Heimdal
article featured image

Contents:

Which patch platform can you run across every client, prove to an auditor, and still make margin on?

This piece covers what has actually changed in the category, where the leading products genuinely differ, and verified pricing and honest trade-offs for the five best patch management software platforms MSPs shortlist most often.

There is also a shorter list of products a complete shortlist would include. Every price and capability figure below was checked against the vendor’s own published pages in August 2026.

The bottom line

  • Heimdal Patch & Asset Management. Our top pick, and the platform we rate best-in-class for patch specifically. Sub-four-hour vendor-to-endpoint delivery, multi-tenancy architected in rather than bolted on, and compliance-framework-aligned reporting, built as a module of a unified security platform for security-led MSPs and MSSPs consolidating several controls onto one agent, in cloud-capable environments.
  • NinjaOne. For MSPs consolidating onto one RMM, where patching should live in the same console as monitoring, scripting, and ticketing.
  • Action1. For small and mid-size MSPs who want a dedicated patch tool alongside an existing RMM, and for anyone who wants to run a real pilot without involving procurement.
  • Automox. For MSPs with genuinely mixed fleets, especially meaningful Linux populations, who want patching plus scripted remediation without adopting a full RMM.
  • ManageEngine Patch Manager Plus. For cost-constrained buyers and estates that must run on-premises, with the caveat that true multi-tenancy lives in a different ManageEngine product.

A disclosure, before you read any further

We publish this blog, and Heimdal Patch & Asset Management is one of the five products reviewed below. So here is how we have handled that.

We’ve ranked ourselves first in the summary above, because we believe our combination of delivery speed, compliance-aligned reporting, and platform consolidation makes us the strongest overall pick for security-led MSPs. The detailed profiles below stay grouped by product architecture rather than reordered best to worst, because architecture is the decision that actually matters once you get past the summary above.

We have listed our own verified limitations next to everyone else’s, including the one that will rule us out for some of you. Every competitor figure comes from that vendor’s own published pages, with the retrieval month stated, not from our sales material. Check them yourself before you buy anything.

What changed in MSP patching, and what is now outdated thinking

MSP patch management isn’t really its own software category. It is a delivery-model constraint applied to two adjacent categories, patch management and RMM. You don’t own the endpoints. You patch on behalf of clients who pay for an outcome, under an SLA, at a per-endpoint cost that has to leave margin.

That one fact drives nearly every requirement that separates MSP patching from enterprise patching. Multi-tenancy, cross-tenant reporting, per-tenant policy inheritance, co-managed role separation, client-facing evidence, and price elasticity at scale.

The exposure window moved faster than remediation did

Verizon’s 2025 Data Breach Investigations Report found that only around 54% of edge-device vulnerabilities were fully remediated during the year studied, and that full remediation took a median of 32 days. For an MSP with a contractual patching commitment, that is the shape of the problem. Not a failure to try, but a remediation pipeline that runs slower than the exposure it is meant to close.

Mandiant’s M-Trends 2026 puts mean time-to-exploit at an estimated minus seven days, meaning that across the incidents studied, exploitation activity on average began before a vendor patch was publicly available. The two figures measure different things and shouldn’t be subtracted from one another. Read together they support one directional conclusion that matters commercially.

Deployment speed alone can’t close the window.

That is why the category has been converging with vulnerability management, and why prioritization anchored to known-exploited-vulnerability data has become an organizing principle rather than a best-practice slide.

Microsoft now covers the easy part

Windows Autopatch and Intune have changed the terrain. For a client that is Entra-joined, licensed at Microsoft 365 E3 or E5, and predominantly Windows, Microsoft’s own stack, built on Windows Update for Business, handles a substantial share of OS and Office patching with ring-based rollout and safeguard holds.

This doesn’t remove the need for MSP patch tooling. It relocates where the value sits. As of mid-2026, Autopatch and Intune are tenant-scoped, and Microsoft provides no native cross-tenant patch SLA view for service providers. Third-party application patching is materially narrower than dedicated catalogs, macOS and Linux coverage is limited or absent, and servers, hypervisors, network appliances, and OT sit outside the model entirely.

The E3 and E5 licensing prerequisite rules out a large share of SMB clients too.

Baseline Windows OS patching is commoditizing. Differentiation has moved to third-party catalog depth, cross-tenant evidence, non-Windows coverage, and workflow control.

Four beliefs worth retiring

“Patch management and vulnerability management are the same thing.” They are distinct disciplines and, in some cases, distinct products at different prices. ManageEngine sells Patch Manager Plus and Vulnerability Manager Plus separately, and the confusion between them is common enough that the older version of this article made the same mistake. Vulnerability management identifies and prioritizes risk. Patch management executes one class of remediation. Some vulnerabilities have no patch at all.

“A green compliance dashboard means the estate is patched.” Dashboard state diverging from endpoint reality is the single most persistent theme in MSP practitioner discussion. Offline devices, failed prerequisites, agent faults, and locally deferred updates all produce green squares over unpatched machines.

“More apps in the catalog is strictly better.” Catalog counts are vendor-defined, unaudited, and count titles differently. No published methodology exists for any of them. They are marketing figures, not benchmarks. What matters is whether your clients’ actual top applications are covered and how quickly packages appear after vendor release.

“Patching within 30 days is adequate.” CISA’s Binding Operational Directive 26-04, which replaced the old flat 14-day rule in June 2026, now requires US federal civilian agencies to remediate known-exploited vulnerabilities on a risk-based schedule of 3, 14, or 60 days depending on exposure and exploit automation. The UK’s Cyber Essentials scheme requires high-risk security updates within 14 days of release. Neither binds a private MSP directly. Both increasingly set the expectation that arrives through client contracts and insurance questionnaires, and the new tiered federal model only tightens that expectation for the highest-risk vulnerabilities.

Where traditional approaches fall short for MSPs

Agent Fatigue. This is the cost that spreadsheets miss. On the technical side, every additional privileged agent on a host is another kernel-level or SYSTEM-level process, and published detection guidance increasingly treats a stack of privileged agents as a risk indicator in its own right rather than a neutral fact.

On the human side, every agent is another console to check, another update cycle to track, another alert stream to triage, and another vendor to chase when something breaks. That load compounds faster than headcount does. An MSP carrying RMM, EDR, backup, DNS filtering, email security, and a standalone patch tool is running six operational surfaces to deliver one service.

The trust deficit in execution. Practitioners consistently report tools declaring success that the endpoint doesn’t reflect. The consequence is that many experienced MSPs re-verify with a second source, which means paying twice for one answer. Any product that can’t explain why a specific endpoint failed, at the endpoint level, gets treated with suspicion for good reason.

Reboot and maintenance-window control. For clients running production systems, uncontrolled reboots are the largest single source of patching escalations. You need separate patch management policies for servers versus workstations and production versus non-production, plus separation of security updates from feature updates with independent reboot behavior. Some clients carry five or six-figure hourly downtime costs. For those, “patch and reboot when needed” is unusable.

Catalog gaps that recreate the sprawl you bought the tool to remove. Windows and Office coverage is table stakes, and so is mainstream third-party software coverage. The gap is line-of-business and long-tail applications. Where the catalog doesn’t reach, MSPs supplement with scripting, Chocolatey, winget, Ninite or Intune, and the stack grows again. The ability to push an arbitrary installer through the same policy engine matters more than the headline count.

Onboarding cost per tenant. Every new client needs policy setup, agent deployment, exception discovery, and baseline remediation. Policy templating, tenant cloning, and centralized policy management cut that materially. Per-tenant configuration from scratch doesn’t scale past a certain client count, and you find out where that count is the hard way.

Blast radius. A bad update deployed at scale across many tenants is an MSP-level incident, not a client-level one. Rings, pilot groups, approval gates, delay windows, and rollback are the patch deployment controls that address it. Support for them is inconsistent across this market.

Where we fit, and how you can buy us

We are a security company that patches, not a service-delivery platform that added patching. That starting point shows up in what we built first and in who we suit.

Every Heimdal module can be bought three ways. As a standalone product on its own. As part of our unified security platform. Or delivered as a managed service through MDR, MXDR or Managed ITDR, for teams who would rather have the SOC run for them than staff one.

Standalone means any module, not one module. Each of these can be licensed on its own.

Buy the one that closes your actual gap, not the whole platform.

Patch & Asset Management is the easiest to picture concretely, so here is that example. If you already run a UEM or systems management tool you intend to keep, and your real gap is third-party patching, patch reporting, and asset visibility, you can buy Patch & Asset Management on its own and run it alongside what you have. It doesn’t replace your existing tool.

The model scales up or down into exactly what you need, all the way to the full platform if you want it, and it isn’t an all-or-nothing choice.

The unified platform, if you go that way. One agent. One console. One contract.

  • DNS Security across network and endpoint
  • Patch & Asset Management, plus Infinity Management for custom software
  • Next-Gen Antivirus, Firewall, and Ransomware Encryption Protection
  • PEDM, PASM, and Application Control with AppFencing
  • Email Security 365, and Advanced Threat Protection with Fraud Prevention
  • Threat-hunting and Action Center, covering estate and M365 user monitoring
  • Remote Desktop, BitLocker Management, Scripting, PXE Deployment, and USB Management

The point for an MSP is arithmetic. Each module you consolidate is one fewer agent on the host, one fewer console in the rotation, and one fewer line on the per-endpoint cost sheet.

On RMM, the honest version. We didn’t start as an RMM vendor and we aren’t built around that starting point. A meaningful number of our MSP customers do run us as their RMM day to day, and we keep building capability that makes that switch easier for others weighing it up. If you want patching to sit inside your service-delivery console next to monitoring and ticketing, either check whether that group’s setup fits yours, or run us alongside your RMM and use the PSA integrations.

Autotask and the other featured RMM and PSA integrations exist so patch failures become tracked work rather than dashboard noise.

Practical buyer guidance

Do you actually need a dedicated patch tool

You probably don’t need dedicated patch automation if your RMM’s patching already produces per-endpoint, per-patch, per-date evidence your clients’ auditors accept, your third-party catalog covers your clients’ real application list, and your failure reporting tells you why something failed rather than just that it did.

You probably do if any of the following is true. Your third-party coverage stops at browsers and runtimes, or you’re reconciling patch status against tickets by hand. You have clients under Cyber Essentials, NIS2, CIS Controls, or an insurance questionnaire with a patch-timeliness clause. Or you’ve caught your dashboard being wrong more than once.

Signals to watch for during evaluation

  • Failure diagnostics beat status reporting. Ask to see what the product shows for an endpoint that failed a patch, not for one that succeeded.
  • Ask which tier multi-tenancy sits in. On at least one product in this list it is gated to the top tier, which changes your cost model entirely.
  • Check the catalog against your client list, not against a number. Send the vendor your twenty most-installed non-Microsoft applications and ask which are covered and how fast packages land after vendor release.
  • Non-Windows parity needs a separate check. Plenty of products patch macOS and Linux operating systems without matching third-party application coverage on those platforms. Parity is rarer than headline claims suggest.
  • Look for a custom-app escape hatch. Scripted deployment through the same policy engine is what stops catalog gaps turning into a second tool.

What MSPs consistently underestimate

Technician licensing. At least one product in this comparison licenses technicians separately from endpoints, which is easy to miss on a pricing page and materially changes cost at scale.

Onboarding cost per tenant. If policy templating and tenant cloning are absent, the tool’s per-endpoint price isn’t its real price.

Co-managed engagements. Where a client keeps internal IT and you supplement, you need role-based access scoped to a single tenant, delegated patch approval, client-visible maintenance-window control, and an audit trail of who approved or deferred what. This is under-served across the whole market and almost entirely absent from published vendor comparisons, including the previous version of this one. Test it specifically. Assume nothing.

What patch tooling won’t fix

Edge and network devices. Firewalls, VPN concentrators, switches, file-transfer platforms, and remote-access gateways feature heavily in mass-exploitation events and sit largely outside endpoint patch tooling. This is a structural gap in the entire category, not a gap in one product. Plan a separate process for it.

Independent verification. Nearly every product in this market self-reports through its own agent. Genuinely independent validation still requires a separate scanner.

Software vulnerabilities with no available patch. Some exposures are closed by configuration change, compensating control or removal, not by an update. If a product’s reporting can’t represent that, your compliance evidence will have holes in it.

Cross-tool SLA reporting. If you run a mixed stack or more than one RMM, no product here will give you one clean patch SLA view across all of it.

How to run a proof of concept that tells you something

  1. Pick two to four representative tenants, and make one of them deliberately awkward. Mixed OS, restrictive maintenance windows, or a client with a line-of-business application nobody has heard of.
  2. Break things on purpose. Take endpoints offline during a window. Block a prerequisite. Then check whether reporting reflects reality or reports success anyway.
  3. Export a real report and ask whether you could put it in front of that client’s auditor without editing it.
  4. Time a full tenant onboarding, start to finish. Multiply by your client count. That is your true switching cost.
  5. Test delegated approval if you run co-managed accounts.
  6. Negotiate on term length, ramp, and the ability to add or remove endpoints monthly, before you negotiate on rate.

The five best patch management software platforms, compared

Grouped by architecture, because that is the fork that determines everything downstream. Pricing and capability figures retrieved from vendor pages in August 2026, and this market reprices often enough that you should re-check before you commit.

Heimdal Patch & Asset Management, the security-suite module

What it is. Patching delivered as a module of our unified security platform, available on its own or as part of the platform, and available as a managed service. Every other module in our line-up is equally available standalone, so this is a starting point rather than a package you have to take whole.

Best for. Security-led MSPs and MSSPs, particularly in the UK and Europe, consolidating several controls onto one agent and needing compliance-framework-aligned evidence for regulated clients, in cloud-capable environments.

Why we call this best-in-class for patch specifically. Patching here isn’t a bolt-on to an RMM or a separately maintained module. Sub-four-hour vendor-to-endpoint delivery, every update tested, sanitized, and repackaged in our own sandbox before distribution, and multi-tenancy architected in from the start rather than layered on afterward, are what earn that claim, on top of the platform consolidation benefits above.

What we deliver. As of August 2026, we patch Windows, macOS, and Linux, with Ubuntu the named Linux distribution and further coverage beyond it. We monitor and patch over 350 third-party applications and drivers. Every patch, update, rollup, hotfix, and security pack is tested, sanitized, and repackaged in our sandbox before it goes to our cloud for distribution, and we deliver vendor-to-endpoint in under four hours. Deployment runs through our own CDN, so there are no additional servers to stand up per tenant.

The Infinity Management add-on handles the catalog-gap problem directly. It lets you automate patching for proprietary or in-house software using command-line scripting inside the same console and the same policy engine, with encrypted packages, so “not in the catalog” becomes a scripting task rather than a second tool. It is documented for Windows and Linux.

On evidence, our audit trail covers CVE and CVSS tracking, patch history, and system changes, with software inventory giving asset, version, and volume visibility. Reporting is aligned to NIS2, Cyber Essentials, CIS Controls, NIST, ISO 27001, DORA, and GDPR. Those are alignments we have built the reporting around, not third-party certifications of the patching module, and you should read them that way.

Multi-tenancy is architected in rather than added on, with isolated policies, reports, endpoint views per tenant, and granular role-based controls. Scheduling is configurable per group and per priority, with rollback available.

Two things on AI, kept separate deliberately. Predictive DNS and AI-powered email fraud prevention are live in the platform today and predate anything branded. The first uses AI and ML analysis to identify malicious destinations before a threat fully materializes. The second uses outlier detection to catch impersonation, CEO fraud, and out-of-character sending behavior.

Separately, AI Wingman is a cross-platform intelligence layer we are building on top of the platform, arriving in phases.

  • AI Wingman Assist gives guidance inside the dashboard.
  • AI Wingman Triage uses multi-agent systems to validate incidents and is included with the Threat-hunting and Action Center.
  • AI Wingman SOC brings the same acceleration into our managed SOC and is included with TAC plus MXDR.

On third-party validation. We were named in the Gartner Europe Context Magic Quadrant for Endpoint Protection in May 2026, and listed as a representative vendor in Gartner’s Market Overview for Workspace Cybersecurity Platforms in August 2026, alongside Microsoft, CrowdStrike, and Sophos. A Market Overview is a different research format from a Magic Quadrant and isn’t a leader ranking, so treat it as what it is. We are also in an analyst relationship with Forrester with a report expected shortly.

Our MITRE ATT&CK coverage is publicly mapped on the Tidal Cyber Registry. Search for Heimdal and you can see exactly which attack techniques and sub-techniques we detect and stop, down to the sub-technique level. We haven’t paid to participate in the MITRE Engenuity Evaluations, which are a vendor-funded program. Our coverage is transparent and independently verifiable at any time. Pull the mapping into your PoC scorecard and compare it directly against every other product on this page.

Trade-offs, including the one that will rule us out for some of you. We are cloud-only, so cloud patch management is the only deployment model on offer here. We don’t support on-premises or hybrid deployments, and for clients with isolated, air-gapped or regulator-mandated on-premises estates, that is disqualifying. Go to ManageEngine or PDQ for those.

Our 350-plus catalog is smaller than several competitors’ published figures. Infinity Management extends coverage, but realizing that extension takes MSP effort, and Infinity Management is documented for Windows and Linux rather than all three platforms.

Our named Linux coverage is narrower than what some competitors publish, so check your distributions against ours. Our review volume on the major software marketplaces is lower than NinjaOne’s or Action1’s, which gives you less independent signal to work with, and we would rather say that than hope you don’t notice.

We also didn’t start as an RMM. Some of our MSP customers run us as one, and we keep building toward making that easier, but if you want patching inside a mature service-delivery console today, plan to run us alongside your RMM and use the PSA integrations.

Pricing. Per device, per year. Enter your modules and endpoint count into our pricing calculator and you get an estimate on the page and by email, without waiting for a sales call. MSPs, MSSPs, distributors, and resellers can also buy through our Partner NEXUS program.

NinjaOne, the RMM-embedded option

What it is. A full multi-tenant RMM with patching as a first-class module rather than a bolt-on.

Best for. MSPs consolidating onto a single platform, Windows and macOS-heavy, who want patching in the same console as monitoring, scripting, and ticketing.

Capability, as published by the vendor. Windows, macOS, and Linux patching. Third-party application patching, with NinjaOne’s MSP materials citing 6,000-plus third-party applications, the largest published figure in this set. Built-in multi-tenancy with per-customer policies, scripts, and alerting. Multi-tenant MDM, integrated ticketing, and documentation.

Strengths. The strongest multi-tenant design in this comparison, with patching, monitoring, remote access, and reporting sharing one tenant model. Consistently high ratings on major review platforms with review volume large enough to be meaningful. It reduces tool sprawl more effectively than any standalone product can, by definition.

Trade-offs. Some MSPs in regulated environments have reported wanting more granular per-endpoint, per-patch reporting than the standard reports provide. If you serve audited clients, test report output specifically rather than assuming it. Total cost climbs once add-ons such as backup, MDM, and documentation are enabled, and the published range covers the core platform only. Buying NinjaOne for patching alone is poor value. This is an MSP platform decision.

Pricing. NinjaOne publishes a range rather than a price list. As low as $1.50 per device per month at 10,000 endpoints, up to $3.75 per device per month at 50 or fewer endpoints, with the vendor’s own caveats that pricing varies by region and product mix and that the range covers the commercial, non-FedRAMP instance. Monthly or annual billing. No free tier, and a 14-day trial instead. Onboarding, implementation, and support are stated as included at no charge.

NinjaOne explains that it declines to publish a full price list because it sells through the channel.

Action1, the patch-first cloud option

What it is. A cloud-native, patch-first platform with the most aggressive free tier in the category.

Best for. Small and mid-size MSPs running a dedicated patch management tool alongside an existing RMM, and any MSP who wants a genuine pilot without a procurement conversation.

Capability, as published by the vendor. Windows, macOS, and Linux patching, with documentation listing specific DEB and RPM-based distributions. Third-party application patching, software deployment, remote access, and vulnerability assessment. Multi-tenancy for MSPs is documented through separate organizations with secure data separation, and the license quota is pooled at account level rather than per organization.

Strengths. The free tier removes evaluation risk entirely and is the most effective acquisition mechanism in this market. Very high ratings with high review volume on major marketplaces, which is among the strongest independent signal in this set as of August 2026. Multi-tenancy is explicitly documented rather than implied. Ease of setup is the most consistently repeated positive theme in reviews.

Trade-offs. Not an RMM, and PSA and ITSM integration depth is lighter than the platform vendors’, so patch status has to be reconciled with ticketing separately. No third-party catalog count is published, so coverage can’t be compared numerically and you will need to check your own application list directly.

Pricing above the free tier is opaque, which sits oddly against the transparency of the free tier itself. The product was historically Windows-first. Non-Windows capability has expanded considerably and current documentation lists broad Linux support, but if you have mature macOS or Linux fleets, verify feature parity rather than assuming it.

Pricing. The first 200 endpoints are free forever with no feature limitations, and Action1 states explicitly that this isn’t a trial. Community support is included at that tier. Above 200 endpoints, pricing is quote-based and not published. No per-endpoint rate, currency or billing period appears on the pricing page.

Third-party sources cite low single-digit per-endpoint monthly figures, but those aren’t vendor-published and shouldn’t be relied on.

Automox, the patch plus automation cloud option

What it is. Cloud-native cross-platform patch and configuration automation, with the broadest published OS coverage in this set.

Best for. MSPs and lean IT teams running genuinely diverse client environments, particularly meaningful Linux populations, who want patching plus scripted remediation without adopting a full RMM.

Capability, as published by the vendor. Windows, macOS, and Linux across workstations and servers. 630-plus third-party patching titles, available from the Automate Essentials tier upward, and 432-plus Worklet automation scripts at Automate Enterprise. The supported-OS documentation lists an unusually broad set of Linux distributions with ARM64 support on several. Multi-organization management is an Automate Enterprise feature. Remote access is a paid add-on limited to Windows and macOS.

Strengths. The best Linux and ARM64 breadth in this set, which is genuinely differentiating if you serve developer, hosting or mixed-fleet clients. Worklets extend the product from patch tool to general endpoint automation and address catalog gaps directly. The policy-driven model is clean and scales well. Published catalog counts, Worklet counts, and an entry price are more transparency than several competitors offer.

Trade-offs. The $1 headline price is OS-only. Third-party patching, which is the capability most MSPs are actually buying, sits in a custom-priced tier, so effective cost can’t be modeled from published information. Multi-organization management is gated to the top tier, which matters directly for MSP economics. Tenant isolation granularity, RBAC depth, and per-tenant billing aren’t detailed publicly and should be validated in a proof of concept.

Cloud-native architecture is a weaker fit for estates with significant isolated or air-gapped assets. Some reviewers have noted gaps in peripheral areas relative to more traditional tools.

Pricing. Three published tiers. Patch OS at $1 per endpoint per month with annual commitment, covering OS patching only. Automate Essentials at custom pricing, adding the 630-plus third-party catalog, software deployment, advanced automation policies, device configuration, and API access. Automate Enterprise at custom pricing, adding Worklets, immediate execution, multi-organization management, and remote control.

Monthly billing with no commitment is available, and annual billing is discounted 25%. Volume discounting applies from 200 device licenses. No perpetual free edition, trial only.

ManageEngine Patch Manager Plus, the dedicated tool with published prices

What it is. A dedicated patch management product, available on-premises or in the cloud. It is a different product from ManageEngine Vulnerability Manager Plus, which is a vulnerability management product that includes patching alongside scanning, security configuration management, high-risk software audit, and compliance benchmarks. The previous version of this article conflated the two. If you are comparing prices between them, note that the band bases differ, so the two price lists aren’t directly comparable.

Best for. Cost-constrained buyers, on-premises-mandated environments, and internal IT teams more than true multi-tenant MSPs, unless you move to ManageEngine’s Endpoint Central.

Capability. Deep reporting and configuration options across Windows, macOS, and Linux, with patch decline, test, and approve workflows. Vulnerability Manager Plus additionally publishes driver and BIOS updates, antivirus definition updates, roaming user support, and CIS, UK Cyber Essentials, and NIST benchmark compliance. Network device management requires additional licensing and is on-premises only.

Strengths. Fully published, banded pricing. It is the only product in this comparison where you can model cost without a sales conversation, which is a real advantage when you are pricing a new client contract. Among the lowest effective per-endpoint costs at most volumes. The only genuine on-premises option here, which matters for estates that can’t use a cloud console.

Trade-offs. MSP multi-tenancy is presented primarily through ManageEngine’s Endpoint Central, its broader unified endpoint management platform, not Patch Manager Plus, which is documented and licensed as a single-organization product with technician-count licensing. In practice this leads some MSPs to run separate instances per client, and that operational cost erodes much of the price advantage at scale.

Configuration complexity is a recurring review theme, with first-time setup commonly described as requiring real patch management expertise. The product-line distinction between Patch Manager Plus, Vulnerability Manager Plus, and Endpoint Central is itself an obstacle when buying.

Pricing, Patch Manager Plus, Professional, annual.

ManageEngine Patch Manager Plus pricing — Professional, annual (retrieved August 2026)
Computers On-premises Cloud (monthly) Cloud (annual)
50 $245 $34.50 $345
250 $895 $119.50 $1,195
1,000 $2,795 $379.50 $3,795
10,000 $13,495 $1,819.50 $18,195

Servers are licensed separately from workstations. Each band includes one technician, and additional technicians are licensed separately from $195 per year on-premises or $19.50 per month on cloud. An Enterprise edition is priced above Professional. A free trial is offered, and no free-edition endpoint limit is published on the pricing page.

Pricing, Vulnerability Manager Plus, annual, for 100 workstations and a single technician. Professional at $695 on-premises or $895 cloud. Enterprise at $1,195 on-premises or $1,545 cloud. A Free edition is listed at $0.00 without a published workstation cap.

Side by side

Catalog counts below are vendor-stated, unaudited, and not measured comparably. Pricing retrieved August 2026.

MSP patch management software compared, 2026. Catalog counts below are vendor-stated, unaudited, and not measured comparably. Pricing retrieved August 2026.
NinjaOne Action1 Automox Heimdal ManageEngine PMP
Product class RMM platform Patch-first cloud Patch + automation cloud Security suite module Dedicated patch tool
OS coverage Windows, macOS, Linux Windows, macOS, Linux Windows, macOS, broadest published Linux Windows, macOS, Linux (Ubuntu named) Windows, macOS, Linux
Stated 3rd-party catalog 6,000+ apps Not published 630+ titles (Essentials and up) 350+ apps and drivers Not published as a count
MSP multi-tenancy Yes, strongest in set Yes, documented Enterprise tier only Yes, vendor-documented Via Endpoint Central
On-premises option No No No No Yes
Pricing transparency Range published Free tier only, paid quoted Entry tier only, higher tiers quoted Self-serve calculator Full price list
Free entry tier No, 14-day trial Yes, 200 endpoints No, trial only No No, trial only
Custom app patching Scripting Software deployment Worklets Infinity Management add-on Yes

Others a complete shortlist would include

Five products is a defensible comparison, not a complete market. These come up constantly in real MSP evaluations and belong on your longlist.

  • Atera. RMM plus PSA with per-technician, unlimited-endpoint pricing. Directly relevant if per-endpoint economics are your constraint. Lighter patching depth and third-party coverage is the trade.
  • Datto RMM (Kaseya). Large MSP installed base, Windows-centric patching, quote-based.
  • N-able N-central and N-sight. N-central for larger MSPs, N-sight for smaller, with long-standing MSP-native multi-tenancy.
  • ConnectWise RMM and Automate. Significant installed base and deep PSA integration.
  • Kaseya VSA. Mid-market MSP RMM with integrated patching and vulnerability scanning.
  • Acronis Cyber Protect Cloud. Backup-first MSP platform with patch management bundled in. Relevant if you want patching and backup from a single vendor relationship.
  • Syncro, SuperOps, and Level. Modern MSP platforms, several on per-technician pricing.
  • PDQ Deploy and Inventory. Windows-only, on-premises, scriptable, with a strong package library and annual per-license pricing. Not multi-tenant, but widely used in Windows-centric shops.

One structural note. Per-technician, unlimited-endpoint pricing is a genuinely different commercial model from per-endpoint pricing and changes MSP unit economics materially. If your endpoint count per technician is high, it can beat everything above on cost. Take current rates from the vendors’ own pricing pages, because they move.

Which patch management software fits your MSP

Which patch management software fits your MSP
If you… Prioritise Look at
Want one platform for everything RMM-embedded patching NinjaOne, Datto RMM, N-able, Atera
Have an RMM whose patching isn’t good enough Standalone patch depth and reporting Action1, Automox, Heimdal, ManageEngine
Sell security as the service Agent consolidation plus compliance evidence Heimdal and other security-suite vendors
Serve regulated or insured clients Evidence quality, exception workflow, CVE mapping Anything with per-endpoint, patch-level reporting, verified in a PoC
Have significant Linux or macOS fleets Cross-OS parity including third-party coverage Automox first, then verify others individually
Are small and price-constrained Free tier or per-technician pricing Action1, Atera, ManageEngine
Must run on-premises On-premises deployment ManageEngine, PDQ
Run co-managed engagements Delegated RBAC and approval workflow Verify individually, because this is weak across the market

If you take one thing from this page, make it the PoC design rather than the shortlist. The products above differ less on whether they can deploy a patch than on whether they can prove they did, explain it when they didn’t, and do both across forty tenants without adding a person to your rota. That is testable in two weeks. Feature matrices aren’t.

Frequently asked questions

What is MSP patch management

Software that automates the patch management process, meaning the detection, approval, scheduled deployment, and verification of OS and third-party application updates, across multiple independently-managed customer estates, with reporting sufficient to evidence compliance to a third party. That last clause carries more weight than it looks like it does. For an MSP, the report is part of the product, because it is how you defend and justify what you are billing for.

Should patching live in my RMM or in a separate tool

This is the primary architectural fork, and there is no universal answer. RMM-embedded patching means one agent, one console, and no reconciliation between patch status and tickets, at the cost of depth in third-party coverage and evidence quality on some platforms. A standalone patch management solution means better depth and usually better reporting, at the cost of another agent and manual reconciliation. A security-suite module is a third answer that consolidates patching with other security controls rather than with service delivery.

A fourth option, managed patch management delivered through a vendor’s own SOC via MDR or MXDR, suits teams who would rather outsource execution entirely than run any tool themselves. Choose based on which sprawl hurts more, service-delivery sprawl or security-agent sprawl.

Is Microsoft Intune and Windows Autopatch enough

For an Entra-joined, E3 or E5-licensed, predominantly Windows client, Microsoft covers a substantial share of OS and Office patching. It doesn’t give you a cross-tenant patch SLA view across your client base, it patches materially fewer third-party applications than a dedicated catalog, its macOS and Linux coverage is limited or absent, and servers, hypervisors, and network appliances sit outside it. The licensing prerequisite also rules out a lot of SMB clients. Most MSPs end up using it for what it is good at and covering the rest elsewhere.

How fast do critical patches actually need to be applied

Neither of the common benchmarks binds a private MSP directly, but both shape what clients ask for. CISA’s BOD 26-04, which superseded the old flat 14-day rule in June 2026, requires US federal civilian agencies to remediate known-exploited vulnerabilities on a risk-based schedule of 3, 14, or 60 days depending on exposure and exploit automation. UK Cyber Essentials requires high-risk security updates within 14 days of release. Fourteen days is still the number that turns up most often in client contracts and insurance questionnaires today, so build your SLA against it, and keep an eye on whether the tighter 3-day federal tier starts showing up in contract language too.

How do I verify a patch tool actually patched something

Don’t take the dashboard’s word for it. During evaluation, take endpoints offline during a maintenance window, block a prerequisite update, and then check what the product reports. A tool that shows the endpoint as compliant despite a missing patch has told you what you needed to know. Beyond that, independent verification generally requires a separate scanner, because nearly every product in this market self-reports through its own agent.

Can patch management software cover firewalls and network devices

Mostly no, and this is a gap in the category rather than in any one product. Endpoint patch tooling covers endpoints. Firewalls, VPN concentrators, switches, file-transfer platforms, and remote-access gateways generally sit outside it, and those are exactly the assets that turn up in mass-exploitation events. Some products offer network device management as a separately licensed, often on-premises-only module. Plan a distinct process for edge devices either way.

What does Heimdal Patch & Asset Management cost

We price per device, per year. Put your modules and endpoint count into our pricing calculator and you get an estimate on the page and by email straight away. You don’t need a sales conversation to get a number you can model against.

What is the difference between ManageEngine Patch Manager Plus and Vulnerability Manager Plus

They are separate products at separate prices. Patch Manager Plus is a dedicated patch tool. Vulnerability Manager Plus is a vulnerability management product that includes patching alongside scanning, security configuration management, high-risk software audit, and compliance benchmarks. If you need risk identification and prioritization as well as remediation, Vulnerability Manager Plus is the closer fit. If you need patching, Patch Manager Plus is cheaper for the same job. Neither is ManageEngine’s MSP multi-tenancy answer, which is Endpoint Central.

*All vendor pricing and capability figures retrieved from vendor sources in August 2026. This market reprices frequently, so re-verify before you commit to anything.*

Author Profile

Head of Content at Heimdal. A journalist by trade who cares about helping MSPs and security teams make better decisions, enjoy their work, and see real results.

CHECK OUR SUITE OF 11 CYBERSECURITY SOLUTIONS

SEE MORE