CASE FILE // PC-2026-04
Status: Open


Filing 05.02.00Field 27 APR 2026Classification PublicStatus Open

Proofpoint Security Awareness Training cost: $25 to $70 per user per year

PSAT is the Wombat-lineage awareness-training platform that Proofpoint acquired in 2018 and rebranded. Pricing is highly dependent on whether the buyer is bundling with Proofpoint TAP. All figures estimated from public RFP awards, reseller listings, and renewal-quote averages as of 2026.

Exhibit A

The PSAT pricing structure


Proofpoint Security Awareness Training (PSAT) pricing in 2026 sits in an estimated band of $25 to $70 per user per year, with the actual quoted figure depending heavily on three variables. First, the standalone-versus-bundle status: PSAT purchased alongside Proofpoint TAP through the Aegis bundle typically yields per-user pricing 15 to 25 percent below standalone purchase. Second, the user-count volume: PSAT, like other enterprise-software platforms, applies discount tiers at typical breakpoints of 1,000, 5,000, and 25,000 users. Third, the feature tier and add-on mix: the base tier covers awareness training and phishing simulation; higher tiers add adaptive content delivery, granular risk-scoring, and behavioural-analytics features.

The pricing estimates on this page are triangulated from three public-record sources: federal and state government contract awards published on USASpending.gov and GovSpend, reseller catalogue listings from CDW, SHI, and SoftwareONE, and renewal-quote averages reported through buyer-community sources. Proofpoint, like most enterprise-software vendors, does not publish a uniform list price. The bands are best treated as planning estimates rather than firm quotes; actual pricing for a specific organisation can vary by 20 to 40 percent depending on negotiation outcome.[USASpending + GovSpend Proofpoint PSAT contract records 2022-2025 + reseller catalogues + buyer-community pricing threads]

Exhibit B

The Aegis bundle and the standalone-PSAT decision


The most consequential PSAT pricing decision for most buyers is whether to purchase the platform standalone or as part of the Proofpoint Aegis bundle that combines PSAT with Proofpoint TAP (URL and attachment sandboxing email security), Proofpoint Sigma (information protection), and additional platform components. For existing Proofpoint email-security customers, the Aegis bundle is typically the better commercial choice because the bundle discount on PSAT is meaningful and the contract negotiation overhead is lower when consolidating products with a single vendor.

For organisations not currently on Proofpoint email security, the decision is more nuanced. The Aegis bundle commits the buyer to Proofpoint's broader email-security architecture, which is a multi-year procurement commitment that may not align with the buyer's preferred architecture. The bundle also typically requires a 3 or 5-year term to access the full discount, which raises optionality concerns if the buyer's environment is evolving. Independent buyers should compare standalone PSAT pricing against KnowBe4, Hoxhunt, and Cofense for the awareness-training function, and separately evaluate the email-security function against alternatives including Microsoft Defender for Office 365, Abnormal Security, and IRONSCALES.

The 2024-2025 pricing trend has seen Proofpoint tighten the bundle discount versus standalone (i.e. making the bundle relatively more attractive) as a response to competitive pressure from Microsoft Defender for Office 365 Plan 2, which now ships with comparable email-security capability included in the Microsoft 365 E5 SKU. The defensive bundle pricing has stabilised the standalone PSAT pricing band but has compressed margins on the bundle relative to historical norms.[Proofpoint product literature + competitive analysis 2024-2025 + buyer-side procurement reports]

Exhibit C

Worked examples by organisation profile


Organisation profilePurchase modePer-user costAnnual total
500-employee mid-market, existing TAP customerAegis bundle$32$16,000
500-employee mid-market, independent buyerStandalone$45$22,500
2,000-employee mid-market, existing TAPAegis bundle$30$60,000
10,000-employee enterprise, Aegis bundleBundle + volume$25$250,000
50,000-employee Fortune 500, Aegis bundleBundle + deep volume$22$1,100,000

Examples assume midpoint negotiation outcomes. Bundle discounts versus standalone are most pronounced for the mid-market segment because the standalone alternative pricing is competitive there; at deep enterprise volumes the bundle premium narrows because Proofpoint negotiates aggressively against Microsoft and Abnormal on volume deals.[Triangulated from USASpending Proofpoint awards + reseller catalogues]

Exhibit D

The Wombat behavioural-science lineage


PSAT is unusual among phishing-training platforms in carrying a documented academic-research lineage. Wombat Security was founded in 2008 as a Carnegie Mellon University spin-off based on research by Lorrie Cranor's CUPS lab (CyLab Usable Privacy and Security Laboratory) into anti-phishing behavioural training. The original Wombat product set, PhishGuru, was developed and validated through peer-reviewed CHI and SOUPS-conference research that demonstrated measurable behavioural change in user populations exposed to embedded-training experiences. Proofpoint acquired Wombat in 2018 for approximately $225M and integrated the platform as PSAT while retaining the underlying behavioural-science approach.

The practical implication of the lineage is that PSAT places relatively more emphasis on behavioural-change methodology than competing platforms. Embedded-training experiences (where a simulated phishing email leads, on click, to an immediate training intervention rather than a deferred training session) are a Wombat-originated technique that PSAT continues to emphasise. Behavioural risk-scoring at the per-user level draws on the same academic-research foundation. Buyers evaluating PSAT should test whether the embedded-training and risk-scoring features are properly enabled in the trial deployment because the platform's strongest distinguishing capability is in those features rather than in the content-library breadth where KnowBe4 leads.[Wombat Security academic record (PhishGuru, CHI / SOUPS publications) + Proofpoint acquisition announcement 2018]

Exhibit E

ROI math: training cost vs phishing event cost


The ROI calculation for PSAT mirrors the calculation for KnowBe4 (see /training/knowbe4-cost) because the click-rate-reduction expectations are similar across the major awareness-training platforms. Proofpoint's annually-published State of the Phish report tracks click-rate-reduction outcomes across PSAT customers and shows results consistent with the 50 to 70 percent reduction over 24 months that other vendors report. The per-platform variance in outcomes is smaller than the variance attributable to program-management quality on the buyer side.

For a 2,000-employee mid-market organisation paying $30 per user per year through the Aegis bundle, the annual PSAT cost is $60,000. Against the modelled $4.20M average mid-market breach cost (see /by-scale/mid-market), even a 5 percent reduction in event-probability-weighted cost pays back the program multiple times over. The same caveats that apply to KnowBe4 apply to PSAT: training is effective against bulk-phishing simulation but materially less effective against AI-grade spear phishing or AitM attacks, where the failure mode is not lure-recognition. The honest framing is that PSAT (and any awareness-training platform) is a necessary layer in a phishing-defence program but not a sufficient one.[Proofpoint State of the Phish Report 2024 + IBM 2025 mid-market cohort]

Exhibit F

What buyers should ask before signing the PSAT contract


Is Aegis bundle pricing or standalone pricing more attractive?

If you are an existing Proofpoint TAP customer, the bundle is typically more attractive. If you are independent, get both quotes and compare against KnowBe4 and Hoxhunt standalone alternatives.

What is the multi-year-term discount?

3-year and 5-year commitments yield meaningful discount versus annual. Compare against the optionality cost of being locked in for the term, particularly if your email-security architecture is in flux.

Are embedded-training and risk-scoring fully enabled?

These are PSAT's distinguishing features versus KnowBe4. Confirm in the trial deployment that both are configured and producing the expected outputs, otherwise you are paying for capabilities you are not using.

What is the renewal-price cap?

Proofpoint contracts can auto-renew at prevailing list price (which is typically higher than initial negotiated pricing). Negotiate a cap on renewal price increases.

What is the integration posture with the rest of the Proofpoint stack?

If you are buying Aegis, confirm which platform components are included (TAP, PSAT, Sigma, others) and what the future-product-add pricing looks like. The bundle is most valuable when you intend to use multiple components.

What does the customer-success engagement include?

PSAT customer-success motion historically includes program-management support, content recommendation, and quarterly performance review. Confirm the level of engagement included at the offered tier.

Exhibit G

Frequently filed questions

ON RECORD

How much does Proofpoint Security Awareness Training cost?[open]

Estimated $25-$70 per user per year. Standalone mid-market typically $35-$50; Aegis bundle with TAP typically $25-$40 at equivalent volumes.

What is PSAT?[open]

Proofpoint Security Awareness Training, formerly Wombat Security. Acquired by Proofpoint in 2018 for approximately $225M and rebranded as PSAT.

Should I buy PSAT standalone or as part of Aegis?[open]

If you are an existing Proofpoint TAP customer, Aegis bundle pricing is typically more attractive. If you are independent, evaluate both PSAT standalone and the KnowBe4 / Hoxhunt alternatives.

How does PSAT compare to KnowBe4?[open]

Similar price band at equivalent functional tiers. PSAT emphasises behavioural-change methodology and embedded training; KnowBe4 emphasises content-library breadth. KnowBe4's lowest tier is below PSAT's entry; KnowBe4's highest tier is similar to PSAT standalone enterprise.

Is PSAT effective?[open]

Yes. Click-rate reduction outcomes are consistent with the industry benchmark of 50-70% over 24 months. The Wombat behavioural-science lineage gives PSAT distinguishing capability in embedded training and per-user risk-scoring.

What is the Wombat lineage?[open]

Wombat Security was a Carnegie Mellon spin-off founded 2008 based on academic research into anti-phishing behavioural training. Proofpoint acquired in 2018. The PSAT platform retains the underlying behavioural-science approach.

What should I negotiate?[open]

Bundle vs standalone pricing, multi-year-term discount, renewal-price cap, customer-success engagement level, embedded-training and risk-scoring enablement.

Updated 2026-04-27