CyberArk licensing is the set of terms under which CyberArk sells identity security software: privileged access management, endpoint privilege management, vendor and remote access, secrets management, workforce identity and the machine identity products that came from Venafi. Palo Alto Networks announced the completion of its acquisition of CyberArk on 2026-02-11 and stated that CyberArk’s identity security solutions remain available as a standalone platform.[1] The current contract documents name “Palo Alto Networks Ltd. (formerly CyberArk Software Ltd.)” and its Affiliates as the contracting CyberArk entity.[2] The documentation site, now titled Idira Docs, describes the products with the Idira name, for example “Idira PAM - Self-Hosted” and “Idira Identity”.[3][4]
CyberArk publishes no public price list and no part numbers. Quantities and terms come from the Order, an accepted CyberArk quote or purchase order that sets the products, quantities, pricing, payment terms and expiration date.[2] What the public documents do state is the licence type or metric that a product consumes, and those documents are the reference for building a licence position.
Editions
CyberArk’s licensing splits first by deployment model. SaaS Products are governed by the SaaS Terms of Service. Self-Hosted Software, meaning CyberArk’s proprietary software that the customer installs, is governed by the Software License Agreement.[5][2] Both documents grant access or a licence for the customer’s and its Affiliates’ internal business purposes, in accordance with the Documentation and in the quantity specified in the Order.[5][2]
| Product line | Deployment | Unit named in public documents |
|---|---|---|
| Privilege Cloud | SaaS | User licence type (Privileged Basic, Standard, External; Standard Lite discontinued 2025), plus Credential Providers and Total Applications lines[6][7] |
| PAM - Self-Hosted (Vault, PVWA, CPM, PSM) | Self-hosted | Vault user type from the licence file; concurrent PSM sessions[8][9] |
| Endpoint Privilege Manager | SaaS | EPM for Workstation and EPM for Server licence per endpoint; concurrent active agents for non-persistent VDI[10] |
| Remote Access | SaaS | Users, Vendors, monthly active Vendors and monthly sessions in the tenant licence[11] |
| Certificate Manager - SaaS | SaaS | Secured Certificate Instance; Standard or Enterprise package plus add-ons[12][13] |
| Zero Touch PKI | SaaS | Active certificates[14] |
| Trust Protection Platform | Self-hosted | Trust Force licence per provisioning endpoint; managed certificates in the Licensing Report[15][16] |
| Secrets Manager, Credential Providers, Secrets Hub, Workforce Password Management, Identity, Identity Governance | SaaS or self-hosted | No licensing metric stated on the public pages retrieved[17][18][19][20][21][22] |
Secrets Manager runs either as a fully managed SaaS service or self-hosted in the customer’s data center.[17] The Secrets Manager - SaaS documentation tells administrators that a Usage page shows how many secrets are in the tenant, but it does not say that secrets are the licensed unit.[23] Treat the Order as the only source for the Secrets Manager metric.
Product names changed with the integration of Venafi. TLS Protect Cloud is now Certificate Manager - SaaS, TLS Protect for Kubernetes is Certificate Manager for Kubernetes and Venafi Firefly is Workload Identity Manager; references to Venafi remain in code, file paths and screenshots.[24]
Metrics
The metrics below are the ones the documentation defines. Each links to its catalog row.
| Metric | Product | What it counts |
|---|---|---|
| Privileged Standard User, Privileged Basic User, Privileged External User | Privilege Cloud | A licence is in use when a user is connected using it or is added to a Safe using it; the user’s role selects the licence.[6][7] |
| Vault user type | PAM - Self-Hosted | Users by type (EPVUser, BizUser, PSMUser, AIMAccount, OPMUser) as defined by the licence.[8] |
| EPM for Workstation licence, EPM for Server licence | Endpoint Privilege Manager | One designated endpoint, or one server serving multiple users.[10] |
| Remote Access subscription licence, Remote Access monthly active Vendor | Remote Access | Licences consumed by users and Vendors, and Vendors active in a calendar month.[11] |
| Secured Certificate Instance (SCI) | Certificate Manager - SaaS | A certificate that is assigned, lifecycle-managed, monitored or installed, counted once per installation location.[25] |
| Zero Touch PKI active certificate | Zero Touch PKI | Certificates issued, not revoked and not expired.[14] |
| Trust Force endpoint licence | Trust Protection Platform | One licence for each endpoint that Agentless Provisioning installs to.[15] |
Counting and floors
CyberArk publishes few floors. The documents that do state a number are the following.
- Endpoint Privilege Manager counts agents that are active or have been inactive for up to seven days, and allows a total of active and inactive endpoints up to three times the licensed number before new endpoints cannot connect.[10]
- The Privilege Cloud user licence counts are configured in the tenant at set-up, and the Setup space shows licences in use out of total per licence type for Privilege Cloud and Idira Identity.[6][4]
- In PAM - Self-Hosted the Vault warns one week before the licence expires and, by default, at 85, 90 and 99 percent of the licensed users of each type.[9]
- A certificate counted by Certificate Manager - SaaS is evaluated contractually each day at a fixed UTC time and the platform does not enforce the entitlement.[25]
For the Privileged Basic User licence the documentation adds a use restriction rather than a count: the licence is not licensed to perform Privileged Session Manager connections, so permissions that allow it must be removed.[7]
Virtualization and partitioning
Only one product has a published virtualization rule. For Endpoint Privilege Manager, sets of non-persistent virtual desktops are checked by the number of concurrent active agents, while full protection and credentials rotation sets are checked by the number of registered agents.[10] The documents retrieved contain no processor, core or hypervisor-based rules for the self-hosted products, whose limits come from the licence file and the Order.[9]
Cloud and self-hosted
CyberArk does not publish a bring-your-own-licence programme for public cloud. The deployment choice is between SaaS and self-hosted. For SaaS, access ends with the Subscription Term and data is deleted within the period stated in the documentation or, if none, within 60 days of termination or expiry, with no obligation to retain it beyond 40 days.[5] For services on the shared services platform, an expired entitlement leads to suspension, and the service and its data are retained for a minimum of seven days before permanent removal.[4] PAM - Self-Hosted runs on a licence file installed in the Vault, with supported versions defined by an end-of-life policy.[3]
A subscription Self-Hosted or SaaS licence includes support unless the Order says otherwise.[2] Customers converting perpetual self-hosted licences to subscription or SaaS licences see the perpetual licences and their associated support terminated under the terms of the Order.[2][5]
Programs
- Support options. Production, Premium, Platinum and Trusted (US only) set different response times; a customer that does not renew an enhanced option reverts to Production Support.[26]
- Managed Services Provider licence. An amending agreement under which a provider operates the software for a designated Tenant.[27]
- Self-Hosted end-of-life policy. Long Term Support and Standard Term Support versions with fee-based extension of the support period for LTS versions.[3]
- Trials. Trial Versions and Trial Services are for internal evaluation only.[2][5]
- Indirect Orders. Orders placed with a Channel Partner are priced between the partner and the customer.[2]
Details for these programmes are in CyberArk contract, support and lifecycle terms.
Audits and compliance
The Software License Agreement lets CyberArk review use of Self-Hosted Software against fee requirements, licensing parameters and metrics, and, not more than once per year on reasonable notice, request licence usage reports if they are reasonably accessible. If CyberArk reasonably determines that the customer used more than the purchased number or type of licences, CyberArk or its Channel Partner invoices the additional use.[2] For SaaS, a customer that exceeds licensed quantities must cooperate to resolve the non-compliance, which may include paying overages at then-current rates.[5] The product-level self-assessment tools are the Privilege Cloud user licences report, the Vault License Capacity report, the EPM licence page and the Certificate Manager - SaaS Licensing page.[6][9][10][28]
Out of scope
This overview does not cover pricing, discounts or part numbers, none of which CyberArk publishes. It does not cover Palo Alto Networks products, which are described in Palo Alto Networks licensing. Workforce Identity, Identity Governance, Secrets Manager, Secrets Hub and Credential Providers are named above without a metric because the public pages retrieved on 2026-10-07 state none.