SOAR renewal
Your SOAR renewal is the budget for your agentic SOC.
The SOAR category is re-platforming. Palo Alto has named a successor to Cortex XSOAR. The cloud editions of IBM QRadar SOAR reached end-of-life on April 14, 2026. Splunk SOAR removed its classic playbook editor. Every path rebuilds something, so the renewal is the moment to decide what you rebuild onto. Morpheus is the agentic SOC platform with a full SOAR built in, and D3 ports your playbooks.
Bring your renewal quote and your playbook count. We model the swap against both, live.

What changed in the SOAR market, with dates
Three vendors, three different moves, one common thread: the product you renew is no longer the product they want to sell you next.
Each move is reasonable from the vendor’s side. Each one also hands the customer a rebuild: a new tenant and data model, a cloud successor for an on-prem estate, or a playbook library that has to be converted before anyone can edit it visually again. If you are rebuilding either way, the renewal quote is the wrong place to stop thinking.
Why keep the SOAR at all?
Because the deterministic playbooks you built are the part of your SOC that works. The alerts they never reach are what fill the queue.
A SOAR runs the response you designed in advance. That is exactly what regulators, auditors and change boards want for containment, notification and evidence collection. What a SOAR cannot do is investigate the alert before the playbook fires, or handle the alert nobody wrote a playbook for. That work still lands on analysts.
Morpheus was built as a SOAR before it was anything else, and the SOAR is still inside it. The agentic layer sits on top: Attack Path Discovery investigates every alert to L2 depth before an analyst opens it, up to 95% in under two minutes per customer-reported production data, July 2026, and every finding is graded Confirmed, Inferred or Gap. Response still runs on deterministic playbooks with approval gates. One platform, one audit trail per incident.
So the bridge position is simple. The SOAR capability moves into the platform that also does the investigation. Your playbooks land in the same engine that triages the alerts, your analysts keep the approvals they trust, and your engineers stop maintaining a second product to hand verdicts across to.
What do the four autonomy modes change about a migration?
Your playbooks arrive in Deterministic mode. Autonomy is a setting you raise per alert type afterward, and lower again without re-migrating.
Deterministic
Human writes the rules
The playbook engine runs alone. No AI in the response chain. Identical behaviour on every execution.
Migration baseline. Regulated workflows. Playbooks your board wants left alone.
AI-Assisted
Human in every action
Morpheus investigates every alert before the analyst opens it. The analyst queries the findings in natural language and takes the action.
First step up on the noisiest alert types.
AI-Led
Human at sign-off
Morpheus completes the investigation and drafts the response. The analyst reviews, and can approve or modify anything before it runs.
Phishing, malware, DLP triage at scale.
Autonomous
Human at design time
End to end against approval gates set in advance. No live sign-off on the alert types you choose. Roll back any action.
High-volume L1 categories. 24/7 coverage. MSSP tenants.
All four are configurations of one engine with one audit format. Phishing can run Autonomous while critical-infrastructure response stays Deterministic, in the same SOC, on the same day, under the same regulator. Attack Path Discovery is read-only in every mode; state-changing actions belong to the analyst or to the gates the analyst configured.
Do the playbooks come with you?
Structural logic ports automatically. Custom code and vendor-specific functions come back on a review list. Your team signs off on each playbook against a side-by-side diff.
| Source platform | Ports automatically | Returned for review |
|---|---|---|
| Cortex XSOAR | Playbook task sequence and sub-playbooks, branching conditions, task inputs and outputs, scheduled report definitions, integration commands that map to a Morpheus connector | Custom Python automation scripts, content-pack logic with no Morpheus equivalent, incident field and layout customisation, in-house transformers and filters |
| Splunk SOAR | Playbook block sequence and execution order, decision blocks and conditions, action blocks that map to a Morpheus connector, report and dashboard definitions | Custom code blocks, embedded search syntax inside steps, apps built in-house, playbooks that call another product’s API directly |
| QRadar SOAR | Workflow, phase and task structure, task ordering and dependencies, rule and condition logic, notification templates, report layouts | Custom scripts attached to tasks, functions with no library equivalent, integrations outside the D3 library |
This describes what the porting harness does. The hours your migration takes are confirmed in the assessment, which checks these rows against your actual export before a scope is written. The review list is the honest part of the output: anything the harness cannot map with confidence comes back with the source step attached.
How does the renewal math work?
Morpheus is an annual subscription sized to your alert volume, with the AI included. D3 absorbs the token cost, so the number you take to finance is the number you pay.
Most teams have no line item called “agentic SOC,” which is why the project waits for next year’s planning cycle. They do have a line item called SOAR, and it renews on a date already on a calendar. Morpheus is priced so a full SOAR and an agentic SOC come out of that spend. Where a vendor program applies, such as the XSOAR Exit Program, billing starts when your current contract ends and the migration runs inside that window at no charge. Nothing here is free, and we will not say it is. You get more from the same number, at the one moment the number is open.
Which SOAR are you renewing?
Cortex XSOAR
AgentiX is the named successor. The XSOAR Exit Program: playbooks converted, parallel run, billing starts at your XSOAR end date, year one at or under your current line.
Splunk SOAR
If the classic editor removal already has you converting playbooks, compare the two rebuilds before you sign the renewal.
Swimlane, Tines, Torq, Google SecOps, FortiSOAR
The migration program covers these too. Same porting harness, same parallel run, same sign-off.
Deployment-restricted or sovereign
On-premises, hybrid, sovereign-region and air-gapped deployment. Evidence for NIS2, DORA, the EU AI Act and KRITIS from one audit trail.
Running a service on a SOAR
Client-by-client cutover, per-tenant autonomy, and subscription that does not meter your margin.
faqs
Questions teams ask at renewal time
Should I renew my SOAR or replace it?
Renew if your vendor has committed in writing to the product you run, on the deployment model you run, at a number you can forecast. Replace if the successor is a different product, a different tenant, or a metered licence. The renewal is the one moment the budget is open, so it is the cheapest time to compare.
What does it mean that the SOAR category is re-platforming?
The three largest SOAR vendors have each moved their roadmap centre of gravity. Palo Alto named Cortex AgentiX the next generation of Cortex XSOAR on October 28, 2025. The cloud editions of IBM QRadar SOAR reached end-of-life under Palo Alto Networks ownership on April 14, 2026. Splunk SOAR 6.4.0 removed the classic visual playbook editor. None of these is a product-wide end-of-life, and each one asks existing customers to rebuild something.
Do I lose my playbooks if I move off my SOAR?
No. D3 porting scripts read the exported playbooks, reports and integration mappings from Cortex XSOAR, Splunk SOAR, QRadar SOAR and other platforms, rebuild the structure inside Morpheus, and return a review list for every step they cannot map with confidence. Your team signs off on each converted playbook against a side-by-side diff.
Is Morpheus a SOAR?
Morpheus is an agentic SOC platform with a full SOAR and case management built in. The deterministic playbook engine, approval gates, case timeline and reporting are part of the same product that investigates alerts. Deterministic is one of four autonomy modes, and a SOC can run it indefinitely.
What are the four autonomy modes?
Deterministic, AI-Assisted, AI-Led and Autonomous. They are configurations of the same engine with the same audit format. Deterministic runs playbooks with no AI in the response chain. AI-Assisted investigates every alert and lets the analyst query the findings; the analyst acts. AI-Led drafts the response for analyst review. Autonomous runs end to end against approval gates you set in advance. Modes are set per alert type and can be changed without re-migrating.
Does an agentic SOC need new budget?
Usually not. Morpheus is priced as an annual subscription sized to your alert volume envelope, with the AI included. D3 absorbs the token cost, so adoption does not move the number. For most teams the swap fits inside the SOAR line item that is already up for renewal.
How long does a SOAR migration take?
D3 runs migrations on a written 60-day plan: inventory and readiness report, conversion with a diff per playbook, replay of closed incidents for a parity report, parallel run on live alerts, then cutover on your sign-off. Custom code, custom integrations outside the D3 library and incident history beyond the agreed scope are confirmed in the assessment before anyone commits.
Can Morpheus run on-premises or air-gapped?
Yes. Five deployment models: EU cloud, on-premises, hybrid, sovereign-region and air-gapped. Data and AI inference stay inside the boundary you choose. This is the path for QRadar SOAR shops and regulated environments where the vendor-recommended successor is cloud-only.
Bring the renewal quote to the demo.
We put your playbook count and your renewal number beside a Morpheus subscription and walk through the 60-day plan on your own alert types. Thirty minutes, your stack, no slideware.
Already exporting? The free migration assessment returns a tagged inventory of your playbooks. No meeting required.
D3 Security builds Morpheus, the agentic SOC platform. Vancouver, Canada. IBM, QRadar and Resilient are trademarks of International Business Machines Corporation. Cortex, XSOAR, XSIAM and AgentiX are trademarks of Palo Alto Networks, Inc. Splunk is a trademark of Cisco Systems, Inc. D3 Security is not affiliated with any of them. Vendor facts reflect public documentation retrieved September 14, 2026 and may change.