password-manager-enterpriseCOMP

Enterprise Password Manager 2026: 6 B2B Solutions Compared (SME, Mid-Market, Enterprise)

Enterprise password manager comparison 2026: Bitwarden Business, 1Password Business, Dashlane, Keeper, NordPass Business, Proton Pass Business. SSO, SCIM, RBAC, SOC 2 criteria, pricing, use cases for SME / mid-market / enterprise.

By Eric Gerard · Editor · PwdFortress15 min readPhoto: Israel Andrade - Unsplash

Do you run security for a company of 10 to 5,000 staff? A B2B password manager is one of the 3 biggest security buys you make. It sits next to MFA and MDM. This guide covers 6 enterprise solutions for setups of ~25 to ~350 users. It is an honest comparison. We score them on clear enterprise points. These are SSO, SCIM, audit logs, RBAC, compliance, and real 3-year price.

Most business plans integrate with single sign-on (SSO).

For our ranked shortlist, jump to the best password managers for business.

Bitwarden Business wins on the simplicity and price ratio for most SME and mid-market in 2026. NordPass Business is the cheapest pick (3,69 USD/user/month). 1Password Business stays the premium UX pick if your budget allows it.

01 - The 2026 enterprise ranking

RankSolutionPrice /user/moSCIMSSO SAMLEU CloudVerdict
🥇 1Bitwarden Business5 USDHostedEnterprise (7 USD)YesBest SME / mid-market
🥈 2NordPass Business3,69 USDYesYesYesCheapest, Nord ecosystem
🥉 31Password Business7,99 USDBridgeIncludedYesPremium UX, larger budgets
4Proton Pass Business7,99 USDYesYesSwitzerlandGDPR-by-design
5Keeper Enterprise6,67 USDYesYesYesStrong compliance, mid UX
6Dashlane Business8 USDYesYesYesVPN included but pricey, dated UX

Methodology: an editorial comparison of 6 solutions. We score them on 14 enterprise points. We also add a 3-year TCO. The basis is vendor docs. It also draws on published security and compliance certs. It draws on the consensus of public reviews too.

02 - B2B evaluation criteria

For an enterprise, B2C points come second. Think UX and single-user pricing. Here are the 14 enterprise points that matter:

Technical points (weight 50 %)

  1. SSO SAML 2.0 (Okta, Azure AD, Google Workspace, OneLogin, JumpCloud)
  2. SCIM 2.0 provisioning (automated joiner-leaver-mover)
  3. RBAC (owner, admin, manager, user, custom roles)
  4. Group management (sync IdP groups, nested groups, shared collections)
  5. Audit logs / Event Logs (retention, SIEM export, alerting)
  6. Documented public REST API (Bitwarden CLI, 1Password CLI, NordPass API)
  7. Self-host possible (EU sovereignty, sector compliance)

Compliance points (weight 30 %)

  1. SOC 2 Type 2 published and recent
  2. ISO 27001 certified
  3. EU data residency guaranteed
  4. GDPR-compliant DPA, HIPAA BAA if US health
  5. Pen test report + active bug bounty

Operational points (weight 20 %)

  1. Support SLA (24/7 for Enterprise, 8/5 for Business)
  2. Onboarding playbook + change management (training, internal comms)

03 - Bitwarden Business - Best SME / mid-market

Price: 5 USD/user/month (Teams) or 7 USD/user/month (Enterprise).

Strengths:

  • Cheapest of the big-4 B2B vendors (5 USD vs 7,99 USD 1Password vs 8 USD Dashlane)
  • SCIM 2.0 hosted endpoint with no bridge to deploy, unlike 1Password. Okta, Azure AD, OneLogin, JumpCloud and Google Workspace work out of the box
  • Open source GPL v3 - code publicly auditable on github.com/bitwarden
  • SOC 2 Type 2 + ISO 27001 published
  • EU Cloud Frankfurt since 2024 (EU data residency)
  • Vaultwarden self-host possible for full sovereignty
  • Cure53 2022 + Insight Risk 2023 audits public
  • No server compromise in 8 years

Limitations:

  • Desktop UX looks visually dated vs 1Password / NordPass
  • SSO SAML reserved for Enterprise plan (7 USD)
  • Admin setup needs ~3-5h of Bitwarden docs on the first rollout

Recommended for: SME 10-50 staff (Teams Starter or Teams plan). Also mid-market 50-500 staff (Teams or Enterprise, based on SSO needs). And tech teams that want to self-host.

See our Bitwarden vs 1Password 2026 comparison and the Bitwarden Business SCIM provisioning guide.

Start a Bitwarden Business trial →5 USD/user/mo · Hosted SCIM · SOC 2 Type 2 · EU Cloud

04 - NordPass Business - The most aggressive price

Price: 3,69 USD/user/month (Teams annual plan) or 5,39 USD/user/month (Business).

Strengths:

  • Cheapest of the serious B2B solutions (3,69 USD/user/month)
  • XChaCha20 + Argon2id encryption (more modern algorithms than AES-256/PBKDF2)
  • SCIM provisioning Okta, Azure AD, Google Workspace, JumpCloud
  • SSO SAML 2.0 included in the Business plan (not only Enterprise)
  • SOC 2 Type 2 + ISO 27001 + Cure53 published
  • Nord Security ecosystem: a possible bundle with NordVPN (NordLayer for B2B) and NordLocker
  • EU data residency optional (Lithuania, Germany)
  • Modern UX (4.7/5 App Store)

Limitations:

  • Proprietary code (not open source)
  • No self-host possible
  • B2B technical community smaller than Bitwarden / 1Password

Recommended for: budget-sensitive SME 10-200 staff. Also companies wanting a coherent Nord ecosystem (B2B VPN plus B2B Password Manager).

See our NordPass 2026 review.

05 - 1Password Business - Premium UX, larger budgets

Price: 7,99 USD/user/month (Business) or quote required for Enterprise.

Strengths:

  • Among the most polished desktop and mobile UX on the market
  • B2B Watchtower: proactive breach alerts built into the admin dashboard
  • Self-hosted SCIM Bridge, a Docker container on your side, for Okta, Azure AD and Rippling. It is more work to set up, but it gives full network control
  • SSO SAML 2.0 included in Business (not reserved for Enterprise like Bitwarden)
  • Cure53 audits regular and public
  • 128-bit Secret Key in addition to master password (anti-brute-force cushion)
  • SOC 2 Type 2 published
  • Premium B2B support (4h SLA response for Enterprise)

Limitations:

  • Closed proprietary code (vs Bitwarden open source)
  • High price (60 % more expensive than Bitwarden, 116 % more than NordPass)
  • No self-host possible
  • SCIM Bridge adds more work to run than a hosted endpoint

Recommended for: mid-market 100-500 staff with bigger budgets. Also creative and journalism teams (Travel Mode). And staff Families (the included Families plan).

See our Bitwarden vs 1Password 2026 comparison.

06 - Proton Pass Business - GDPR-by-design

Price: 7,99 USD/user/month (Business).

Strengths:

  • Swiss jurisdiction: strong legal protection outside EU and outside US
  • Open source (public application clients)
  • Built into the Proton Business ecosystem (Mail, VPN, Drive, Calendar). It is a handy bundle for SME
  • Built-in TOTP 2FA in the vault
  • End-to-end encryption by design, with a zero-knowledge setup
  • SCIM + SSO SAML since late 2024

Limitations:

  • B2B product still young (launched late 2023, matured in 2025)
  • Smaller B2B admin community than Bitwarden / 1Password
  • Vault search slower than Bitwarden / NordPass
  • No self-host for the password manager (vs Proton Mail Bridge)

Recommended for: GDPR-sensitive companies and EU governmental bodies. Also media, NGO and journalism teams. And teams averse to US jurisdiction.

See our Proton Pass vs Bitwarden 2026 comparison.

07 - Keeper Enterprise - Strong compliance, mid UX

Price: 6,67 USD/user/month (Business) or quote required for Enterprise.

Strengths:

  • FedRAMP authorized and FIPS 140-2 validated. It is the default pick for US government and defense
  • SCIM + SSO SAML + dedicated Active Directory bridge
  • SOC 2 Type 2 + ISO 27001 + ISO 27017 + ISO 27018 (one of the most complete on the market)
  • BreachWatch integrated (compromised credential alerts)
  • KeeperPAM module (Privileged Access Management) as an option

Limitations:

  • Less polished desktop and mobile UX than NordPass / 1Password
  • Opaque pricing above 50 users (quote required)
  • Closed proprietary code
  • No self-host

Recommended for: US government, the defense sector, and US health (HIPAA). Also companies wanting integrated PAM.

08 - Dashlane Business - VPN included but pricey

Hands holding a smartphone
Hands holding a smartphone

Price: 8 USD/user/month (Business).

Strengths:

  • Integrated VPN (Hotspot Shield via partnership). It is an argument for companies without an existing B2B VPN
  • Aggregated Password Health Score for the CISO
  • SCIM + SSO SAML + Active Directory sync
  • SOC 2 Type 2 published
  • Guided admin onboarding simpler than Bitwarden

Limitations:

  • Highest price in the benchmark (8 USD = 60 % more than Bitwarden, 117 % more than NordPass)
  • Partner VPN (Hotspot Shield) less performant than dedicated NordVPN / Proton VPN
  • Desktop UX less polished than in 2020. The product has lost its edge
  • Closed proprietary code

Recommended for: companies wanting a Password Manager plus VPN bundle in a single invoice. Also US legacy teams already on Dashlane.

09 - Full comparison table

CriterionBitwarden BusinessNordPass Business1Password BusinessProton Pass BusinessKeeper EnterpriseDashlane Business
Price /user/mo5 USD3,69 USD7,99 USD7,99 USD6,67 USD8 USD
3-year TCO 100 users18,000 USD13,284 USD28,764 USD28,764 USD24,012 USD28,800 USD
SSO SAMLEnterprise (7 USD)IncludedIncludedIncludedIncludedIncluded
SCIM 2.0HostedHostedBridgeHostedHostedHosted
Open sourceYes (GPL v3)NoNoPartialNoNo
Self-hostYes (Vaultwarden)NoNoNoNoNo
EU data residencyYes (Frankfurt)Yes (LT / DE)YesSwitzerlandYesYes
SOC 2 Type 2YesYesYesYesYesYes
ISO 27001YesYesIn progressYesYesYes
HIPAA BAAYesYesYesOn requestYesYes
FedRAMPNoNoNoNoYesNo
Recent Cure53 audit2022202420242024InternalInternal
REST APIDocumentedDocumentedDocumentedDocumentedDocumentedDocumented
Active bug bountyYes (HackerOne)Yes (HackerOne)Yes (Bugcrowd)Yes (in-house)Yes (Bugcrowd)Yes (HackerOne)

10 - Use cases by company size

SME 10-50 staff

Recommendation: Bitwarden Business Teams plan (5 USD/user/month) or NordPass Business (3,69 USD/user/month).

At this size, you want a low price and a fast setup (under 1 IT day). You want WebAuthn MFA to be required. Add SCIM if you already have an IdP (Google Workspace, Microsoft 365). Keep staff training under 2h.

Typical stack:

  • Bitwarden Business Teams plan at 5 USD/user/month
  • SCIM via Google Workspace or Microsoft 365 (free on IdP side)
  • Mandatory WebAuthn MFA for all admins
  • Collections per department (IT, Marketing, Finance, Sales)
  • 90-day audit logs (default retention)

Annual budget: 25 staff × 5 USD × 12 = 1,500 USD/year (~1,350 EUR).

Mid-market 50-500 staff

Recommendation: Bitwarden Enterprise (7 USD/user/month) or 1Password Business (7,99 USD/user/month).

At this size, SSO SAML 2.0 becomes key for onboarding-as-code. SCIM is a must to avoid ghost accounts. You also need audit logs sent to a SIEM (Splunk, Datadog, Sumo Logic). This serves your own SOC 2 and ISO 27001 compliance.

Typical stack:

  • Bitwarden Enterprise plan at 7 USD/user/month
  • SSO SAML 2.0 via Okta / Azure AD / Google Workspace
  • Automatic SCIM provisioning (joiner-leaver-mover)
  • Mandatory WebAuthn MFA for ALL employees (not only admins)
  • Master password policies (min length 14, rotation every 12 months)
  • Nested collections per BU + department
  • Event Logs export to SIEM every 24h
  • Staff onboarding included in IT onboarding (30 min training)

Annual budget: 200 staff × 7 USD × 12 = 16,800 USD/year (~15,100 EUR).

Enterprise 500+ staff

Recommendation: Bitwarden Enterprise hybrid self-host, 1Password Business with SCIM Bridge, or Keeper Enterprise if government or defense.

At this size, you want audit logs kept for 18-24 months. You want SSO with required hardware MFA (WebAuthn or YubiKey). You want PAM built in (Keeper) or paired (CyberArk plus Bitwarden). You also want an active bug bounty. You want a yearly pen test. And you want a dedicated vendor management team.

Typical stack:

  • Quote-based Enterprise plan (~10-15 USD/user/month custom)
  • SSO via central IdP (Okta Workforce Identity Cloud, Azure AD Premium P2)
  • SCIM provisioning + Active Directory bridge
  • Mandatory hardware WebAuthn MFA (YubiKey or Titan)
  • RBAC with custom roles (PCI scope, GDPR scope, HIPAA scope)
  • Event Logs export to SIEM in real time
  • Vendor-independent encrypted backup (Bitwarden daily encrypted GPG export)
  • Annual external audit (Cure53 or equivalent) on the stack

Annual budget: 1,000 staff × 10 USD × 12 = 120,000 USD/year (~108,000 EUR).

11 - Self-host (Vaultwarden) vs SaaS

Vaultwarden is a popular open-source build by a third party. It works with the official Bitwarden clients. It is the top self-host option in 2026. GitHub shows over 50,000 deployed instances.

When to choose Vaultwarden self-host

  1. You have an in-house SOC team able to patch day-0 and monitor 24/7
  2. You have a strict regulatory obligation that forbids multi-tenant cloud (health, defense, sensitive banking)
  3. You want EU sovereignty control (Vaultwarden on OVH, Scaleway, Hetzner Germany)
  4. You have under 500 staff. You also have solid IT that can absorb 2-4h/month maintenance
  5. You want to save 60-80 % vs SaaS over 3 years

Typical Vaultwarden self-host cost:

  • Hetzner CX22 server (2 vCPU, 4 GB RAM, 40 GB SSD): 4,90 EUR/month
  • Encrypted S3 backup (Hetzner Storage Box): 3,50 EUR/month
  • Domain + TLS (Let's Encrypt): 0 EUR/month
  • Monitoring (Uptime Kuma self-host): 0 EUR/month
  • Infra total: ~100 EUR/year
  • Hidden IT cost: 4h setup + 2h maintenance × 12 months × 50 EUR/h = 1,300 EUR/year
  • Total Vaultwarden 50 users 3-year TCO = ~4,200 EUR vs SaaS Bitwarden Business = ~7,500 EUR

When to stay on SaaS

  1. You do not have an in-house SOC team able to patch day-0
  2. You want contractual SLAs (Bitwarden Cloud SLA 99.9 %, 1Password SLA 99.95 %)
  3. You need 24/7 Premium support
  4. You want to transfer operational risk to the vendor, with a reachable C-level in case of breach
  5. You do not have over 4h/month IT to dedicate to maintaining a critical service

See our complete Vaultwarden self-host tutorial with Docker setup, encrypted backup, monitoring and patching.

12 - Enterprise rollout playbook

Here is a playbook we suggest for mid-market rollouts (100-500 users). It runs on a 6-week plan:

Week 1 - Discovery + 10-user pilot

  • Audit existing state: how many staff reuse passwords? (Have I Been Pwned API plus interviews)
  • Vendor selection finalized (see criteria in section 02)
  • Free trial 14-30 days activated (Bitwarden, NordPass, 1Password all offer trials)
  • 10 tech-user pilot: IT, security, DPO
  • Internal documentation: admin runbook + user guide under 10 pages

Week 2 - SSO + SCIM provisioning

  • SSO SAML 2.0 activation on IdP side (Okta, Azure AD, Google Workspace)
  • SCIM configuration (token, endpoint, attribute mapping)
  • SCIM test on 5 pilot users (joiner-leaver-mover)
  • Audit logs export to SIEM validation

Week 3 - Hardware MFA enforcement

  • YubiKey 5 Series distribution to all admins (~50 EUR/key)
  • Mandatory WebAuthn MFA policy for admins
  • TOTP MFA minimum policy for users (escalation to WebAuthn in week 6)
  • Master password policy: minimum 14 chars, rotation every 12 months

Week 4 - Department pilot rollout

  • Select 1 department (typically Marketing or Sales - not IT, not Finance)
  • 30-min live training per staff member, not on-demand video alone
  • Personal vault import from Chrome / LastPass / etc.
  • Dedicated support Slack channel #password-manager-rollout

Week 5 - Full enterprise rollout

  • Official communication CISO + HR (email + town hall)
  • Mandatory onboarding in IT onboarding for new hires
  • 30-day deadline for full migration
  • Weekly reporting: % active staff, % migrated vaults

Week 6 - Hardening

  • Watchtower / BreachWatch audit: how many staff have compromised passwords?
  • Forced rotation of sensitive shared passwords (system admins, prod API keys)
  • WebAuthn mandatory escalation for 100 % of staff
  • Export disable policy to stop staff from exporting their vault in cleartext

13 - Change management: avoiding the 5 classic mistakes

There are 5 common mistakes on B2B password manager rollouts. They often derail projects:

  1. No pilot: a big-bang rollout with no 10-20 user pilot brings heavy pushback
  2. No SSO: MFA alone, with no SSO, makes onboarding hard. The staff member must create an account, turn on MFA, and import a vault
  3. No SCIM: ghost accounts from staff who left stay active for months. This is the #1 breach risk
  4. No live training: just an on-demand video means many staff never log in
  5. No export disable policy: a staff member who quits can export every shared password as a plain CSV

See also our LastPass to Bitwarden migration guide for companies migrating post-breach 2022.

14 - 2026 verdict

Most enterprises have 10-500 staff. For them, Bitwarden Business at 5 USD/user/month gives the best simplicity, price and sovereignty ratio. It is our #1 B2B pick 2026.

For budget-sensitive enterprises, or those already on NordVPN B2B, NordPass Business at 3,69 USD/user/month is the cheapest pick. It comes with no big security trade-off.

Some enterprises have a premium budget and want the best UX and a self-hosted SCIM Bridge. For them, 1Password Business at 7,99 USD/user/month stays a strong fit.

For GDPR-sensitive organizations, or those wary of US jurisdiction, Proton Pass Business at 7,99 USD/user/month stands alone. Its Swiss jurisdiction sets it apart.

For US government, defense and US health, Keeper Enterprise stays the default pick. It earns this thanks to FedRAMP plus FIPS 140-2.

Start a free Bitwarden Business trial →14-day trial · 5 USD/user/mo · Hosted SCIM · SOC 2 Type 2 · EU Cloud Frankfurt

Frequently asked questions

What is the best enterprise password manager in 2026?

**Bitwarden Business** is our #1 B2B pick 2026. It fits most companies with 10 to 500 staff. It costs 5 USD/user/month, the cheapest in B2B. It has a SCIM 2.0 hosted endpoint for Okta, Azure AD and Google Workspace. SOC 2 Type 2 and ISO 27001 are published. The code is open source and auditable. You also get a Vaultwarden self-host option for full sovereignty. **1Password Business** (7,99 USD/user/month) stays better if you want premium UX and a self-hosted SCIM Bridge. **NordPass Business** (3,69 USD/user/month) wins if you want the most aggressive B2B price. It also brings a coherent Nord Security ecosystem (NordVPN, NordLayer). See our [Bitwarden vs 1Password 2026 comparison](/en/blog/bitwarden-vs-1password-2026) for the full breakdown.

Is SSO or MFA enough for a company under 100 employees?

**Required MFA is enough for companies under 100 staff with no strong compliance needs**. Use TOTP at least. WebAuthn or passkeys are better. SSO SAML 2.0 starts to matter from 100-150 staff. It can matter sooner if you already have an IdP (Okta, Azure AD, Google Workspace). Such an IdP pushes SCIM and SAML by default. Bitwarden SSO SAML comes with the Enterprise plan (7 USD/user/month). 1Password SSO comes with Business. **Decision rule**: put SCIM auto-setup ahead of SSO. SCIM removes the #1 risk. That risk is a ghost account from a staff member who left. See our [Bitwarden Business SCIM provisioning 2026 guide](/en/blog/bitwarden-business-scim-provisioning-2026).

Which enterprise password manager is GDPR-compliant with EU data residency?

**Proton Pass Business** is our #1 GDPR-by-design pick. It runs under Swiss jurisdiction. EU data residency is guaranteed. Open-source audits are published. It runs on 100 % Proton infrastructure. **NordPass Business** offers optional EU data residency (Lithuania, Germany). It is also SOC 2 Type 2 certified. **Bitwarden Business** has had an EU Cloud setup (Frankfurt) since 2024. It gives you full EU data residency. **1Password** lets you pick data residency in US, EU or CA when you set up the company. **The only way to get full control is Vaultwarden self-host**. Run it on your own servers or a sovereign EU cloud (OVH, Scaleway, Hetzner). See our [Vaultwarden self-host tutorial](/en/blog/self-host-vaultwarden-tutoriel).

How much does an enterprise password manager cost for 100 employees over 3 years?

**Real 3-year cost for 100 staff**. Bitwarden Business = 100 × 5 × 36 = **18,000 USD**. NordPass Business = 100 × 3,69 × 36 = **13,284 USD** (cheapest). 1Password Business = 100 × 7,99 × 36 = **28,764 USD**. Dashlane Business = 100 × 8 × 36 = **28,800 USD**. Keeper Enterprise = 100 × 6,67 × 36 = **24,012 USD**. Proton Pass Business = 100 × 7,99 × 36 = **28,764 USD**. **Real TCO also includes more**. SSO and SCIM setup take 8-40h of IT. Staff training takes 2-5h × 100 = 200-500h. Audit trails save about 2 auditor days per year. That is roughly 2,400 EUR/year avoided.

Should you self-host (Vaultwarden) or use SaaS for an enterprise?

**SaaS covers the vast majority of SME and mid-market cases**. This means Bitwarden Cloud, 1Password Cloud, NordPass and others. You get no maintenance, a contractual SLA, SOC 2 Type 2 published audits, and 24/7 support. **Self-host makes sense only in three cases**. The options are Vaultwarden, Bitwarden Self-host Enterprise or Passbolt. (1) You have an in-house SOC team able to patch day-0. (2) You have a strict rule that bans multi-tenant cloud (health, defense, sensitive banking). (3) You want strong EU sovereignty control (Vaultwarden on OVH, Scaleway or Hetzner). **Otherwise SaaS wins**. You are not safer self-hosting if you cannot patch Postgres or watch a Docker container. See our [Vaultwarden self-host tutorial](/en/blog/self-host-vaultwarden-tutoriel).

How do you handle employee off-boarding with an enterprise password manager?

**Standard 2026 off-boarding steps**. (1) The IdP turns off the staff account. SCIM then pushes the revoke to the password manager in under 30 seconds. (2) The admin forces rotation of the shared passwords the staff member could reach. Bitwarden Business does it via export then manual rotation. 1Password Business does it via Travel Mode plus rotation. NordPass does it via Activity Log plus force rotation. (3) The audit log keeps the access history for 12-24 months of traceability. (4) The staff member may have had a personal vault under the free Families plan you gave them. The admin can keep or delete it per policy. **SCIM removes most of this risk**. Without SCIM, a ghost account from a staff member who left stays active for weeks or months. It is the #1 risk in B2B password management.

What certifications should you require at a minimum in 2026?

**Minimum stack to require from an enterprise password manager in 2026**. (1) **SOC 2 Type 2**, published and renewed each year. Bitwarden, 1Password, NordPass, Dashlane, Keeper and Proton Pass all have it. (2) **ISO 27001**. Bitwarden, NordPass, Keeper and Dashlane have it. 1Password is in progress. (3) An **independent Cure53 or Insight Risk audit**, published within the last 24 months. (4) A **GDPR-compliant DPA** you can sign directly. (5) A **penetration test report**, available under NDA. Also check more by sector. **HIPAA BAA** for US health. **FedRAMP and FIPS 140-2** for US government. **PCI DSS** for payments. **C5** for Germany cloud security.

How do you handle a breach response with an enterprise password manager?

**Standard incident response plan if a breach hits a password manager vendor**. (1) Turn on required hardware 2FA for all admins right away (WebAuthn or YubiKey), if it is not already on. (2) Force a master password rotation for all staff via admin policy. Use Bitwarden Enterprise master password policies, 1Password recovery, or NordPass force rotation. (3) Check Event Logs over 90 days to spot odd access. (4) Rotate all sensitive shared passwords. This covers system admins, production API keys and prod database credentials. (5) Start your internal breach response. Tell the DPO. Tell the data protection authority within 72 hours if personal data is involved (GDPR Article 33). **Learn from the LastPass 2022 breach**. Never store plain items outside the vault, such as URLs or text notes. Do not do it even if the vendor allows it.

What company size justifies a dedicated password manager vs informal sharing?

**From 5 staff and 10 shared SaaS services**, an enterprise password manager pays for itself. Around **20 staff**, the risk of an internal breach gets hard to ignore. Think of a staff member who left but still has access. Think of Slack or email credential sharing. Think of passwords on Post-its. Breaches cost a lot. The IBM Cost of a Data Breach 2024 puts the **global average at 4.88 M USD**. By comparison, the 3-year B2B cost for 20 staff is 3,600 USD (Bitwarden) to 5,760 USD (1Password). **The ROI is clear from 10 staff** if you handle client data, critical IP, or financial accounts.

Bitwarden Business or Vaultwarden self-host for a 50-employee SME?

**Bitwarden Business at 5 USD/user/month = 250 USD/month (3,000 USD/year)**. **Now the Vaultwarden self-host side**. Hetzner CX22 costs 4,90 EUR/month (60 EUR/year). Add about 4h of initial setup plus 2h of maintenance per month. At 50 EUR/h internal IT, that is a 1,260 EUR/year hidden cost. **Bottom line**: Vaultwarden self-host saves about 1,700 EUR/year. But you take on patching, monitoring and restore. **Practical verdict**: if your IT is already solid (Linux, Docker, monitoring), Vaultwarden is worth it. If your IT is outsourced or thin, pay for Bitwarden Business. You hand the operational risk to Bitwarden. You also keep the Enterprise audit logs. Details in our [Vaultwarden self-host tutorial](/en/blog/self-host-vaultwarden-tutoriel).