pfSense CE and pfSense Plus differ in release timing, commercial terms and some performance features. Start with Netgate’s published version table to compare release dates, FreeBSD bases and configuration revisions, then check whether your workload needs a Plus-specific feature. Licensing and upgrade eligibility should be checked against Netgate’s current documentation before committing to an edition.
One lineage, two release trains
pfSense CE is the community edition. pfSense Plus is the commercial edition Netgate ships on its own appliances and also sells for third-party hardware and cloud instances. They share a lineage: the version table shows releases with matching FreeBSD bases and configuration schema revisions. Shared ancestry does not make their feature sets identical.
What differs is the schedule. The editions were released in lockstep as recently as February 2021, when CE 2.5.0 and Plus 21.02 both shipped on 17 February 2021 from the same FreeBSD 12.2-STABLE base. They have not been in lockstep since.
The cadence gap, from the table
Count the releases in the version table and the divergence is arithmetic rather than opinion.
| Edition | Releases from 2021 to 2026 (major and minor, excluding patch levels) |
|---|---|
| pfSense Plus | 21.02, 21.05, 22.01, 22.05, 23.01, 23.05, 23.09.1, 24.03, 24.11, 25.07, 25.11, 26.03, 26.07 |
| pfSense CE | 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.7.0, 2.7.1, 2.7.2, 2.8.0, 2.8.1, 2.9.0 |
The single most informative gap in that list sits in the middle of it. CE 2.7.2 was released on 7 December 2023. The next CE feature release, 2.8.0, arrived on 28 May 2025, roughly seventeen and a half months later. During that same window Plus shipped 24.03 on 23 April 2024 and 24.11 on 25 November 2024.
Release timing is one practical difference for anyone running pfSense on their own hardware. Check each release’s notes for the specific driver or fix you need; the edition name alone does not establish when it became available.
The divergence is not permanent, and it has flipped direction
It would be easy to read the gap above as CE being permanently behind. The table does not support that reading.
CE 2.8.0 shipped on 28 May 2025 with the FreeBSD base recorded as 15.0-CURRENT@bf06074106cf. Plus 25.07, carrying the identical base commit, shipped on 4 August 2025, more than two months later. In that cycle the community edition reached the newer base first.
The current cycle runs the other way. Plus 26.07 shipped on 13 August 2026 on 16.0-CURRENT@4bdcff554368. CE 2.9.0 shipped on 20 August 2026 against the same base commit, one week behind Plus. The base is shared; the release timing is not.
So the honest summary is that the two trains run on the same track at different, irregular intervals, and the lead changes hands. Anyone told that one edition is simply “newer” is being sold a version of the table rather than the table.
Configuration revisions decide portability
The column most people skip is the one that matters when hardware changes hands. Each release carries a configuration revision, and it is shared across editions at matching points in the lineage.
| Config revision | pfSense CE | pfSense Plus |
|---|---|---|
| 23.3 | 2.7.1, 2.7.2 | 23.09.1, 24.03 |
| 24.0 | 2.8.0, 2.8.1 | 25.07, 25.07.1 |
| 24.6 | 2.9.0 | 26.07 |
A configuration backup has a schema revision. Netgate’s restore documentation permits restoring the same or an older revision onto a target release; a newer backup cannot generally be restored onto an older target. Matching revisions do not remove the need to check interface assignments and edition-specific settings.
The operational rule that follows is simple. Before restoring a configuration onto replacement hardware or a different edition, check the revision the backup was written at and the revision the target release expects. That check costs a minute and prevents the most common bad afternoon in a firewall migration.
Keep workload capacity separate from installation prerequisites
Netgate publishes a shared minimum-requirements page for pfSense software. That installation floor does not promise equal VPN throughput across editions: available acceleration features and compatible hardware still matter.
Budget the state table, inspection engine and network buffers using pfSense workload sizing for VPN, IDS and state tables. Then use the pfSense throughput bottleneck guide to distinguish resource capacity from the processing limit on a particular traffic path.
Check CE and Plus features for your workload
Two documented examples make the feature question concrete. OpenVPN DCO requires Plus 22.05 or later and is unavailable on CE. Netgate’s accelerator documentation also marks IPsec-MB and QAT support as Plus-only. DCO has tunnel compatibility limits; acceleration depends on the hardware and algorithms involved. Check these details before assuming an edition change will improve a VPN.
How to check this yourself
The release and configuration tables above come from Netgate’s version list, checked for this update on 6 September 2026. Read that list alongside the feature and migration documentation because each answers a different part of the decision.
The version list has four columns worth attention. Released gives the release date for a cadence comparison. FreeBSD Version identifies the base commit. Config Rev identifies the configuration schema used for backup compatibility. Branch identifies the source branch, which helps describe the installed build when reporting a problem.
Compare dates rather than version numbers: Plus uses a year-and-month scheme and CE uses a sequential one. Use the base commit to understand the lineage, then consult the release notes for a particular driver change. A matching base commit alone is not evidence that every module and feature is available in both editions.
Check pfSense Plus licensing and cost
Plus is the edition attached to Netgate’s commercial support subscriptions and to its appliance line. CE is supported by the community, principally through the Netgate forum, which is also where the documentation itself directs users with software problems.
Licensing terms for running Plus on hardware Netgate did not sell have changed more than once, and any specific figure quoted in an article ages badly. Netgate’s own product and pricing pages are the only authority worth acting on, and they should be checked at the moment of purchase rather than trusted from a summary.
Before upgrading pfSense CE to Plus
Read Netgate’s CE-to-Plus migration procedure and export a configuration backup first. The documented path requires CE 2.6.0 or later, internet connectivity and an activation token from the store. Migration preserves the existing filesystem, so it does not convert UFS to ZFS. Check backup compatibility and recovery options before starting; these prerequisites are not a substitute for the complete vendor procedure.
How to choose
Buying a Netgate appliance settles it. The appliance ships with Plus and is tuned for that combination; the edition question never comes up.
For your own hardware, choose by required features, support and the releases available for your device. Plus is relevant when you need a documented Plus-only acceleration feature or commercial support. CE remains an option when its available features and community support meet the requirement. The historical cadence does not guarantee a future release date, so check the current release notes for either edition.
For an existing performance problem, start with finding the real bottleneck behind slow pfSense speeds. Then use the pfSense throughput and state-table sizer for a memory estimate and planning tiers. It does not model edition-specific acceleration or predict the speed gain from an upgrade.
Common mistakes
Treating release cadence as the only difference and overlooking acceleration features. Assuming one edition is permanently ahead, when the lead has changed hands between cycles. Restoring a configuration backup without checking its revision. Quoting licence pricing from a secondary source instead of the vendor page. Expecting an edition change to repair a physical-link problem or remove a state-memory limit.