Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk Gross Revenue Retention
Governance, Ownership & Risk

Gross Revenue Retention

← Back to Glossary
By NHI Mgmt Group Updated August 28, 2026 Domain: Governance, Ownership & Risk

Gross revenue retention measures how much recurring revenue remains from existing customers over a period, before adding expansion revenue. It helps show whether the customer base is stable and whether the business is preserving value through renewals, renewals pricing, and churn control.

Expanded Definition

Gross revenue retention is the portion of recurring revenue that remains from a starting customer cohort over a measured period before any expansion revenue is added. In subscription businesses, it isolates the preservation problem: whether renewals, contractions, downgrades, and churn are being controlled tightly enough to keep the base intact. The metric is usually discussed alongside net revenue retention, but the two answer different questions. Gross retention asks how much value was kept; net retention asks how much value was kept after growth from the same customers. For governance-heavy domains such as NHI security, the distinction matters because retained customers do not always mean retained risk posture. Definitions vary across vendors, especially on whether implementation fees, one-time services, or late renewals are included, so teams should document the calculation method explicitly. For a broader identity security context, NIST Cybersecurity Framework 2.0 helps anchor resilience thinking around identity and access outcomes. The most common misapplication is treating gross retention as a growth metric, which occurs when expansion revenue is blended into the calculation and churn is no longer visible.

Examples and Use Cases

Implementing gross revenue retention rigorously often introduces reporting complexity, requiring organisations to balance clean cohort measurement against the messiness of real billing and renewal data.

  • A SaaS company measures gross retention on annual contracts to see whether renewals are holding steady before upsells are counted.
  • A managed security platform excludes expansion seats from the figure so the finance team can isolate churn caused by product gaps or poor onboarding.
  • A compliance-focused vendor uses the metric to compare customer stability across regions where procurement cycles and renewal timing differ.
  • A security operations provider ties renewal outcomes to customer success milestones, then reviews whether contract losses correlate with unresolved access and governance issues described in the Ultimate Guide to NHIs.
  • A platform team uses cohort-level gross retention alongside NIST Cybersecurity Framework 2.0 mappings to see whether control adoption is stabilising renewals.

In NHI-adjacent services, gross retention is often most useful when customer renewals depend on operational trust, audit readiness, and the ability to prove control maturity over time.

Why It Matters in NHI Security

Gross revenue retention matters in NHI security because recurring revenue is often tied to whether a buyer believes the product reduces identity risk reliably enough to renew. When NHI controls are weak, churn can follow failed audits, missed remediation deadlines, or repeated exposure of secrets and service accounts. That is not just a commercial issue. It can signal that the buyer does not trust the platform to govern machine identities at scale. NHI Mgmt Group research shows that 79% of organisations have experienced secrets leaks, with 77% of those incidents resulting in tangible damage, underscoring how identity control failures can quickly become renewal blockers. The same risk conditions that lower retention for a security vendor often mirror the control failures inside the customer environment: poor visibility, weak rotation, and incomplete offboarding. Gross retention therefore becomes a practical indicator of whether the market believes a solution is operationally dependable. Organisations typically encounter retention loss only after a failed renewal review, at which point gross revenue retention becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02Retention pressure often reflects failures in secret and lifecycle control.
NIST CSF 2.0GV.RM-1Governance and risk management shape whether identity controls sustain renewals.
NIST SP 800-63Digital identity assurance informs trust in access and renewal decisions.
NIST Zero Trust (SP 800-207)Zero trust depends on strong identity control, which affects platform credibility.
NIST AI RMFRisk framing helps explain how operational failures affect business continuity.

Align customer-facing identity assurance evidence with renewal expectations and assurance claims.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org