Cisco Smart Licensing is the system Cisco Systems uses to deliver, organize and track software entitlements across its portfolio. Purchased licenses are deposited into a customer’s Smart Account, a central pool that can be divided into Virtual Accounts, and devices report what they consume to Cisco Smart Software Manager (CSSM). Cisco describes Smart Software Licensing as a model that gives customers “visibility to what you have purchased and what you are using”, in contrast to the older Product Activation Key (PAK) method, where keys are configured device by device and delivered on paper, with the device or by email.[1]
Smart Licensing Using Policy (SLP) is the current generation of the model. Cisco calls it “an evolved version of Smart Licensing”: products boot without an evaluation period and without per-product registration, and no longer have to contact CSSM every 30 days. Products running Cisco IOS XE 17.3.2/17.4.1, IOS XR 24.1.1 or NX-OS 10.2(1) and later support only SLP.[1]
Neither Smart Licensing nor SLP is a unit of purchase. What a customer pays for is set by the meters in Cisco’s Offer Descriptions (Device, Endpoint Session, Knowledge Worker, Covered User and others), described in Cisco software subscription and Flex Plan licensing. Smart Licensing decides where those entitlements sit, who can move them, and how usage is compared against them. For an effective license position, the Smart Account is therefore the main source of entitlement data for Cisco.
Account structure
Smart Accounts and Virtual Accounts
Cisco states that “the first step to using Smart Licensing is to set up a Smart Account”. The Smart Account is where users are viewed, products registered and Smart Licenses managed.[1] For some hardware lines it is a precondition of ordering: the Catalyst 9300 ordering guide says Smart Accounts are mandatory when a Catalyst 9300 switch is ordered, and that a new Smart Account must be created at the time of purchase if the customer has none (rule).[3]
Virtual Accounts are “customizable sub-accounts” within the Smart Account, used to organize licenses by department, network or any other division the customer chooses.[1] The split has licensing consequences. The Secure Firewall configuration guide explains that licenses are assigned to the Default Virtual Account unless moved, and that “only that virtual account’s appliances can use the licenses assigned to the account”. An unused license can be transferred from another Virtual Account when more are needed (rule).[4] A shortfall in one Virtual Account can therefore coexist with spare licenses in another, and it stays a shortfall until a transfer is made.
Special account types
- Limited Use Smart Account. A reduced version for small and medium businesses that have no company email domain and use a public email domain.[1]
- Partner Holding Account. A Smart Account type that lets Cisco partners hold orders before the end customer is known. Licenses can be consumed only in Smart Accounts, not in Partner Holding Accounts, so entitlements parked there cannot cover deployed devices until they are transferred (rule).[1]
Roles
The licensing guide defines five roles with different rights:[1]
| Role | Can manage licenses | Other rights |
|---|---|---|
| Smart Account approver | No | Approves licensing terms, edits Smart Account properties, views users and event logs |
| Smart Account administrator | Yes, whole Smart Account | Edits properties, adds users and Virtual Accounts, views event logs |
| Smart Account user | Yes, all Virtual Accounts | Cannot create Virtual Accounts or manage users |
| Virtual Account administrator | Yes, assigned Virtual Accounts | Adds users to assigned Virtual Accounts, views their event logs |
| Virtual Account user | Yes, assigned Virtual Accounts | Cannot add users |
The approver restriction is catalogued as a rule.
Metrics
Smart Licensing adds no metric of its own. Each Smart License in the pool carries the meter of the offer it was bought under, such as the per-device Catalyst Subscription or the Secure Firewall feature licenses. The catalog records the account and reporting rules on this page as rules, not metrics.
Counting / floors
Compliance under classic Smart Licensing
Under classic Smart Licensing, devices “call home” to the Smart Account and receive one of two answers. “Authorized” means the pool covers current use across all devices in it. “Out of compliance” means it does not. In most cases the product keeps working but begins to issue notices, and “after 90 days, product functionality may be limited until the license shortage is resolved” (rule).[1] CSSM raises a “major” alarm in the affected Virtual Account showing the licenses needed and the quantity required.[1]
A pool can fall out of compliance without any new deployment. The guide lists new consumption and a decrease in licenses “due to expiration of subscriptions or terms” as the two causes.[1] Subscription end dates are therefore compliance events in their own right.
Enforcement types under SLP
Under SLP every license has an enforcement type.[2]
- Unenforced licenses need no authorization or registration before use. Cisco gives the Cisco DNA licenses on all Catalyst 9000 switches as its example (rule).
- Enforced licenses need an authorization code installed before use. None of the Catalyst 9000 licenses are of this type; Cisco’s example is the Media Redundancy Protocol client license on Industrial Ethernet switches.
- Export-controlled licenses are restricted by U.S. trade-control law and also need authorization. Cisco’s example is the High Security (HSECK9) key on certain Catalyst 9000 models (rule).
The authorization takes the form of a Smart Licensing Authorization Code (SLAC), requested from CSSM. A SLAC can be returned to the pool only after the feature that uses it has been disabled.[2]
“Unenforced” does not mean “free”. The software does not stop an unlicensed feature from running, but use still has to be covered by purchased entitlements and is reported to CSSM. The Catalyst 9300 ordering guide requires a DNA or Catalyst subscription with every switch purchase regardless of enforcement type.[3]
Policies and RUM reports
Under SLP the product records its usage in Resource Utilization Measurement (RUM) reports, which are sent to CSSM and acknowledged with a RUM ACK. A policy, chosen by CSSM, tells the product whether an acknowledgement is required, when the first report is due, how often to report, and how quickly to report a change in usage. Customers cannot configure a policy themselves, but they can ask Cisco’s Global Licensing Operations team for a customized one.[2]
The Cisco default policy values are:[2]
| License type | ACK required | First report (days) | Reporting frequency (days) | Report on change (days) |
|---|---|---|---|---|
| Export-controlled (perpetual or subscription) | Yes | 0 | 0 | 0 |
| Enforced (perpetual or subscription) | Yes | 0 | 0 | 0 |
| Unenforced / non-export perpetual | Yes | 365 | 0 | 90 |
| Unenforced / non-export subscription | Yes | 90 | 90 | 90 |
The 365-day first-report value for perpetual licenses applies only when hardware or software was bought from a distributor or partner. A product that has never consumed a license does not need to report even under a non-zero policy.[2] The subscription row is catalogued as a rule. Under SLP a device shows only whether it has reported; any comparison of usage against entitlements happens in CSSM or in CSSM On-Prem, not on the device.[1]
Evaluation and grace periods
Evaluation and grace periods vary by product line. The Catalyst 9300 base and add-on licenses have a 90-day evaluation period, and an expired evaluation license cannot be reactivated after a reload (rule).[3] A registered Secure Firewall Threat Defense device normally contacts the License Authority every 12 hours but can operate for up to 90 days without doing so. After that it enters an “Authorization Expired” state in which licensed features continue to work (rule).[4]
Virtualization & partitioning
Smart Licensing does not tie a license to one piece of hardware. Cisco says software “is not node-locked to your hardware”, so licenses can be moved as needed.[1] The Catalyst 9300 ordering guide narrows this for switching: Smart Licenses transfer between devices of the same type, for example from one Catalyst 9300 to another.[3] Partitioning rules for virtual appliances, such as Firewall Threat Defense Virtual performance tiers, are product-specific and covered in Cisco Secure Firewall and Duo licensing.
Cloud / BYOL
Cisco offers three ways to connect products to CSSM:[1]
- Direct. Devices reach Cisco over the internet or an HTTPS proxy and report automatically. Cisco calls this its most widely used option.
- On-premises (mediated). A CSSM On-Prem server, available as a free download, keeps device traffic on the local network. Once a month it synchronizes its database with CSSM, either over the network or by manual offline transfer (rule). Under SLP, the Cisco Smart License Utility (CSLU) or Cisco DNA Center can also collect reports.
- Disconnected (license reservation). Fully offline. Reservation codes are copied by hand between product and Cisco.com, and every change, including RMAs, is processed manually. Only a subset of products supports it.
SLP changes the disconnected option. A new Specific License Reservation (SLR) cannot be requested under SLP “because the notion of ‘reservation’ does not apply”. Existing SLR codes carry over on upgrade, and air-gapped networks use the “No Connectivity to Cisco SSM and No CSLU” topology instead (rule).[2] Some product lines still support Permanent License Reservation (PLR). The Secure Firewall guide describes switching a device to Universal PLR, which Cisco must first enable for the account.[4]
Cisco Networking Subscription adds a cloud option for wireless and switching. Licenses can be managed in the Meraki Dashboard, with or without cloud management of the devices, or in CSSM for purely on-premises deployments.[5]
Programs
Smart Accounts are the delivery vehicle for Cisco’s buying programs rather than a program themselves. The licensing guide lists the Enterprise Agreement, Managed Service License Agreement and Service Provider Networking Agreement as Software Buying Programs, alongside à la carte transactional purchases, and states that a Smart Account covers “all of your Cisco software assets (including PAK licenses and Enterprise Agreements)”.[1] See Enterprise Agreement for the Enterprise Agreement and Cisco Networking Subscription for the networking subscription wrapper.
PAK licenses can be converted to Smart Licenses in CSSM by Smart Account administrators or users, and Cisco recommends assigning licenses to a Smart Account at the time of purchase.[1] My Cisco Entitlements builds on the Smart Account to show services, subscriptions, licenses and devices in one view, with exports of up to 100,000 lines.[1]
Out of scope
- Purchase meters and prices. See Cisco software subscription and Flex Plan licensing.
- Product-specific enforcement beyond the examples above, for example Webex, Meraki and ISE.
- SLP behaviour on IOS XR and NX-OS. The SLP guide cited here covers Catalyst 9000 switches.
- The legal terms of Smart Account use, which sit in the Cisco General Terms. The licensing guide notes only that Cisco may restrict Smart Account features by location and that Smart Licensing may be used only in the country of purchase.[1]