Cisco Nexus 9000 and 3000 NX-OS License Guide & Selector
Choose the switch’s license class first, then the feature tier, consumption model, term, and any add-ons. Essentials covers common routing, VXLAN BGP EVPN, and telemetry; Advantage adds multi-site, MPLS, advanced multicast, and intelligent packet-flow functions. Security, storage, SyncE, Nexus Data Broker, and Fine Grain Load Balancing are separate add-ons, and every candidate PID still has to be checked against the exact switch and NX-OS release.
Nexus License Selector
Use this browser-based tool to identify the current Cisco ordering PID or PID combination that best matches your design. It covers current Nexus 9000 and Nexus 3000 tier-based licenses, add-ons, perpetual options, and published Nexus 9000 upgrade PIDs. Legacy feature-based licenses are documented later in the guide but are not recommended as new purchases.
Find the right Nexus license bundle
Identify the base license, term, and add-ons for a Nexus 9000 or 3000 switch in three guided steps.
Which switch are you licensing?
Enter an exact PID for the safest match, or choose the platform class manually.
Enter the complete hardware PID, including its suffix.
The license class is a Cisco ordering category, not simply the switch generation suffix.
What does the network need?
Choose the deployment, minimum feature tier, and any independent add-ons.
How will the license be purchased?
Select a consumption path. Only applicable terms or upgrade fields will appear.
The result deliberately says candidate rather than “guaranteed compatible.” Cisco's tables assign the ordering family, while the exact switch datasheet, platform support matrix, release notes, and configuration guide establish whether the hardware and software can actually run the feature.
The Five Decisions Behind Every Nexus License
The PID becomes predictable when the decisions are made in the right order:
- Identify the exact switch and its license class. The suffix is a commercial platform class, not a direct copy of the hardware generation name. For example, several FX3 switches remain in Cisco's XF license column.
- Choose the operating scope. Nexus 9000 subscriptions are DCN entitlements for ACI and NX-OS. A perpetual order must distinguish NX-OS-only from DCN/ACI coverage. Nexus 3000 tier licensing is NX-OS-only.
- Choose the minimum base tier. Buy Essentials for the documented Essentials functions, Advantage when the design crosses an Advantage boundary, and Premier when assurance and insights functionality in the Cisco design requires it.
- Add independent feature licenses. MACsec, storage networking, SyncE, NDB, and FGLB do not automatically appear merely because the base tier is Advantage or Premier.
- Choose subscription, perpetual, or upgrade. The available terms and PIDs differ by series and class. An existing LAN or Essentials entitlement may justify an upgrade PID instead of a full new license.
If the hardware decision is still open, use the Cisco Nexus 9000 series selection guide first. If the unresolved question is ACI versus standalone NX-OS, resolve it with the Nexus 9300 NX-OS vs ACI mode guide before finalizing the license BOM.
Essentials vs Advantage vs Premier
Cisco's current NX-OS Licensing Options Guide groups the current NX-OS functions as follows. Platform and release support remains a separate gate.
| Tier | What it includes | When it changes the order |
|---|---|---|
| Essentials | BGP, EIGRP, GRE, IS-IS, MSDP, OSPF, EPBR/ITD/PBR, PIM, SSM, VXLAN BGP EVPN, microsegmentation, IP Fabric for Media non-blocking multicast, PTP, iCAM, RIP, OFM, NGOAM, VRRP, and telemetry such as NetFlow, sFlow, and analytics | Normal Layer 3 routing, one-fabric VXLAN EVPN, and telemetry commonly stop here |
| Advantage | Everything in Essentials, plus Inter-AS Option B, Tenant Routed Multicast, SR-MPLS, Layer 3 EVPN over SRv6, MPLS Layer 3 VPN, VXLAN EVPN Multi-Site border gateways, Multicast NAT, RTP/PTP flow monitoring, and intelligent packet-flow functions | Multi-site, MPLS/SR, advanced multicast, or the named packet-flow features move the design to Advantage |
| Premier | Essentials and Advantage plus Premier functionality | Use when Cisco's design or Nexus Dashboard assurance/insights requirement explicitly calls for Premier; it is a subscription tier |
Three details prevent frequent overbuying. First, ordinary VXLAN BGP EVPN is in Essentials; VXLAN EVPN Multi-Site is the Advantage boundary. Second, static routes, SVIs, and HSRP are available on Nexus 9000 without a separate license. Third, current Essentials is subscription-only: if the project insists on a perpetual entitlement, the available base tier is Advantage.
What Each Add-On License Enables
| Add-on | Licensed function | Important scope check |
|---|---|---|
| Security | MACsec and, where supported, Secure VXLAN EVPN Multi-Site using CloudSec | Some 9300-GX platforms do not support MACsec; Cisco marks Security as mandatory for N9K-C9348D-GX2A |
| Storage | FCoE, native FC, and DCNM/NDFC SAN rights on supported platforms | Storage support is limited to named fixed or modular platforms; do not infer it from an Ethernet port speed |
| SyncE | Synchronous Ethernet | Cisco limits the add-on to supported Nexus 9300-FX3 platforms and applicable releases |
| NDB | Nexus Data Broker | Not listed for every fixed or modular class, including current XF3 subscription columns |
| FGLB | End-to-end adaptive routing, real-time congestion mitigation, packet spraying, and intelligent load distribution | Requires DCN Advantage plus the add-on, supported hardware, and the required NX-OS release; current PIDs are 3- or 5-year terms |
Add-ons are independent. A design requiring Advantage, MACsec, and FGLB needs a base Advantage entitlement plus both applicable add-on lines; the higher base tier does not absorb them.
Check stock, compare options, or talk with our team.
Nexus 9000 Current License PIDs
Fixed-Platform Subscription PIDs
All of these are DCN subscriptions covering ACI and NX-OS within Cisco's documented scope.
| Class | Essentials | Advantage | Premier | Available terms |
|---|---|---|---|---|
| GF | C1E1TN9300GF-{3Y,5Y,7Y} | C1A1TN9300GF-{3Y,5Y,7Y} | C1P1TN9300GF-{3Y,5Y,7Y} | 3, 5, 7 years |
| XF | C1E1TN9300XF-{3Y,5Y,7Y} | C1A1TN9300XF-{3Y,5Y,7Y} | C1P1TN9300XF-{3Y,5Y,7Y} | 3, 5, 7 years |
| XF2 | C1E1TN9300XF2-{3Y,5Y,7Y} | C1A1TN9300XF2-{3Y,5Y,7Y} | C1P1TN9300XF2-{3Y,5Y,7Y} | 3, 5, 7 years |
| XF3, N9300/9364E family | C1E1TN9300XF3-{3Y,5Y,7Y} | C1A1TN9300XF3-{3Y,5Y,7Y} | C1P1TN9300XF3-{3Y,5Y,7Y} | 3, 5, 7 years |
| XF3, N9100/9164E family | C1E1TN9100XF3-{3Y,5Y,7Y} | C1A1TN9100XF3-{3Y,5Y,7Y} | C1P1TN9100XF3-{3Y,5Y,7Y} | 3, 5, 7 years |
The braces show the valid term suffixes, not literal characters in the PID. For example, the XF Advantage row expands to C1A1TN9300XF-3Y, C1A1TN9300XF-5Y, and C1A1TN9300XF-7Y.
Modular-Platform Subscription PIDs
| Platform class | Essentials prefix | Advantage prefix | Premier prefix | Terms |
|---|---|---|---|---|
| Nexus 9504, M4 | C1E1TN9500M4 | C1A1TN9500M4 | C1P1TN9500M4 | -3Y, -5Y, -7Y |
| Nexus 9508/9516, M8/16 | C1E1TN9500M816 | C1A1TN9500M816 | C1P1TN9500M816 | -3Y, -5Y, -7Y |
| Nexus 9808, DM8 | C1E1TN9800M8 | C1A1TN9800M8 | C1P1TN9800M8 | -3Y, -5Y, -7Y |
| Nexus 9408, CM8 | C1E1TN9400CM8 | C1A1TN9400CM8 | C1P1TN9400CM8 | -3Y, -5Y, -7Y |
| Nexus 9804, DM4 | C1E1TN9800M4 | C1A1TN9800M4 | C1P1TN9800M4 | -3Y, -5Y, -7Y |
Perpetual and Upgrade PIDs
| Purpose | Fixed-platform PIDs | Modular-platform PIDs |
|---|---|---|
| NX-OS Advantage perpetual | NXOS-AD-GF, NXOS-AD-XF, NXOS-AD-XF2, NXOS-AD-XF3, N9100-DCN-AD-XF3 | NXOS-AD-M4, NXOS-AD-M8-16, NXOS-AD-CM8, NXOS-AD-DM4, NXOS-AD-DM8 |
| DCN/ACI Advantage perpetual | ACI-AD-GF, ACI-AD-XF, ACI-AD-XF2 | No current modular PID is listed in the corresponding Cisco table |
| LAN or Essentials to NX-OS Advantage | NXOS-UPG-L-AD-GF=, NXOS-UPG-L-AD-XF=, NXOS-UPG-L-AD-XF2=, NXOS-UPG-ES-AD-XF=, NXOS-UPG-ES-ADXF2= | NXOS-UPG-L-AD-M4=, NXOS-UPG-ES-AD-M4=, NXOS-UPG-L-AD-M8=, NXOS-UPG-ES-AD-M8= |
| NX-OS Advantage to ACI/DCN Advantage | NXOS-ACI-UP-AD-GF=, NXOS-ACI-UP-AD-XF= | No current modular PID is listed |
| ACI Base or Essentials to ACI Advantage | ACI-UPG-B-AD-GF=, ACI-UPG-ES-AD-GF=, ACI-UPG-B-AD-XF=, ACI-UPG-ES-AD-XF=, ACI-UPG-B-AD-XF2=, ACI-UPG-ES-AD-XF2= | No current modular PID is listed |
Current perpetual tier licenses are device-bound and nonportable. If the specific decision is whether NXOS-AD-XF fits an installed or proposed switch, the dedicated NXOS-AD-XF buying guide covers the XF class, proof, and purchase paths in more depth.
Current Nexus 9000 Add-On PID Families
| Add-on | Subscription PIDs | Perpetual PIDs or status |
|---|---|---|
| NDB | Fixed: C1-N9K-NDB-{3Y,5Y,7Y}; M4: C1-N9K-NDB-M4-{3Y,5Y,7Y}; M8/16: C1-N9K-NDB-M816-{3Y,5Y,7Y} | Fixed: NXOS-NDB; M4: NDB-MODM-SWT-K9; M8/16: NDB-MODL-SWT-K9 |
| Security | Fixed GF/XF/XF2: C1-N9K-SEC-XF-{3Y,5Y,7Y}; modular: C1-N9K-SEC-M-{3Y,5Y,7Y} | Fixed: ACI-SEC-XF or the documented XF2 DCN variant ACI-SEC-XF2; modular: ACI-SEC-XM |
| Storage | Fixed XF: C1-N9K-STRG-XF-{3Y,5Y,7Y}; M4/M8/16: C1-N9K-STRG-M-{3Y,5Y,7Y} | Fixed XF: ACI-STRG; M4/M8/16 NX-OS: NXOS-STRG-M |
| SyncE | Supported XF/FX3 scope: C1-N9K-SYNCE-XF-{3Y,5Y,7Y} | DCN-SYNCE-XF is listed for the applicable DCN perpetual scope |
| FGLB | XF2: C1N9K-FGLB-XF2-{3Y,5Y}; XF3: C1N9K-FGLB-XF3-{3Y,5Y} | No perpetual FGLB PID is listed in the current table |
Nexus 3000 Current and Legacy Licenses
Current Nexus 3000 tier PIDs use a different class rule: XF applies below 6.4 Tbps, XF2 applies above 6.4 Tbps, and XM applies to modular switches. Do not derive that class from a similar-looking Nexus 9000 suffix.
| Current path | Published PIDs |
|---|---|
| Essentials subscription | N3K-ES-XF-3Y, N3K-ES-XF-5Y, N3K-ES-XF2-3Y, N3K-ES-XF2-5Y, N3K-ES-XM-3Y, N3K-ES-XM-5Y |
| Advantage subscription | N3K-AD-XF-3Y, N3K-AD-XF-5Y |
| Advantage perpetual | N3K-AD-XF, N3K-AD-XF2 |
| NDB add-on | Subscription: N3K-NDB-3Y, N3K-NDB-5Y; perpetual: N3K-NDB |
| Security add-on | Subscription: N3K-SEC-3Y, N3K-SEC-5Y; perpetual: N3K-SEC |
Cisco's surrounding tier description mentions 3-, 5-, and 7-year subscriptions, but its current Nexus 3000 PID table lists only 3- and 5-year PIDs. The selector follows the PID table and treats any 7-year N3K requirement as a quotation-level validation rather than inventing a SKU.
Legacy Feature-Based and Hardware License Families
Cisco places the following families in the feature-based section and states that feature-based licenses are legacy and no longer sold. They still matter when auditing an installed switch, interpreting show license usage, planning an upgrade, or identifying a port-limited chassis.
| Platform or package | Representative legacy PIDs | Function |
|---|---|---|
| Nexus 9000 LAN Enterprise | N95-LAN1K9, N93-1G-LAN1K9, N93-LAN1K9, N93-LAN1K9-XF2 | Routing, multicast, PBR, GRE, VRF route leaking, VXLAN BGP EVPN, and related platform functions |
| Nexus 9000 VPN Fabric | N95-FAB1K9, N93-FAB1K9 | Inter-AS Option B, L3 EVPN over SR-MPLS, MPLS L3VPN, PLB, TRM, EVPN Multi-Site, and EPBR |
| Nexus 9000 Network Services | N95-SERVICES1K9, N93-SERVICES1K9 | iCAM, ITD, non-blocking multicast, and historically smart channel |
| Nexus 9000 FC/FCoE | N95-FNPV1K9, N93-FNPV1K9, N93-16Y-SSK9, N93-48Y-SSK9 | FCoE NPV or SAN switching/FC port activation on supported systems |
| Nexus 9000 24-port hardware upgrades | N9K-EX-24P-UPG=, N9K-FX-24P-UPG= | Enables the additional 24 ports on the named -24 hardware variants; independent of the software tier |
| Nexus 3600 | N3K-LAN1K9, N3K-FAB1K9 | Enterprise routing and the VPN Fabric feature set |
| Nexus 3500 | N3548-24P-LIC, N3548-24P-UPG, N3548-ALGK9, N3548-BAS1K9, N3524-LAN1K9, N3548-LAN1K9 | Port activation, Algo Boost, base routing, and enterprise routing |
| Nexus 3000 port activation | N3K-16T-UPG, N3K-32X-LIC, N3064T-16T-UPG, N3064T-32T-LIC | Enables the documented port count on specific 3172TQ or 3164T systems |
| Nexus 3000 routing | N3K-BAS1K9, N3K-LAN1K9, N3K-LAN2K9 | Base or enterprise Layer 3 functions, with the applicable PID determined by model |
| Nexus 3000 streaming telemetry | N3K-STR1K9, N3K-STR2K9 | In-band and postcard hardware streaming telemetry on the named 34xx platforms |
Do not replace one of these legacy PIDs with a current tier merely because the feature names overlap. First record the exact switch mode, installed entitlement, NX-OS release, and target architecture; then use Cisco's upgrade table or a license case to determine the valid path.
Smart Licensing, SLP, and Honor-Based Operation
The feature tier answers what entitlement is required. The licensing workflow answers how that entitlement is reported and managed.
Cisco describes Nexus 3000 and 9000 enforcement as honor-based in the current guide. That does not make the license optional: a feature may continue to operate while warnings or compliance obligations remain. Most Nexus 3000 and 9000 switches support Smart Software Licensing beginning with NX-OS 9.3(3), with the Nexus 3016 and 3064 called out as exceptions. From NX-OS 10.2(1)F onward, Smart Licensing Using Policy is the supported management method.
Before changing an installed switch, capture at least:
show license summary
show license usage
show license status
show version
show inventory
Interpret the output using the commands and terminology for that exact NX-OS release. For the operational differences among CSSM, SLP, connected, and disconnected workflows, use the separate Cisco Smart Licensing guide; this page owns PID selection rather than registration procedure.
Pre-Order License Checklist
Before placing the order, put these items on the quotation or BOM review request:
- Exact switch PID, including every hardware suffix.
- Current and target NX-OS release.
- NX-OS standalone or DCN/ACI deployment.
- License class from Cisco's current platform table.
- Minimum tier justified by the actual feature list.
- Every independent add-on and the ports or roles that use it.
- Subscription term, perpetual requirement, or existing entitlement to upgrade.
- Smart Account and Virtual Account destination when applicable.
- Device count: license each switch role required by the design rather than assuming the spine or standby device is free.
- Written confirmation of PID, term, portability, support scope, and delivery method.
If a model is absent from the selector, a combination returns “manual review,” or the project mixes legacy and current entitlements, send the exact switch PIDs, target features, software release, and desired term through the Layer23 project inquiry form. The response should confirm the candidate license lines before they are added to the hardware quote.
Source Scope and Update Policy
This guide and selector were checked on August 16, 2026 against Cisco's NX-OS Licensing Options Guide updated July 18, 2026, Cisco's current NX-OS software licensing material, and the older Nexus License Navigator for comparison. The 2022 Navigator remains useful as a branching example, but it omits newer platform classes and current additions such as XF3 and FGLB. The current Cisco guide therefore controls the PID tables on this page.
License data changes more often than protocol fundamentals. Recheck the source date, exact platform row, relevant footnotes, and current CCW availability whenever Cisco adds a switch, changes a term, replaces a PID, or moves a feature between tiers.