Home/Broadcom Audit Risk
Compliance guide

Is Broadcom auditing VMware customers?

Yes, and the first letter can be the audit itself. Here is who has been targeted, what an auditor looks for, and how to get your inventory in order before three business days is all the time you have.

Quick answer: Yes. Since mid-2025 Broadcom has sent formal VMware audit letters, mostly to organizations still running perpetual licenses without an active support contract. The letters give three business days to respond and bring in an outside audit firm. Customers on a current subscription are less exposed, but not immune: an audit compares what you run against what you are entitled to, and the per-core rules make gaps easy to create by accident.

This guide covers what has actually been reported, what tends to put an organization on the list, where your real exposure sits, and how to get ready before a letter arrives. It is not legal advice. If you already have a letter in hand, read your own agreement with counsel before you reply.

What Broadcom has actually done

Audit pressure arrived in two steps, a few months apart.

  • Cease-and-desist letters (spring 2025). Organizations running perpetual VMware licenses without active support received letters telling them to remove any updates, patches, and releases issued after their support ended, with an exception only for zero-day security patches. Some arrived within a week of a support contract lapsing, and they warned that VMware may check customers for compliance. Techzine, May 8, 2025.
  • Formal audit letters (June 2025 onward). A letter dated June 20, 2025, reviewed by Ars Technica, told a Netherlands-based VMware user it "has been selected for a formal audit" of its VMware software and support services. The review covered deployment and entitlements, and could include fieldwork, remote testing, and meetings with accounting, licensing, and IT staff. SDxCentral, June 27, 2025. Reporting on the same letter named Connor Consulting as the audit firm and noted the three-business-day response window. It's FOSS, June 27, 2025.
  • No warning required. The company in that report had not received an earlier cease-and-desist letter. The first letter can be the audit itself.

Broadcom has not published audit volumes, and there is no public count of how many letters have gone out. What is clear is the direction: the relationship moved from "renew support if you like" to "prove what you are entitled to run."

What tends to trigger an audit

Nobody outside Broadcom knows its selection method. Based on who has reported receiving letters, these situations carry the most risk:

SituationRiskWhy it gets attention
Perpetual licenses, support lapsed, still runningHighestThis is the group the reported letters went to. Any patch applied after the support end date is a potential finding.
Declined or ignored a renewal quoteHighA quote that goes quiet tells Broadcom exactly who is still running VMware without paying for a subscription.
Renewal missed its anniversary dateMediumDistributor notices reported by The Register describe a 20% surcharge on the first year of a renewed subscription when a renewal lands after the anniversary date. Broadcom did not confirm it to the paper. The Register, March 28, 2025.
Grew hosts or cores since the last orderMediumSubscriptions are counted per physical core, with a 16-core minimum per CPU. New or upgraded hosts can quietly exceed what you bought.
Current subscription, count matches realityLowerAn audit is still possible under the agreement, but there is little for it to find.

Your actual exposure

An audit compares three things: what you deployed, what you are entitled to, and what you did with updates. Most findings come from the gaps between them.

  • Perpetual licenses. A perpetual license still gives you the right to run the version you owned. It does not give you the right to builds, patches, or upgrades released after your support ended. That boundary is exactly what the cease-and-desist letters targeted.
  • Support entitlements. Check the actual end date on every support contract, not the date you think it ended. Patches downloaded or applied after that date are the first thing an auditor will look for.
  • Version rights. Hosts upgraded to a newer major or update release than your entitlement covers are a finding, even if the upgrade happened years ago.
  • Core counts. Subscription licensing counts every physical core, with a 16-core minimum per CPU, and cores switched off in the BIOS still count. Broadcom's core-counting method is in KB 313548. Our subscription licensing explainer walks through the math.
  • Lab, DR, and forgotten hosts. Test clusters, disaster recovery sites, and old hosts that were never decommissioned all show up in an inventory. If it runs ESXi, assume it will be counted.
The one-sentence version: audit risk is the gap between what you run and what you can prove you are entitled to run. Close that gap on your own schedule, not the auditor's.

How to prepare before a letter arrives

Three business days is not enough time to build an inventory from scratch. Do the work now, while it is quiet.

  • Build your own usage inventory. Every host, CPU, physical core count, ESXi and vCenter build, and cluster purpose (production, DR, lab). Export it and date it.
  • Pull your entitlement records. Download your license keys, contracts, and support history from the Broadcom support portal while you still have access. Match every host to an entitlement.
  • Map patches to dates. For any perpetual host without current support, list which builds were applied and when. Know where the line falls before someone else draws it.
  • Retire what you do not need. Decommission idle hosts and shut down forgotten labs now. A smaller footprint is a smaller audit and a smaller renewal.
  • Name one owner. Decide who answers an audit letter, and who reviews it with counsel, before one arrives. Do not let an IT admin reply on the fly.

If a letter does arrive: acknowledge it inside the deadline, ask for the scope and the contract clause it relies on in writing, and route everything through the named owner. Do not volunteer data beyond what the scope requires.

How audit risk changes the stay-or-go decision

An audit does not make the decision for you, but it changes the timing. If you are running lapsed perpetual licenses, the choice is no longer between paying and not paying. It is between a planned move now and a forced negotiation later, possibly with a compliance finding already on the table.

  • Staying on VMware. Get your entitlements current first, then negotiate. A clean inventory is also your best tool in the renewal negotiation, because you know your number before Broadcom tells you theirs.
  • Managed VMware. A VMware Cloud Service Provider licenses the stack itself and rents you capacity, so the licensing compliance burden sits with the provider. You keep vSphere and your tools. See the multitenant VMware cloud guide and the provider directory.
  • Leaving VMware. Moving to Nutanix, Proxmox, Hyper-V, or public cloud ends future exposure, but not the past. Hosts you ran before the move can still be in scope, so do the inventory either way. Start with the comparison guide and the migration timeline to see how long a real move takes.

Common mistakes

  • Assuming a current subscription means zero risk. Core growth and untracked hosts still create gaps.
  • Applying post-support patches to perpetual hosts. The exception reported in the letters covers zero-day security patches only.
  • Replying without a scope. Answer the deadline, but ask what the audit covers before you hand over anything.
  • Waiting for the letter to inventory. The response window is days. The inventory takes weeks.
  • Treating the audit and the renewal as separate problems. They are the same conversation. Whatever the audit finds becomes part of the price.

Broadcom VMware audit FAQ

Is Broadcom auditing VMware customers?

Yes. Formal audit letters have been reported since June 2025, mainly to organizations still running perpetual VMware licenses without active support. Reported letters gave three business days to respond and named an outside audit firm to review deployment and entitlements.

Who is most likely to be audited?

Organizations running perpetual licenses after their support ended, and those that declined or ignored a renewal quote, carry the most risk. Growth in hosts or cores beyond what you bought is the next most common gap. Broadcom does not publish its selection method.

Can I keep using perpetual VMware licenses after support ends?

You can keep running the version you owned. You cannot apply builds, patches, or upgrades released after support ended, except zero-day security patches according to the reported cease-and-desist letters. Check your own agreement for the exact terms.

How long do I have to respond to a VMware audit letter?

Reported letters asked for a response within three business days. Acknowledge inside that window, then ask for the audit scope and the contract clause it relies on in writing before sharing data. Involve counsel.

Does moving off VMware end audit risk?

It ends future exposure, but hosts you ran before the move can still be in scope. Keep your inventory and entitlement records after you migrate.

Get ahead of the letter

Know your options before Broadcom asks.

A Bridgepointe advisor helps you line up renewal, managed VMware, and migration options side by side, so an audit or a renewal quote never becomes your only data point.