Google SecOps (Chronicle) pricing in 2026: the GB data-cap model, real cost
The independent Google SecOps and Chronicle pricing reference. The GB data-cap and credit-balance model explained, Standard vs Enterprise vs Enterprise Plus, the only published unit price (UK G-Cloud, about £2,000 per TB per year), five real cost scenarios by ingest volume, and where a bundled data cap beats per-GB SIEMs. Updated July 2026.
Published unit price from the UK G-Cloud (Crown Commercial) Digital Marketplace listing; billing mechanics from cloud.google.com Security Operations documentation. US commercial pricing is quote-based and not published.
How much does Google SecOps (Chronicle) cost in 2026?
Google SecOps (formerly Chronicle) is billed by data volume, not by headcount. You buy a package (Standard, Enterprise, or Enterprise Plus) against a data cap measured in GB, and ingestion is metered against that cap under the Bytes of data ingested SKU. Google does not publish US commercial unit prices, so deals are quote-based; the only openly published unit price is the UK G-Cloud (Crown Commercial) listing at about £2,000 per terabyte per year. At that rate a 100 GB per day environment is roughly £73K per year before discount, and 500 GB per day is roughly £365K. The package bundles 12 months of hot retention and, on Enterprise and above, curated detections, UEBA, SOAR, and Mandiant intelligence. From 1 February 2026 the Data Benefit Program can exempt qualifying data sources from the cap on Enterprise and Enterprise Plus subscriptions above a minimum annual contract value. Per-employee figures circulate as an informal partner deal-sizing heuristic, but they are not Google's meter or a published rate.
Curated detections, SecOps SOAR, Mandiant intel feed, UEBA; Data Benefit Program eligible. Metered as Bytes of data ingested against a purchased GB data cap; ingestion above the cap is billed as overage in arrears. Includes 12 months hot retention.
How Google SecOps pricing actually works
Google SecOps is billed on data volume. You commit to a data cap measured in GB, and the package you choose (Standard, Enterprise, Enterprise Plus) determines what is bundled on top of that ingestion allowance: 12 months of hot retention by default, and on Enterprise and above, curated detections, UEBA, SecOps SOAR, and Mandiant intelligence. Ingestion is metered against the data cap rather than charged per event or per SOAR action, and there is no separate per-event detection meter or per-action SOAR meter. The cap is a prepaid volume commitment: you buy the GB you expect to use, and usage above it bills as overage.
Contractually, the meter is a data cap measured in GB. When you buy SecOps your billing account receives a credit balance equal to the GB purchased (the Units on the order form), and ingestion draws that balance down under the Bytes of data ingested SKU. Consume more than the purchased Units and Google invoices the excess in arrears at the prorated list price less your negotiated discount. From 1 February 2026, Google's Data Benefit Program lets it designate specific data sources that do not count toward the data cap, but only for Enterprise and Enterprise Plus subscriptions that meet a minimum annual contract value. Google does not publish US commercial unit prices; the one openly listed rate is the UK G-Cloud figure of about £2,000 per terabyte per year.
The real cost difference from Splunk and Sentinel is the unit rate and what is bundled at that rate, not the cap mechanism itself (a prepaid GB commitment is still volume pricing, and cost scales with ingest on both sides). At 50 GB per day the published UK G-Cloud rate puts Chronicle at roughly £36,500 per year, where Splunk runs roughly $50K base and about $100K all-in once Enterprise Security is layered on. Chronicle lands below Splunk all-in at this volume because its per-terabyte rate is lower and SOAR, curated detections and (on Enterprise) UEBA and Mandiant intel are bundled rather than sold as separate lines.
Chronicle is less compelling where ingest volumes are low or highly variable. A per-GB competitor with a low entry floor can undercut a packaged data cap when a buyer ingests only a few GB per day, because the packaged commitment carries a minimum. The buyer-fit math comes down to sustained ingest volume and how much of the bundled detection, SOAR, and intelligence stack the SOC will actually use.
Package selection materially affects the bill. Standard is genuine SIEM (data plane, detection engine, search) and includes SOAR with 300-plus integrations and a subset of curated detections; what it lacks is UEBA, the full curated-detection set, and Mandiant intelligence. For SOCs that have already invested in their own detection content and threat intelligence pipeline, Standard can be the right answer. For most buyers, Enterprise is the default because the expanded curated detections, UEBA, and Mandiant intel collectively replace stack components that on competitor platforms are separate line items adding 40-100 percent on top of base SIEM licence.
Negotiation discipline matters. The committed data cap (the GB you purchase) is the single largest lever, and multi-year commits at high ingest volume attract committed-volume discounts off list. Discount depth is not published and varies by deal, so treat any specific percentage as deal-dependent rather than a rate card. Google's cross-product commitment discount, where SecOps spend rolls into a broader Google Cloud committed-use agreement, is an additional lever for organisations already on GCP at scale.
Google SecOps packages
| Package | List price | Retention | What it actually buys |
|---|---|---|---|
| Standard | Quote-based | 12 months hot | Core SIEM detection and search, SOAR (300+ integrations) and a subset of curated detections; no UEBA or Mandiant intel |
| Enterprise | Quote-based | 12 months hot | Curated detections, SecOps SOAR (Siemplify), Mandiant intel feed, UEBA; eligible for the Data Benefit Program |
| Enterprise Plus | Quote-based | 12 months hot | Adds Mandiant Hunt managed services and Frontline intel; eligible for the Data Benefit Program |
| Add-on: Data Lake retention | Per-GB-month archive rate | Same as parent tier | Beyond the included 12 months hot; BigQuery export at $0.02/GB/month is usually cheaper |
Google prices all packages by data volume and does not publish US commercial per-GB rates; packages are quote-based. The only openly published unit price is the UK G-Cloud (Crown Commercial) listing at about £2,000 per terabyte per year; that listing does not state package tiers, so treat it as a single reseller reference point.
Real-world Chronicle cost scenarios
| Scenario | Ingest profile | Annual cost (UK G-Cloud rate) | Notes |
|---|---|---|---|
| Small deployment | 20 GB/day ingest (~7.3 TB/yr) | ~£15K/yr | At the published UK G-Cloud rate; US commercial pricing is quote-only |
| Mid-market | 100 GB/day ingest (~36.5 TB/yr) | ~£73K/yr | Enterprise package bundles SOAR, UEBA, and Mandiant intel on top of ingest |
| Large mid-market | 200 GB/day ingest (~73 TB/yr) | ~£146K/yr | Ingestion above the purchased data cap is billed as overage in arrears |
| Enterprise | 500 GB/day ingest (~182.5 TB/yr) | ~£365K/yr | Committed-volume discounts are typically negotiated at this scale |
| Global enterprise | 1,000 GB/day ingest (~365 TB/yr) | ~£730K/yr | Data Benefit Program can exempt qualifying sources from the cap (Enterprise/Plus, min ACV) |
Figures apply the only published Chronicle unit price (UK G-Cloud, about £2,000 per terabyte per year, at TB/yr = GB/day x 365 / 1000). US commercial pricing is quote-based and not published; treat these as an order-of-magnitude guide before discount.
Five Chronicle cost optimisations that genuinely work
Negotiate the committed GB rate
Deal-dependentThe data cap you commit to (the GB purchased on the order form) is the single largest cost lever. Multi-year commits at high ingest volume attract committed-volume discounts off the list per-GB rate, and quarter-end is the right pressure point. Discount depth is not published and varies by deal, so treat any headline percentage as negotiable, not a rate card.
Right-tier; don't over-buy Plus
Package-dependentEnterprise Plus adds Mandiant Hunt as a managed service. For SOCs with internal threat hunting capability, the Plus premium is wasted; the Enterprise package delivers the full SIEM stack. Re-evaluate the package at every renewal.
Use BigQuery export for long retention
60-80% on archiveChronicle exports to BigQuery for retention beyond the included 12 months hot. BigQuery storage at $0.02/GB/month is dramatically cheaper than a Chronicle archive add-on. Querying back via BigQuery requires more analyst skill but suits compliance-only access.
Filter ingest before it draws down the cap
Directly on the meterBecause the contractual meter is bytes of data ingested against a purchased GB balance, filtering low-value telemetry at the forwarder (verbose debug logs, duplicate sources, health-check chatter) protects the data cap and defers overage. This is the one optimisation that moves the contractual bill rather than just operational cost.
Bundle with a Google Cloud commit
Deal-dependentGoogle offers cross-product commitment discounts when SecOps spend rolls into a broader Google Cloud committed-use agreement. For organisations already on GCP at scale this is the cleanest discount path; for pure-Chronicle customers the lever does not apply.
When Chronicle is the right SIEM
Chronicle is the right pick wherever sustained ingest is high and the SOC will use the bundled detection and response stack. Cloud-native engineering organisations, SaaS companies, fintech with deep audit-log requirements, and organisations consolidating from Splunk after a per-GB bill explosion all fit the profile. The advantage is a lower published per-terabyte rate with the detection and response stack bundled in; the commitment is still sized to your volume, so model expected ingest honestly rather than assuming the cap absorbs unlimited growth.
Chronicle is the weaker pick where ingest is low or highly variable, and where a per-GB competitor with a low entry floor can come in under a packaged data-cap commitment. It is also the wrong pick where the buying decision is dominated by detection content depth or specific compliance content packs that Chronicle does not match (high-end financial services with bespoke content needs, defence contractors with specific government content libraries). Sentinel or Sumo Logic typically win cleanly in the low-ingest profile.
The 2026 product trajectory is favourable. Google's SecOps consolidation push has improved Mandiant intelligence integration meaningfully since the 2022 acquisition, and the Siemplify SOAR rebrand into SecOps SOAR has cleaned up the product UX that previously created complaints. For new Chronicle deployments evaluated in 2026, the product is materially more cohesive than it was 18 months earlier.