---
title: "Calico Commercial Editions"
source: "https://www.tigera.io/tigera-products/calico-commercial-editions/"
description: "Compare Calico's commercial editions, Calico Enterprise and Calico Cloud, for advanced Kubernetes networking, security, observability, and compliance."
---

Product

# Calico Commercial Editions

Unified Network Security & Observability for Kubernetes

[Start Free](https://www.calicocloud.io/)
[Request a Demo](https://www.tigera.io/demo/)

![Calico diagram illustrating unified network security and observability for Kubernetes across various distributions and data planes](https://www.tigera.io/app/uploads/2026/01/Hero-Calico-diagram-1200x628-04.png)

Jump to

- Benefits

- Partners

- Architecture

- Capabilities

- Cloud Marketplace

- Key Features

- How It Works

- Testimonials

- Resources

- Get Started

## Benefits

Calico provides a single network security and observability solution for any Kubernetes distribution in the cloud, on-premises or at the edge. Deploy as a self-managed Calico Enterprise or a fully-managed Calico Cloud SaaS.

![A gear icon with a checkmark.](https://www.tigera.io/app/uploads/2023/05/icon-Configuration-Security.svg)

### A single, unified platform for all K8s network security & observability needs

![A padlock icon for consistent network security.](https://www.tigera.io/app/uploads/2025/04/icon-security-lock-84x84-1.svg)

### Consistent network security controls for any Kubernetes distribution

![Network icon](https://www.tigera.io/app/uploads/2024/05/icon-networking.svg)

### Extends network security to multi-cluster applications, VMs & bare-metal

## Trusted by Customers Worldwide

[![Orange logo](https://www.tigera.io/app/uploads/2022/03/logo-Orange.png)](http://www.orange.com/en)

[![Essentra logo](https://www.tigera.io/app/uploads/2022/04/logo-Essentra.png)](https://www.essentra.com/en)

[![Siemens Healthineers logo](https://www.tigera.io/app/uploads/2022/09/logo-siemens-healthineers.png)](https://www.siemens-healthineers.com/)

[![RBC logo](https://www.tigera.io/app/uploads/2024/05/logo-RBC.png)](https://www.rbcroyalbank.com/)

[![Marsh McLennan logo](https://www.tigera.io/app/uploads/2022/03/logo-Marsh-and-McLennan.png)](http://www.mmc.com/)

[![Presidio logo](https://www.tigera.io/app/uploads/2024/05/logo-Presidio.png)](https://www.presidio.com/)

[![Box logo](https://www.tigera.io/app/uploads/2022/03/logo-box.png)](http://www.box.com/home)

[![Nvidia logo](https://www.tigera.io/app/uploads/2024/05/logo-Nvidia.png)](https://www.nvidia.com/)

[![FM Global logo](https://www.tigera.io/app/uploads/2023/03/logo-FM-Global.png)](https://www.fmglobal.com/)

[![Upwork logo](https://www.tigera.io/app/uploads/2022/12/logo-upwork.png)](https://www.upwork.com/)

[![GoDaddy logo](https://www.tigera.io/app/uploads/2023/03/logo-GoDaddy.png)](https://www.godaddy.com/)

[![Arvato Systems logo](https://www.tigera.io/app/uploads/2025/01/logo-Arvato-systems.png)](https://www.arvato-systems.com/)

[![Aldagi logo](https://www.tigera.io/app/uploads/2022/10/logo-aldagi.png)](https://aldagi.ge/en/)

[![NBC Universal logo](https://www.tigera.io/app/uploads/2022/09/logo-NBC-Universal.png)](https://www.nbcuniversal.com/)

[![Chipotle logo](https://www.tigera.io/app/uploads/2024/05/logo-Chipotle.png)](https://www.chipotle.com/)

[![Meridianlink logo](https://www.tigera.io/app/uploads/2022/03/logo-Meridianlink.png)](http://www.meridianlink.com/)

[![Mulligan Funding logo](https://www.tigera.io/app/uploads/2022/03/logo-MulliganFunding.png)](https://www.mulliganfunding.com/)

[![HanseMerkur logo](https://www.tigera.io/app/uploads/2022/03/logo-HanseMerkur.png)](http://www.hmrv.de/en)

[![Fiserv logo](https://www.tigera.io/app/uploads/2022/12/logo-fiserv.png)](https://www.fiserv.com/)

[![Berenberg logo](https://www.tigera.io/app/uploads/2022/03/logo-BERENBERG.png)](http://www.berenberg.de/en/)

[![eHealth logo](https://www.tigera.io/app/uploads/2023/10/logo-eHealth.png)](https://www.tigera.io/ehealth-case-study/)

[![Coinmetrics logo](https://www.tigera.io/app/uploads/2022/03/logo-coinmetrics.png)](http://coinmetrics.io/)

## Architecture

![Diagram showing multi-cloud and hybrid cloud architecture components.](https://www.tigera.io/app/uploads/2025/12/Solution-Architecture-Dec-2025-1.svg)

## Capabilities

Distribution-agnostic solution for Kubernetes network security. Unified solution for ingress, egress, in-cluster and multi-cluster networking.

- High-performance networking

- Network security & observability

- Container networking

- Ingress Gateway

- Egress Gateway & universal firewall integration

- Cluster mesh

- Istio Ambient Mode

#### Container networking

Fast, scalable, and highly available pod-to-pod networking for single and multi-cluster Kubernetes environments.

Choice of data planes, including eBPF, nftables, IP tables, Windows and VPP for network traffic.

Unified networking across hosts, virtual machines, bare metal, and containers for interoperability across clusters and environments.

Data-in-transit encryption with WireGuard for better performance and lower CPU consumption compared to standard encryption approaches.

![Diagram showcasing Tigera Calico's pluggable data planes with eBPF, iptables, nftables, VPP, and Windows options](https://www.tigera.io/app/uploads/2025/07/Pluggable-data-planes-1200x548-1.png)

#### Ingress Gateway

Provides a standardized approach to managing Kubernetes ingress traffic using the Gateway API. Integrates Envoy Gateway, hardened for enterprise use, to provide comprehensive security and observability for ingress traffic.

![Ingress Gateway Diagram](https://www.tigera.io/app/uploads/2025/03/diagram-Calico-Ingress-Gateway.png)

#### Egress Gateway & universal firewall integration

Provides stable, routable IP addresses assigned to egress traffic from a pod or namespace.

Enables firewalls to identify and secure egress traffic from specific workloads and namespaces.

Extends network firewall rules to secure Kubernetes workloads.

![Diagram of a Kubernetes cluster connecting to external resources like the internet, partner APIs, and databases](https://www.tigera.io/app/uploads/2023/10/Destination-Based-Routing-diagram.png)

#### Cluster mesh

Provides pod-to-pod connectivity across clusters.

Enables service discovery of Kubernetes services running across multiple clusters.

Enforces network policies and provides network traffic visibility for local and remote workloads across clusters in a single pane of glass.

#### Istio Ambient Mode

Provides lightweight, sidecarless service-mesh security and traffic control for Kubernetes.

Delivers automatic mTLS authentication and encryption for all service-to-service communication without modifying applications.

Enables advanced traffic management, authorization, and deep application-level observability.

- Egress access controls

- Policy management

- Network threat detection

- Shift left: CI/CD integration

- Network visibility

- Compliance & audit

#### Egress access controls and microsegmentation

Enforces DNS policies and network sets for simplified egress access controls.

Deploys Layer 7 network security policies for application-level protection.

Automatically isolates namespaces to prevent the risk of lateral movement.

Enables microsegmentation based on environments, application tiers, compliance needs, user access, or individual workload requirements.

#### Network policy lifecycle management

Provides a single pane of glass to view, recommend, stage, preview, order, and troubleshoot network security controls across multi-cluster environments.

Enables multiple teams to create security policies using policy tiers and customize the order of enforcement based on organizational structure.

Supports more extensive policies than Kubernetes, including policy ordering, deny rules, DNS names, and IP ranges.

#### Network threat detection

Provides workload-level IDS/IPS that utilizes pre-configured and custom threat intelligence feeds to monitor malicious IPs, domains, and VPNs. Promptly alerts upon receiving traffic from recognized malicious addresses and blocks workloads from accessing them.

Includes a workload-centric WAF that protects ingress and intra-cluster traffic against HTTP-based attacks.

Detects potential DDoS attacks based on intelligent network traffic analysis and prevents them with early packet processing.

#### Shift left: CI/CD integration

Deploys network security policies as code to automate the enforcement of consistent security across the cluster, including any necessary security changes.

Integrates policy deployment with CI/CD tools like ArgoCD, Jenkins, and others.

#### Network visibility, analytics dashboards

Aggregates and correlates flow logs with rich Kubernetes context, including network, DNS, application, service, process, sockets, and audit logs.

Provides fine-grained observability with a graph-based representation of network topology, traffic flows, and network policy enforcement with suspicious event alerts.

Pre-built and custom dashboards to analyze network flow data at the workload-level, such as DNS, L7 (HTTP) traffic, TCP, and flow logs for troubleshooting.

Built-in packet capture for network activity analysis on each workload, for faster troubleshooting with Kubernetes RBAC integration.

#### Compliance & audit

Supports major compliance standards, including PCI DSS, HIPAA, GDPR, SOC 2, NIST, CCPA, and any custom frameworks.

Provides real-time, continuous monitoring to detect compliance violations and leverages automatically generated audit-ready reports.

Author compliance controls as code to continuously collect, correlate, and prepare data to provide proof of compliance at any time. Monitors and logs all changes to compliance policies with Calico.

[See what Calico can do for you Book Live Demo](https://www.tigera.io/demo/)

## Available on Microsoft Azure, AWS, and Google Marketplace

Get started right away on Azure, AWS, or Google Cloud—every Calico component you need to get up and running is ready to go.

[On Azure](https://azuremarketplace.microsoft.com/en-ca/marketplace/apps/tigerainc1620235671643.calicocloudsaas?tab=overview)
[On AWS](https://aws.amazon.com/marketplace/pp/prodview-pq3tgvtlj3wce)
[On Google Cloud](https://console.cloud.google.com/marketplace/product/tigera-public/calico-cloud?inv=1&invt=Ab27_g&project=tigera-public)

![Microsoft Azure, AWS, and Google Cloud logos.](https://www.tigera.io/app/uploads/2025/07/Solution-cloud-marketplace-AWS-Azure-03.svg)

## Key Features

### Networking

![Icon of a hierarchical diagram.](https://www.tigera.io/app/uploads/2024/07/icon-CNI-60x45-2.svg) #### Calico CNI Choose from eBPF, iptables, nftables, or VPP to power scalable, high-performance, secure Kubernetes networking. + More
![Ingress gateway icon with two crossing arrows.](https://www.tigera.io/app/uploads/2025/02/icon-ingress-gateway-3.svg) #### Ingress gateway Securely manage incoming traffic using enterprise-grade ingress controls and load balancing based on Kubernetes Gateway API standards. + More
![Gear icon with a checkmark.](https://www.tigera.io/app/uploads/2024/07/icon-vulnerability-management-60x45-2.svg) #### Egress gateway Secure outbound traffic with fixed, routable IP assignment, policy enforcement, and centralized control over external egress communications. + More
![A mesh of seven connected circles.](https://www.tigera.io/app/uploads/2024/07/icon-cluster-mesh-60x45-2.svg) #### Cluster mesh Streamline cluster mesh operations with complete visibility, security, and networking through a centralized management plane. + More
![Istio logo.](https://www.tigera.io/app/uploads/2025/12/icon-Istio-60x45.svg.svg) #### Istio Ambient Mode Enable lightweight, sidecar-free service mesh capabilities with built-in mTLS encryption and authentication, authorization, advanced traffic control, and deep application visibility. + More
![A WAF icon showing a square with horizontal lines and arrows.](https://www.tigera.io/app/uploads/2024/07/icon-WAF-60x45-2.svg) #### Firewall integrations Connect traditional and cloud-native firewalls with Kubernetes by enabling IP-based firewall enforcement of Kubernetes network policies. + More

### Network Security

![Kubernetes network policy icon.](https://www.tigera.io/app/uploads/2024/07/icon-Kubernetes-network-policy-60x45-2.svg) #### Calico Network Policies Define and enforce traffic control at both the network layer (L3/L4) and application layer (L7) with Kubernetes network and application layer policies. + More
![Security padlock icon with an egress arrow.](https://www.tigera.io/app/uploads/2024/07/icon-egress-access-controls-60x45-2.svg) #### DNS policies & network sets Use DNS names and IP sets to simplify policy rules, enforce DNS security, and monitor DNS-based activity. + More
![Icon of connected circles.](https://www.tigera.io/app/uploads/2024/07/icon-microsegmentation-60x45-2.svg) #### Microsegmentation Enforce fine-grained network security controls between workloads to contain threats and limit lateral movement in Kubernetes. + More
![Document with checkmark inside a circular arrow.](https://www.tigera.io/app/uploads/2024/07/icon-security-policy-management-60x45-2.svg) #### Network policy management Simplify, scale, and automate the creation, testing, and enforcement of Kubernetes network security policies. + More
![Shield outline with an infinity symbol.](https://www.tigera.io/app/uploads/2024/07/icon-shift-left-security-60x45-2.svg) #### Shift left security Proactively scan and fix security policy risks during CI/CD to prevent misconfigurations before they reach production. + More
![Microchip with a padlock icon.](https://www.tigera.io/app/uploads/2024/07/icon-encryption-60x45-2.svg) #### Encryption Encrypt Kubernetes pod-to-pod traffic using high-performance WireGuard for strong in-transit data protection. + More
![Checklist icon with a checkmark.](https://www.tigera.io/app/uploads/2024/07/icon-compliance-and-audit-60x45-2.svg) #### Compliance and audit Continuously monitor, log, assess, and report on Kubernetes network security posture to simplify audits and meet compliance requirements. + More

### Network Threat Detection, Observability and Incident Response

![A WAF icon showing a square with horizontal lines and arrows.](https://www.tigera.io/app/uploads/2024/07/icon-WAF-60x45-2.svg) #### Workload-based IDS/IPS, DDoS, DPI, and WAF Detect threats and block malicious traffic with built-in IDS, WAF, and DDoS protection at the workload level. + More
![A bar graph with an upward arrow.](https://www.tigera.io/app/uploads/2024/07/icon-dynamic-service-threat-graph-60x45-2.svg) #### Dynamic service and threat graph Visualize and troubleshoot traffic flows with real-time service-level visibility into Kubernetes workloads. + More
![Dashboard icon with a globe.](https://www.tigera.io/app/uploads/2024/07/icon-DNS-dashboard-60x45-2.svg) #### Calico Dashboards Dashboards to provide insights and help analyze Kubernetes security, compliance, and network behavior. + More
![A central circle connected to four squares.](https://www.tigera.io/app/uploads/2024/07/icon-dynamic-packet-capture-60x45-2.svg) #### Dynamic packet capture Use self-service, targeted packet capture to diagnose issues and investigate suspicious traffic in Kubernetes. + More

Select a card to see detailed content.

Select a card

Select a card to see detailed content.

[Learn More](https://www.tigera.io/features/packet-capture/)

## How It Works

Calico commercial editions provide high-availability networking and simplified network security for cloud-native applications

[See Tutorials](https://docs.tigera.io/calico-cloud/tutorials/)

## Customer Testimonial

Here’s what our customers are saying about us

![Quotation marks](https://www.tigera.io/app/themes/tigera2021/dist/img/quotes-sign.svg)

Tigera helped Upwork migrate to Kubernetes on Amazon EKS and meet our InfoSec team’s mandate for zero-trust security. We were able to deploy Calico in two weeks and secure our EKS cluster in just six months.

Angelos Lenis

Sr. Manager, Platform Engineering,
Upwork

![Upwork Logo](https://www.tigera.io/app/uploads/2023/10/logo-Upwork-170x60-1.png)

[Learn More](https://www.tigera.io/upwork-case-study/)

[All Customer Stories](https://www.tigera.io/customer-stories/)

## Featured Resources

Developer-created resources to help you secure your Kubernetes deployment

![Calico for Networking, Network Security, and Observability](https://www.tigera.io/app/uploads/2024/05/Featured-resources-Container-Networking-Network-Security.png)

Datasheet

### Calico for Networking, Network Security, and Observability

Learn how Calico can help you achieve networking, network security, and observability for Kubernetes.

[Read More](https://info.tigera.io/rs/805-GFH-732/images/Tigera_Calico_product_datasheet.pdf)

![Interactive Training](https://www.tigera.io/app/uploads/2022/12/Self-paced-workshops-380x200.png)

Workshop

### Interactive Training

In-depth product feature demonstrations showcasing capabilities for Kubernetes networking and security use-cases.

[Read More](https://www.tigera.io/interactive-training/)

![Application Security for Playtech](https://www.tigera.io/app/uploads/2024/06/Featured-resources-Playtech-CS.png)

Case Study

### Application Security for Playtech

Calico seamlessly integrates with Amazon EKS GitOps model to enhance Playtech’s application security.

[Read More](https://www.tigera.io/playtech-case-study/)

![Introducing the Calico eBPF data plane](https://www.tigera.io/app/uploads/2022/06/Calico-eBPF-data-plane-02.png)

Blog

### Introducing the Calico eBPF data plane

Learn more about Calico’s eBPF dataplane for faster, leaner Kubernetes networking.

[Read More](https://www.tigera.io/blog/introducing-the-calico-ebpf-dataplane/)

![How Network Security Policies can Protect Your Environment](https://www.tigera.io/app/uploads/2021/12/cloud-malware-Log4j.png)

Blog

### How Network Security Policies can Protect Your Environment

Find out how network security policies defend against future threats like Log4j.

[Read More](https://www.tigera.io/blog/how-network-security-policies-can-protect-your-environment-from-future-vulnerabilities-like-log4j/)

![8 Best Practices to Secure Your Cluster](https://www.tigera.io/app/uploads/2025/04/Kubernetes-Security-8-Best-Practices-to-Secure-Your-Cluster-Blue-380x200.png)

Learn Guide

### 8 Best Practices to Secure Your Cluster

Learn to implement Kubernetes Security best practices with policies, RBAC, and more for stronger defense.

[Read More](https://www.tigera.io/learn/guides/kubernetes-security/)

![Kubernetes Networking: The Complete Guide](https://www.tigera.io/app/uploads/2021/08/Kubernetes-Networking-The-Complete-Guide-Blue.png)

Learn Guide

### Kubernetes Networking: The Complete Guide

Learn to understand the Kubernetes networking model, services, DNS, and how to implement network policies.

[Read More](https://www.tigera.io/learn/guides/kubernetes-networking/)

[All Resources](https://www.tigera.io/resources/)

![Calico Logo](https://www.tigera.io/app/uploads/2026/01/Calico-logo-2026-black-text.svg)

## Ready to Get Started?

Get started for free or request a demo to see Calico in action

[Start Free](https://www.calicocloud.io/)
[Get a Demo](https://www.tigera.io/demo/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=8907 metric#misses=35 metric#hit-ratio=99.6 metric#bytes=2350735 metric#prefetches=373 metric#store-reads=45 metric#store-writes=72 metric#store-hits=383 metric#store-misses=24 metric#sql-queries=31 metric#ms-total=1033.50 metric#ms-cache=86.73 metric#ms-cache-avg=0.7477 metric#ms-cache-ratio=8.4 -->
