200 GB a month are exhausted within hours at production scale. Inter-region and inter-availability-zone transfer is often billed in both directions, so a resilience architecture that replicates across zones charges every month. Disaster-recovery restores, logging and telemetry add recurring egress that rarely appears until it lands on an invoice.

The forward signal is regulatory. The EU Data Act removes blanket egress fees from 12 January 2027, while still allowing genuinely cost-based transfer. That matters for Australian businesses serving EU customers or holding EU data. Model egress as a declining exit cost rather than a permanent one. This feeds the workload placement decision and the Australian sovereignty picture.

What is the “lock-in threshold”, and when does the cost of leaving a cloud stop being worth it?

The lock-in threshold is the point at which the cost of moving data, modifying applications and reskilling your staff exceeds the savings the cloud promised. It’s a testable crossover you can calculate per workload: weigh switching cost (transfer, rewrite, ramp, parallel running) against net present savings of leaving.

For most estates the threshold is driven by the proprietary layer (managed databases, AI/ML services and analytics) rather than raw compute or storage, which are largely portable. Every managed service you adopt makes the exit more expensive.

So is AWS lock-in real? Yes, but it is workload-specific. Compute and storage move cleanly, while the proprietary managed services are where you get stuck. The same logic answers the CapEx question: staying, or going private, is rational when the operational complexity of moving outweighs the saving. With high data gravity, thin margins and deep managed-service dependency, leaving stops being worth it. See workload placement and the repatriation landscape.

What should I look for when assessing whether a repatriation claim will deliver savings in our environment?

So how do you test a repatriation claim? A genuine saving is a full-lifecycle TCO result, and most claims fail a simple four-bucket test.

Start with an inventory: steady-state versus bursty workloads, instrumented baselines, egress exposure, and the staffing and day-2 operations you’d need. Then run every option through the same four buckets: migration, steady-state run-rate, staffing and day-2, and risk.

Migration is easiest to model per unit. Gartner’s planning benchmark runs about $300 to $3,000 per VM depending on complexity, and you should treat that as a range.

The reason to distrust vendor savings claims sits in your own cloud bill. Ninety-seven percent of IT leaders believe some public cloud spend is wasted, and 52 percent put it at more than a quarter. That’s why the sequence is lift first, measure second, optimise third: measure a baseline, then optimise against evidence rather than vendor calculators. The workload economics and repatriation reality check apply here.

How should I frame the repatriation decision for the board when the CFO asks what our strategy is?

With the four buckets filled in, reframe the question from “should we leave the cloud?” to “which workloads, on what data?”, and present a workload-by-workload allocation across public cloud, private cloud and on-premises. The Barclays figure that 86 percent of CIOs plan repatriation is true but misleading; what matters is which workloads, and how many.

Compare destination stacks on economics and exit optionality. HPE’s private cloud plays as a VMware landing zone with a native hypervisor and migration tooling. VMware Cloud Foundation is the bundled full stack, and Dell AI Factory is the private-cloud and AI option. For each, state what it costs to leave later.

Then name the trade-off: CapEx and complexity now versus predictable OpEx, as a three-year TCO per path with assumptions stated and sensitivity drivers called out (utilisation shape, power, day-2 staffing). A steady-state 24/7 workload may be cheaper on-prem once hardware and depreciation are modelled, while bursty work stays public. Present ranges rather than a single number. Fold in data residency and sovereignty, the cost and control trade-offs, and how to spot sovereignty-washing.

The decision, priced properly

The VMware reset and cloud egress fees are two visible edges of one structural cost: lock-in. And lock-in can be priced rather than merely feared.

The question stops being “should we leave the cloud?” and becomes “which workloads, on what data, at what exit cost?” The lock-in threshold turns anxiety into a calculation: a testable crossover between switching cost and net present savings, priced per workload. Staying becomes a deliberate decision rather than the result of limited time, limited options or limited visibility. None of that stands alone: it is the economics half of the broader digital sovereignty and the internal service provider question, where cost, control and sovereignty meet.

Frequently Asked Questions

What happens if we miss the VMware renewal deadline?

Miss it and you pay a flat 20% surcharge on the renewal, on top of per-core pricing, and Broadcom can require up to 180 days of compliance reporting to confirm your core counts. On a large estate that is a material sum lost for a late signature. Treat the renewal date as a hard design deadline rather than an administrative one.

Does the EU Data Act’s egress fee ban apply to Australian businesses?

The blanket egress fee ban starts 12 January 2027 and applies where the EU Data Act governs the service, so Australian businesses serving EU customers, or holding EU data, can fall within its scope. It bans blanket fees but still allows genuinely cost-based transfer charges. Model egress as a declining exit cost rather than a permanent one, and check your contract’s governing terms.

Is “egress-free” cloud storage actually free?

Rarely in practice. Egress-free offers usually remove only the headline per-GB charge for internet transfer, while inter-region, inter-availability-zone and API-driven movement still bill, sometimes in both directions. Free tiers of 100 to 200 GB per month disappear within hours at production scale. Read the whole data-transfer schedule, not just the marketing line.

Can we run a hybrid model instead of choosing cloud or on-premises?

Yes, and for most estates it is the realistic answer. The decision is not binary: you allocate each workload across public cloud, private cloud and on-premises based on data gravity, switching cost and utilisation shape. A steady-state 24/7 workload may suit private cloud, while bursty or experimental work stays public. Hybrid is a portfolio, not a compromise.

How long does a cloud repatriation project typically take?

Plan for months, not weeks. A typical project runs through workload inventory, instrumented baselines, a pilot migration, then staged cutover, with parallel running during the transition. That parallel-running period carries real cost and belongs in the model. Rushing the measurement stage is the most common reason claimed savings fail to appear.

What is data gravity, and how do I measure it?

Data gravity is the tendency for applications and services to accumulate around large, established data sets, because moving the data is costly and slow. You measure it by the volume and growth rate of your stored data, how many dependent services query it, and the egress cost of moving it. High data gravity raises switching cost and pushes the lock-in threshold closer.

How much should we budget for staff reskilling in a repatriation?

Budget it as a line item, not an afterthought. Leaving a hyperscaler means rebuilding skills in virtualisation, storage, networking and day-2 operations, plus retaining or hiring specialists. Staffing and day-2 operations form the third bucket of a full TCO model, alongside migration, run-rate and risk. Underestimating it is a common cause of repatriation disappointment.

Does moving to the cloud always reduce capital expenditure?

No. Cloud shifts spend from capital to operating expenditure, which improves cash flow but does not automatically lower total cost. Over a three-year horizon, a steady-state 24/7 workload can be cheaper on-premises once hardware, depreciation and power are modelled against subscription pricing. The trade-off is upfront capital and operational complexity versus predictable OpEx.

Which workloads are the weakest candidates for repatriation?

Workloads with high data gravity, deep dependency on proprietary managed databases, AI or analytics services, and bursty demand are the weakest candidates. Rewriting them is expensive and the switching cost usually exceeds the saving. Raw compute and storage, by contrast, are portable and often move cleanly. Test the lock-in threshold per workload rather than applying a blanket rule.

What hidden cloud egress charges should I look for in my bill?

Look past the headline data-transfer-out rate. Inter-region and inter-availability-zone traffic is often billed in both directions, disaster-recovery restore and replication generates recurring charges, and telemetry or logging egress can quietly accumulate. Resilience-oriented architectures generate more cross-zone traffic than teams expect. Map every data path that crosses a provider network boundary.

Is it cheaper to renegotiate with Broadcom than to migrate away?

Sometimes, but never assume it. Renegotiation can cap per-core pricing or soften the bundle scope, yet you remain subscription-only with the 72-core floor and the late-renewal surcharge intact. Migration carries its own costs: hardware, migration, reskilling and day-2 operations. Model both paths over three years with assumptions stated rather than trusting either vendor’s headline.

How do we estimate migration cost per virtual machine?

Use a per-VM range rather than a single figure. Gartner’s planning benchmark sits around $300 to $3,000 per VM, with the spread driven by application complexity, data volume and whether a rewrite is needed. Apply that range to your inventory, then add egress, parallel-running and rollback risk. A range with named drivers is more defensible than a precise-looking point estimate.

AUTHOR

James A. Wondrasek James A. Wondrasek

SHARE ARTICLE

Share
Copy Link

Related Articles

Need a reliable team to help achieve your software goals?

Drop us a line! We'd love to discuss your project.

Offices Dots
Offices

BUSINESS HOURS

Monday - Friday
9 AM - 9 PM (Sydney Time)
9 AM - 5 PM (Yogyakarta Time)

Monday - Friday
9 AM - 9 PM (Sydney Time)
9 AM - 5 PM (Yogyakarta Time)

Sydney

SYDNEY

55 Pyrmont Bridge Road
Pyrmont, NSW, 2009
Australia

55 Pyrmont Bridge Road, Pyrmont, NSW, 2009, Australia

+61 2-8123-0997

Yogyakarta

YOGYAKARTA

Unit A & B
Jl. Prof. Herman Yohanes No.1125, Terban, Gondokusuman, Yogyakarta,
Daerah Istimewa Yogyakarta 55223
Indonesia

Unit A & B Jl. Prof. Herman Yohanes No.1125, Yogyakarta, Daerah Istimewa Yogyakarta 55223, Indonesia

+62 274-4539660
Bandung

BANDUNG

JL. Banda No. 30
Bandung 40115
Indonesia

JL. Banda No. 30, Bandung 40115, Indonesia

+62 858-6514-9577

Subscribe to our newsletter