Cisco Secure Workload License provides organizations with workload visibility, Zero Trust microsegmentation, vulnerability insight, and security policy enforcement across data centers, cloud platforms, containers, and hybrid multicloud environments. Formerly known as Cisco Tetration, Secure Workload helps security teams understand application dependencies and control communication between workloads without relying only on traditional perimeter security.
With a Cisco Secure Workload License, organizations can continuously analyze workload communications, create segmentation policies, identify vulnerable software packages, and detect suspicious workload behavior. The platform supports both SaaS and on-premises deployment models, allowing enterprises to select an architecture that fits their operational, security, and data-control requirements.
Quick Benefits
- Zero Trust microsegmentation across workloads
- Application dependency and traffic visibility
- Automated segmentation policy recommendations
- Workload vulnerability detection
- Behavioral anomaly detection
- Policy simulation before enforcement
- Hybrid and multicloud workload protection
- Agent and agentless visibility options
- Centralized compliance monitoring
- Integration with Cisco Secure Firewall

At a Glance
- Product: Cisco Secure Workload
- Former Name: Cisco Tetration
- Parent Category: Cisco Security
- Primary Use: Microsegmentation and workload protection
- Deployment: SaaS or on-premises
- License Types: Workload Protection and Endpoint Visibility
- Subscription Terms: 1, 3, or 5 years
- Coverage: VMs, bare-metal servers, container hosts, VDI and endpoints
- Security Model: Zero Trust
- Environments: Data center, cloud, containers and hybrid multicloud
- Key Capabilities: Visibility, segmentation, vulnerability analysis and behavioral detection
Cisco Secure Workload License Overview
Cisco Secure Workload licensing is primarily based on the assets from which the platform collects telemetry or applies workload-security controls. The main license is the Secure Workload Protection license, which covers protected workload equivalents such as virtual machines, bare-metal servers, container hosts, and supported virtual desktop environments.
The Workload Protection license enables capabilities such as telemetry collection, application insight, vulnerability detection, forensic analysis, policy recommendations, policy simulation, segmentation enforcement, and compliance tracking.
Cisco also provides an Endpoint Visibility license for collecting additional context from user endpoints. This can include telemetry obtained through supported Cisco endpoint and identity integrations. Endpoint licensing is separate from workload protection licensing and is intended primarily for organizations that need endpoint context as part of their workload visibility and policy model.
Secure Workload subscriptions are available for both SaaS and on-premises environments. Organizations should determine their intended deployment model before purchasing because SaaS and on-premises licenses are treated as separate licensing options.
Cisco Secure Workload Product Overview
Cisco Secure Workload provides detailed visibility into communications between applications and workloads. It observes traffic patterns, workload attributes, processes, and application dependencies to help security teams understand which systems communicate and why those communications are required.
This information forms the foundation for microsegmentation. Instead of manually designing firewall rules for every server or application, administrators can use observed communication patterns to build more accurate segmentation policies.
Secure Workload can then enforce policies at different control points depending on the architecture. This makes it possible to limit unnecessary east-west communication and reduce the ability of an attacker to move laterally after compromising a workload.
The platform also adds workload-security context by identifying vulnerable packages and abnormal process behavior, allowing segmentation decisions to incorporate security conditions rather than relying only on IP addresses or network locations.
Core Technical Flow
Cisco Secure Workload begins by collecting telemetry and contextual information from workloads and supported infrastructure. Depending on the deployment, this can involve software agents as well as agentless sources and integrations.
The collected data allows the platform to map application communications and dependencies. Administrators can organize workloads using attributes such as application, environment, location, role, or other relevant labels.
Secure Workload analyzes these relationships and generates recommended segmentation policies based on observed behavior. Before enforcement, policies can be analyzed and simulated to identify potential communication disruptions.
Approved policies can then be enforced across the appropriate enforcement points. Continuous monitoring helps security teams identify policy violations, changes in application behavior, vulnerabilities, and potentially suspicious activity after deployment.
Options & Licensing Models
| Licensing Option | Primary Purpose | Typical Scope |
|---|---|---|
| Workload Protection License | Visibility, microsegmentation, vulnerability analysis, policy enforcement and workload protection | VMs, bare-metal servers, container hosts and supported VDI workloads |
| Endpoint Visibility License | Adds endpoint telemetry and contextual information to Secure Workload | Supported laptops, desktops and other endpoint environments |
| SaaS Deployment | Cisco-hosted Secure Workload platform | Organizations preferring cloud-delivered management |
| On-Premises Deployment | Secure Workload deployed within the organization’s own environment | Organizations requiring local control of applications and data |
| 1-Year Subscription | Shorter subscription commitment | Flexible or initial production deployments |
| 3-Year Subscription | Multi-year software subscription | Established enterprise deployments |
| 5-Year Subscription | Longer-term software subscription | Long-term workload-security programs |
The required quantity depends primarily on the number and type of workloads or endpoints being monitored and protected. On-premises deployments may also require the appropriate Secure Workload platform infrastructure in addition to software subscriptions.
Features & Benefits
Zero Trust Microsegmentation and Application Visibility
Cisco Secure Workload provides detailed visibility into workload communications and application dependencies, allowing security teams to understand how applications actually interact before applying segmentation. The platform can recommend policies based on observed traffic and enforce granular controls around individual workloads or application groups. This helps reduce unnecessary east-west connectivity, limit lateral movement, and implement Zero Trust principles without depending exclusively on traditional network boundaries.
Vulnerability and Behavioral Workload Protection
Secure Workload extends beyond segmentation by analyzing workload security conditions. With supported telemetry, the platform can identify vulnerable software packages and container images while monitoring processes for behavioral changes and suspicious activity. Vulnerability and runtime context can then contribute to security policies, allowing organizations to isolate higher-risk workloads or coordinate additional protection through integrated Cisco security technologies.
Policy Automation, Simulation, and Hybrid-Cloud Consistency
Application environments constantly change as workloads move, scale, or migrate between infrastructure platforms. Cisco Secure Workload uses workload attributes and automated policy recommendations to reduce dependence on static IP-based rules. Administrators can simulate proposed policies before enforcement, helping identify unintended application impact. Consistent segmentation policies can then follow applications across on-premises, cloud, containerized, and hybrid environments.
Compatibility & Requirements
Before ordering a Cisco Secure Workload License, organizations should assess:
- Number of virtual machines and physical servers
- Container hosts and containerized applications
- VDI workloads requiring protection
- SaaS versus on-premises deployment requirements
- Supported operating systems and agent versions
- Public-cloud platforms in use
- Application and workload segmentation requirements
- Existing firewall and security architecture
- Endpoint visibility requirements
- Cisco Secure Firewall integration requirements
- Data-retention and telemetry requirements
- High-availability and scalability requirements
Operating-system and software-agent support can vary between Secure Workload releases. Compatibility should therefore be validated against Cisco’s current platform support matrix before finalizing the architecture or license quantity.
Activation and Deployment
Deployment normally begins with sizing the environment and determining which workloads require visibility and enforcement. Administrators then deploy or connect the appropriate telemetry sources and organize discovered workloads using relevant labels and attributes.
The next stage is application dependency analysis. Secure Workload observes communication patterns and helps administrators identify legitimate relationships between application components.
Segmentation policies can then be generated and reviewed before enforcement. Policy simulation is especially important in production environments because it allows security teams to evaluate the potential impact of a proposed rule without immediately disrupting application traffic.
After validation, enforcement can be introduced gradually according to application, environment, or workload group. Continuous monitoring should remain enabled so that infrastructure changes, policy violations, vulnerabilities, and behavioral anomalies can be evaluated after deployment.
Cisco Secure Workload License Pricing and Quote
Cisco Secure Workload License pricing depends primarily on the number of workloads or endpoints requiring coverage, subscription duration, and whether the solution will be deployed as SaaS or on-premises.
Cisco offers software subscriptions with 1-, 3-, and 5-year terms. Workload Protection licensing is calculated according to the number of workload equivalents that require Secure Workload capabilities, while Endpoint Visibility licensing is based on the number of endpoints for which additional telemetry and context are required.
For an accurate quote, prepare the number of virtual machines, physical servers, container hosts, VDI instances, required endpoints, deployment model, subscription duration, and existing Cisco security infrastructure. On-premises projects should also identify any platform or appliance requirements before the final bill of materials is prepared.
Cisco Secure Workload pricing depends on your license type, deployment model and support requirements.
