In short
A licence remediation budget is not a single number but the sum of five cost lines, and only one of those lines can be fixed before the work starts. This article breaks down each line, explains why the machine count is not the unit of cost, converts the figures across three size milestones — 20 / 50 / 200 machines — using the published Dzo.software price list, and points out the year-two cost that most plans forget.
The short answer
Last updated: 05/08/2026.
The cost of software licence remediation is not a single number but the sum of five cost lines. Only one of those five — the audit fee — can be fixed before the work begins; the largest line, the cost of buying the missing licences, can only be determined once the machines have been counted and the purchase records reconciled. The right question is therefore not “how much does it cost” but “which variables decide that number, and which of them does the business actually control”.
The part that can be fixed in advance is the audit fee, and it moves in tiers rather than along a straight line. The publicly listed Dzo.software price table for the software licence audit and compliance service has three tiers: VND 42 million for fewer than 50 machines, VND 78 million for 50 to 200 machines, and from VND 144 million above 200 machines. These three figures are list prices, not market estimates, and they immediately reveal something important: there is a price tier boundary between a business with 49 machines and a business with 50.
The part that cannot be fixed in advance is the cost of buying the missing licences. This article deliberately leaves the unit price of each software product blank, because unit prices depend on the vendor, the edition, the term, the licensing programme and the exchange rate at the time of purchase — writing a specific number into an article today is a trap for anyone budgeting next month. Instead, the article gives you the formula, the list of variables, and a clear pointer to where the official unit prices are published.
There is a sixth cost that never appears in the budget yet is always used as the benchmark: the cost of doing nothing. The administrative penalty framework for copyright infringement and the level of criminal liability applicable to commercial legal entities are set out below, with links to the source documents so you can verify them yourself rather than take this article on trust.
Dzo.software advises Vietnamese businesses on software licence inventory, standardisation and remediation: genuine vendor licences, electronic VAT invoices, payment in VND. If you have to put a number in front of the board before there is time for an inventory, book a consultation to get the budget framework first.
This article is provided for reference and is not legal advice. The list prices cited here were read directly from the Dzo.software service pages on 05/08/2026 and may change; the official quotation is always the document Dzo issues for each individual business.
The numbers worth remembering
The ten data points below fall into two groups: service prices taken from the published Dzo.software price list, and legal figures taken from the source legislation on the Official Gazette. Every number obtained by division is labelled (derived) so you can tell a published figure from a recalculated one.
One point to grasp before reading the penalty table below, because it changes the way the budget has to be built: the penalty bracket for reproducing a work is not a fixed amount but escalates with value. Article 16, clause 2 of Decree 341/2025/NĐ-CP sets four fine tiers for organisations, and the applicable tier is determined by the illicit profit obtained, or the loss caused to the rights holder, or the value of the infringing goods. In other words, the potential fine rises in step with the very licence budget the business is deferring — the larger the shortfall, the higher the tier it falls into.
- VND 42 / 78 / from 144 million are the three list price tiers for the audit and compliance service, corresponding to fewer than 50 machines, 50 to 200 machines and more than 200 machines — Dzo.software price list, read on 05/08/2026.
- An 85.7% increase for a single extra machine (derived): a business with 49 machines pays VND 42 million, a business with 50 machines pays VND 78 million. The VND 36 million difference sits entirely on the tier boundary, not on a corresponding increase in workload.
- VND 0.39 million per machine is the lowest audit fee within the middle tier (derived: VND 78 million divided by 200 machines), compared with VND 2.10 million per machine at the bottom of the lowest tier (derived: VND 42 million divided by 20 machines). The audit fee per machine drops sharply as scale increases.
- VND 60.0 million per year is the maintenance cost if the business buys both listed add-on packages (derived: Compliance Watch at VND 4.2 million per month times 12, plus re-audit at VND 4.8 million times 2 occasions per year) — excluding licence renewal fees.
- 30 free minutes is the length of the pre-audit call, the first step in Dzo’s five-step process — used to scope the engagement before the price tier is confirmed.
- VND 250 million for individuals and VND 500 million for organisations is the maximum administrative fine in the field of copyright and related rights. Verbatim: “Mức tiền phạt tối đa trong lĩnh vực quyền tác giả, quyền liên quan là 250.000.000 đồng đối với cá nhân và 500.000.000 đồng đối với tổ chức” (the maximum fine in the field of copyright and related rights is VND 250,000,000 for individuals and VND 500,000,000 for organisations) — Decree 341/2025/NĐ-CP, as introduced by the Copyright Office of Viet Nam.
- 15/02/2026 is the date Decree 341/2025/NĐ-CP took effect. Verbatim, Article 63 clause 1: “Nghị định này có hiệu lực thi hành từ ngày 15 tháng 02 năm 2026” (this Decree takes effect from 15 February 2026) — the digitally signed version on the Government Official Gazette. The same provision repeals Decree 131/2013/NĐ-CP, Decree 28/2017/NĐ-CP and Article 3 of Decree 129/2021/NĐ-CP. For each individual penalty bracket, see the article Decree 341/2025 and penalties for unlicensed software.
- VND 60 to 100 million is the highest fine bracket for an organisation that reproduces a work without permission, under Article 16, clause 2, point d of Decree 341/2025 — applicable when the illicit profit obtained is from VND 60 million to under VND 100 million, or the loss caused to the rights holder is from VND 120 million to under VND 200 million, or the value of the infringing goods is from VND 120 million to under VND 200 million.
- VND 1 to 3 billion is the fine applicable to a commercial legal entity in aggravated cases under Article 225, clause 4, point b of the Penal Code, together with the possibility of “đình chỉ hoạt động có thời hạn từ 06 tháng đến 02 năm” (suspension of operations for a fixed term of 06 months to 02 years). The base case is VND 300 million to VND 1 billion — consolidated document 135/VBHN-VPQH on the Official Gazette, the version consolidating amending laws up to Law 86/2025/QH15.
- One backup copy is the entirety of the reproduction right a lawful user enjoys. Verbatim, Article 22, clause 1 of the Law on Intellectual Property, in the version in force after Law 131/2025/QH15 amended it from 01/4/2026: an organisation or individual lawfully using a copy of a computer program “được làm một bản sao dự phòng để thay thế khi bản sao đó bị xóa, bị hỏng hoặc không thể sử dụng nhưng không được chuyển giao cho tổ chức, cá nhân khác” (may make one backup copy to replace that copy when it is deleted, damaged or unusable, but may not transfer it to any other organisation or individual) — consolidated document 67/VBHN-VPQH.
| Tier | Illicit profit obtained | Or loss caused to the rights holder | Or value of the infringing goods | Fine for organisations |
|---|---|---|---|---|
| a | Under VND 10 million | Under VND 20 million | Under VND 20 million | VND 10 – 20 million |
| b | VND 10 – under 30 million | VND 20 – under 60 million | VND 20 – under 60 million | VND 20 – 40 million |
| c | VND 30 – under 60 million | VND 60 – under 120 million | VND 60 – under 120 million | VND 40 – 60 million |
| d | VND 60 – under 100 million | VND 120 – under 200 million | VND 120 – under 200 million | VND 60 – 100 million |
| Overall ceiling | — | — | — | A maximum of VND 500 million for organisations (Article 5, clause 1) |
| Cost group | Can it be fixed before starting? | Which variables it depends on | Typical share of the budget |
|---|---|---|---|
| 1. Inventory and audit fee | Yes — list price by machine-count tier | Number of machines, onsite versus remote only, number of branches | A small share, known in advance |
| 2. Buying the missing licences | No — only known after the inventory | Share of machines missing licences, each vendor’s unit of measure, edition, term | Usually the largest line |
| 3. Mandatory supporting infrastructure | No — depends on the current estate | Servers, virtualisation, operating systems and software past end of life | Varies enormously between businesses |
| 4. Training and internal process | Partly — by number of sessions and software groups | Number of users, number of software groups, onsite or online delivery | A small share, but the first to be cut |
| 5. Annual maintenance | Yes — if calculated correctly from the start | Renewal fees, continuous monitoring, re-audit frequency | Recurs every year, frequently forgotten |
The five cost lines that make up a remediation budget
The correct way to build the budget is to break it into five lines and handle each with a different method, rather than hunting for one all-inclusive unit price per machine. An all-inclusive per-machine price is what every client asks for and what no honest adviser can give before an inventory, because four of the five lines are not proportional to the machine count.
The first line is the inventory and audit fee. This is the only part that can be fixed from the very first call, because it depends solely on scale and survey scope. Dzo’s published process has five steps: a free 30-minute pre-audit call to scope the engagement, a scan of every machine either remotely or onsite, analysis and a gap analysis between the licences held and the machines actually in use, a recommended purchase roadmap prioritised by budget and urgency, and finally certification with 12 months of monitoring. The deliverables include a compliance report in PDF form, an inventory of the licences in use, the gap analysis, the additional-purchase roadmap and a legal file ready to present when inspectors arrive.
The second line is the cost of buying the missing licences, and this is almost always the largest amount. Nobody can calculate it before the inventory, because it equals the sum of each missing licence line multiplied by the corresponding vendor’s unit price. The important point: the number of missing licence lines is not the same as the number of machines missing licences. A machine running three licensed products is three licence lines; one user with two machines may need only one licence if the vendor permits it; a two-socket server may have to be licensed by core count rather than by machine.
The third line is the cost of mandatory supporting infrastructure, the part most likely to break a budget because it appears on no software price list at all. If the business still has machines running an operating system or software that has reached end of support, remediation drags in either upgrade costs, or extended support fees, or hardware replacement. If the business runs virtualised infrastructure, the way cores and virtual machines are counted can multiply the figure several times over compared with initial intuition.
The fourth line is training and internal process. This amount is small and is usually the first thing cut when the budget is tight, but cutting it is exactly why businesses have to redo the whole remediation exercise 18 months later. A clean licence estate with no process for issuing, reclaiming and recording licences will drift straight back out of alignment the moment there is a hiring round or a restructure. Dzo provides software training in Vietnamese delivered onsite, online or as a blend of both.
The fifth line is annual maintenance. Most plans treat remediation as a project with an end date, when in reality it is a state that has to be held. Maintenance costs comprise renewal fees for subscription licences, continuous monitoring costs and periodic re-inspection costs. How to allocate this amount across departments so that it does not all land on one owner is discussed in more depth in the article managing SaaS licence costs by department.
Written as a formula, the first-year budget equals the audit fee for the applicable machine-count tier, plus the sum of each missing licence line multiplied by the corresponding vendor’s list price, plus mandatory infrastructure costs, plus training. From year two onwards the budget equals total renewal fees, plus monitoring costs, plus re-inspection costs. Neither formula produces a number until the inventory results are in, and that is precisely the point: the inventory is not the expensive step; the inventory is the step that turns a budget from guesswork into a number that can be approved.

Why the machine count is not the unit of licence cost
The most expensive mistake in remediation budgeting is multiplying the machine count by an average unit price. The machine count is the unit for the audit fee, not the unit for licence money. Software vendors sell in several different units, and it is precisely that difference that pushes the final figure far from the original estimate, in both directions.
Some vendors sell by named user: one seat per person, and that person may install on several devices within a permitted limit. Under this model, a business with 200 machines but only 140 staff actually using design software needs 140 seats, not 200. Other vendors sell by device: the licence is tied to the machine, anyone who sits at it may use it, and in that case the machine count really is the correct unit.
Some vendors sell by processor core, mainly at the server and database layer. This is where budgets get multiplied several times over without anyone seeing it coming: one physical two-socket server with 16 cores per socket is 32 core units to buy, even though the asset register still shows a single machine. When that server runs virtualisation and the virtual machines move between hosts in a cluster, the scope requiring licences can spread across the entire cluster rather than stopping at the host currently running the workload. This counting mechanism is dissected in detail in the article software licensing on virtualised infrastructure.
There is one more dimension few people account for: a single machine can generate several licence lines. One machine in the design department may simultaneously need licences for the operating system, the office suite, the graphics suite, the archiving tool, the antivirus product and commercial typefaces. Six licence lines on one machine, each from a different vendor, each with its own unit of measure and its own term. Typefaces in particular are the line item omitted almost by default, even though a downloaded font is not the same as a licensed font.
The practical consequence: the correct counting step is not “count the machines” but build a machine-by-software matrix, then convert each cell into the unit of measure used by the vendor that owns the product. This is exactly what the gap analysis in an audit report contains, and it is why the inventory has to be listed by licence line rather than by machine. How to build a licence repository and the standardisation roadmap are set out in full in the article SAM for mid-sized businesses.
This counting exercise has an international standard behind it; it is not something every organisation improvises. ISO/IEC 19770-1:2017 is the IT asset management system standard, describing 15 process groups in its normative annex and suggesting three implementation tiers in order: trustworthy data, lifecycle integration, then optimisation. That order matters to anyone building a budget: the first tier to reach is “trustworthy data”, meaning a correct inventory — cost optimisation only arrives at the third tier. At the technical layer, ISO/IEC 19770-2 defines software identification tags that tools can read automatically; NIST describes the standard as giving an organisation a transparent way to track the software installed on the devices it manages.
And where do you look up unit prices? There is only one correct answer: the vendor’s own official pricing page, on the day you build the budget. The price table for Microsoft 365 for business, Vietnamese edition carries one detail that belongs in your spreadsheet immediately: the list price is quoted in US dollars per user per month, billed annually, not in dong. That means the budget has to add the exchange rate as a variable, together with the taxes and fees attached to transacting with an overseas supplier. For Adobe Creative Cloud for business and Autodesk, the pricing pages display by region and by package configuration, so the figure is only final once the page is opened in a browser with the correct region and the correct number of seats selected — which is also why this article copies no figure at all from either of those two pages.
This is also why this article does not state a specific unit price for any individual product. A number copied into an article today will be wrong once the vendor changes its price list, restructures its packages, or the exchange rate shifts — and the reader will still take that number to a budget meeting. What holds its value longer is the formula and the list of variables; unit prices should be looked up at the official source on the very day you build the spreadsheet.
| Unit of measure | What has to be counted | Example situation | Risk of substituting the machine count |
|---|---|---|---|
| By named user | Number of staff who actually use the software | 200 machines but only 140 people use the design software | Over-buying — the estimate comes in above reality |
| By device | Number of machines with the software installed | Shared machines used across several shifts by several people | A match — this is the one case where the machine count is correct |
| By processor core | Total server cores, potentially across the whole cluster | 1 server × 2 sockets × 16 cores = 32 units | Severe under-buying — 1 machine on the register, 32 units to pay for |
| By concurrent session | Number of simultaneous sessions, not the number of installs | Specialist software used in rotation across shifts | Over-buying if counted by headcount, under-buying if peak hours are miscounted |
| Several lines on one machine | Number of cells in the machine × software matrix | 1 design machine needs 6 licence lines from different vendors | Up to 5 times short if only machines are counted |
Converting by size: what separates 20, 50 and 200 machines
These three size milestones differ not only in the amount of money but in the kind of work required, and it is the kind of work that pushes the price into a new tier. What follows is how to read Dzo’s published price list in terms of what is actually being bought at each tier, together with the derived per-machine cost so the real curve becomes visible.
At the 20-machine mark, a business typically has only one group of software: an office suite, an antivirus product, perhaps an accounting package. There is no dedicated server, or only a simple file server. A remote scan is sufficient, and Dzo’s published price list confirms this: for businesses under 50 machines, a remote scan is enough; larger businesses should combine onsite and remote. The applicable tier is the basic package at VND 42 million, equivalent to VND 2.10 million per machine (derived). This is the highest per-machine rate of the three milestones, because the fixed cost of running an inventory does not shrink with scale.
At the 50-machine mark, the business has just crossed a tier boundary. The same service package moves from VND 42 million to VND 78 million, an increase of VND 36 million, or 85.7% (derived), purely because of the fiftieth machine. What is bought in addition at this tier is not “one more machine scanned” but an onsite scan with IT team interviews, a budget-prioritised purchase roadmap and a legal file ready for inspection. At this scale, departments start buying specialist software on their own, so the number of licence lines grows faster than the number of machines — the IT interview exists precisely to catch that hidden portion.
At the 200-machine mark, the middle tier is described as “50–200 machines” while the tier above is described as “200+ machines”, so exactly 200 sits on the boundary and has to be confirmed during the pre-audit call rather than assumed. If the middle tier applies, VND 78 million is equivalent to VND 0.39 million per machine (derived) — five times lower than at the 20-machine mark, and that is the most efficient point on the price list. Once clearly past 200 machines the enterprise package applies from VND 144 million, and what is bought in addition is the capacity to handle multiple branches and multiple sites, 12 months of Compliance Watch monitoring and a dedicated support contact with an SLA. In other words, the third tier does not sell additional machine volume; it sells the ability to handle geographic and organisational dispersion.
Reading the table backwards produces a very pragmatic budgeting tactic: if the business currently has 47 to 49 machines and plans to hire during the quarter, running the inventory before crossing the 50 mark saves exactly one price tier on the first audit. Conversely, at 52 machines there is no way back down a tier, and the optimisation lies elsewhere: make the fullest possible use of the middle tier’s scope, that is, run a single inventory across every machine rather than splitting it into several rounds.
One point needs stating clearly to avoid misunderstanding: the figures in this section are the audit fee only, and include not one dong of licence purchase money. In practice, the ratio between the two depends entirely on the current estate: a business that has bought almost everything and is short only a few lines may find the licence money smaller than the audit fee; a business that has never bought anything will find the licence money several times larger than the audit fee. Nobody knows which situation they are in before counting — which is the entire reason the inventory step comes before budget approval and not the other way round.

| Size | Tier and list price | What is bought in addition to the tier below | Audit fee per machine (derived) |
|---|---|---|---|
| 20 machines | Basic package — VND 42 million | Remote scan of every machine, PDF report, gap analysis, Dzo Verified certification | VND 2.10 million/machine |
| 49 machines | Basic package — VND 42 million | As above, still within the lowest tier | VND 0.86 million/machine |
| 50 machines | In-depth package — VND 78 million | Onsite scan + IT interviews, budget-prioritised purchase roadmap, legal file ready for inspection | VND 1.56 million/machine |
| 200 machines | In-depth package — VND 78 million | As above, still within the middle tier — the most efficient point on the price list | VND 0.39 million/machine |
| Over 200 machines | Enterprise package — from VND 144 million | Multi-branch / multi-site coverage, 12 months of Compliance Watch, a dedicated support contact with an SLA | from VND 0.72 million/machine (at the 200 mark) |
Year-two costs: the line most plans forget
Remediation is not a project with an end date but a state that has to be held, so the budget must carry a recurring cost line from year two onwards. This is the most common planning error and also the most expensive one, because it causes no immediate damage yet quietly returns the business to the starting line after one to two years.
Year-two costs fall into three groups. The first is renewal fees for the subscription licences bought in year one; this group does not shrink and may grow when the vendor adjusts prices or when the business expands. The second is continuous monitoring to detect newly emerging drift; Dzo’s published price list includes a Compliance Watch retainer at VND 4.2 million per month, monitoring for 12 months and detecting new gaps as teams grow or restructure. The third is periodic re-inspection, with a six-monthly re-audit package at VND 4.8 million per occasion.
Adding the two listed add-on packages together, the maximum maintenance cost is VND 60.0 million per year (derived: VND 4.2 million times 12 months equals VND 50.4 million, plus VND 4.8 million times 2 occasions equals VND 9.6 million). This figure excludes licence renewal fees, which depend on the number of licence lines and each vendor’s policy. Worth noting: for businesses in the enterprise tier, 12 months of Compliance Watch is already included in the package, so the year-two cost structure at that tier looks quite different from the two tiers below.
Why does drift return so quickly? Because the licence repository is a snapshot in time, while the organisation is in motion. Every new hire needs a seat; every departure leaves behind a seat nobody reclaims; every new department signs up for a cloud tool on a personal credit card; every machine replacement means a licence reinstalled with no record kept. After 12 months with nobody watching, last year’s clean inventory no longer describes reality.
The cheapest way to avoid paying for remediation a second time is not to buy more services but to attach licence issue and reclaim to the HR processes that already exist: onboarding issues the licence, offboarding reclaims it, and one person signs off on the record. This costs no money, only a decision. Monitoring services exist to catch the remainder — the part internal processes do not see.
| Cost item | Year 1 | Year 2 onwards | How it is calculated |
|---|---|---|---|
| Initial inventory / audit fee | Yes — VND 42 / 78 / from 144 million by tier | Does not recur | List price by machine-count tier |
| Buying the missing licences | Yes — usually the largest amount | Does not recur (for perpetual licences) | Σ (missing units of measure × vendor unit price) |
| Subscription licence renewal fees | Included in the first term | Yes — recurs every term | Σ (number of seats × renewal unit price) |
| Continuous monitoring (Compliance Watch) | Optional | Yes — VND 4.2 million/month | 4.2 × 12 = VND 50.4 million/year (derived) |
| Periodic re-inspection (re-audit) | Not required | Yes — VND 4.8 million/occasion | 4.8 × 2 occasions/year = VND 9.6 million/year (derived) |
| Training and internal process | Yes | Only when there are new staff or a software change | By number of sessions and software groups |
The sixth cost line: the back-charge invoice if you let the vendor ask first
Beyond the administrative penalty framework applied by state authorities, there is another route to the same sum of money that very few budgets account for: the software vendor itself runs a compliance verification and issues a back-charge invoice. This mechanism sits not in Vietnamese law but in the terms of use the business agreed to when it installed the software, and it is not calculated against a penalty bracket but against the value of the shortfall plus the cost of the verification.
Autodesk states both halves plainly. Section 8, “Verification of Compliance”, in the Terms of Use allows the vendor to conduct “a remote or on-site audit”, requires the customer to submit the results within 15 days of being notified, and lists “machine IDs, serial numbers, Autodesk IDs, NT/Windows username, device ID”. And if a shortfall is found, the wording is: the customer “must immediately purchase new Offerings at least equal to the total of the value of the identified noncompliance and Autodesk's reasonable costs to complete the Verification” — that is, buy the shortfall at the value of the identified noncompliance, plus whatever the vendor spent carrying out the audit.
Adobe goes one step further, and this is the detail every IT director should read closely. Section 11.2 of the General Terms, 2025v1 edition allows Adobe to verify compliance no more than once every 12 months, and when it does, the customer must submit within 30 days “raw data from a software asset management tool of all On-premise Software and Distributed Code installed or deployed by or on behalf of Customer”. In other words, the vendor assumes by default that the business already has a software asset management tool and can export raw data from it. A business with no licence repository to export from will have to build one in 30 days, under pressure, instead of building it proactively to a plan. Section 11.3 allows Adobe to verify on site with 14 days’ notice if the data submitted does not adequately demonstrate compliance, and section 11.4 provides that if usage exceeds the licensed entitlement by more than 5%, the customer must also pay Adobe’s verification costs.
On the Microsoft side, the publicly readable documentation says far less: the Universal License Terms in the Product Terms state that Microsoft “may verify compliance with those terms as provided in Customer's volume license agreement”, meaning the full verification clause sits in the volume licensing contract rather than on the public page. But there is one mechanism Microsoft does publish clearly, and it affects next year’s budget directly: the annual true-up under an Enterprise Agreement. According to Microsoft’s true-up guidance document, each year the customer must count every device, user and processor added over the previous 12 months, and the true-up order must reach Microsoft in the window from 60 days to 30 days before the contract anniversary date. Even where there has been no growth, an Update Statement must still be filed — the so-called “zero-usage order”.
How common is this? According to Flexera’s 2025 State of ITAM survey of 506 IT professionals, published on 18/06/2025, “nearly half (45%) of surveyed organizations report spending over $1 million on software audits over the past three years”, and half of the respondents said Microsoft had audited their organisation within the last three years, followed by IBM at 37% and Adobe at 24%. One caveat so you can discount it appropriately: Flexera sells software asset management tools, so this is a survey run by an interested party rather than neutral data; the figures are still worth citing because the sample size and publication date are specific.
Set side by side, the budget picture becomes clear: for the same set of missing licences, a business has two ways to pay. The proactive route is buying at list price, choosing the term and the package configuration, receiving full VAT invoices, and spreading the budget across a phased roadmap. The reactive route is buying at the value of the shortfall as the vendor determines it, within 15 to 30 days, plus the verification costs, and with no remaining room to negotiate the configuration. The gap between the two routes lies not in the software unit price but in timing and posture — and that is exactly what a proactive inventory buys.
| Vendor | Frequency / response deadline | What the vendor requires you to submit | What you pay if a shortfall is found |
|---|---|---|---|
| Autodesk | Submit results within 15 days of notification; remote or on-site audit | Machine ID, serial number, Autodesk ID, Windows username, device ID | Buy the shortfall “at least equal to the total of the value of the identified noncompliance” plus the vendor’s verification costs |
| Adobe | No more than 1 verification / 12 months; submit data within 30 days; on-site audit with 14 days’ notice | “raw data from a software asset management tool” covering all on-premise software installed, together with valid proof of purchase | Adobe invoices the excess, payable within 30 days; more than 5% over entitlement means also paying the verification costs |
| Microsoft | The public page states only “may verify compliance… as provided in Customer volume license agreement” | Not published on the Product Terms page | Not published on the Product Terms page — do not speculate; check your own licensing contract |
| Microsoft (EA true-up) | Annually; the true-up order must arrive in the window 60 to 30 days before the contract anniversary | A count of the devices, users and processors added over the previous 12 months | Pay for the increase; even with no increase you must still file an Update Statement (zero-usage order) |
Six mistakes that break a remediation budget
A remediation budget rarely breaks because unit prices came in higher than expected; it breaks because an entire cost line is missing. All six errors below are missing-line errors rather than wrong-price errors, and all six are detectable at the inventory step if the inventory is done properly.

- Multiplying the machine count by an average unit price. This ignores the fact that each vendor sells in a different unit of measure — user, device, processor core or concurrent session. It is the number one error and also the one that causes the biggest variance.
- Budgeting for year one only. Treating remediation as a one-off cost, leaving renewal and monitoring out of the following year’s plan, and then having to request a supplementary budget mid-cycle.
- Forgetting specialist software. Design, CAD, ERP and analytics tools usually involve only a handful of seats but carry unit prices far above office software, so a few overlooked seats can outweigh a hundred office licences.
- Forgetting servers and virtualised infrastructure. Counting by machine while the vendor counts by processor core — and when virtual machines move around a cluster, the scope requiring licences spreads wider still.
- Forgetting operating systems and software past end of life. Remediating software that runs on an unsupported platform usually drags in platform upgrade costs, or extended support fees, or hardware replacement — none of which appear on any software price list.
- Approving the budget before the inventory. Locking in a number based on guesswork, then discovering the gap is larger than estimated and having to go back for more — this time with diminished credibility and a deadline already close.
Where to start if you have to present a budget this week
If you need a number to present this week, the correct order is to fix the audit fee tier first, put the licence purchase money into the plan as a conditional estimated range, and state explicitly that the range will be replaced by real figures once the gap analysis is done. Presented that way it is more honest, and it is also easier to get approved than an all-inclusive number you cannot defend when asked how it was calculated.
Three things can be done immediately at no cost. First, count the machines in active use and classify them by department — this figure determines the price tier and you can produce it yourself. Second, collect every software purchase record still on file: invoices, licence confirmation emails, administrator accounts on vendor portals; whatever can be proven is whatever you do not have to buy again. Third, list specialist software by department, because this is the hidden portion that automated machine-scan reports are most likely to miss.
After those three steps, a free 30-minute pre-audit call is enough to scope the engagement and fix the price tier. If the business also needs the deployment work after the licences are bought, deployment services and Vietnamese-language training come from the same single point of contact. If you simply need to look up the catalogue of licensed software and each product’s licensing model before building your spreadsheet, the software catalogue is the place to start. For a direct conversation, contact Dzo.
Finally, a note on prioritisation when the budget will not cover the whole gap. The principle is to prioritise by risk, not by price: the software installed on the most machines, software from vendors with a history of strict auditing, and software supporting core business operations should be remediated first. The remainder goes into a phased roadmap with dates and named owners — a roadmap with clear milestones is evidence of good-faith compliance, which is entirely different from doing nothing.
Software licence remediation has no single price per machine, because four of the five budget lines are not proportional to the machine count: only the audit fee follows machine-count tiers, while the licence purchase money follows each vendor’s unit of measure, infrastructure costs follow the state of the servers and the software lifecycle, and maintenance costs recur every year — so an approvable number only appears after the inventory step, not before.
Frequently asked questions
1. How much does software licence remediation cost for 20 machines? The part that can be fixed immediately is the audit fee: according to the published Dzo.software price list, businesses with fewer than 50 machines fall into the basic package at VND 42 million, equivalent to VND 2.10 million per machine if divided evenly across 20 machines. The part that cannot yet be fixed is the licence purchase money, because it equals the sum of each missing licence line multiplied by the corresponding vendor’s unit price, and can only be determined once the gap analysis exists.
2. Why is there no all-inclusive quotation from the outset? Because the largest amount in the budget is the licence purchase money, and nobody knows how many licence lines a business is short of before counting. An all-inclusive quotation issued before the inventory is either padded high to protect the seller, or too low and will have to be revised midway. The audit fee is the opposite: it can be fixed immediately because it depends only on scale and survey scope.
3. Is it one licence per machine? No. Vendors sell in several different units of measure: by named user, by device, by server processor core, or by number of concurrent sessions. A machine running six licensed products is six licence lines; conversely, one user with two machines may need only one seat. The correct counting step is to build a machine-by-software matrix and then convert each cell into the unit of measure used by the owning vendor.
4. Is the year-two budget the same as year one? No, the structure is entirely different. Year one carries the audit fee and the licence purchase money, and neither recurs for perpetual licences. From year two onwards there are subscription licence renewal fees, continuous monitoring costs and re-inspection costs. According to Dzo’s list prices, the two add-on packages alone are VND 4.2 million per month for Compliance Watch and VND 4.8 million per six-monthly re-audit, totalling VND 60.0 million per year if both are bought, excluding licence renewal fees.
5. Does the inventory process disrupt business operations? According to the Dzo.software service description, no. Scanning can be carried out remotely or onsite outside working hours, without affecting day-to-day operations. For businesses with fewer than 50 machines, a remote scan is sufficient; larger businesses should combine onsite and remote so the IT team can be interviewed and the specialist software that automated scans tend to miss can be captured.
6. What should we do if the budget will not cover the entire gap? Prioritise by risk rather than by price: remediate first the software installed on the most machines, software from vendors with a history of strict auditing, and software supporting core operations. Put the remainder into a phased roadmap with dates and named owners. A roadmap with clear milestones is entirely different from doing nothing, both as a management matter and when an explanation is required.
Sources
- Decree 341/2025/NĐ-CP dated 26/12/2025 on administrative penalties for infringement of copyright and related rights — digitally signed version, Công báo Chính phủ (Articles 5, 16 and 63). Accessed 05/08/2026
- Introduction to Decree No. 341/2025/NĐ-CP — Copyright Office of Viet Nam (cov.gov.vn). Accessed 05/08/2026
- Consolidated document 135/VBHN-VPQH — Penal Code (Article 225), consolidated up to Law 86/2025/QH15, Công báo Chính phủ. Accessed 05/08/2026
- Consolidated document 67/VBHN-VPQH — Law on Intellectual Property (Article 22, clause 1), the MOST RECENT consolidation incorporating Law 131/2025/QH15. Note: the older consolidation 155/VBHN-VPQH does NOT contain this amendment. Accessed 05/08/2026
- Law No. 131/2025/QH15 amending and supplementing a number of articles of the Law on Intellectual Property, effective 01/4/2026 — Công báo Chính phủ. Accessed 05/08/2026
- Price list and scope of the software licence Audit Compliance service — Dzo.software (the source of every 42 / 78 / from 144 million VND figure and of the add-on packages in this article). Read 05/08/2026
- ISO/IEC 19770-1:2017 — IT asset management systems: Requirements. Official page of technical committee ISO/IEC JTC 1/SC 7 (this host is used because iso.org returns 403 to automated access). Accessed 05/08/2026
- Software Identification (SWID) Tags — NIST Computer Security Resource Center, describing the ISO/IEC 19770-2:2015 standard. Accessed 05/08/2026
- Autodesk Terms of Use — General Terms, section 8 “Verification of Compliance”. Accessed 05/08/2026
- Adobe General Terms (2025v1), section 11 “License Compliance” — Adobe’s OFFICIAL PDF (the PDF footer reads “ADOBE GENERAL TERMS (2025v1)”), accessed via the Internet Archive snapshot. Why the original URL is not used: adobe.com did not respond to automated access from any tool tried (HTTP 000, including the home page), whereas the archived copy returns HTTP 200 and the full text is readable. Original URL: adobe.com/cc-shared/assets/pdf/legal/terms/enterprise/pdfs/generalterms-na-2025v1.pdf. Accessed 05/08/2026
- Microsoft Product Terms — Universal License Terms for All Software, section “Technical Measures”. Accessed 05/08/2026
- The Microsoft Enterprise Agreement True-up Guide — Microsoft’s official document on the annual true-up process. Accessed 05/08/2026
- Microsoft 365 for business pricing — official Vietnamese-edition page (list prices in USD per user per month). Accessed 05/08/2026
- Autodesk AutoCAD — official subscription and pricing page. Accessed 05/08/2026
- Flexera 2025 State of ITAM Report — official press release, survey of 506 IT professionals, published 18/06/2025. Note that Flexera sells ITAM tooling (an interested party). Accessed 05/08/2026
Need a software compliance review?
DZO experts provide a free compliance roadmap within 24 hours — e-VAT invoice, local implementation.
Book a free consultation



