The SSO Tax and the Enterprise-Readiness Ladder: What B2B Software Really Charges For
Single sign-on is the most resented line item in business software. A team using a product happily at a modest per-seat price discovers that connecting it to their identity provider requires the enterprise tier, and the enterprise tier costs three, five, or ten times more. The reaction is always the same, and it is always framed as a fairness argument: SAML is a mature open standard, the libraries are free, implementing it is a week of engineering work, and charging a multiple of the entire product price for it is extortion dressed as packaging.
The fairness argument is correct on its facts and wrong about what is happening. The enterprise tier is not priced to recover the cost of building SSO. It is priced to segment the market, and SSO sits behind the fence not because it is expensive but because it is an almost perfect indicator of which customers can pay more. Understanding that distinction is what separates buyers who negotiate this well from buyers who write an angry post and then pay list price.
The strategic claim worth making is sharper than "vendors are greedy." The SSO tax is a rational response to a genuine pricing problem, it is becoming less defensible for reasons that have nothing to do with customer resentment, and the fence is already migrating to a new set of features where the economics are fundamentally different. Vendors defending the old fence are fighting the last war. Buyers who understand which rung they are actually paying for hold more leverage than they realize.

The Fence Is the Product
Start with the cost structure, because it is the part both sides of the argument get wrong.
Implementing SAML or OIDC in a modern application is not free, but it is not expensive either. The protocols are mature, the libraries are well maintained, and identity providers publish thorough integration documentation. The genuine costs are in the long tail rather than the initial build: supporting the specific configuration quirks of many identity providers, handling just-in-time provisioning and its edge cases, keeping up with certificate rotation, and supporting customers whose identity teams are themselves confused. Call it a meaningful engineering investment with an ongoing support burden, in the same range as several other integrations the vendor ships without charging a multiple for.
The other rungs cost more. Audit logs at enterprise retention require storage architecture, query performance work, and export mechanisms. SCIM provisioning is a genuine surface with real edge cases around deprovisioning and group mapping. Data-loss-prevention and security-tooling integrations, residency guarantees, and compliance attestations carry substantial and continuing costs, and attestation in particular is a recurring audit expense rather than a one-time build.
None of these, individually or together, explain a five-times price multiple on the base product. The multiple is not cost recovery. It is value capture, and the feature set behind the fence was selected by a different criterion entirely: correlation with willingness to pay.
That criterion works because the moment a buyer genuinely needs SSO is a moment with a specific and highly legible shape. Nobody wants SSO for its own sake. An organization needs it when it has enough employees that manual account management has become painful, when it has an identity provider deployed, when it has a security function that has written a policy requiring centralized authentication, and, most importantly, when a security review has been triggered on this purchase. Every one of those conditions correlates with a larger budget. The security review is the decisive one: it means the purchase has escalated out of a team's discretionary spend and into a process where a real budget exists and a business case has been made.
So the fence is not really around SSO. It is around the procurement moment, and SSO is simply the most reliable tripwire anyone has found for detecting it. This is textbook second-degree price discrimination, the same mechanism as airline fare classes, and it is economically rational rather than malicious. It is also why appeals to the low cost of implementation never move a vendor: the vendor already knows SAML is cheap, and cost was never the input to the price.

This is a Premium Article
Sign up for a Premium membership to read this article and get full access to strategic intelligence on technology and business.
Already a member? Sign in