Support Plans

Direct access to the team behind the OpenSSL Library.
No vendor lock-in.

Work directly with the maintainers of the OpenSSL Library for faster fixes, expert consulting, and scalable support. Options include FIPS rebranding, PQC, custom solutions, and extended LTS for critical systems.

EVERY PLAN INCLUDES
  • Direct line to the OpenSSL Corporation team
  • Customer portal & ticketing
  • Annual contract — renewal optional
  • No vendor lock-in. Library stays open source.
All tiers · Corporation-grade
Engineering
For mid-sized businesses
$65,000
annually

Tailored for mid-sized businesses relying on OpenSSL Library in core products. Provides direct maintainer access, FIPS rebranding, and extended release support at an accessible level.

  • Customer portal & ticketing
  • Direct access to OpenSSL Library maintainers
  • One complimentary FIPS rebrand per year
  • Extended LTS release coverage
  • Priority triage on tickets
Contact Sales
Basic
For small and mid-sized teams
$25,000
annually

For small and mid-sized businesses that depend on standard OpenSSL Library but lack internal resources for troubleshooting and maintenance. Provides essential portal access without extended services.

  • Customer portal & ticketing
  • Troubleshooting & maintenance support
  • Coverage for standard OpenSSL Library
  • Standard response handling
Contact Sales
— Help me choose

Not sure which plan fits?

Talk to engineering. Tell us what you run, where the library lives in your stack, and what would happen if it broke. We’ll recommend the right tier — or scope something custom if none of the three fit.

— Track record

2025 by the numbers.

Verified from the OpenSSL Corporation Annual Report 2025. We grew volume and improved response at the same time.

86%
Renewal rate
Customers who renewed their support contracts in 2025
267%
Ticket volume growth
Increase in new tickets — handled while response improved
32%
Full resolution time
Reduction in median time to full ticket resolution
12%
First response time
Reduction in median time to first response
21
Staff in 2025Nearly doubled from 2024
66%
Of all OpenSSL contributionsCame from the Corporation team
$5M
Reinvested in 2025Income matched by expenses — a build year
400+
At OpenSSL Conference 2025From 30+ countries, rated 4.8/5
Source: Annual Report 2025 (PDF)
— Partners & collaborations

Projects we work with.

The OpenSSL Corporation actively collaborates with adjacent cryptographic projects to drive technical alignment, knowledge exchange, and long-term ecosystem sustainability.

— Honestly

What we don't do.

Buying support is partly about knowing what you’re NOT buying. Here’s where we draw the line.

01
We don't tell you what to run.

The library is open source. We support the version you build and deploy — on your schedule, not ours.

02
We don't replace your security team.

We collaborate with them and give them direct access to the maintainers.

03
We're not a managed service.

Your infrastructure stays yours. We're the expertise behind the cryptography.

04
We don't lock you in.

The library remains open source. The relationship is the support, not the software.

— FAQ

Questions, answered.

Onboarding starts with a kickoff session where we map the OpenSSL versions you depend on, the environments they run in, and how escalations should reach us. Timing depends on the complexity of your estate — get in touch and we’ll scope it.

Engineering tier includes one complimentary rebrand per year. Enterprise tier supports multiple rebrands annually, which matters if you ship validated modules across several products or release cycles.

Yes. The exact mechanics depend on your contract — reach out and we’ll work through it together. Most customers stay or grow: our 2025 renewal rate was 86%.

Yes — for needs that don’t fit the three tiers (PQC migrations, dedicated engineering hours, custom LTS windows), reach out and we’ll scope it together.

The OpenSSL Corporation team — the same engineers who maintain the library, including the people writing and reviewing the cryptographic code. No tiered call-center between you and the source.

Talk to engineering