Sales Enablement

Deal Playbook
Close Faster, Close Bigger

Deal registration mechanics, PAN co-selling best practices, slippage prevention, and scoping checklists for every solution area.

Deal Registration

Register Early, Protect Your Deal

Deal registration provides margin protection and deal protection for the partner who uncovers the opportunity first.

Why Register Early

  • Deal protection: Registered partner gets priority positioning on the opportunity — one partner per opportunity rule.
  • Margin enhancement: Registered deals receive enhanced partner margins beyond standard discount levels.
  • PAN sales alignment: Registration triggers PAN Account Manager engagement and SE resource allocation to your deal.
  • Competitive defense: If another partner tries to register the same opportunity, your registration takes precedence.
  • Register BEFORE the first meeting. This is the single most important timing decision in the deal lifecycle.

Common Rejection Reasons

  • Duplicate registration: Another partner already registered this opportunity. Check with your PAN AM before investing time.
  • Incomplete information: Missing customer legal entity name, decision maker, or estimated deal value. Fill every field.
  • Wrong account: The customer account in CRM doesn't match the legal entity purchasing. Verify parent/subsidiary relationships.
  • Existing opportunity: PAN already has an active opportunity with this customer for this solution. Align with the AM.
  • Late registration: Registering after the customer is already engaged with PAN direct or another partner.

90-Day Registration Timeline

Phase 1: 90 Days Registration → Installed Evaluation
Phase 2: +90 Days Evaluation → Close
  • Initial period: 90 days from registration to reach installed evaluation (POC, trial, or formal eval).
  • Extension period: Additional 90 days from evaluation to close the deal.
  • Extensions available: If you need more time, request an extension through the Partner Portal before expiration.
  • Important: You cannot discuss the deal registration program with customers. This is a partner-PAN program only.

Registration Best Practices

  • Register before the first customer meeting. Don't wait until you've qualified the deal — register the moment you identify the opportunity.
  • Use the correct legal entity. Not the parent company unless they're the purchaser. Verify with the customer's procurement team.
  • Verify the account in PAN CRM. Work with your PAN AM to confirm the customer account exists and is mapped correctly in Salesforce.
  • Include a decision maker. Registration requires a named contact at the customer. Get the CISO, VP, or director's name — not just "IT Department."
  • Be specific about the opportunity. "Security platform" is too vague. Specify "XSIAM replacement of Splunk SIEM" or "Prisma SASE for 5,000 remote users."
  • One partner per opportunity. If another partner is already registered, collaborate through PAN AM rather than competing on the same deal.
  • Track your timeline. Set calendar reminders at 60 days and 80 days to ensure you're moving toward evaluation before the 90-day window closes.

Co-Selling

Working with PAN Sales

Know the key roles, engagement model, and fiscal calendar to align with PAN sales motion.

Account Manager (AM)

Your primary PAN contact. Owns the customer relationship and quota. Engage the AM first on every deal. They control resource allocation, pricing approvals, and executive engagement. Build a quarterly rhythm with your AM — don't just reach out when you need something.

Systems Engineer (SE)

Technical counterpart to the AM. Runs POCs, demos, and technical deep-dives. Request a PAN SE when the customer needs product-specific validation that your SE can't deliver. For XSIAM and AIRS deals, PAN SE involvement is usually required for the eval.

Channel Solutions Partner (CSP)

Your partner program contact. Handles deal registration issues, program questions, and escalations. The CSP is your advocate inside PAN. Keep them informed on deal progress — they can unlock resources and approvals you can't access directly.

Business Development Rep (BDR)

Lead generation and early qualification. BDRs can surface opportunities to you and vice versa. Sharing intel on customer initiatives, budget cycles, and competitive situations builds a mutually beneficial relationship.

Co-Selling Best Practices

  • Engage Partner Architects early: Reach out to your Palo Partner Architects at the start of the deal process — not after you're stuck. They can help with solution design, competitive positioning, licensing strategy (ELA/ESA/CDSS), and technical validation. Getting them involved early prevents deal slippage and misquoted BOMs.
  • Lead with your value: PAN wants partners who bring customer relationships, industry expertise, and services wrap. Don't just pass leads — co-sell by owning the customer relationship.
  • Prepare joint account plans: For strategic accounts, build a joint plan with the PAN AM covering which solutions to lead with, competitive positioning, and timeline to close.
  • When to lead with your SE: If your SE has product certification and the deal is a straightforward refresh/expansion, lead the technical. Bring PAN SE for complex evaluations, competitive bake-offs, and new product areas (XSIAM, AIRS, Identity).
  • When to request PAN SE: For POCs involving XSIAM, Cortex Cloud, or AIRS. For competitive evaluations against CrowdStrike or Microsoft. For customer-requested reference architecture sessions.
  • Share intelligence both ways: Tell the AM what competitors are in the deal, what the customer's budget cycle looks like, and who the decision makers are. The AM will share pricing flexibility, product roadmap timing, and executive engagement options.
  • Respect the fiscal calendar: PAN reps are most motivated to close at quarter-end and especially fiscal year-end (July 31). Align your deal timing to maximize PAN's willingness to offer aggressive pricing and concessions.

Quote Review Process

Understanding the quote flow is critical. Quotes pass through multiple hands before reaching the client — each step is an opportunity to catch errors and optimize the deal.

1
PAN Sales Creates the Quote

The PAN Account Manager / SE builds the quote in PAN's quoting system based on the scoped solution. This includes hardware, subscriptions (CDSS), support SKUs, and any enterprise agreements (ELA/ESA).

2
Distributor Sends Quote to Partner

The quote flows through your authorized distributor (disti), who applies partner pricing and sends the formatted quote to you. The disti does not typically validate solution accuracy — that's your job.

3
Partner Reviews for Accuracy

This is the most critical step. Before sending anything to the client, carefully review the quote for:

  • Deal Registration: Confirm your deal reg is reflected in the pricing and margin protection is applied.
  • Vendor Services: Check if any PAN professional services are included. If you deliver services yourself, make sure PAN vendor services aren't on the quote competing with your practice.
  • ELA (Enterprise License Agreement): If ELA is included, partners generally want ELA — it bundles the five core CDSSs (ATP, WildFire, URL Filtering, DNS Security, GlobalProtect) into one agreement. This simplifies licensing and is typically a win for the partner and customer.
  • ESA (Enterprise Support Agreement): If ESA is included, partners typically do not want ESA on the quote — because ESA means PAN delivers support directly. Most partners prefer to deliver support themselves through Partner-Enabled Premium Support (backline support). Selling your own support wrap is higher-margin and strengthens your customer relationship. Flag ESA line items and request they be replaced with partner-delivered support SKUs.
  • Subscription accuracy: Verify every CDSS subscription matches what was scoped. Missing a subscription (e.g., IoT Security, AI Access Security) creates change orders post-sale.
  • Term alignment: Confirm all subscriptions, support, and hardware are co-termed to the same end date.
4
Questions? Reach Out Before Sending

If anything looks off — wrong SKUs, unexpected line items, pricing questions, or ELA/ESA confusion — reach out to your PAN SE and/or Partner Architect before forwarding to the client. It's far easier to fix a quote before the client sees it than to issue corrections after.

5
Send Quote to Client

Once validated, send the quote to the client with a cover summary highlighting the solution, value, and any commercial incentives (quarter-end pricing, co-term savings, etc.).

Client Has Questions? Repeat the Review

If the client comes back with questions, change requests, or needs a revised scope — go back through Steps 1–4. PAN revises the quote, disti sends the update, you review again for accuracy. Don't forward a revised quote without re-validating every line item — changes in one area can cascade to pricing, support terms, and entitlements.

ELA vs ESA — Partner Rule of Thumb:

ELA = Yes, partners want this. Bundles CDSS subscriptions into one agreement — simplifies licensing, good for customer and partner. ESA = Usually no for partners. ESA bundles PAN-delivered support — most partners prefer to deliver support themselves for higher margins and deeper customer relationships. If you see ESA on a quote, flag it and discuss with your SE or Partner Architect.

PAN Fiscal Year Calendar (Aug 1 – Jul 31)

Q1

Aug – Oct

New year — build pipeline

Q2

Nov – Jan

Mid-year push

Q3

Feb – Apr

Acceleration quarter

Q4

May – Jul

★ Fiscal year end — maximum deal velocity

Timing matters:

PAN reps have the most pricing flexibility and executive support at Q4 (May-Jul). If your deal can close in this window, you'll get the best terms. Conversely, Q1 deals often face slower approvals as new quotas and territories are being set. Plan your deal timeline around PAN's fiscal calendar, not just your customer's budget cycle.

Slippage Prevention

Why Deals Slip — And How to Save Them

The 8 most common reasons PAN deals slip, with warning signs and recovery tactics for each.

#1

No Executive Sponsor

The deal is driven by mid-level champions who can't get budget approval. Without a CISO or CIO sponsor, deals stall at procurement.

Warning: No C-level meetings after initial discovery. Champion keeps saying "I need to check with my boss."

Fix: Ask PAN AM to arrange an executive-to-executive session. Prepare a business case document the champion can present upward. Map the buying committee early.

#2

Competing Projects

The customer's budget gets redirected to a different initiative — cloud migration, ERP upgrade, or a breach-response purchase. Your deal gets deprioritized.

Warning: Meetings keep getting rescheduled. Budget timelines keep shifting. Champion mentions "other priorities."

Fix: Align your deal to the competing project. If it's cloud migration → lead with Cortex Cloud. If it's a breach → lead with XSIAM incident response capabilities. Make PAN part of the priority, not competing with it.

#3

POC Creep

The proof of concept expands beyond the original scope, adding use cases, data sources, and evaluation criteria that delay the close.

Warning: POC scope document keeps growing. New stakeholders join with new requirements. Timeline extends past 30 days.

Fix: Set a hard POC scope and success criteria BEFORE the eval starts. Include a "time-boxed" clause. If new requirements surface, acknowledge them and agree to address them post-purchase.

#4

Microsoft Bundling

Microsoft ELA renewal includes "free" Sentinel/Defender, and procurement pushes to consolidate on Microsoft to save money. Your deal gets challenged on cost.

Warning: Customer mentions "E5 already includes this." Procurement asks for a cost comparison vs "free" Microsoft security.

Fix: Calculate the real Sentinel cost at scale (see compete.html). Show multi-cloud blind spots. Position PAN as the security platform that protects the Microsoft environment better than Microsoft protects itself.

#5

Procurement Bottleneck

Technical evaluation is done, but procurement adds 4-8 weeks for legal review, contract negotiation, and approval cycles.

Warning: Technical team says "we're ready" but procurement hasn't started. No master agreement in place.

Fix: Engage procurement in parallel with the tech eval — not after. Check if the customer has an existing PAN master agreement. Use PAN CSP to expedite standard terms. Start legal redlines early.

#6

Champion Changes Role

Your internal champion gets promoted, leaves the company, or changes teams. The new person doesn't have the same urgency or relationship.

Warning: Champion stops responding. LinkedIn shows a role change. Meetings get reassigned to someone you haven't met.

Fix: Always have 2-3 contacts at the customer, not just one champion. Build the business case in writing so it survives personnel changes. Ask PAN AM to engage the replacement proactively.

#7

Analysis Paralysis

The customer evaluates 4-5 vendors simultaneously and can't make a decision. RFP scoring takes months. No clear winner emerges because the criteria keep changing.

Warning: Customer is running parallel POCs with 3+ vendors. Decision date keeps moving. New evaluation criteria appear mid-process.

Fix: Help the customer define success criteria before the eval. Position PAN as the platform that eliminates multi-vendor evaluation fatigue — one vendor for network + SASE + SOC + cloud. Offer a "pilot-to-production" deal structure.

#8

Contract Renewal Misalignment

The customer's existing security contracts don't expire for 12-18 months. There's no urgency to buy now because the current tools are "good enough" until renewal.

Warning: "We love the product but our Splunk/Zscaler/CrowdStrike contract doesn't end until next year."

Fix: Offer co-term deals that align with the existing contract expiration. Propose a "land and expand" — start with a new use case not covered by the existing contract, then expand at renewal. PAN offers ramp-up pricing structures for this exact scenario.

Scoping

Solution Scoping Checklists

Checklists now cover the full portfolio — network security, Cortex, cloud, SASE, browser, identity, AI security, observability, Unit 42 services and licensing agreements. Gather this information early to size the deal correctly and avoid surprises during quoting.

Daily log ingestion volume (GB/day) — current and projected 2-year growth
Number of managed endpoints (Windows, macOS, Linux, mobile)
Data sources to ingest — list each: firewalls, cloud trails, EDR, identity, email, SaaS apps
Current SIEM vendor and contract expiration date
Current SOAR vendor (if any) and number of active playbooks
Number of SOC analysts and tiers (L1/L2/L3)
Ingestion minimums to size against: Analytics tier minimum 100 GB/day; optional Cortex Data Lake tier add-on minimum 50 GB/day
Data retention requirements (hot/warm/cold, compliance mandates)
Region/data residency requirements (US, EU, other)
Add-on modules needed: Attack Surface Management, Threat Intelligence Management, Extended Threat Intelligence (XTI), Exposure Management (distinct module, separate from ASM/Xpanse), Forensics, Host Insights, ITDR, Advanced Email Security, DLP
License tier: Cortex XSIAM NG-SIEM, Enterprise, or Premium — Premium is required for the full cloud posture bundle (Cloud Posture Security, Cloud Runtime Security, XTI, TIM, ASM)
Endpoint count by OS — Windows servers, Windows workstations, macOS, Linux, mobile (Android/iOS)
Cloud and container host count (VMs, nodes, containers) to be covered per hour/per host
5.x plan decision: Cortex XDR Pro EP (on-prem endpoints) vs Cortex XDR EP Cloud (cloud/containers), both on the Enterprise Runtime Security (XDR) + Core Analytics base SKU
Whether the installed base is still quoted on legacy 3.x tiering (Prevent / Pro per Endpoint / Pro per GB / Cloud per Host) and must be re-mapped to the 5.x model
Incumbent EDR/EPP vendor, seat count under contract, and contract end date
Add-on selection: ITDR, Endpoint DLP, Forensics, Host Insights, Extended Threat Hunting, Exposure Management, Advanced Email Security
Agent version and OS support constraints — XDR agent 9.3 supported kernel/OS matrix, legacy OS exceptions
File Integrity Monitoring requirement (separately licensed)
Data retention period required (days/months) and any Data Retention add-on volume
Air-gapped, sovereign, or FedRAMP deployment requirement
Prisma Browser and XSIAM integration scope — which telemetry is forwarded and to which tenant
AV displacement scope — number of sites, business units, and OUs in phase 1
Total seat count to license (workstations vs servers, split by count)
Legacy AV/EPP vendor, licensed seat count, and renewal date
OS mix and version spread (Windows 10/11, Windows Server, macOS, Linux distros) with legacy/unsupported OS exceptions listed
Exclusion inventory — number of existing AV exclusions and applications requiring performance tuning
Performance constraints on constrained endpoints (VDI density, CPU/memory ceilings, Linux CPU/memory throttling needs)
Migration window — cutover dates, co-existence period length, and change-freeze windows
Upgrade path to Cortex XDR 5.x — which endpoints move to Cortex XDR Pro EP later and on what timeline
Number of endpoints requiring device control, disk encryption visibility, or host firewall management
Deployment tooling available (SCCM/Intune/Jamf/Ansible) and packaging effort in days
Endpoint count and daily log volume (GB/day) in scope for managed monitoring
Incumbent MSSP or MDR provider, annual spend, and contract end date
Offering fit: Unit 42 Managed XSIAM (MSIAM 2.0) vs legacy Unit 42 MDR built on Cortex XDR Pro
Third-party EDR to be supported by the service (vendor and version) if not replacing it
Shift coverage required (8x5, 16x5, 24x7) and response SLA expectations in minutes
250-hour Breach Response Guarantee eligibility — prerequisites met and named in the order
Escalation matrix and containment authority — who authorizes isolation, and in-hours vs after-hours
In-scope data sources by count and type (identity, cloud, email, network, OT)
Delivery model: Palo Alto delivered vs partner delivered under the Cortex XMDR Specialization
Onboarding runway in weeks — tenant build, data source onboarding, and use-case tuning
Managed Threat Hunting and Digital Forensics hours to bundle alongside the service
Number of playbooks to build or migrate and complexity band (simple / branching / multi-tenant)
Incumbent SOAR vendor, licensed action or incident volume, and contract end date
Integration inventory — count of products requiring integrations and how many are custom/unsupported
Monthly incident volume and average incidents per analyst
Automation engineering headcount available and current automation maturity
Deployment decision: XSOAR 8.13 on-prem vs 8.15 SaaS
Multi-tenant / MSSP requirement — number of tenants and per-tenant isolation needs
Whether Cortex AgentiX is the better fit — Palo Alto positions AgentiX as the natural evolution of the SOAR platform, and XSOAR remains available standalone
Data residency and hosting constraints (region, sovereign, air-gapped)
Professional services scope in days for playbook development and integration build-out
Number of users to license — AgentiX is licensed per user per year
Tier decision: Enterprise (4 users, 800 compute units/year, includes threat intel management) vs Base (2 users, 400 CU/year)
Expected compute-unit consumption per year and whether additional compute units are needed
Agent use cases to deploy in phase 1 (triage, enrichment, response, reporting) with expected run volume per day
Source systems for Personalized Agents (Google Drive, Confluence, SOP repositories) and document counts
Human-in-the-loop governance — approval model, which actions require sign-off, and named approvers
FedRAMP Moderate or High requirement (AgentiX 1.4 holds both)
Existing Cortex XSOAR estate to migrate — playbook count and integration count
Target platform version (AgentiX 1.4, July 2026) and tenant region
Success metrics — MTTR target in minutes and analyst hours to be returned per month
Inventory of AI agents in use — count by business unit and whether managed or unmanaged
Count of MCP servers in the environment and who operates each
Count of plugins and browser extensions in use, and how many are unsanctioned
Estimated unmanaged AI tool sprawl — number of AI SaaS tools accessed without approval
Deployment mode: integral to the Cortex XDR agent from XDR 5.2 (zero additional deployment), standalone alongside a third-party EDR, or delivered via Prisma AIRS
Whether Cortex XDR agent 9.3+ is already deployed and on what percentage of the estate
Guardrail and enforcement policy owner — named team accountable for allow/block decisions
Browser estate — count of managed browsers by type, and Prisma Browser seats if any
Prisma AIRS overlap — which AI protections are already licensed to avoid double-buying
Endpoint counts by OS for standalone AES coverage and any air-gapped segments
Internet-facing IPv4/IPv6 count and number of registered domains in scope
Number of subsidiaries, brands, and recent/pending M&A entities to include in the attack surface
Network-size SKU band — total IP count determines the Expander base sizing
Packaging decision: standalone Cortex Xpanse Expander vs the Attack Surface Management module inside XSIAM/XDR
Active Response requirement — which remediation actions may be automated and by whom
Attack Surface Testing requirement and permitted testing windows
Third Party Assess scope — number of suppliers/vendors to monitor
Whether Exposure Management (a separate XSIAM/XDR module, distinct from Xpanse/ASM) is also required
Cloud accounts to correlate (AWS, Azure, GCP) and connector access approvals
Target release and features needed — Expander 2.14 (July 2026) on-demand rescan and business-unit asset mapping
Owner of remediation workflow and ticketing integration (ITSM platform and instance count)
Number of cloud accounts/subscriptions/projects (AWS, Azure, GCP)
Total cloud workloads (VMs, containers, serverless functions)
Kubernetes clusters — number, distribution (EKS, GKE, AKS, OpenShift)
Current CNAPP/CSPM vendor and contract expiration
Agent vs agentless preference per workload type
Module selection: Application Security, Cloud Posture Security, Cloud Runtime Security, Security Operations
Application Security scope: SAST, SCA, IaC scanning, ASPM (Code Security is licensed separately)
Security Operations requirement — does the SOC need cloud detection and response alerts in XSIAM?
Compliance frameworks: SOC 2, PCI, HIPAA, FedRAMP, CIS Benchmarks
DevOps toolchain: CI/CD platform, container registry, IaC tools
Existing Prisma Cloud estate to migrate — Prisma Cloud is legacy; the path is upgrade from Prisma Cloud to Cortex Cloud
Multi-cloud vs single-cloud — which clouds and what percentage of workloads
Number of remote/hybrid users requiring Prisma Access
Number of contractors/BYOD users needing browser-only access
Number of branch locations requiring SD-WAN
Current WAN architecture (MPLS, broadband, both) and bandwidth per site
Current VPN solution and concurrent session capacity
Private applications that need ZTNA (number, hosting location)
DLP requirements — data types, compliance frameworks (PCI, HIPAA, etc.)
CASB requirements — sanctioned vs unsanctioned SaaS apps to monitor
Performance-sensitive SaaS apps (video, collaboration, ERP)
Prisma Browser deployment scope (contractor count, use cases)
GlobalProtect to Prisma Access Agent transition scope — seat count and migration window
Contractor, BYOD, and unmanaged device counts requiring browser-delivered access
VDI/DaaS seats being displaced and their current annual cost per seat
Target application list — number of internal web apps and SaaS apps to be accessed through the browser
Agentic-AI and AI-tool usage policy scope — which AI sites/agents are allowed, monitored, or blocked
DLP and data-egress requirements — copy/paste, download, print, screenshot controls per app
Cortex XDR / XSIAM integration scope — native integration shipped with XDR 5.2; confirm which telemetry is forwarded
Identity provider in use (Okta, Entra ID, Ping) and SSO/conditional-access dependencies
OS mix of endpoints receiving the browser (Windows, macOS, Linux, ChromeOS, mobile)
Existing browser estate and enterprise extension inventory to be replaced or retained
PAN-OS 12.2 NGFW-native Prisma Browser identification requirement for enforcement at the network layer
Required throughput (App-ID with all services enabled)
Port density — 1G, 10G, 25G, 40G, 100G, 400G interface requirements
HA requirements (active/passive, active/active, clustering up to 1.4 Tbps)
Current firewall vendor, model, and support expiration dates
Number of locations (DC, campus, branch) and model per location
PA-5450 refresh flag — PA-5450 goes End-of-Sale Nov 22, 2026 (last supported OS PAN-OS 12.2); size the PA-5500 Series replacement now
TLS decryption requirements — percentage of encrypted traffic, compliance constraints
Security subscriptions needed: Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, IoT/OT Security, Enterprise DLP, Enterprise CASB, AI Access Security, Advanced IP Defense, Quantum-Safe Security
PAN-OS target version — 12.2 “Ceres” (released Jul 30 2026, EOL Jul 30 2029) vs 12.1 “Orion” (EOL Aug 28 2028); note 12.2 mandates master key replacement with a 30-day grace period
Management preference: Strata Cloud Manager (Essentials free / Pro paid) or Panorama — note Panorama multi-tenancy is closed to greenfield since Apr 15, 2026
Virtual/container requirements: VM-Series vCPU count per deployment profile (max 64) and Software NGFW Credit estimate; CN-Series decision — End-of-Sale Nov 1, 2026, replaced by AI Runtime Firewall (AIRS), so record cluster/node counts and the migration target
OT/Industrial requirements: PA-400R and PA-50R ruggedized families, IoT/OT Security subscription, proactive OT microsegmentation in PAN-OS 12.2 (K2-Series is End-of-Life as of Feb 28, 2026)
Certificate inventory — total known certificates and estimated unknown/shadow certificates
Annual certificate issuance volume (certs/year) and average certificate lifetime in days
Current PKI/CA estate — internal CAs, issuing CAs, and HSM count
Public CA vendor, annual spend, and contract end date
Certificate-related outage history — number of expiry-driven outages in the last 24 months and cost per incident
Machine and workload identity counts — servers, containers, service meshes, IoT/OT devices
Strata Cloud Manager tenancy — existing tenant or new, and which firewalls are onboarded (NGTS is embedded in SCM)
Idira (formerly CyberArk) machine-identity integration scope — which certificate and secrets workflows connect
Crypto-agility and post-quantum requirements — PQC migration deadline and inventory of algorithms in use
Automation targets for certificate lifecycle — percentage of issuance/renewal to automate and protocols required (ACME, SCEP, EST)
Number of teams and applications to onboard, and ownership model for certificate policy
Number of AI models, AI applications, and AI agents to protect, by environment
LLM providers and gateways in use (vendor, endpoint count, monthly token volume)
AI Gateway requirement — Prisma AIRS AI Gateway comes from the Portkey acquisition, closed May 29, 2026
Module selection: AI Model Security, AI Runtime Security, AI Agent Security, AI Red Teaming
CN-Series estate to migrate to AI Runtime Firewall (AIRS) ahead of the Nov 1, 2026 CN-Series End-of-Sale — cluster and node counts
Software NGFW Credit funding — credit balance available, since Prisma AIRS is funded by Software NGFW Credits
Target platform version (Prisma AIRS 3.0, March 23, 2026) and deployment region
Compliance drivers — EU AI Act obligations and ISO/IEC 42001 certification timeline
Kubernetes and cloud footprint hosting AI workloads (clusters, namespaces, accounts)
Data sensitivity of AI inputs/outputs and DLP or redaction requirements
Red-teaming cadence required (tests per quarter) and who owns findings remediation
Total identity count — human users, service accounts, machine identities
Current PAM tool and contract expiration date
Number of privileged accounts under management today
Identity governance tooling — current vendor (SailPoint, Saviynt, etc.)
Idira Privileged Access Manager scope — number of privileged users, sessions per day, and target systems
Idira Secrets Hub scope — number of secrets, existing vaults, and applications consuming them
Certificate Manager scope — certificate count and annual issuance volume (align with NGTS scoping if both are in play)
Idira Secure AI Agents scope — number of AI agents with system access and the credentials they consume
AI/agentic identity requirements — non-human identity growth rate per year
Compliance requirements: SOX, PCI, HIPAA — privilege access audit needs
Integration requirements: Idira Endpoint Privilege Manager into XSIAM via Cortex Marketplace, plus directory services (AD, Entra, Okta)
Just-in-time vs standing privilege current state, by account class
Incumbent observability vendor, annual spend, and contract end date
Metric volume — active time series and peak cardinality; log volume in GB/day; trace spans per second
Number of services and environments (prod/stage/dev) emitting telemetry
Retention requirements per data type in days, including any compliance-driven minimums
Kubernetes footprint — clusters, nodes, and pods generating telemetry
SLO and on-call maturity — number of defined SLOs, alert volume per week, and on-call rotation size
Telemetry-pipeline noise-reduction target — Chronosphere Telemetry Pipeline is natively integrated with Cortex XDL 2.0 (30%+ noise reduction observed)
Mobile RUM requirement — Embrace mobile RUM was announced Jul 21, 2026 with close expected Q1 FY2027, so it is not yet available
Instrumentation state — OpenTelemetry coverage percentage and remaining agents to migrate
Cortex AgentiX integration interest — the Cortex tie-in is not GA, so scope it as roadmap only; sell under the Chronosphere brand within the Palo Alto Networks Observability platform
Number of engineering teams to onboard and chargeback/quota model required
Incident history — number of security incidents and breaches in the last 24 months, with severity
Existing retainer state — current provider, hours remaining, and expiration date
Retainer hour-bank sizing — target hours per year and permitted use across IR, forensics, and assessments
IR plan maturity — plan exists/last tested date, and whether IR Plan development or tabletop exercises are needed
Environment scope for assessments — endpoint count, cloud accounts, and domains for Compromise Assessment or Cyber Risk Assessment
Compromise or ransomware readiness drivers — regulator, insurer, or board mandate and the deadline
AI and agentic footprint for Unit 42 Frontier AI Defense scoping — number of AI apps and agents; select Exposure Analysis, Autonomous Security Blueprint, or Agentic Defense Transformation (includes 6 months free Cortex XDR, Xpanse and Koi)
External AI Hyperattack Assessment requirement and internet-facing AI surface count
Threat-intelligence requirements — Unit 42 Threat Intelligence launched Aug 3, 2026, delivered via Cortex XTI plus Unit 42 Threat Intel Services
Purple Teaming or Zero Trust Advisory scope in engagement weeks
Delivery model — Unit 42 direct, partner-assisted, or Cortex XMDR Specialization partner, and onsite vs remote
Total current Palo Alto spend by product line (network, Cortex, cloud, SASE, identity) in annual dollars
Renewal dates by product line and support contract, listed individually
Legacy ELA End-of-Sale is Aug 20, 2026 and is replaced by ELA8 — flag as a near-term deadline; ELA8 SKU detail is not yet published, so do not quote ELA8 line items
Enterprise Support Agreement (ESA) entitlement — in place or to be added
Strata Cloud Manager Pro entitlement — SCM Pro is bundled into ESAs via a single auth code; confirm the auth code is issued
Three-year consumption forecast — firewalls by model, Software NGFW Credits, ingestion GB/day, endpoint and user counts
Platform-consolidation candidates — third-party tools to retire, with annual spend and contract end date for each
Co-term requirements — target common anniversary date and any stub periods to true up
Software NGFW Credit balance today, burn rate per quarter, and reclaim opportunities
Approval path and procurement calendar — signing authority, fiscal year end, and required budget cycle date