Guide

identity services engine ordering guide

Identity Services Engine (ISE) ordering guide offers a concise roadmap for acquiring, deploying, and supporting Cisco’s AAA platform. It details licensing tiers, order types, and pricing models, ensuring customers align solutions with security and compliance goals. It outlines support options. See!!!!!

Core ISE Licensing Models

ISE licensing splits into software‑only and hardware‑integrated models. Software‑only licenses cover core AAA functions, while hardware‑integrated bundles pair ISE with dedicated appliances for high‑availability and scalability. Each tier scales by concurrent sessions, offering flexibility for growth.!!!!

Software-Only Licenses

Software‑only licenses provide the core Identity Services Engine (ISE) functionality without dedicated hardware. They cover authentication, authorization, and accounting (AAA) services, endpoint profiling, guest portal, and policy enforcement. Licenses are sold in tiers—Basic, Enhanced, and Premium—each scaling by the number of concurrent user or device sessions. The Basic tier includes the software, configuration guidance, and access to Cisco support with a standard response time. Enhanced and Premium tiers add a richer feature set, including advanced reporting, policy templates, and faster response times. These higher tiers are priced per concurrent session and can be ordered via the top‑level ATO PID in Cisco’s CCW system (CISE‑SW‑SUPP). The ordering guide details packaging, pricing, and the process for selecting the appropriate tier based on expected traffic and security requirements. Software‑only licenses are ideal for organizations that already own or plan to deploy their own hardware or prefer a virtual appliance deployment. Customers can also opt for a perpetual license or a subscription model, with the latter offering annual renewal and continuous updates, ensuring the platform stays current with evolving threat landscapes. Additionally, the licensing agreement offers a tiered support plan with 24/7 assistance, priority incident handling, and access to Cisco’s knowledge base, upgradeable to premium support for critical deployments needing rapid response. These options allow tailoring ISE to security budget needs. Customers may also buy a perpetual license, access to the software and a set number of concurrent sessions, renewal fees!!

Hardware-Integrated Licenses

Hardware‑integrated licenses bundle the Identity Services Engine (ISE) software with Cisco’s dedicated appliance, delivering a turnkey solution that simplifies deployment and management. These licenses are sold as a single unit, combining the ISE software, a pre‑configured appliance, and a defined number of concurrent session slots. The appliance provides a secure, hardened platform that eliminates the need for separate server hardware, reducing operational overhead and ensuring consistent performance. Licensing tiers—Basic, Enhanced, and Premium—mirror the software‑only model but include the hardware component, allowing customers to scale session capacity while benefiting from integrated hardware support. The ordering guide specifies that hardware‑integrated licenses are available through Cisco’s Configuration and Ordering System (CCW) and are identified by the ATO PID CISE‑HW‑SUPP. Customers can choose a perpetual license or a subscription model; subscription licenses include annual renewal and continuous software updates, ensuring the appliance remains current with the latest security features and bug fixes. Support for hardware‑integrated licenses is tiered: Basic support provides standard response times and access to Cisco’s knowledge base, while Enhanced and Premium tiers offer expedited response, 24/7 assistance, and priority incident handling. The guide emphasizes that hardware‑integrated licenses are ideal for organizations seeking a ready‑to‑run solution that guarantees compatibility, optimized performance, and streamlined maintenance, thereby reducing total cost of ownership and accelerating time to deployment. The ordering process includes selecting the appropriate appliance model, determining session capacity, and configuring the license type to match organizational security objectives. This integrated approach ensures that enterprises can deploy a robust, scalable ISE environment with minimal complexity and maximum reliability.

ISE Order Types

ISE ordering offers three distinct order types: Standard, Enhanced, and Premium. Each tier aligns with feature depth, support speed, and session capacity, enabling customers to match licensing to security needs while optimizing cost and deployment flexibility.

See guide. Info.

Standard Order

The Standard Order tier is designed for organizations that require core ISE functionality without the extended feature set of Enhanced or Premium packages. It includes the base software license, essential AAA services, and basic policy enforcement capabilities. Customers receive a limited number of concurrent session seats, typically sufficient for small to medium deployments. The Standard Order supports fundamental authentication methods such as 802.1X, MAC authentication bypass, and web portal access. It also provides basic device profiling, guest access, and simple role‑based access control. Licensing is delivered through a single product SKU, simplifying procurement and renewal processes. Support for Standard Orders is available through Cisco’s standard support channel, offering 24/7 access to technical documentation and community forums. The order type is suitable for environments that prioritize cost efficiency while maintaining essential network access controls. It does not include advanced analytics, integration with external identity providers, or advanced policy scripting. However, it can be upgraded to Enhanced or Premium tiers through a license add‑on, allowing organizations to scale features as security requirements evolve. The Standard Order is ideal for new deployments that need a proven, stable foundation for identity‑based network access management. In addition, the Standard Order provides a straightforward licensing model that aligns with Cisco’s subscription‑based approach, enabling predictable budgeting and reducing upfront capital expenditure. It also includes access to Cisco’s online knowledge base and a limited set of configuration templates to accelerate deployment. For organizations with hybrid environments, the Standard Order supports integration with existing RADIUS servers and basic policy mapping, ensuring seamless transition from legacy solutions. It also supports basic VPN integration for remote users.

Enhanced Order

Enhanced Order expands upon the core ISE capabilities by adding advanced policy controls, integration options, and higher session limits. It includes the full suite of device profiling, guest management, and role‑based access control, plus the ability to enforce contextual policies based on location, device health, and threat intelligence. The Enhanced Order supports integration with external identity providers (IdPs) via SAML, OAuth, and LDAP, enabling single sign‑on across corporate applications. It also offers advanced reporting and analytics, providing real‑time visibility into network access patterns and user behavior. Licensing for Enhanced Order is delivered through a multi‑seat SKU that scales with concurrent sessions, allowing organizations to accommodate growth without re‑licensing. Support for Enhanced Order is available through Cisco’s enhanced support channel, which offers faster response times, dedicated technical account managers, and access to expert configuration guidance. The order type is ideal for mid‑size to large enterprises that require granular policy enforcement, automated remediation, and integration with broader security orchestration platforms. It also supports advanced VPN features, such as split tunneling and dynamic routing, to improve remote user experience. The Enhanced Order can be upgraded to Premium Order for additional features such as advanced threat detection, zero‑trust network access, and full integration with Cisco SecureX. Overall, Enhanced Order provides a balanced mix of advanced functionality and cost‑effective licensing, a popular choice for organizations looking to strengthen network access controls while maintaining operational flexibility.

Premium Order

Premium Order delivers the highest level of ISE functionality, combining all core features with advanced security services, zero‑trust enforcement, and comprehensive integration across the Cisco security portfolio. It includes the full set of device profiling, guest management, and role‑based access control, plus the optional Advanced Threat Defense (ATD) module that correlates network activity with global threat intelligence feeds. Premium Order supports multi‑factor authentication (MFA) integration, dynamic policy updates via Cisco SecureX, and automated remediation workflows that trigger network segmentation or device quarantine when anomalous behavior is detected; Licensing is based on concurrent session capacity, with a flexible SKU that scales from 1,000 to 10,000 sessions, allowing enterprises to grow without re‑licensing. Support for Premium Order is delivered through Cisco’s Premium Support channel, offering 24/7 access to senior engineers, priority incident handling, and proactive health checks. The order also includes a dedicated technical account manager who provides strategic guidance on policy design, deployment best practices, and ROI analysis. Premium Order is ideal for large organizations that require end‑to‑end visibility, automated threat response, and seamless integration with identity, threat intelligence, and network segmentation solutions. It is the recommended choice for customers that demand the most robust security posture and the highest level of operational assurance. Additionally, the Premium Order includes automated policy drift alerts to maintain security postures daily

Deployment Scenarios

Deploying Cisco Identity Services Engine (ISE) requires careful alignment of licensing, hardware, and network architecture with an organization’s security strategy. For small‑to‑mid‑sized businesses (SMBs) that host a few hundred endpoints, a Software‑Only license is typically adequate. The ISE appliance can be installed on a single physical or virtual server, providing core authentication, authorization, and accounting (AAA) services without the need for additional hardware modules. Large enterprises with thousands of devices and multiple campus sites usually opt for a Hardware‑Integrated license. In this scenario, ISE is distributed across core, distribution, and access layers, often paired with Cisco Identity Services Engine Edge appliances to enforce local policy. The deployment incorporates Guest Access and Guest Portal features for secure onboarding of contractors and visitors, and integrates multi‑factor authentication (MFA) with Active Directory or LDAP to strengthen user verification. Coupling ISE with Cisco SecureX delivers real‑time threat intelligence. Hybrid cloud environments leverage ISE’s integration with Cisco SecureX and Cisco Umbrella. The ISE appliance runs in a virtualized data center, while SecureX orchestrates policy updates and threat feeds. This hybrid model gives on‑premises control over local policy and benefits from cloud threat intelligence and automated response. It also supports secure connectivity for remote workers by enforcing device posture assessment, ensuring only compliant devices can access corporate resources. ISE also supports integration with Cisco Identity Services Engine Analytics for detailed reporting and trend analysis, enabling proactive security posture management. Additionally, the solution can be extended with Cisco Secure Firewall integration, allowing policy enforcement across both network and application layers. All deployments benefit from Cisco’s 24/7 support and regular software updates, and continuous monitoring for compliance daily and!

Ordering Process Steps

Step 1: Assess your environment and determine the appropriate ISE license type—Software‑Only or Hardware‑Integrated—based on the number of concurrent sessions and deployment scale. Step 2: Choose an order type that matches your business needs: Standard for baseline AAA, Enhanced for added support and configuration guidance, or Premium for advanced features and priority response. Step 3: Add optional support packages, such as Software Support, which is tied to the ISE‑SW‑SUPP PID, and select the desired support level (Basic, Enhanced, Premium). Step 4: Prepare the order in Cisco’s Commerce Workspace (CCW) or through a Cisco partner, ensuring all required fields (licensing, support, delivery method) are completed. Step 5: Submit the order for approval; Cisco will validate the configuration and confirm availability of the selected licenses. Step 6: Receive an order confirmation and a unique order number. Step 7: Track the order status via the Cisco Order Tracking portal and coordinate delivery with the logistics team. Step 8: Upon receipt, install the ISE appliance following Cisco’s installation guide, apply the license key, and configure initial network settings. Step 9: Verify the deployment by running the ISE Self‑Test and validating connectivity to authentication sources. Step 10: Document the deployment and update the asset inventory. Step 11: Schedule regular maintenance windows and adapt quickly. This structured approach ensures compliance, minimizes downtime, and aligns the ISE deployment with organizational security objectives.

Pricing and Cost Factors

Pricing for Cisco Identity Services Engine (ISE) is driven by several key variables that influence the final cost of acquisition and ongoing support. The base license fee is determined by the selected license model—Software‑Only or Hardware‑Integrated—and the number of concurrent user sessions the deployment is expected to handle; Cisco typically offers tiered pricing where lower session counts benefit from a lower per‑session rate, while higher volumes may qualify for volume discounts or enterprise agreements. In addition to the core license, optional support packages add a recurring cost that scales with the chosen support level (Basic, Enhanced, Premium). Support fees are calculated as a percentage of the base license price and are billed annually. The order type selected (Standard, Enhanced, Premium) also affects the cost: Premium orders include extended feature sets and accelerated response times, which are reflected in a higher upfront fee. Delivery method—electronic download versus physical media—can introduce a nominal surcharge for shipping and handling. Currency conversion and regional tax rates further modify the final invoice. Finally, Cisco offers bundled pricing for multi‑product purchases, such as combining ISE with other security solutions, which can provide cost savings through negotiated discounts. Understanding these variables allows organizations to forecast expenses accurately and negotiate favorable terms during the ordering process. All amounts are estimates and may vary in.

Support and Maintenance Options

Cisco’s Identity Services Engine (ISE) support ecosystem is structured around tiered service levels that align with an organization’s operational demands and risk appetite. The baseline “Basic” package delivers essential technical assistance, including access to Cisco’s knowledge base, community forums, and a standard 24‑hour response window for critical incidents. For environments that require faster intervention, the “Enhanced” tier expands the response window to 4 hours for high‑priority issues and offers dedicated account management, proactive health checks, and quarterly security advisory briefings. The highest tier, “Premium,” provides 24‑hour on‑site support, a dedicated technical account manager, and a guaranteed resolution time of 2 hours for critical problems. Each tier is billed annually and can be bundled with the selected ISE license to create a comprehensive solution footprint. In addition to the tiered packages, Cisco offers optional “Extended Maintenance” add‑ons that cover firmware upgrades, patch releases, and compliance updates beyond the standard lifecycle. These add‑ons are priced as a percentage of the base license and can be tailored to the number of managed endpoints. For large deployments, Cisco’s Enterprise Support Program offers volume discounts, priority scheduling, and a dedicated support portal that aggregates ticketing, status dashboards, and knowledge articles. All support contracts include SLA guarantees, defined escalation paths, and a clear definition of “critical” versus “non‑critical” incidents. Organizations should assess their risk tolerance, compliance obligations, and operational tempo when selecting a support level to ensure alignment with ISE’s security objectives. The portal provides real‑time dashboards that display ticket volume, resolution times, and SLA compliance!!

Order Verification Practices

Before finalizing an Identity Services Engine (ISE) purchase, organizations should conduct a structured verification process to confirm that the ordered components match the intended deployment architecture and licensing requirements. The first step is to cross‑check the order number against the Cisco Configuration Wizard (CCW) entry, ensuring the correct product code (e.g., CISE‑SW‑SUPP for software‑only support) and the selected order type (Standard, Enhanced, or Premium). Next, validate the license count: the number of concurrent session seats must align with the projected user base and the chosen support tier. Cisco’s licensing portal provides a real‑time seat calculator; discrepancies should be corrected before the order is approved. Following license validation, confirm the hardware integration details: if a hardware‑integrated license is selected, verify that the serial numbers of the target appliances match the order documentation. For software‑only licenses, ensure that the deployment plan includes the necessary virtual machine images and that the ISE version is compatible with the existing network infrastructure. After these technical checks, review the support level: the order should reflect the correct SLA commitments (Basic, Enhanced, or Premium) and any optional maintenance add‑ons. Finally, perform a reconciliation audit by comparing the order confirmation email, the CCW summary, and the invoice. Any mismatches should trigger a ticket in the Cisco Service Portal, where a technical account manager can intervene. This verification cycle reduces the risk of post‑deployment gaps, ensures compliance with Cisco’s licensing policy, and guarantees that the ISE solution delivers the promised security posture without unexpected service interruptions. All verification steps should be documented in the project management system, and any changes to the order must be logged with a timestamp and the name of the approving authority to maintain audit trails. Additionally, periodic re‑validation is recommended after major network upgrades to ensure that the ISE configuration remains aligned with the updated device inventory and policy changes.

Leave a Reply