Independent reference. Not affiliated with any vendor mentioned on this site.
Vendor / Google SecOps

Google SecOps (Chronicle) pricing in 2026: the GB data-cap model, real cost

The independent Google SecOps and Chronicle pricing reference. The GB data-cap and credit-balance model explained, Standard vs Enterprise vs Enterprise Plus, the only published unit price (UK G-Cloud, about £2,000 per TB per year), five real cost scenarios by ingest volume, and where a bundled data cap beats per-GB SIEMs. Updated July 2026.

Pricing model
GB data cap
Metered as Bytes of data ingested
Published rate
~£2,000/TB/yr
UK G-Cloud list; US quote-only
Log ingest
Credit balance
Draws down purchased GB; overage billed
Hot retention
12 months
Included; BigQuery export for longer

Published unit price from the UK G-Cloud (Crown Commercial) Digital Marketplace listing; billing mechanics from cloud.google.com Security Operations documentation. US commercial pricing is quote-based and not published.

How much does Google SecOps (Chronicle) cost in 2026?

Google SecOps (formerly Chronicle) is billed by data volume, not by headcount. You buy a package (Standard, Enterprise, or Enterprise Plus) against a data cap measured in GB, and ingestion is metered against that cap under the Bytes of data ingested SKU. Google does not publish US commercial unit prices, so deals are quote-based; the only openly published unit price is the UK G-Cloud (Crown Commercial) listing at about £2,000 per terabyte per year. At that rate a 100 GB per day environment is roughly £73K per year before discount, and 500 GB per day is roughly £365K. The package bundles 12 months of hot retention and, on Enterprise and above, curated detections, UEBA, SOAR, and Mandiant intelligence. From 1 February 2026 the Data Benefit Program can exempt qualifying data sources from the cap on Enterprise and Enterprise Plus subscriptions above a minimum annual contract value. Per-employee figures circulate as an informal partner deal-sizing heuristic, but they are not Google's meter or a published rate.

Google SecOps ingest cost estimator
GB data-cap model. Enter daily ingest for an annual estimate at the published UK G-Cloud rate.
200
101,0002,000
Estimates only. Applies the only published Chronicle unit price (UK G-Cloud, about £2,000 per TB/yr). US commercial pricing is quote-based and packages do not carry a published per-TB rate. Always obtain a vendor quote.
Enterprise package, 200 GB/day ingest
£146K/ year (UK G-Cloud rate)

Curated detections, SecOps SOAR, Mandiant intel feed, UEBA; Data Benefit Program eligible. Metered as Bytes of data ingested against a purchased GB data cap; ingestion above the cap is billed as overage in arrears. Includes 12 months hot retention.

Committed-volume discount
Multi-year commits at high ingest attract negotiated discounts off list. Depth is not published and varies by deal, so no net figure is estimated here.
Ingest / year
73.0 TB
Published rate
£2,000 / TB/yr

How Google SecOps pricing actually works

Google SecOps is billed on data volume. You commit to a data cap measured in GB, and the package you choose (Standard, Enterprise, Enterprise Plus) determines what is bundled on top of that ingestion allowance: 12 months of hot retention by default, and on Enterprise and above, curated detections, UEBA, SecOps SOAR, and Mandiant intelligence. Ingestion is metered against the data cap rather than charged per event or per SOAR action, and there is no separate per-event detection meter or per-action SOAR meter. The cap is a prepaid volume commitment: you buy the GB you expect to use, and usage above it bills as overage.

Contractually, the meter is a data cap measured in GB. When you buy SecOps your billing account receives a credit balance equal to the GB purchased (the Units on the order form), and ingestion draws that balance down under the Bytes of data ingested SKU. Consume more than the purchased Units and Google invoices the excess in arrears at the prorated list price less your negotiated discount. From 1 February 2026, Google's Data Benefit Program lets it designate specific data sources that do not count toward the data cap, but only for Enterprise and Enterprise Plus subscriptions that meet a minimum annual contract value. Google does not publish US commercial unit prices; the one openly listed rate is the UK G-Cloud figure of about £2,000 per terabyte per year.

The real cost difference from Splunk and Sentinel is the unit rate and what is bundled at that rate, not the cap mechanism itself (a prepaid GB commitment is still volume pricing, and cost scales with ingest on both sides). At 50 GB per day the published UK G-Cloud rate puts Chronicle at roughly £36,500 per year, where Splunk runs roughly $50K base and about $100K all-in once Enterprise Security is layered on. Chronicle lands below Splunk all-in at this volume because its per-terabyte rate is lower and SOAR, curated detections and (on Enterprise) UEBA and Mandiant intel are bundled rather than sold as separate lines.

Chronicle is less compelling where ingest volumes are low or highly variable. A per-GB competitor with a low entry floor can undercut a packaged data cap when a buyer ingests only a few GB per day, because the packaged commitment carries a minimum. The buyer-fit math comes down to sustained ingest volume and how much of the bundled detection, SOAR, and intelligence stack the SOC will actually use.

Package selection materially affects the bill. Standard is genuine SIEM (data plane, detection engine, search) and includes SOAR with 300-plus integrations and a subset of curated detections; what it lacks is UEBA, the full curated-detection set, and Mandiant intelligence. For SOCs that have already invested in their own detection content and threat intelligence pipeline, Standard can be the right answer. For most buyers, Enterprise is the default because the expanded curated detections, UEBA, and Mandiant intel collectively replace stack components that on competitor platforms are separate line items adding 40-100 percent on top of base SIEM licence.

Negotiation discipline matters. The committed data cap (the GB you purchase) is the single largest lever, and multi-year commits at high ingest volume attract committed-volume discounts off list. Discount depth is not published and varies by deal, so treat any specific percentage as deal-dependent rather than a rate card. Google's cross-product commitment discount, where SecOps spend rolls into a broader Google Cloud committed-use agreement, is an additional lever for organisations already on GCP at scale.

Google SecOps packages

PackageList priceRetentionWhat it actually buys
StandardQuote-based12 months hotCore SIEM detection and search, SOAR (300+ integrations) and a subset of curated detections; no UEBA or Mandiant intel
EnterpriseQuote-based12 months hotCurated detections, SecOps SOAR (Siemplify), Mandiant intel feed, UEBA; eligible for the Data Benefit Program
Enterprise PlusQuote-based12 months hotAdds Mandiant Hunt managed services and Frontline intel; eligible for the Data Benefit Program
Add-on: Data Lake retentionPer-GB-month archive rateSame as parent tierBeyond the included 12 months hot; BigQuery export at $0.02/GB/month is usually cheaper

Google prices all packages by data volume and does not publish US commercial per-GB rates; packages are quote-based. The only openly published unit price is the UK G-Cloud (Crown Commercial) listing at about £2,000 per terabyte per year; that listing does not state package tiers, so treat it as a single reseller reference point.

Real-world Chronicle cost scenarios

ScenarioIngest profileAnnual cost (UK G-Cloud rate)Notes
Small deployment20 GB/day ingest (~7.3 TB/yr)~£15K/yrAt the published UK G-Cloud rate; US commercial pricing is quote-only
Mid-market100 GB/day ingest (~36.5 TB/yr)~£73K/yrEnterprise package bundles SOAR, UEBA, and Mandiant intel on top of ingest
Large mid-market200 GB/day ingest (~73 TB/yr)~£146K/yrIngestion above the purchased data cap is billed as overage in arrears
Enterprise500 GB/day ingest (~182.5 TB/yr)~£365K/yrCommitted-volume discounts are typically negotiated at this scale
Global enterprise1,000 GB/day ingest (~365 TB/yr)~£730K/yrData Benefit Program can exempt qualifying sources from the cap (Enterprise/Plus, min ACV)

Figures apply the only published Chronicle unit price (UK G-Cloud, about £2,000 per terabyte per year, at TB/yr = GB/day x 365 / 1000). US commercial pricing is quote-based and not published; treat these as an order-of-magnitude guide before discount.

Five Chronicle cost optimisations that genuinely work

Negotiate the committed GB rate

Deal-dependent

The data cap you commit to (the GB purchased on the order form) is the single largest cost lever. Multi-year commits at high ingest volume attract committed-volume discounts off the list per-GB rate, and quarter-end is the right pressure point. Discount depth is not published and varies by deal, so treat any headline percentage as negotiable, not a rate card.

Right-tier; don't over-buy Plus

Package-dependent

Enterprise Plus adds Mandiant Hunt as a managed service. For SOCs with internal threat hunting capability, the Plus premium is wasted; the Enterprise package delivers the full SIEM stack. Re-evaluate the package at every renewal.

Use BigQuery export for long retention

60-80% on archive

Chronicle exports to BigQuery for retention beyond the included 12 months hot. BigQuery storage at $0.02/GB/month is dramatically cheaper than a Chronicle archive add-on. Querying back via BigQuery requires more analyst skill but suits compliance-only access.

Filter ingest before it draws down the cap

Directly on the meter

Because the contractual meter is bytes of data ingested against a purchased GB balance, filtering low-value telemetry at the forwarder (verbose debug logs, duplicate sources, health-check chatter) protects the data cap and defers overage. This is the one optimisation that moves the contractual bill rather than just operational cost.

Bundle with a Google Cloud commit

Deal-dependent

Google offers cross-product commitment discounts when SecOps spend rolls into a broader Google Cloud committed-use agreement. For organisations already on GCP at scale this is the cleanest discount path; for pure-Chronicle customers the lever does not apply.

When Chronicle is the right SIEM

Chronicle is the right pick wherever sustained ingest is high and the SOC will use the bundled detection and response stack. Cloud-native engineering organisations, SaaS companies, fintech with deep audit-log requirements, and organisations consolidating from Splunk after a per-GB bill explosion all fit the profile. The advantage is a lower published per-terabyte rate with the detection and response stack bundled in; the commitment is still sized to your volume, so model expected ingest honestly rather than assuming the cap absorbs unlimited growth.

Chronicle is the weaker pick where ingest is low or highly variable, and where a per-GB competitor with a low entry floor can come in under a packaged data-cap commitment. It is also the wrong pick where the buying decision is dominated by detection content depth or specific compliance content packs that Chronicle does not match (high-end financial services with bespoke content needs, defence contractors with specific government content libraries). Sentinel or Sumo Logic typically win cleanly in the low-ingest profile.

The 2026 product trajectory is favourable. Google's SecOps consolidation push has improved Mandiant intelligence integration meaningfully since the 2022 acquisition, and the Siemplify SOAR rebrand into SecOps SOAR has cleaned up the product UX that previously created complaints. For new Chronicle deployments evaluated in 2026, the product is materially more cohesive than it was 18 months earlier.

FAQ

Common questions

How much does Google SecOps (Chronicle) cost in 2026?

Google SecOps (formerly Chronicle SIEM) is billed by data volume, not by headcount. You buy a package (Standard, Enterprise, or Enterprise Plus) against a data cap measured in GB, and ingestion is metered against that cap under the Bytes of data ingested SKU. Google does not publish US commercial unit prices, so deals are quote-based. The only openly published unit price is the UK G-Cloud (Crown Commercial) listing at about £2,000 per terabyte per year. At that rate, 100 GB per day works out to roughly £73,000 per year before any negotiated discount, and 500 GB per day to roughly £365,000. Some partners size deals informally by employee count, but that is a scoping heuristic, not Google's contractual meter or a published rate.

How is Google SecOps billed, and is ingestion really unlimited?

Not literally unlimited. Google SecOps subscriptions are sold by package (Standard, Enterprise, Enterprise Plus) against a data cap measured in GB, recorded as the Units purchased on the order form. Your billing account receives a credit balance equal to the GB purchased, and ingestion draws it down under the Bytes of data ingested SKU; consume more than the purchased Units and Google invoices the overage in arrears at the prorated list price less your discount. From 1 February 2026, Google's Data Benefit Program lets it exempt specific data sources from the data cap, but only on Enterprise and Enterprise Plus subscriptions that meet a minimum annual contract value. Any per-employee figure you see is an informal deal-sizing heuristic used by some partners, not a Google meter or a published rate.

Does Chronicle price per employee or per GB?

Per GB. The contractual meter is a data cap measured in GB, drawn down under the Bytes of data ingested SKU, with overage billed in arrears. Per-employee pricing is not Google's published model; at most it is an informal way some partners size and quote a deal before mapping it back to a GB commitment. The only publicly listed unit price, the UK G-Cloud rate of about £2,000 per terabyte per year, is expressed per terabyte of data, not per employee. The practical effect of the data-cap model is a lower per-terabyte rate with the detection stack bundled, which is how Chronicle competes against per-GB SIEMs like Splunk and Sentinel.

What is the difference between Chronicle and Google SecOps?

Google SecOps is the rebranded product family launched in 2024 that combines Chronicle SIEM, Siemplify SOAR, Mandiant threat intelligence, and Mandiant managed services into a single suite. Chronicle remains the SIEM component; SecOps is the umbrella. Packages (Standard, Enterprise, Enterprise Plus) determine which components are bundled. The naming change matters for purchase orders but the underlying SIEM product is the same.

Is Chronicle cheaper than Splunk?

At equal log volume, the published Chronicle rate generally lands below Splunk all-in. At 50 GB per day, the UK G-Cloud rate (about £2,000 per TB per year) works out to roughly £36,500 per year, versus Splunk at roughly $50,000 base and about $100,000 all-in once Enterprise Security is added. Even allowing for the currency gap, Chronicle's published rate sits below Splunk all-in at this volume because the per-terabyte rate is lower and the security stack is bundled; both vendors' costs scale with volume, so the advantage is the rate, not the mechanism. Where Chronicle is less compelling is at low, variable ingest volumes, where a per-GB competitor with a low entry floor can undercut a packaged data-cap commitment. US Chronicle commercial pricing is quote-only, so treat the cross-currency comparison as indicative.

What is included in Chronicle Enterprise tier?

Chronicle Enterprise includes the Chronicle SIEM data plane and detection engine, curated detections from Google's threat intelligence team, the Siemplify SOAR product (rebranded as SecOps SOAR), Mandiant threat intelligence feed integration, UEBA via Risk Analytics, and 12 months hot retention. The combination replaces a stack that on competitor platforms requires Splunk plus Splunk SOAR plus Mandiant Advantage plus a separate UEBA bolt-on. The bundle math is the strongest argument for Enterprise over Standard at any meaningful scale.

Updated 13 July 2026