Why Traditional Programs Fail
Most cybersecurity partner programs still share the same skeleton. There's a Silver, Gold, and Platinum ladder. Partners climb it by hitting annual revenue thresholds. Higher tiers unlock bigger discounts and MDF. Certifications are a box to tick once a year, and everything lives behind a partner portal login.
That design made sense when partners mostly resold boxes and licenses. It doesn't fit the channel cybersecurity actually has today, for three reasons.
1. The Channel Sells Services
Omdia, a channel analyst firm (previously Canalys), puts it bluntly: over 90% of cybersecurity spending, including both technology and services, flows through channel partners, the highest proportion of any IT domain, and services make up two-thirds of the total addressable market, according to Omdia chief analyst Matthew Ball and practice leader Adam Etherington. The most recent publicly reported quarterly data backs this up. Omdia's Worldwide Cybersecurity Market Summary for the first quarter of 2026 found that $22.88 billion of the $25.1 billion spent on cybersecurity technology flowed through the channel, or 91.3% of the total, with spending through service providers up 15.9% and through MSSPs up 11.3% year over year, as reported by Channel Dive. The channel is also concentrated: Omdia's Cybersecurity Partner 500 ranking finds its top 500 partners drive more than half of global cybersecurity revenue. Meanwhile, Gartner forecasts worldwide information security spending will rise 12.5% in 2026 to $240 billion, with security services alone at roughly $92.8 billion.
The most telling number comes from Omdia chief analyst Jay McBain, estimates that the channel now generates roughly $2 in cybersecurity services revenue for every $1 in product revenue. A tier ladder that measures resale volume is measuring the smaller half of a partner's business. It can't see the MSSP who runs 24/7 detection for 60 customers but transacts modestly, or the integrator whose deployment work drives every renewal.
2. Programs Are Aging
Forrester's Partner Ecosystem Marketing Survey, 2026 found that current B2B partner programs have existed for an average of 6.4 years, that nearly half of B2B organizations say their program is not profitable by tier level, and that two-thirds plan to rearchitect, change, or significantly update their program within the next 12 months, according to Forrester's Kathy Contreras. She notes that older programs were designed for smaller ecosystems focused on transactional relationships, while today's include "transactional and nontransactional partners" contributing value at different stages of the customer lifecycle. Her question is the one every security vendor should be asking: "Can yesterday's partner program support tomorrow's partner ecosystem?"
3. Partners Want Co-Selling
Partners are telling vendors what they value, and it isn't more of the same. Futurum Group's channel research shows co-sell support rising 14.6 points to 39.2% to become partners' number one vendor support priority, while training programs fell from 32.2% to 17.5%, according to Futurum's analysis of Rapid7's PACT program. Generic enablement, delivered through a portal partners visit once a quarter, is losing its pull.
Put those together and the problem is clear. Traditional programs reward the wrong behaviour, through the wrong interface, for a partner base that no longer looks like the one they were designed for.
What New Programs Do Differently
If it feels like every security vendor relaunched its partner program this year, that's because many did. Reading across the 2026 launches, I see four innovations doing most of the work.
AI Personalisation
The traditional portal treats every partner the same: the same resource library, the same training catalogue, the same campaign kit. AI is turning that into a personalised journey.
Orca Security's new Partner POD Program, launched in September 2026, is a clear example. Its AI-powered Partner Success Platform scores prospective accounts against Orca's ideal customer profile across 11 vectors in under 30 seconds, lets partners generate co-branded social content and landing pages in about a minute, and produces AI-generated quizzes, certifications, and business plans, according to Orca's launch announcement. Acronis similarly describes AI-powered growth guidance with recommendations tailored to each partner's business on its Acronis Cyber Partner Program page.
This mirrors where software is heading generally. Gartner predicts that 40% of enterprise applications will include task-specific AI agents by the end of 2026, up from less than 5% in 2025, according to the Gartner announcement. Expectations are shifting on the human side too: Forrester notes that younger B2B buyers bring "consumerlike expectations for personalization, convenience, and value," according to Forrester's Maria Chien.
A note of caution: Gartner also predicts that over 40% of agentic AI projects will be canceled by the end of 2027, according to its June 2025 forecast. Personalisation only works if it's grounded in accurate partner data and approved content. An AI assistant that confidently gives a partner the wrong discount rule is worse than no assistant at all.
Rewards Beyond Revenue
This is the shift I find most interesting, because it's borrowed straight from consumer marketing.
Think about Costa Coffee's loyalty scheme. Costa Club members earn a Bean for every barista-made drink, and every 10 Beans earns a free drink. But Costa also gives an extra Bean when you bring a reusable cup, and layers personalised offers on top, according to Costa Club. That small detail is the whole idea: the program rewards a behaviour the brand wants (sustainability, repeat habit), not just how much you spend. Forrester's B2C research makes the same distinction, noting that points and discounts drive short-term behaviour while "exclusive access, personalized experiences, and recognition foster long-term emotional loyalty," per Forrester.
Cybersecurity vendors are now applying the same logic to partners:
- AvePoint introduced a points-based structure that rewards "enablement, customer success and solution adoption—rather than revenue alone," according to CRN's 2026 Partner Program Guide.
- Acronis lets partners earn points, badges, and rewards for certifications, business growth, and partner engagement, while tracking progress against individual and company goals, per the Acronis Cyber Partner Program.
- SolarWinds is piloting a North American rewards centre where partner sellers accrue points toward rewards including cash and prizes, according to ChannelE2E.
- Orca's Partner POD Program rewards value created across new business, expansion, and net retention, not just initial bookings, according to Orca.
The equivalent of Costa's reusable cup in a security program might be completing a certification, running a security assessment, onboarding a customer within 30 days, or keeping net retention above target. These are the behaviours that predict long-term revenue, and a revenue-only tier can't see them. One design caution: rewarding individual sellers with cash or prizes raises compliance questions in some regions and customer contracts, so the rules need to be as clear as Costa's "10 Beans, one drink."
Headless Partner Experience
The third innovation goes after the portal itself. Partners at an MSSP live in their PSA, their RMM, their own CRM, Slack or Teams, and their inbox. Asking them to log into a separate portal for each of the 10 to 20 vendors they work with is a big part of why portals go unused.
A headless partner experience separates the program's data and logic from any single interface, so partners can register deals, check MDF balances, or find a battlecard from the tools they already use. I've written about this in more depth in why your partner program needs a headless partner portal, including how bidirectional CRM sync lets a partner register a deal in their own Salesforce or HubSpot without re-entering it anywhere else.
MCP and AI Assistants
The logical endpoint of headless is the AI assistant. The Model Context Protocol (MCP), an open standard introduced by Anthropic in November 2024, gives AI assistants a standard way to discover and use a system's tools and data. Connected to a partner program, it means a partner can ask Claude, ChatGPT, or Gemini "what's the status of my registered deal with Acme?" or "which campaigns can I launch this quarter?" and get a live, permissioned answer, or have the assistant take the action directly.
This is already moving from concept to practice. AWS Partner Central now offers agents that surface pipeline insights and pre-fill funding requests, and HubSpot's remote MCP server lets AI tools read and update CRM data. I break down how this works, and the permissioning and audit controls security vendors should insist on, in PRM Meets MCP: How AI Agents Actually Connect to Partner Platforms. For a cybersecurity vendor, the governance piece isn't optional: user-scoped permissions, action logging, and central revocation are what make it safe to let an agent register deals on a partner's behalf.
Routes, MSSP Tracks, Marketplaces
The four innovations above sit on top of structural changes documented in CRN's 2026 Partner Program Guide for 5-Star security vendors:
- Routes are replacing tiers. Armis replaced its tiered model with three routes (Sell, Service, Connect), Cloudflare added four (Resell, Manage, Distribute, Consult), and Exabeam swapped volume-based tiers for a competency-first model with persona-based paths for MSSPs, VARs, distributors, and advisors.
- MSSPs are getting their own track. Darktrace introduced a dedicated MSSP track, CyberArk launched a multi-tenant MSP Hub, and eSentire's Atlas Nexus Network lets MSPs and integrators run their own instance of its XDR platform.
- Newer launches follow suit. Vectra AI's Ascent program is organised around co-sell, co-market, co-deliver, and co-innovate, according to Channel Insider, and Censys reported partner-sourced bookings up 186% year over year after moving to a unified global framework, also per Channel Insider.
- Marketplaces are a route, not a threat. Omdia's Matthew Ball called hyperscaler marketplaces "the fastest route-to-market," with cybersecurity spending through AWS, Azure, and Google Cloud projected to grow 33.9% to $10.96 billion this year, per Channel Dive. Proofpoint's revamped Partner Network added AWS and Azure marketplace routes alongside incumbency protection at renewal, according to Channel Insider.
What the Best Programs Share
"Best" is a slippery word in this category. CRN awards 5-Star status to programs with "the most comprehensive lineups of incentives, resources, training, services and benefits," which is a useful shortlist but not a verdict. Comprehensive is not the same as right for your business.
Based on the 2026 changes, I'd boil the strongest programs down to six traits:
- Multiple ways to participate, with routes for referral, resale, managed services, integration, distribution, and marketplace partners.
- Rewards for behaviour, not just bookings, using points, badges, and recognition for certifications, adoption, and retention.
- A personalised journey, where AI recommends the next training module, campaign, or account based on each partner's profile.
- A headless experience, so partners can work from their CRM, collaboration tools, or AI assistant rather than a portal they forget the password to.
- Service economics for MSSPs, including multi-tenant management, consumption billing, NFR licenses, and room to build branded services.
- Deal protection that survives renewal, with clear rules of engagement and marketplace transactions credited fairly.
What MSPs Should Look For
For MSPs searching for the best cybersecurity vendors' partner programs, the question is less "who has the most benefits" and more "who makes my security practice more profitable and easier to run."
- Margin and pricing: Is there monthly or consumption billing? Are there NFR licenses for my own stack? MSP revenue is recurring; annual upfront licensing breaks cash flow.
- Operations: Is there a multi-tenant console with per-customer reporting? Managing 80 customers in 80 tabs doesn't scale.
- Deal protection: How fast is deal registration approved? Is incumbency protected at renewal? Your services relationship is the asset; the vendor shouldn't go around it.
- Co-selling: Will a channel account manager or SE join customer calls? This is now partners' top support priority.
- Rewards: Are certifications, assessments, and retention rewarded, or only revenue? Behaviour-based rewards recognise the work an MSSP actually does.
- Experience: Can I register deals and access content from my CRM, Slack, Teams, or AI assistant? Every extra portal login is friction across 10+ vendors.
- Marketing: Are campaigns co-brandable and ready to launch? Is MDF easy to claim? Small MSP teams can't build campaigns from scratch.
How to Find a Program
If you're a partner asking how to find a cybersecurity partner program that fits, three sources save time. CRN's annual Partner Program Guide is a reasonable starting shortlist. Analyst rankings such as the Omdia Cybersecurity MSP Ecosystems Leadership Matrix evaluate how well vendors support MSPs specifically. And industry events are still where channel chiefs make their pitch in person; our roundup of cybersecurity conferences and events for 2027 lists the major shows that vendors, MSPs, MSSPs, VARs, and other channel partners attend.
How to Build an MSSP Program
If you're a cybersecurity SaaS vendor, here's how I'd design an MSSP program today, in order.
1. Define Partner Types
Map how each partner type creates value: referral partners bring introductions, resellers transact, MSSPs operate, integrators implement, distributors scale reach, and marketplaces close. Then decide what each route earns. Tiers can come later, if at all.
2. Build MSSP Economics
MSSPs evaluate you like a supplier to their own business. They need multi-tenant administration, monthly or usage-based pricing, NFR access, and the freedom to wrap your product in their own services. AI is raising the bar. Gartner's 2026 Market Guide for Managed Detection and Response predicts that by 2029, 90% of initial MDR findings will be processed with AI support and no human action, up from 30% today, as summarised by Expel. MSSP Alert similarly reports that MSSPs are becoming AI-native across triage, investigation, response, and reporting. Your APIs and automation hooks are part of the partner value proposition.
3. Design a Points Model
Apply the loyalty-club principle. List the four or five partner behaviours that predict long-term revenue, such as certifications completed, assessments delivered, customers onboarded within 30 days, and net retention, and attach points, badges, or benefits to each. Keep the rules simple enough for partners to explain to each other. Revenue still matters, but it shouldn't be the only thing you can see.
4. Protect Registered Deals
Publish rules of engagement, set approval SLAs, protect partner-sourced deals through renewal, and decide upfront how marketplace transactions are credited. Acronis, for example, offers a deal registration discount of up to 25% for VARs, per CRN. Our guide to deal registration software covers the workflow in detail.
5. Tie Training to Selling
Security is technical and regulated, so partner education can't be optional. But generic training is losing value in partners' eyes. Use role-based paths for sales, presales, and SOC staff, let certifications unlock points, deal registration, or MDF eligibility, and pair coursework with live co-selling. Barracuda's 2026 update expanded its Mastery Program with role-based learning, technical labs, and advanced badges, according to ITPro.
Where that learning lives matters. Our comparison of the best LMS platforms for 2026 and our explainer on partner training platforms break down the trade-off between a general-purpose LMS and one connected to partner records, where completing a course can actually trigger a reward.
6. Offer Ready-Made Marketing
Most MSPs don't have a marketing department, so "access to the marketing portal" isn't a benefit. Ready-to-launch co-branded campaigns are. Barracuda added a through-channel marketing automation platform with co-branded campaigns and social and email syndication, per ITPro. Forrester's Contreras also notes that partner incentive strategies are becoming "broader, more strategic, and increasingly tied to business outcomes," according to Forrester's Partner Ecosystems research.
Visibility matters more in an AI-driven buying journey. Forrester's Buyers' Journey Survey, 2025 found that 94% of business buyers use AI during their buying process, and that buyers select the vendor they had in mind at the start 80% of the time, according to Forrester's Maria Chien. For playbooks, see our breakdown of the best partner marketing software and our MDF best practices for mid-market EMEA cybersecurity partners.
7. Go Headless Gradually
Don't try to rebuild the whole partner experience at once. Pick the highest-friction workflow, usually deal registration or MDF claims, and make it available where partners already work: their CRM, Slack or Teams, or an MCP-connected assistant. Measure adoption, then expand. Our pieces on the headless partner portal and PRM and MCP cover the architecture and security controls. If you're choosing the platform to run it on, our Top 15 PRMs for Cybersecurity and Security Access (2026) compares the options security vendors most often shortlist.
8. Use Events Strategically
Cybersecurity buyers still gather in person, and so do the partners who serve them. Events work best when they're planned with partners: co-hosted dinners, joint booth time, and deal registration links ready before the show. Our list of cybersecurity conferences and events and our guide to generating high-quality leads at partner events cover the calendar and the follow-up.
9. Measure Partner Profitability
Track what each partner type costs and returns: time to first deal, partner-sourced versus influenced pipeline, certification-to-revenue conversion, points-to-revenue correlation, and MDF return. Forrester's research points to aligning "partner investments, benefits, incentives, and support resources with measurable business outcomes," and you can't do that if partner data lives in spreadsheets.
Where Programs Break
In our experience, programs rarely fail at the design stage. They fail in operations, once partner count grows and onboarding, training, points, deal registration, MDF, and reporting live in five different tools. Partners log into a portal once, can't find what they need, and go back to email.
That's the operational layer a partner relationship management (PRM) platform is meant to hold. As one example, Dune Security connected its PRM to Salesforce and automated onboarding and partner education, cutting partner onboarding time by about 50%, according to its case study. If you're assessing options, our Top 15 PRMs for Cybersecurity and Security Access (2026) compares the field on use cases, ease of implementation, pricing, and support for capabilities such as multi-tier distribution, deal registration, partner certification, and CRM integration.
Final Thoughts
The traditional partner program was built for a channel that sold products. The cybersecurity channel now sells outcomes, mostly as services, through partners who work across dozens of vendors and increasingly through AI assistants. Coffee chains figured out years ago that the most loyal customers are the ones rewarded for the right habits, not just the biggest spend. B2B partner programs are finally catching up. With two-thirds of B2B organisations already redesigning their programs, the vendors that personalise the journey, reward the right behaviours, and meet partners where they already work will be the ones partners choose to lead with.
Reach out for a personalised consultation on how to design your future cybersecurity partner program.






