Yes, and the first letter can be the audit itself. Here is who has been targeted, what an auditor looks for, and how to get your inventory in order before three business days is all the time you have.
Quick answer: Yes. Since mid-2025 Broadcom has sent formal VMware audit letters, mostly to organizations still running perpetual licenses without an active support contract. The letters give three business days to respond and bring in an outside audit firm. Customers on a current subscription are less exposed, but not immune: an audit compares what you run against what you are entitled to, and the per-core rules make gaps easy to create by accident.
This guide covers what has actually been reported, what tends to put an organization on the list, where your real exposure sits, and how to get ready before a letter arrives. It is not legal advice. If you already have a letter in hand, read your own agreement with counsel before you reply.
Audit pressure arrived in two steps, a few months apart.
Broadcom has not published audit volumes, and there is no public count of how many letters have gone out. What is clear is the direction: the relationship moved from "renew support if you like" to "prove what you are entitled to run."
Nobody outside Broadcom knows its selection method. Based on who has reported receiving letters, these situations carry the most risk:
| Situation | Risk | Why it gets attention |
|---|---|---|
| Perpetual licenses, support lapsed, still running | Highest | This is the group the reported letters went to. Any patch applied after the support end date is a potential finding. |
| Declined or ignored a renewal quote | High | A quote that goes quiet tells Broadcom exactly who is still running VMware without paying for a subscription. |
| Renewal missed its anniversary date | Medium | Distributor notices reported by The Register describe a 20% surcharge on the first year of a renewed subscription when a renewal lands after the anniversary date. Broadcom did not confirm it to the paper. The Register, March 28, 2025. |
| Grew hosts or cores since the last order | Medium | Subscriptions are counted per physical core, with a 16-core minimum per CPU. New or upgraded hosts can quietly exceed what you bought. |
| Current subscription, count matches reality | Lower | An audit is still possible under the agreement, but there is little for it to find. |
An audit compares three things: what you deployed, what you are entitled to, and what you did with updates. Most findings come from the gaps between them.
Three business days is not enough time to build an inventory from scratch. Do the work now, while it is quiet.
If a letter does arrive: acknowledge it inside the deadline, ask for the scope and the contract clause it relies on in writing, and route everything through the named owner. Do not volunteer data beyond what the scope requires.
An audit does not make the decision for you, but it changes the timing. If you are running lapsed perpetual licenses, the choice is no longer between paying and not paying. It is between a planned move now and a forced negotiation later, possibly with a compliance finding already on the table.
Yes. Formal audit letters have been reported since June 2025, mainly to organizations still running perpetual VMware licenses without active support. Reported letters gave three business days to respond and named an outside audit firm to review deployment and entitlements.
Organizations running perpetual licenses after their support ended, and those that declined or ignored a renewal quote, carry the most risk. Growth in hosts or cores beyond what you bought is the next most common gap. Broadcom does not publish its selection method.
You can keep running the version you owned. You cannot apply builds, patches, or upgrades released after support ended, except zero-day security patches according to the reported cease-and-desist letters. Check your own agreement for the exact terms.
Reported letters asked for a response within three business days. Acknowledge inside that window, then ask for the audit scope and the contract clause it relies on in writing before sharing data. Involve counsel.
It ends future exposure, but hosts you ran before the move can still be in scope. Keep your inventory and entitlement records after you migrate.
A Bridgepointe advisor helps you line up renewal, managed VMware, and migration options side by side, so an audit or a renewal quote never becomes your only data point.