Something has shifted in how enterprise security gets bought, and I do not think the channel has fully caught up with it yet.
Palo Alto Networks, CrowdStrike, Snowflake, these are not simple or lightweight vendors. They have sophisticated direct sales motions, large enterprise field teams and complex solution architectures that have traditionally required significant pre-sales and professional services to land properly. And yet all three have crossed $1 billion in AWS Marketplace transactions. That is not a coincidence and it is not just about procurement convenience. It reflects something more fundamental: security and data budgets are increasingly sitting inside cloud commitments, and customers want to use them there.
From what I am seeing in enterprise accounts, a few things are driving this. The consolidation of security spend is a big one. Organisations that spent years accumulating point solutions are now under serious pressure to rationalise, and platform vendors are the beneficiaries of that rationalisation. Then there is the rise of cloud-native security requirements: if your workloads are in AWS or Azure, there is a strong operational and commercial logic to procuring the security tooling through the same environment. And probably the most underappreciated factor is that Microsoft Azure Consumption Commitments and the equivalent AWS construct give customers a commercial incentive to route security spend through the hyperscaler channel that simply did not exist five years ago.
The interesting question for partners is what this means for the services model. Security has always been a domain where trust, expertise and long-term relationship matter more than almost any other technology category. A CISO is not going to buy a complex detection and response platform through a marketplace checkout and figure out the rest independently. They need someone who understands the threat landscape, the integration requirements, the compliance picture and the operational model. None of that goes away because the transaction routes through a marketplace. If anything it becomes more important, because the speed of the marketplace motion means customers need a partner who can move at the same pace on the services side.
There is also a newer dynamic worth watching. The ServiceNow and AWS $1 billion marketplace announcement was specifically anchored to an AI governance platform, combining ServiceNow AI Control Tower with Amazon Bedrock AgentCore to manage and govern AI agents across an enterprise. Security, IT operations and telecoms were the first industry integrations launched. That tells you something about where the security and AI governance conversation is heading, and it is heading through the marketplace.
This is why I think security is actually one of the strongest arguments for a services-first marketplace model rather than a purely transactional one. The commercial motion simplifies. The services complexity does not. The partners who understand both, and can show up in the right place in the customer’s buying journey, will do well. The ones who treat it as a faster checkout will find the margin has moved somewhere else.
The real question is not whether this shift is happening, but how quickly security leaders will need to adapt as purchasing decisions increasingly move through marketplace-driven channels.
The real question is not whether this shift is happening, but how quickly security leaders will need to adapt as purchasing decisions increasingly move through marketplace-driven channels.
Want to learn more? Connect with one of our specialists:
Fabienne Porquet, Marketplace Sales Specialist – SCC UK Sales Software
Author: Andy Dunbar, Managing Director, Software & Security (UK)
We also recommend reading The Real Challenge Behind ServiceNow’s New Licensing Model
