The range is the useful part, not the average. A buying group of five is a decision. A buying group of sixteen is a negotiation between four functions who each measure success differently, and the vendor is not a party to it.

Security purchases sit at the upper end for a structural reason. A security tool touches identity, so IT is in. It processes data, so privacy and legal are in. It has a contract and a renewal, so procurement is in. It needs to be operated, so the security team is in. And it needs an architecture sign-off, so somebody who will never speak to the vendor gets asked for a private opinion.

For a buyer, the practical consequence is that consensus is the constraint, not conviction. Most security evaluations do not fail because the product was wrong. They fail because two of the four functions never reached the same view and the purchase quietly lost its slot.