Join our Newsletter — 33% off our NHI Course

Gross Revenue Retention

Gross revenue retention measures how much recurring revenue remains from existing customers over a period, before adding expansion revenue. It helps show whether the customer base is stable and whether the business is preserving value through renewals, renewals pricing, and churn control.

Expanded Definition

Gross revenue retention is the portion of recurring revenue that remains from a starting customer cohort over a measured period before any expansion revenue is added. In subscription businesses, it isolates the preservation problem: whether renewals, contractions, downgrades, and churn are being controlled tightly enough to keep the base intact. The metric is usually discussed alongside net revenue retention, but the two answer different questions. Gross retention asks how much value was kept; net retention asks how much value was kept after growth from the same customers. For governance-heavy domains such as NHI security, the distinction matters because retained customers do not always mean retained risk posture. Definitions vary across vendors, especially on whether implementation fees, one-time services, or late renewals are included, so teams should document the calculation method explicitly. For a broader identity security context, NIST Cybersecurity Framework 2.0 helps anchor resilience thinking around identity and access outcomes. The most common misapplication is treating gross retention as a growth metric, which occurs when expansion revenue is blended into the calculation and churn is no longer visible.

Examples and Use Cases

Implementing gross revenue retention rigorously often introduces reporting complexity, requiring organisations to balance clean cohort measurement against the messiness of real billing and renewal data.

  • A SaaS company measures gross retention on annual contracts to see whether renewals are holding steady before upsells are counted.
  • A managed security platform excludes expansion seats from the figure so the finance team can isolate churn caused by product gaps or poor onboarding.
  • A compliance-focused vendor uses the metric to compare customer stability across regions where procurement cycles and renewal timing differ.
  • A security operations provider ties renewal outcomes to customer success milestones, then reviews whether contract losses correlate with unresolved access and governance issues described in the Ultimate Guide to NHIs.
  • A platform team uses cohort-level gross retention alongside NIST Cybersecurity Framework 2.0 mappings to see whether control adoption is stabilising renewals.

In NHI-adjacent services, gross retention is often most useful when customer renewals depend on operational trust, audit readiness, and the ability to prove control maturity over time.

Why It Matters in NHI Security

Gross revenue retention matters in NHI security because recurring revenue is often tied to whether a buyer believes the product reduces identity risk reliably enough to renew. When NHI controls are weak, churn can follow failed audits, missed remediation deadlines, or repeated exposure of secrets and service accounts. That is not just a commercial issue. It can signal that the buyer does not trust the platform to govern machine identities at scale. NHI Mgmt Group research shows that 79% of organisations have experienced secrets leaks, with 77% of those incidents resulting in tangible damage, underscoring how identity control failures can quickly become renewal blockers. The same risk conditions that lower retention for a security vendor often mirror the control failures inside the customer environment: poor visibility, weak rotation, and incomplete offboarding. Gross retention therefore becomes a practical indicator of whether the market believes a solution is operationally dependable. Organisations typically encounter retention loss only after a failed renewal review, at which point gross revenue retention becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-02 Retention pressure often reflects failures in secret and lifecycle control.
NIST CSF 2.0 GV.RM-1 Governance and risk management shape whether identity controls sustain renewals.
NIST SP 800-63 Digital identity assurance informs trust in access and renewal decisions.
NIST Zero Trust (SP 800-207) Zero trust depends on strong identity control, which affects platform credibility.
NIST AI RMF Risk framing helps explain how operational failures affect business continuity.

Align customer-facing identity assurance evidence with renewal expectations and assurance claims.