SSO Blocks Half Your Enterprise Deals. A 425% Markup to Turn It On Just Moves the Churn to Renewal.
SSOJet says missing SSO blocks half of enterprise SaaS deals. Gating it behind a 400%+ markup doesn't close the gap — it just delays the churn.
Somewhere in your pipeline right now is a deal that was going well — good champion, budget approved, verbal yes — until security asked one question: does this support SSO? If the answer is "yes, on our Enterprise plan," and Enterprise costs three or four times what the prospect was expecting to pay, you haven't lost the deal yet. But you've just handed your own sales team the hardest conversation in the cycle, and you've planted the same conversation a year from now at renewal, when the account has to decide whether the markup was worth it a second time.
SSOJet's framing of that number is blunt: missing SSO now blocks roughly half of otherwise-winnable enterprise deals, and the rejections tend to land weeks into a sales cycle, after a sales engineer has already burned real hours on the account. That's the demand side of this problem, and most SaaS teams already feel it. What gets less attention is the supply side — most vendors that do offer SSO still price it as a luxury add-on, which turns a security requirement into a negotiation the customer has to win or lose, every single renewal.
What the SSO tax actually looks like
The term comes from a community-maintained tracker, sso.tax, which catalogs what SaaS vendors charge to unlock SAML or OIDC-based single sign-on relative to their base plan. As of its 2026 snapshot it covers roughly 150 vendors, and a newer, quarterly-verified index called the SSO Premium Index sorts 34 of the best-known ones into three bands: Fair, where SSO ships at no markup; Premium, a markup under 50%; and Tax, a markup of 50% or more. A meaningful share of well-known tools land in that last bucket.
| Vendor | What's gated | Approximate markup to unlock it |
|---|---|---|
| GitHub | SAML SSO (Team → Enterprise) | 425% ($4 → $21 per user/month) |
| Figma | SSO + SCIM provisioning | ~275% |
| Notion | SSO | ~88% |
| Slack | SSO + SCIM provisioning | ~72% |
Figures approximate, drawn from the sso.tax public catalog and independent vendor pricing checks (2026); vendors adjust pricing regularly.
The pattern holds across almost every entry on the list: the underlying cost of supporting SAML or OIDC is dominated by a one-time integration and some ongoing maintenance, not a per-seat infrastructure expense that scales the way these markups do. What scales instead is willingness to pay. A team that's decided it can't pass a security review without SSO has already lost most of its negotiating leverage before the quote even arrives.
Why demand for SSO outpaces supply of it
Two forces are pushing SSO from "nice to have" to "must have" faster than most vendors' pricing tiers have adjusted. Cyber insurance underwriters increasingly require MFA and centralized identity management as a condition of coverage or a lower premium, which means a customer's entire SaaS stack can get swept into a renewal-time audit that has nothing to do with how happy they are with any individual tool. And enterprise procurement, the same tightening trend we've covered in our piece on security review churn, now treats SSO/MFA availability as a checkbox that has to be checked in the plan being bought, not just offered somewhere in the product.
The result is a supply-demand mismatch that shows up clearly in how little of the average company's SaaS footprint is actually behind SSO today, despite how much of it buyers say they now require.
Sources: SSOJet, 2026 enterprise identity research; Zylo, 2026 SaaS Management Index.
Zylo's 2026 SaaS Management Index puts average SSO coverage across a company's SaaS stack at just 21%, and separate research from Grip Security, based on conversations with over 100 CISOs, found roughly 80% of the SaaS applications employees actually use never touch their company's SSO portal at all. Some of that gap is inertia. A real chunk of it is that the tool in question simply doesn't offer SSO below a price point the buyer's team was never budgeted for.
Where this turns into a renewal problem instead of a sales problem
A prospect who walks away from an SSO markup during the sales cycle is a lost deal, and it's visible — someone on your team watches it happen and can name the reason. The more expensive version of this plays out after the sale, inside an account that's already live. A customer signs up on your mid-tier plan with ten seats, grows to sixty over eighteen months, and only then runs into a mandate — a cyber insurance renewal, a new enterprise customer of their own requiring vendor security attestations, an internal IT policy tightening after an unrelated breach in the news — that says every tool touching company data now needs to sit behind SSO. At that point they're not shopping. They're already your customer, already dependent on the product, and the only path to compliance runs through whatever number your enterprise tier costs.
Most of those accounts pay it. Switching costs on an embedded tool are real, and a security mandate with a deadline doesn't leave much room to run a vendor bake-off. But paying under duress is not the same as staying happy about it, and it's structurally similar to what we've described in our guide to raising SaaS prices without spiking churn: a sudden, large, non-negotiated cost increase is one of the few single events that can flip a stable account into an active flight risk, even when they sign the new invoice without complaint. The difference here is that the increase isn't framed as a price change at all — it's framed as a security requirement, which makes it feel less negotiable and more resented at the same time.
The trigger that makes this worse: renewal timing
The accounts most exposed to this are the ones whose SSO mandate lands close to their contract renewal date, because that's the moment a customer is already evaluating the relationship anyway. A forced upgrade that arrives mid-contract at least gets absorbed into a relationship the customer has already committed to for months. One that arrives at renewal collapses two decisions into one: does this vendor still deserve our business, and can we afford what they're now asking for to keep using it securely. Bundling a security-driven price shock with a renewal decision is close to the worst timing available, and it's timing most vendors don't choose deliberately — it's just where the mandate happens to land.
What to actually do about it
- Move SSO into the tier your growth-stage accounts land in, not your top-of-ladder enterprise plan. If a sixty-seat account is a realistic size for your mid-market tier, that tier needs SSO in it before a mandate forces the conversation.
- Price SSO as a flat add-on fee, not a per-seat multiplier, if you're not ready to include it standard. A flat $200-500/month charge reads as a feature fee. A per-seat markup that scales with headcount reads as, and functions as, a tax on growth.
- Get ahead of the mandate instead of waiting for it to surface at renewal. If you can see which accounts are growing into the headcount range where a security review becomes likely, offer the SSO upgrade proactively, priced reasonably, before it arrives as an ultimatum from their side.
- Don't let sales quote SSO access without a documented rationale a security team could push back on. CISA and the FBI's Secure by Demand Guide gives procurement teams language to challenge a paid SSO add-on directly — expect that citation to show up in negotiations more often as the guidance gets more traction.
- Capture "couldn't get SSO at an acceptable price" as an explicit reason wherever you track lost deals and lost renewals, the same way a well-built cancellation flow captures every other specific reason someone leaves, rather than letting it disappear into a generic "budget" or "switched vendors" bucket.
None of this is really a pricing question dressed up as a security one — it's the reverse. The vendors currently winning mid-market security-conscious deals aren't necessarily the ones with the best product; some of them are simply the ones that didn't make a customer choose between staying compliant and staying on budget. If you want to see what even a handful of these forced-upgrade renewals are worth in either direction, our churn calculator turns a segment's renewal and price-sensitivity assumptions into an MRR number in a couple of minutes. And whatever you decide about SSO pricing, the accounts it eventually pushes toward the door deserve the same thing every churn-risk account does: a cancellation path, like the one CancelFlow builds, that actually tells you why they left instead of leaving you to guess.
Frequently asked questions
What is the "SSO tax" in SaaS pricing?+
The SSO tax is the practice of gating single sign-on — a standard authentication feature, not a premium one — behind a company's highest-priced plan, then charging a steep markup to unlock it. The public tracker sso.tax catalogs roughly 150 vendors doing this as of 2026, with markups ranging from under 50% to well over 400% of the base plan price for functionally the same product.
Why do SaaS vendors charge extra for single sign-on?+
The honest answer is willingness to pay, not cost. Building and maintaining SAML or OIDC support takes real one-time integration and ongoing maintenance work, but that cost doesn't scale per seat the way the markups do. Vendors gate SSO behind an enterprise tier because the buyers who need it — security-conscious mid-market and enterprise teams — have already decided they can't operate without it, which makes their demand for the feature almost perfectly inelastic once a security review is underway.
Does gating SSO behind an enterprise tier actually cause churn?+
It shows up less as a cancellation and more as a grudging, price-resistant renewal that eventually breaks. A team already embedded in your product rarely cancels on the spot when SSO is quoted at a 300-400% markup — switching costs are real. What it does is convert that account into a flight risk that takes the next competitor's inbound call seriously, and gives them a specific, articulable reason to leave the moment a rebuild becomes less painful than paying your markup again.
What does CISA's Secure by Demand guidance say about SSO pricing?+
CISA and the FBI's 2024 Secure by Demand Guide directly asks software buyers to check: "Does the manufacturer support integrating standards-based single sign-on (SSO) for customers at no additional cost?" It frames charging extra for SSO as a secure-by-design anti-pattern buyers should screen for, not a security decision. The guidance has no enforcement teeth over private SaaS pricing, but it gives procurement and security teams an official citation to push back with during a renewal negotiation.
Stop losing subscribers today
One script tag. One function call. A live cancellation flow in under 10 minutes.
Start free trial →