Software NGFW Credit Distribution and Management
Focus
Focus
Cloud NGFW for AWS

Software NGFW Credit Distribution and Management

Table of Contents

Software NGFW Credit Distribution and Management

Interchange and allocate credits among your Cloud NGFW resources regardless of the Cloud deployment method.
Where Can I Use This?What Do I Need?
  • Cloud NGFW for AWS
  • Cloud NGFW subscription
  • Palo Alto Networks Customer Support Account (CSP)
  • AWS Marketplace account
  • User role (either tenant or administrator)
Software NGFW Credits fund your consumption of Cloud NGFW resources and their related usage of Cloud-Delivered Security Services (CDSS) and Centralized management (Panorama, Strata Cloud Manager, and Strata Logging Service). Software NGFW credits allow you to consume Cloud NGFW resources in your tenant at a lower cost than PAYG rates, up to a specific capacity until your contract expires.
You may currently be using legacy Cloud NGFW credits for your AWS and Azure tenants. Please work with your Palo Alto Networks sales teams to migrate to the more flexible Software NGFW Credits for better flexibility.
Credit usage for your AWS tenant is based on pricing here. Credit usage for your Azure tenant is based on pricing here.
You can procure and associate Software NGFW credits to your Cloud NGFW AWS and Azure tenants by paying an upfront cost for a long-term contract between one and five years. You can procure these credits directly from Palo Alto Networks or its partners. Your Palo Alto Networks sales team and its partners can send these credits to you directly or by using the Cloud provider marketplace Private Offers. These private offers (a.k.a AWS Private Offers, AWS Consulting Partner Private Offers, Azure Private Offers, or Azure Multiparty Private Offers) allow you to take advantage of Cloud Marketplace benefits such as consolidated billing, and their spend commitments (AWS EDP and Azure MACC).
Consider the following when using Software NGFW credits with Cloud NGFW services:
  • Software NGFW credits are term-based. Terms can be defined for any amount of time between one and five years. Both allocated and unallocated credits expire at the end of the agreed-upon term.
  • If your monthly average consumption exceeds the purchased credits, additional usage/overage charges are charged at PAYG rates.
  • If you add Software NGFW credits during a free-trial period, your contract starts immediately and overrides the free trial.
  • Use the Cloud NGFW for AWS pricing estimator to help you determine AWS pricing for your Cloud NGFW tenant.
  • You can procure credits for Cloud NGFW and all the CDSS services you intend to use for Cloud NGFW.
    You must first subscribe to the Cloud NGFW through AWS Marketplace and create a tenant prior to setting up your deployment profile.

Prerequisites

To manage and allocate credits, your user account in the Palo Alto Networks Customer Support Portal (CSP) must have either the Credit Admin or Super User role assigned. These roles grant the necessary permissions to access the Credit Management Application.

Start Using Software NGFW Credits with Cloud NGFW

Once you book the order for credits, they become active immediately, and an email is sent to enable you to start using your credits; for example, if you purchased credits for a one year term on September 6, 2026, the credits are active from that day forward, while the term lasts, in the case of this example, until September 5, 2027. The person listed as the administrative contact in the quote receives the activation email. The email provides details about the subscription, the credit pool ID, the subscription start and end date, the number of credits purchased, and the description of the default credit pool. You can use these details to activate credits in your Customer Support Portal (CSP) account.
Palo Alto Networks recommends retaining this email to access information related to your account.
You will select one of your CSP accounts for the credit pool during activation. Once your credit pool is active, you can manage and allocate the credits to your Cloud NGFW tenants using the Credit Management Application described below.
  1. In the email, click Activate.
  2. After clicking Activate, you’re redirected to the CSP. Select the CSP account in which you want to activate the credits.
  3. Select Start Activation to start using your credits by depositing them into the CSP and allocating the credits.
  4. Select the Palo Alto Networks Customer Support portal account (you can search by account number or name) where you want to deposit the credits and clickDeposit Credits:
  5. You can view your deposited credits in the customer support portal (CSP):
    1. In the CSP, within the left navigation panel go to Product, select Software/Cloud NGFW Credits.
    2. If there is an active contract, the credit pool is visible on this page.
    3. Use the Account Selector field to ensure that you're viewing the correct account. Select Go to Details for a specific pool to see more granular information, such as the deployment profiles (also known as parent deployment profiles) associated with that pool.
  6. Click Go to Cloud NGFW Credits to access the Cloud NGFW Credit Management application in the Palo Alto Networks hub.

Manage Credits

The Cloud NGFW Credit Management Application provides a single location where you can manage your purchased credit pools, create deployment profiles and associate them with your Cloud NGFW tenants.
The credit configuration process depends on whether you are deploying Cloud NGFW credit allocations or Software NGFW credit allocations.
Follow the appropriate section below for your deployment type:
Option A: When Using Cloud NGFW Credits
  1. In the hub, click Cloud NGFW Credit Management to display the app:
    The Cloud NGFW Credit Management application displays the credit pools associated with the CSP account:
    Each credit pool, displayed as an individual tile, provides two options:
    • Check Details. Use this option to display information about the credit pool. If a deployment profile already exists, it appears in the Deployment Profile table:
    • Create Deployment Profile. Use this option to create a deployment profile to consume activated credits from the pool.
    Before you create a deployment profile, estimate the number of firewalls that will use the configuration. You don't have to deploy all the firewalls at once.
  2. Click Create Deployment Profile. In the Create Deployment Profile screen, specify the following information:
    1. In the Name field, use the drop-down menu to select the Credit Pool ID from the list of available options. Enter the corresponding name for the credit pool ID.
    2. Select the Cloud Type (either Amazon Web Services or Microsoft Azure).
    3. Use the drop-down menu to select the Cloud NGFW Serial Number.
      If you don't see a Cloud NGFW Serial number in the drop down, it's because of the following reasons:
      • Your firewall in the Cloud Service Provider’s portal isn't registered to the Palo Alto Networks CSP where your credit is deposited. In this case, go to the Cloud Service Provider’s portal and register the firewall to the CSP account.
      • Your firewall is registered in a different CSP account that you're not part of. In this case, add yourself as an admin to the CSP account and visit the deployment profile screen again. It should display the serial number.
    4. Specify the Number of Credits you want to allocate from the credit pool; the number of available credits from the credit pool appears.
    5. Optionally include a description.
    6. Click Save.
    After you have successfully created the deployment profile, the CNGFW Credits page displays the newly created profile along with the number of allocated credits:

Option B: When Using Software NGFW Credits

Step 1: Create a Parent Deployment Profile (CSP)
  1. Log in to your Palo Alto Networks Customer Support Portal (CSP).
  2. In the left navigation menu, expand Products and select Software/Cloud NGFW Credits.
  3. Click Create New Profile.
  4. Provide a descriptive name, select your target unified pool SKU, and specify CNGFW as the primary service type.
  5. Enter your desired credit capacity and click Submit.
    The global unallocated support balance will show a reduction equal to your input amount plus the 18% support overhead block.
  6. Copy the automatically generated DP Authorization Code (AuthCode) from the profile grid for confirmation tracking.
  7. Click Create Deployment Profile.

Configure a Child Deployment Profile on CMS Hub

Step 2: Configure a Child Deployment Profile on Credit Management System (CMS Hub App)
  1. Log into the CMS Hub App.
  2. The dashboard automatically fetches your updated unallocated details from backend IT microservices. Verify that you see a credit pool container matching your CSP configuration, labeled with your explicit DP AuthCode.
  3. Click Create Deployment Profile on the target credit pool row.
  4. Select Amazon Web Services (AWS) as your cloud infrastructure provider.
  5. Enter the target AWS Tenant ID string and assign a specific credit allocation limit to this tenant.
  6. Check or uncheck the Enable Smart Credit Buffer box depending on your overage preferences.
    During Deployment Profile setup or modification in CMS, the Enable Smart Credit Buffer checkbox controls buffer access rules:
    • Enable Smart Credit Buffer (Default): If an overage occurs, the tenant automatically draws from the central unallocated credit buffer. If the buffer has a sufficient balance, it covers the entire overage, resulting in zero direct marketplace PAYG charges for that billing period.
    • Enable Smart Credit Buffer Disabled: If you want to enforce strict budgetary isolation for an individual environment (such as an isolated lab or testing tenant), you can disable the buffer. If consumption breaches the assigned limit, the system bypasses the unallocated pool entirely and routes the overage directly to AWS Marketplace PAYG billing.
    • If multiple active AWS tenants exceed their allocated budgets in the same hour, the system satisfies requests using a first-come, first-served strategy based on when each billing microservice reaches the validation step. If the total shared overage exceeds the available buffer, any remaining uncovered consumption overflows to standard marketplace PAYG tracking.
  7. Click Save.

Manage Deployment Profiles in Credit Management System (CMS)

After you create your deployment profile you can edit (add or remove allocated credits), delete it, or view an audit trail. Before modifying your deployment profile, ensure that you understand the following terms—consumption and allocation in the context of Software NGFW credits:
  • Consumption—the number for Software NGFW credits used by a deployment profile to license deployed firewalls and subscriptions.
  • Allocation—the total number of Software NGFW credits assigned to a particular deployment profile.
Edit a Deployment Profile
To edit an existing deployment profile:
  1. In the Cloud NGFW Credits page, select the deployment profile you want to edit.
  2. In the Edit Deployment Profile screen, change the Number of Credits.
    The number of available credits appears below the Number of Credits field.
  3. After changing the number of credits, click Save.

View an Audit Trail

The Cloud NGFW Credit Management application provides an audit trail that allows you to track changes made to a deployment profile. This information includes:
  • Date and time when the deployment profile was modified.
  • The serial number associated with the deployment profile.
  • The profile name.
  • The status, for example, edited.
  • Modified by indicates the user who edited the deployment profile.
  • The description describes the nature of the change.
To view an audit trail, in the Cloud NGFW Credits page, click Audit Trail.

Tracking Tenant Usage Details on CMS Hub

The Cloud Next-Generation Firewall (CNGFW) platform automatically monitors and streams tenant information and credit usage statistics to a backend data lake maintained by Palo Alto Networks.
  1. Log into the CMS Hub App and select Chart View to display an interactive layout that visualizes real-time and historical peaks.
  2. Click Table View in the top right corner of the dashboard to track historical consumption by date period across identical columns.