Survey. Self-reported by a sample. Read it as what this population says it does, not as a measurement of what it does.
The range is the useful part, not the average. A buying group of five is a decision. A buying group of sixteen is a negotiation between four functions who each measure success differently, and the vendor is not a party to it.
Security purchases sit at the upper end for a structural reason. A security tool touches identity, so IT is in. It processes data, so privacy and legal are in. It has a contract and a renewal, so procurement is in. It needs to be operated, so the security team is in. And it needs an architecture sign-off, so somebody who will never speak to the vendor gets asked for a private opinion.
For a buyer, the practical consequence is that consensus is the constraint, not conviction. Most security evaluations do not fail because the product was wrong. They fail because two of the four functions never reached the same view and the purchase quietly lost its slot.
What this does not mean
This does not mean bigger committees make worse decisions. Gartner's own research points the other way on quality when the group functions well. It also does not support a specific committee size for cybersecurity: the widely repeated claim that security committees run eight to fifteen people is a synthesis by third-party marketers, not a figure Gartner publishes for the security category. Treat the five-to-sixteen range as the documented one and anything narrower as an estimate.
Take this to your board
Gartner puts a B2B buying group at five to sixteen people drawn from as many as four functions, and a security purchase sits at the upper end because it pulls in legal, privacy, procurement, and architecture.
Say the peer figure and your own in the same breath. A number without a comparison invites the board to supply one from memory.
Sources
Every external figure on this page, with its origin, sample, and the date it was last checked by hand.
Gartner describes the modern B2B buying group as ranging from five to sixteen people drawn from as many as four functions, each carrying different priorities and evaluating in parallel.
Gartner's public sales-insight page summarizes findings whose underlying survey detail sits behind a client paywall. The range is quoted as published; no sample size is stated publicly. Secondary reporting commonly cites a median of eleven for enterprise technology purchases above $100,000, which is consistent with but not identical to this range.
Common questions
How many people are involved in a B2B software purchase?
Gartner puts the modern B2B buying group at five to sixteen people drawn from as many as four functions. Secondary reporting of Gartner's research commonly cites a median near eleven for enterprise technology purchases above $100,000 of annual contract value, with the largest and most complex deals reaching twenty.
Why are security buying committees so large?
Because a security tool crosses more internal boundaries than most software. It touches identity and infrastructure, which brings in IT. It processes data, which brings in privacy and legal. It carries a contract, which brings in procurement. And it needs an architecture review, which brings in an engineer who never joins a sales call.
Does a larger buying committee make a purchase less likely?
Secondary reporting of Gartner's research suggests each additional stakeholder reduces the probability of purchase, and Gartner separately found that 74% of buying teams experience unhealthy conflict while deciding. Size alone is not the cause; the difficulty is that every added function brings another party who can object and none who can approve alone.