You can buy CrowdStrike Falcon in an afternoon.
Operating it is the other purchase.
On 13 August 2026 CrowdStrike extended Project QuiltWorks to small and mid-sized businesses through the channel. Here is what that actually changes for a company of 25 to 250 people, in plain English, with sources.
Project QuiltWorks is CrowdStrike's coordinated framework for securing frontier AI risk. On 13 August 2026 CrowdStrike extended it to SMBs worldwide through Arrow Electronics, Ignition Technology, Nord Security, Pax8, TD SYNNEX, Westcon-Comstor and Zip Security, reaching smaller organizations through distributors, cloud marketplaces and MSP partners rather than a direct sales motion.
There is no employee-count eligibility threshold. Anyone quoting "250 employees or fewer" as a QuiltWorks rule is quoting something CrowdStrike never published.
What the expansion changes is access. What it does not change is who operates the platform once you have it. CrowdStrike's own announcement is direct about this: most SMBs lack the resources and expertise to access and operationalize these capabilities on their own, and the channel is how they get there. Vijilan is a CrowdStrike Powered Service Provider that operates exactly that layer: our stack, our SOC, our analysts on your alerts.
CrowdStrike described the gap
on its own letterhead.
“Most SMBs lack the resources and expertise to access and operationalize these capabilities on their own.”
“The channel is how QuiltWorks can reach every organization, regardless of size, sector, or geography.”
We do not have to argue the premise. The vendor building the platform has already said that smaller organizations need help operating it, and that partners are how they get it. Read the announcement.
Why this lands differently
above about a hundred devices.
Falcon Go stops at 100 devices
CrowdStrike’s own small-business page states that purchases of Falcon Go are limited to a maximum of 100 devices. A 140-person company cannot buy the SMB product. They move to Falcon Pro or Falcon Enterprise, sold per device, and the question of who operates it does not come with the license.
Source: crowdstrike.com/pricing/falcon-go · checked 21 September 2026
The tools ship. The operator does not.
Falcon Go lists at $7.99 per device per month or $59.99 per year, Falcon Pro at $14.99 or $99.99, Falcon Enterprise at $19.99 or $184.99. Every one of those is a license to excellent software. None of them is a person awake at 3am on a Sunday when something fires.
Source: crowdstrike.com/pricing · checked 21 September 2026
CrowdStrike routed the answer through the channel
The SMB expansion reaches smaller organizations through distributors, cloud marketplaces and MSP networks rather than through a direct CrowdStrike SMB motion. The operating layer is explicitly delivered by partners. Vijilan is a CrowdStrike Powered Service Provider already operating that layer.
Source: CrowdStrike press release, 13 August 2026 · checked 21 September 2026
CrowdStrike list pricing moves. These figures were checked on 21 September 2026 and are re-checked quarterly. Confirm current pricing with CrowdStrike or your distributor before you budget against it.
25 to 250 people,
and that is our line, not CrowdStrike's.
Vijilan defines its SMB segment as organizations of 25 to 250 employees. That is a Vijilan segment definition. CrowdStrike has published no employee-count eligibility gate for QuiltWorks or any SMB program, and we will not invent one for them.
The sharpest fit sits between roughly 100 and 250 people, for the reason in fact 01: above the Falcon Go device cap, and below the headcount that justifies hiring three analysts to cover three shifts, every day, including the holidays and the month somebody leaves.
Below 25, the honest answer is usually a good MSP with an EDR they actually watch. Above 250, the conversation is normally about correlating telemetry beyond the endpoint, which is where NextDefend™ starts rather than ThreatDefend.
The disclosures,
in plain sight.
Vijilan is not in QuiltWorks.
We are not named in any QuiltWorks release and are not a member, partner or participant. We are a CrowdStrike Powered Service Provider, which is a partner-program designation, and we comment on QuiltWorks in that capacity.
CrowdStrike is not too expensive.
It is not, and saying so would insult a platform we sell every day. The gap is operational, not commercial.
You do not need to skip Falcon.
We sell Falcon. ThreatDefend™ is our stack and our SOC, and Falcon is in it. This page is about what happens after the license, not instead of it.
There is no 250-employee QuiltWorks rule.
No CrowdStrike source states one. Where you see that number here it is our own segment definition, labelled as such.
Not a dashboard you log into.
An operator who answers.
ThreatDefend™ is Vijilan’s stack and Vijilan’s SOC. We bring CrowdStrike Falcon, deploy it, and run it: Tier 1 through Tier 3 analysts on every alert. When something is real we act, rather than forwarding it to you with a severity label. Host isolation, account disable, token revoke, process kill, then a forensics report that says what happened and what we did.
Identity is included from the entry tier, which is not the norm. Dark web exposure, impossible travel, MFA fatigue, business email compromise, OAuth abuse and lateral movement across Active Directory, Entra ID and Microsoft 365. Identity is how smaller organizations actually get breached, and it is frequently the thing an entry-tier managed service leaves out.
Praxis AI™ investigates, correlates and triages at machine speed. A trained analyst authorizes every consequential action. Never autonomous-only, and that is a design decision about accountability rather than a gap we are closing.
Before any of this is a decision, see what is already exposed.
ThreatAssess™ is a free external attack surface assessment. Give us a domain, no agent and no credit card, and see what an attacker sees when they look at you today. It is the honest place to start, and it prices the conversation against what is actually there rather than a guess.
ISO/IEC 27001 Certified · SOC 2 Type II Audited · CrowdStrike Powered Service Provider (CPSP)
SOC 2 Type II independently audited annually. HIPAA, PCI and CMMC L2 evidence packs available on request.
The ones people
actually ask.
What is CrowdStrike Project QuiltWorks?
Project QuiltWorks is CrowdStrike’s coordinated framework for securing frontier AI risk, launched in April 2026. On 13 August 2026 CrowdStrike extended it to small and mid-sized businesses worldwide through Arrow Electronics, Ignition Technology, Nord Security, Pax8, TD SYNNEX, Westcon-Comstor and Zip Security, making it available via distributors, cloud marketplaces and MSP partners rather than a direct SMB sales motion.
Is there a company size limit for Project QuiltWorks?
No. CrowdStrike has published no employee-count eligibility threshold for QuiltWorks. If you see "250 employees or fewer" quoted as a QuiltWorks rule, it is not one. Vijilan uses 25 to 250 employees as its own definition of the SMB segment for this program, which is a Vijilan segment definition and nothing to do with CrowdStrike eligibility.
Is Vijilan part of Project QuiltWorks?
No. Vijilan is not named in any QuiltWorks release and is not a member, partner or participant in the program. Vijilan is a CrowdStrike Powered Service Provider, which is a CrowdStrike partner-program designation, and comments on QuiltWorks in that capacity.
What does the QuiltWorks SMB expansion actually change for a 150-person company?
Access, not operation. It puts AI-driven vulnerability discovery, prioritization and expert-led remediation within reach of smaller organizations through the channel. What it does not do is staff the seat that reads the console at 3am. CrowdStrike said as much in its own announcement: most SMBs lack the resources and expertise to access and operationalize these capabilities on their own.
We already bought CrowdStrike Falcon. What is missing?
Usually nothing about the platform and everything about the hours around it. Falcon detects; somebody has to decide and act. The practical test is to look at the last real detection in your console and ask what happened next, who decided, and how long it took. If the answer is that it waited for Monday, that is the gap ThreatDefend fills.
Does Falcon Complete already cover this?
Falcon Complete is genuinely excellent and it responds on the endpoint. The differences that matter for an SMB are scope and price rather than quality: ThreatDefend covers identity from the entry tier, and NextDefend extends correlation and containment past the endpoint into cloud, SaaS, network and identity telemetry. They are complements, and the honest way to choose is to put both scopes side by side.
Selling Falcon into SMB accounts
with no delivery arm attached?
We operate the SOC behind your brand and we never compete with our partners for their clients. White-label delivery, bi-directional PSA ticketing, and a repeatable Deploy, Sustain and Operate scope you can attach to a Falcon quote.