Our verdict
- Best for: Current Cisco Umbrella customers who need to plan a supported transition, or Cisco/Meraki shops evaluating the successor Secure Access DNS Defense.
- Avoid if: You need a self-service published price or cannot assign someone to own DNS policy, device coverage and exceptions.
- Price: A current Secure Access quote is required; old Umbrella reseller ranges are not a dependable budget.
- Research status: Vendor documentation checked September 24, 2026. We have not tested this product hands-on.
Last updated: September 24, 2026
Umbrella DNS and SIG are entering end-of-sale
Cisco's September 2026 announcement lists January 31, 2027 as the last order date for affected Umbrella DNS/SIG products, January 31, 2028 as the last renewal/addition date, and January 31, 2029 as the last support date. The notice names affected part numbers. Existing customers should check their own SKU and contract with Cisco or their partner. New buyers should evaluate Cisco Secure Access rather than assume a retiring Umbrella package is the long-term path.
What Umbrella still does well
Cisco Umbrella's DNS security can block requests to known malicious or disallowed domains before a connection is established. Its DNS product documentation describes network-level DNS forwarding, off-network protection through Cisco components, category filtering, policy and reporting. The Cisco footprint, including Meraki, may reduce integration work for teams already operating it. Verify this in a pilot: the presence of a network integration does not prove roaming laptops are covered.
The DNS layer is a useful control, not a substitute for endpoint protection, MFA, patching or recovery. It also does not inspect every URL or encrypted web session simply because DNS queries pass through it. Cisco's package comparison distinguishes DNS-only packages from SIG web and network capabilities; the current Secure Access quote must make the same distinction for the package you select.
What to buy now
Cisco describes Secure Access – DNS Defense as the evolution of Umbrella DNS and offers Essentials and Advantage packages in its current ordering guide. For broader internet and SaaS controls, ask about Secure Internet Access; for private-app access, ask whether a separate Secure Private Access entitlement is needed. Do not treat a generic “Secure Access” label as proof that each capability is included.
A new 10-, 25- or 50-person business should request an itemized quote showing product name, SKU, covered-user definition, seat minimum, term, support, logging, client prerequisites, setup and renewal. Public official USD pricing for a comparable new configuration was not available in the sources checked. The Cisco pricing guide has a quote worksheet and a published-price Cloudflare benchmark.
For an existing Umbrella contract, first inventory the exact part numbers and license end dates. Ask Cisco or your MSP for a written mapping to Secure Access and a policy migration plan. Cisco's upgrade guide says to read its prerequisites before upgrading. Preserve a rollback route and the old policy/export until you have tested the new environment.
Limitations to test before signing
- Coverage: Confirm office, roaming and mobile devices send queries to the intended policy path. Test a laptop away from the office network.
- Existing controls: Check whether your firewall, MSP or another licensed service already blocks the target domain categories.
- Policy detail: List the exact controls required: DNS categories, URL inspection, SaaS visibility, private-app access, DLP and log export. Map each to the quoted entitlement.
- Operations: Name an owner for false positives, allowlist requests and alert review. Ask who supplies support outside office hours.
- Migration: Test identity mapping, policy order, logs, exceptions and Cisco Secure Client behavior on representative devices.
- Contract: Confirm legacy part-number deadlines, new subscription start date, renewal, migration services and exit terms in writing.
A practical 30-day evaluation
In week one, record the current DNS path and its gaps. In week two, pilot the proposed Cisco configuration on one office device and one roaming device; verify logs and a harmless blocked-category test. In week three, run an exception request through the actual support owner and compare the same workflow with the current control. In week four, review the quote, coverage evidence and migration steps with the business owner. Expand only if the new service closes a documented gap at an acceptable operational cost.
Cloudflare is a useful comparison because its Zero Trust plans publish Free and Pay-as-you-go entry points, but its support, retention and add-ons differ. See the Cisco versus Cloudflare decision guide. The free SMB assessment can help decide whether DNS filtering is your next action at all.
This review is documentation-based; we have not measured detection rates, deployment time or support response. Sources were checked September 24, 2026. Links to Cisco and Cloudflare go to official pages; no commission is assumed. See our methodology and affiliate disclosure.