NNetify

Which Security & MSSP Vendors Have the Best Channel Partner Programmes? A Comparison for UK Resellers

Harry YellandUpdated 31 August 202618 min read

By Harry Yelland, Cybersecurity Writer | Published 19 August 2026 | Fact-checked by: Robert Sturt, Managing Director

When it comes to reselling security and managed security services, the market has plenty of options – though comparing these reseller and partner programmes can be difficult. Each programme offers different incentives, entry requirements and commission structures, however in this article we’ll cover our picks for the top channel partner programmes and explain how reselling can differ from product to product.

This guide compares six of the major security and SASE vendor channel programmes, including the likes of Cato Networks, Palo Alto Networks, Fortinet, Cisco, CrowdStrike and Zscaler, as well as BT's security channel.

What Does a Security or MSSP Channel Partner Programme Actually Include?

Whilst each partner programme will differ from vendor to vendor, a typical programme will include:

  • A structured set of tiers,
  • Commission terms,
  • Deal protection
  • Training requirements (that may also determine how a vendor governs how partners resell, refer or manage its products).

Partner tiers explained

Typically, providers will try to reward vendors more if they draw in greater amounts of businesses, often through structured partner tiers. These differentiate the likes of benefits, discounts and support that providers offer based on a partner's investment, certification and revenue commitment.

As to be expected, structures vary by name – for example, Cato uses Starter and Advanced, Palo Alto Networks uses Registered, Innovator, Platinum and Diamond, Fortinet uses Advocate, Select, Advanced and Expert, and Zscaler uses Base Camp, Alpine and Zenith. However, regardless of the naming conventions used, the underlying logic is essential the same, with higher tiers providing resellers with better discounts, dedicated account management and marketing funds (in exchange for higher certification requirements and revenue commitments).

Commission and margin models

Similarly to partner tiers, depending on the provider, commission and margin models differ, often falling into one of:

  • An upfront discount off list price (the reseller/VAR model),
  • A recurring percentage of a referred deal's value (the referral/agent model),
  • A wholesale rate the partner marks up themselves (the white-label MSSP model).

We would, however, warn that few vendors publish an exact blanket percentage for these and most instead publish a discount schedule that varies by tier, specialisation and deal registration status.

Deal registration and lead protection

Deal registration is the process by which a partner formally logs a prospective deal with the vendor. This does two things:

  • Secures pricing protection on that opportunity,
  • Unlocks an enhanced discount, in most programmes, for having sourced the deal in the first place.

Without it, a partner risks a competing reseller (or even the vendor's own direct sales team) undercutting them on a deal they originated. Cato Networks, who publish more detail on this than most, state in their own programme documentation that opportunities without an approved deal registration receive a materially lower discount score than registered ones.

Enablement - training, certification and accreditation

Enablement is the training, exams and accreditations that a partner's staff need to work through to unlock higher tiers or sell specific security products. This typically costs real staff time rather than a cash fee, which gets overlooked when weighing up a programme's headline benefits.

Palo Alto Networks, who run one of the more demanding programmes in this comparison, are a good example: partners at every level, including entry-level Registered partners, are expected to invest continuously in training to progress, with certification status now tracked through partner-facing performance dashboards.

How We Compared These Channel Programmes

We at Netify try to simplify comparisons as much as possible, and so we’ve broken down each vendor's channel programme on six different criteria:

  • Commission/discount structure,
  • Ease of onboarding,
  • Deal registration and lead protection,
  • Support quality,
  • SMB-friendliness,
  • Breadth of product portfolio available to resell.

We’ve verified all information below against each of the vendor's own current partner-programme materials, official press announcements or named trade press coverage.

Security & MSSP Vendor Channel Partner Programmes Compared

The table below compares all six vendors on programme name, tier structure, commission model, deal registration and best-fit reseller type, based on each vendor's own published programme materials as of August 2026.

VendorPartner Programme NamePartner TiersCommission / Margin ModelDeal RegistrationBest Suited To
Cato NetworksChannel First Partner ProgramStarter, Advanced (plus VAR/MSP/SP/Distributor/TSD-Agent tracks)15% commission on new business bookings for referral (TSD/Agent) partners; VAR/MSP margins are tier-based discounts, not a published flat %Yes - approved registration required for full discount; unregistered deals score materially lowerReferral partners wanting a clearly published rate, and MSPs building managed SASE without owning infrastructure
Palo Alto NetworksNextWave Partner ProgramRegistered, Innovator, Platinum, DiamondDiscounts vary by tier and specialization via a Partner Development Fund (replaced traditional MDF); exact % not publicly disclosedYes - streamlined deal registration under the 2026 programme refreshEstablished partners investing in platform-wide (network, cloud, SOC) specialisation, including MSSP-specific tracks
FortinetEngage Partner ProgramAdvocate, Select, Advanced, Expert (crossed with Integrator, MSSP, Cloud business models)Deal registration discounts plus FortiRewards incentive scheme; exact % not publicly disclosedYes - available from Advocate (entry) level upwardMSPs/MSSPs wanting managed-security-specific benefits from day one, not just after reaching a top tier
CiscoCisco 360 Partner Program (replaced Gold/Premier/Select, effective 25 Jan 2026)Integrator/Provider/Developer/Advisor partner types, plus Preferred Partner specializations (incl. Cisco Preferred Security Partner)Cisco Partner Incentive (CPI) rebates plus dedicated Security Deal Registration Discounts; exact % not publicly disclosedYes - dedicated Security Deal Registration programme (Hunting/Teaming incentives)Established integrators already selling Cisco networking who want to add security as a specialization
CrowdStrikeElevate Partner Program (successor to CrowdStrike Powered Service Provider)Tiered structure; exact current tier names not consistently published in vendor materials as of August 2026Volume Incentive Rebates (VIR) and CrowdCard rewards on Falcon Flex licensing; exact commission % not publicly disclosedYes, via partner portalMSSPs and GSIs building recurring endpoint/identity managed services at scale
ZscalerSummit Partner ProgramBase Camp, Alpine, ZenithCo-sell and deal/renewal-registration incentives; exact commission % not publicly disclosedYes - including renewal registration, a feature most competitors don't separately call outPartners co-selling zero trust/SASE alongside an existing primary platform relationship rather than pure transactional resale

Cato Networks - Channel First Partner Program

Cato's programme is built around two tiers, Starter and Advanced, layered with specialisation tracks for VARs, MSPs, service providers, distributors and referral partners or agents. Margin scales with tier and specialisation, and the VAR track's Advanced tier, for example, requires around $300,000 in new business bookings, whilst Cato also explicitly promotes a zero-upfront-cost entry point, so new partners can start selling without any capital outlay to begin with.

What's genuinely different here is the transparency of it all. Cato are the only vendor in this whole comparison publishing an exact referral commission figure, that 15% on new business bookings for TSD/Agent partners we mentioned earlier, rather than leaving margin entirely to a private discount schedule like most of the others do. In our view, Cato is the strongest starting point for a reseller who wants a published number to actually plan around, rather than negotiating blind and hoping for the best.

Palo Alto Networks - NextWave Partner Program

NextWave's four tiers, Registered, Innovator, Platinum and Diamond, were substantially rewritten back in February 2026, shifting the reward structure away from pure deal volume and toward partners who sell the likes of Palo Alto's integrated network, cloud and SOC platform rather than single point products. The new Partner Development Fund reinvests earned rebates into partner-led demand generation and training, rather than paying out a traditional flat MDF allowance like it used to, and the programme's also expanded its MSSP-specific pathways as part of that same refresh.

We'd recommend this route for resellers who are prepared to invest seriously in certification and platform-wide expertise, given that the programme's structure now actively rewards depth over transaction count. It's a heavier onboarding lift than Cato's, we won't pretend otherwise, but the ceiling on rebate value is a lot higher for partners who actually commit to it.

Fortinet - Engage Partner Program

Engage runs four engagement levels, Advocate, Select, Advanced and Expert, crossed against three business models a partner can register under: Integrator, MSSP and Cloud/Marketplace. The notable bit for security resellers specifically is that MSSP-track benefits, including access to Fortinet's MSSP portfolio and deal registration, are available from the entry-level Advocate tier rather than being gated behind a top tier like with some of the others, which lowers the practical barrier to starting a managed-security line quite a bit.

Fortinet don't publish a blanket commission percentage, relying instead on FortiRewards incentives and tier-based discounting to do the work. In our experience this makes Fortinet a sensible option for a reseller wanting to build MSSP revenue without a long qualification runway before the managed-services benefits actually kick in.

Cisco - Cisco 360 Partner Program

Cisco replaced its long-standing Gold, Premier and Select tiers entirely on 25 January 2026 with the Cisco 360 Partner Program, structured around partner types (Integrator, Provider, Developer, Advisor) plus a Preferred Partner designation carrying specific specialisations, including a new Cisco Preferred Security Partner track that got introduced alongside AI-infrastructure specialisations back in February 2026. Security-specific deal protection runs through a dedicated Security Deal Registration programme, offering additional upfront discounts via Hunting and Teaming incentive routes.

This is a genuinely new programme rather than an incremental update, so any figures and requirements published before January 2026 should really be treated as superseded at this point. Put simply, Cisco suits an existing Cisco networking partner extending into security far more than it suits a security-only reseller starting from scratch, given how much of the value sits in cross-portfolio rebates like the Cross Sell Bonus.

CrowdStrike - Elevate Partner Program

CrowdStrike's current programme, Elevate, succeeds the earlier CrowdStrike Powered Service Provider (CPSP) structure and centres on Falcon Flex, a flexible licensing model that lets partners bundle modules from across the Falcon platform rather than reselling fixed SKUs. Partner earnings are shaped through Volume Incentive Rebates and a CrowdCard rewards scheme rather than a single published commission line, and CrowdStrike's own partner terms explicitly state it makes no commitment regarding a partner's profit or margin outcomes. What's distinctive is the recurring-revenue emphasis: CrowdStrike cites a $7-in-partner-services-per-$1-of-product ratio as evidence of the services opportunity around its platform. Best for MSSPs and global systems integrators building a large recurring endpoint and identity security book rather than a reseller wanting a quick, simple commission structure.

Zscaler - Summit Partner Program

Zscaler's Summit programme runs three technical-enablement tiers, Base Camp, Alpine and Zenith, and is explicitly built around co-selling rather than transactional resale: Zscaler's FY26 partner communications specifically highlight renewal registration as a distinct, rewarded activity alongside net-new deal registration, which is unusual among the vendors compared here. As with most of this list, Zscaler doesn't publish a blanket commission percentage. Zscaler, in our view, fits a partner who already has an established relationship with a customer's wider security or networking estate and wants to layer in zero trust access as a co-sell motion, rather than one looking to build a standalone Zscaler resale business from a cold start.

BT's Security Channel

BT also runs its own security channel for partners, spanning Endpoint Threat Protect, Cloud Threat Protect and the combined Connect and Protect proposition, sold through BT's Authorised Partner network rather than direct vendor enrolment. We won't re-cover the commercial detail here since it's already documented on BT's cloud security services page, worth a look if you're weighing a bundled connectivity-plus-security route against going direct with one of the specialist vendors above.

Referral, Reseller or White-Label MSSP - Which Commercial Model Fits Your Business?

The commercial model you go with is really a separate decision from which vendor you actually pick. The same vendor can typically be sold under a referral, reseller or white-label arrangement, and which one's right for you depends mostly on how much operational risk and customer ownership your business actually wants to take on.

The referral / agent model

The referral model means introducing a prospect to the vendor and collecting a commission once the deal closes, with the vendor handling delivery, billing and support directly themselves. It's the lowest-effort, lowest-risk route into a security revenue line, though it also caps your upside at whatever commission the vendor's willing to publish, and Cato's 15% new-business rate is one of the only concrete numbers going in this space right now.

The reseller / VAR model

The reseller (VAR) model means you buy at a partner discount and invoice the customer directly yourself, taking on billing and first-line relationship ownership whilst the vendor still delivers the underlying service on their end. This sits somewhere in the middle on both effort and margin, and it's the model most of the tiered programmes we've compared above, the likes of Cato's VAR track, Palo Alto's NextWave discount schedule, Fortinet's Integrator model, are really built around.

The white-label MSSP model

The white-label MSSP model means reselling the vendor's technology under your own brand and your own managed-service wrapper, typically buying capacity at a wholesale rate and setting your own retail price on top. It's a lot more operational responsibility, staffing a SOC function yourself, or partnering into one, but in exchange you're looking at a materially larger margin. Published examples of white-label SOC rate cards elsewhere in the market show partners retaining somewhere in the 35-50% range once their own pricing's applied on top of the wholesale rate, though this varies quite a bit depending on the underlying technology and service scope involved.

ModelTypical Margin RangeOperational BurdenWho Owns the Customer RelationshipBest Fit For
Referral / agentSingle-figure to low-double-figure % of deal value (e.g. Cato's published 15% on new business)Lowest - vendor delivers, bills and supportsVendorResellers testing a new vendor relationship or wanting security as a light-touch add-on
Reseller / VARTier-based discount off list price, varies by vendor and tier - not uniformly publishedMedium - partner bills and owns first-line relationship, vendor still deliversPartner (commercially), vendor (technically)Established IT/connectivity resellers adding security as a core, ongoing line
White-label MSSPCommonly cited in the 35-50% range on published white-label SOC rate cards, though scope-dependentHighest - partner brands, prices and often staffs the deliveryPartnerMSPs with (or partnering into) genuine SOC/delivery capability wanting maximum margin and brand control

Where the Best Margins Currently Sit

In our view, the strongest margin opportunity right now sits with white-label MSSP delivery of the higher-value, less-commoditised services, the likes of MDR/XDR and zero trust access especially, rather than chasing the highest headline reseller discount on point products like standalone endpoint AV.

Canalys, who Infosecurity Magazine cited back in February 2026, are pretty explicit on this point: managed detection and response gets described as a higher value, margin and growth service compared with legacy MSSP-style offerings, mostly because standard antivirus, MFA and EDR are becoming saturated and commoditised right across the channel now. Separately, Canalys chief analyst Jay McBain reported in 2026 analysis that the global cybersecurity market, worth $311 billion and growing at 12.1% annually, now sells 91.7% of its revenue through or alongside partners, so the channel opportunity itself isn't shrinking as such, it's more that the margin's migrating away from flat product resale and toward services layered on top instead.

There is a trade-off to bear in mind before chasing a headline commission rate though: a vendor advertising the highest published percentage isn't necessarily going to be the best net margin once you've factored in certification time and deal registration friction. Palo Alto Networks' NextWave, who we'd flag as a good example of this, now explicitly rewards partners investing continuously in training and platform-wide specialisation over those just closing volume, meaning the effective margin for a well-certified Diamond-tier partner ends up structurally different to a partner doing the bare minimum at Registered level, even though neither figure gets published as a flat percentage.

Vendor / ModelYear 1 Margin RangeRecurring / Renewal MarginNotes
Cato Networks (referral)15% of new business bookings (published)Not separately published for referral partnersOnly vendor in this set with a published flat commission figure
Palo Alto Networks (NextWave)Not publicly disclosed - varies by tier and specializationRebates via Partner Development Fund, replacing traditional MDFStructurally shifted in Feb 2026 to reward platform depth over deal volume
Fortinet (Engage)Not publicly disclosed - deal-registration discount plus FortiRewardsNot separately publishedMSSP-track benefits available from entry tier, lowering time-to-margin
Cisco (360 Partner Program)Not publicly disclosed - CPI rebate plus Security Deal Registration DiscountNot separately publishedNew programme from Jan 2026; pre-2026 figures are superseded
CrowdStrike (Elevate)Not publicly disclosed - Volume Incentive Rebates on Falcon FlexNot separately publishedVendor's own partner terms state no margin outcome is guaranteed
Zscaler (Summit)Not publicly disclosed - co-sell and deal-registration incentivesRenewal registration separately incentivisedOne of few vendors here to call out renewal margin as distinct from new-business margin
White-label MSSP (market example)Commonly cited around 35-50% on published white-label SOC rate cardsTypically consistent with Year 1, since partner sets retail priceScope-dependent; not a single vendor's guaranteed figure

What UK Resellers Should Check Before Signing a Security Vendor Agreement

When joining a programme, you’ll be expected to sign a security vendor agreement, however before signing anything we’d recommend that you check for the following things:

  • How deal registration protects you in practice,
  • What support and escalation look like on a day-to-day basis,
  • How much certification you’re expected to complete and how certification levels affect your margins
  • How billing runs alongside your existing accounts.

Deal registration protections - what good ones look like

In our experience, a good deal registration policy will clearly state how long any protection lasts, what happens if the vendor's own direct sales team engages the same account and what discount uplift registration earns you. We’d therefore warn that vague or undocumented deal registration terms can be a common source of lost margins, so clarifying this ahead of time is best practice.

Support and escalation - SLAs, UK-based support, out-of-hours cover

Given that resellers have different levels of expertise and readiness to take on responsibilities, we’d strongly recommend that you clarify upfront whether first-line support sits with you or the vendor and then whether there's a UK-based escalation path, as well as what the vendor's own SLA commits to for critical incidents. We’d argue that this matters more for security than pretty much any other category we cover, given that a slow escalation during an active incident becomes a reputational risk to your business, not just the vendor's.

Certification and training burden vs payoff

It’s also beneficial to consider and weigh up the man hours taken for certain certification paths, especially given that some are required for unlocking greater margins. Several of the programmes compared above, particularly Palo Alto's NextWave, now offer significant rebate increases to sustained training investment (rather than to a one-off exam), so we’d suggest taking this into consideration, with the payoff assessed as an ongoing cost, instead of a single onboarding hurdle.

Billing - consolidated onto an existing account vs a new separate relationship

Taking on security services can not only appeal to new customers but also enhance the services you provide to your existing customer base - though this brings its own billing complexities. We’d recommend that you establish early on whether the vendor will let you consolidate billing onto an existing distributor or connectivity account, or whether it requires a wholly separate commercial relationship. A separate relationship adds administrative overhead that's easy to underestimate, especially when you're only weighing the headline commission rate.

Common Mistakes Resellers Make When Choosing a Security Vendor Partner

  • Chasing the highest headline commission percentage without factoring in the certification time and deal-registration admin required to actually earn it: a lower published rate with a faster path to margin can beat a higher one that takes six months of training to unlock.
  • Signing with a vendor that has no UK-based support desk, then discovering during a live incident that escalation runs through a US or APAC time zone.
  • Ignoring deal registration terms until after losing a deal to a competing partner or the vendor's own direct sales team. Read the protection terms before you register your first opportunity, not after.
  • Assuming a single vendor relationship is enough. Most established resellers in this space run two or three vendor lines so they aren't forced into a one-size-fits-all pitch with every prospect.
  • Underestimating the ongoing cost of staying certified: several programmes now tie discount tier to continuous training investment rather than a one-off exam, which is easy to miss when comparing headline tier names.
  • Treating a referral commission and a white-label wholesale rate as directly comparable numbers: they represent fundamentally different operational commitments, not just different percentages.
  • Skipping the billing-consolidation question until after signing, then discovering the vendor requires a wholly separate account relationship that adds real administrative overhead.

Frequently Asked Questions

Which security vendor has the best reseller margins?

There's no single vendor that publishes the highest margin across every model, so it really depends what you're after. Cato Networks, who we'd rate as the most transparent of the bunch, publish a flat 15% commission on new business bookings for referral partners, whilst most of the other vendors we've compared keep their exact discount percentages behind partner-portal login and vary them by tier and specialisation instead.

What's the difference between a security reseller and an MSSP?

A security reseller sells a vendor's product, typically at a discount off list price, with the vendor still delivering and supporting the service themselves. An MSSP, on the other hand, wraps that same technology in its own ongoing managed service (monitoring, response, support, the likes of that) usually under its own brand, which is a big part of why MSSP margins tend to run structurally higher, though they also carry a lot more operational responsibility with it.

Do I need certifications to resell CrowdStrike, Fortinet or Palo Alto products?

In practice, yes. All three vendors gate their higher partner tiers, discounts and MSSP-specific benefits behind staff certification and training requirements, and Palo Alto Networks especially, who now expect continuous training investment at every level of their NextWave programme, including entry-level Registered partners.

However, one way of getting to resell something like CrowdStrike Falcon Go without the hassle is to consider reselling BT Endpoint Threat Protect (built on CrowdStrike Falcon Go), which can be resold through Netify’s reseller programme with no joining fee or minimum requirements.

Can I resell more than one security vendor at the same time?

Yes, and it's actually common practice. None of the programmes we've looked at here require exclusivity, so running two or three vendor lines alongside each other is normal among established resellers, mostly so they're not stuck pitching one platform to every single prospect that comes through the door.

How does deal registration work, and why does it matter?

Deal registration is essentially the process of formally logging a prospective sale with a vendor, which secures pricing protection and, typically, an improved discount for having sourced the opportunity yourself. It matters because an unregistered deal can be undercut by a competing partner, or the vendor's own direct sales team for that matter, and Cato's own programme materials confirm unregistered opportunities receive a lower discount than registered ones do.

Is it better to go direct to a security vendor or through a channel like BT's?

That really depends how much of the commercial and delivery relationship you want to own yourself. Going direct to a vendor like Cato or Palo Alto gives you the full programme and margin structure, but you're managing certification, deal registration and support on your own, whereas a bundled channel like BT's cloud security services folds security into an existing connectivity relationship, with less operational overhead but also less direct control over the underlying vendor relationship.

How long does it typically take to get set up as a security reseller?

Entry-level referral or reseller tiers with vendors like Cato or Fortinet can usually be activated within days to a few weeks, given their published zero-upfront-cost or low-barrier entry models. Reaching the higher tiers with meaningful rebate uplifts is a different story though, particularly under Palo Alto's NextWave or Cisco's new 360 programme, where it's more of a multi-month process tied to sustained certification and revenue commitments.