LICENSEWARE

CyberArk licensing

This article is an overview of how CyberArk, now part of Palo Alto Networks and branded Idira in newer documents, licenses its privileged access, endpoint privilege, remote access, secrets and machine identity products. Deeper articles cover privileged access management, Endpoint Privilege Manager, certificate and machine identity licensing, and the contract, support and lifecycle terms. It is not legal advice.

On This Page

CyberArk licensing is the set of terms under which CyberArk sells identity security software: privileged access management, endpoint privilege management, vendor and remote access, secrets management, workforce identity and the machine identity products that came from Venafi. Palo Alto Networks announced the completion of its acquisition of CyberArk on 2026-02-11 and stated that CyberArk’s identity security solutions remain available as a standalone platform.[1] The current contract documents name “Palo Alto Networks Ltd. (formerly CyberArk Software Ltd.)” and its Affiliates as the contracting CyberArk entity.[2] The documentation site, now titled Idira Docs, describes the products with the Idira name, for example “Idira PAM - Self-Hosted” and “Idira Identity”.[3][4]

CyberArk publishes no public price list and no part numbers. Quantities and terms come from the Order, an accepted CyberArk quote or purchase order that sets the products, quantities, pricing, payment terms and expiration date.[2] What the public documents do state is the licence type or metric that a product consumes, and those documents are the reference for building a licence position.

Editions

CyberArk’s licensing splits first by deployment model. SaaS Products are governed by the SaaS Terms of Service. Self-Hosted Software, meaning CyberArk’s proprietary software that the customer installs, is governed by the Software License Agreement.[5][2] Both documents grant access or a licence for the customer’s and its Affiliates’ internal business purposes, in accordance with the Documentation and in the quantity specified in the Order.[5][2]

Product line Deployment Unit named in public documents 
Privilege Cloud SaaS User licence type (Privileged Basic, Standard, External; Standard Lite discontinued 2025), plus Credential Providers and Total Applications lines[6][7] 
PAM - Self-Hosted (Vault, PVWA, CPM, PSM) Self-hosted Vault user type from the licence file; concurrent PSM sessions[8][9] 
Endpoint Privilege Manager SaaS EPM for Workstation and EPM for Server licence per endpoint; concurrent active agents for non-persistent VDI[10] 
Remote Access SaaS Users, Vendors, monthly active Vendors and monthly sessions in the tenant licence[11] 
Certificate Manager - SaaS SaaS Secured Certificate Instance; Standard or Enterprise package plus add-ons[12][13] 
Zero Touch PKI SaaS Active certificates[14] 
Trust Protection Platform Self-hosted Trust Force licence per provisioning endpoint; managed certificates in the Licensing Report[15][16] 
Secrets Manager, Credential Providers, Secrets Hub, Workforce Password Management, Identity, Identity Governance SaaS or self-hosted No licensing metric stated on the public pages retrieved[17][18][19][20][21][22] 

Secrets Manager runs either as a fully managed SaaS service or self-hosted in the customer’s data center.[17] The Secrets Manager - SaaS documentation tells administrators that a Usage page shows how many secrets are in the tenant, but it does not say that secrets are the licensed unit.[23] Treat the Order as the only source for the Secrets Manager metric.

Product names changed with the integration of Venafi. TLS Protect Cloud is now Certificate Manager - SaaS, TLS Protect for Kubernetes is Certificate Manager for Kubernetes and Venafi Firefly is Workload Identity Manager; references to Venafi remain in code, file paths and screenshots.[24]

Metrics

The metrics below are the ones the documentation defines. Each links to its catalog row.

Metric Product What it counts 
Privileged Standard User, Privileged Basic User, Privileged External User Privilege Cloud A licence is in use when a user is connected using it or is added to a Safe using it; the user’s role selects the licence.[6][7] 
Vault user type PAM - Self-Hosted Users by type (EPVUser, BizUser, PSMUser, AIMAccount, OPMUser) as defined by the licence.[8] 
EPM for Workstation licence, EPM for Server licence Endpoint Privilege Manager One designated endpoint, or one server serving multiple users.[10] 
Remote Access subscription licence, Remote Access monthly active Vendor Remote Access Licences consumed by users and Vendors, and Vendors active in a calendar month.[11] 
Secured Certificate Instance (SCI) Certificate Manager - SaaS A certificate that is assigned, lifecycle-managed, monitored or installed, counted once per installation location.[25] 
Zero Touch PKI active certificate Zero Touch PKI Certificates issued, not revoked and not expired.[14] 
Trust Force endpoint licence Trust Protection Platform One licence for each endpoint that Agentless Provisioning installs to.[15] 

Counting and floors

CyberArk publishes few floors. The documents that do state a number are the following.

  • Endpoint Privilege Manager counts agents that are active or have been inactive for up to seven days, and allows a total of active and inactive endpoints up to three times the licensed number before new endpoints cannot connect.[10]
  • The Privilege Cloud user licence counts are configured in the tenant at set-up, and the Setup space shows licences in use out of total per licence type for Privilege Cloud and Idira Identity.[6][4]
  • In PAM - Self-Hosted the Vault warns one week before the licence expires and, by default, at 85, 90 and 99 percent of the licensed users of each type.[9]
  • A certificate counted by Certificate Manager - SaaS is evaluated contractually each day at a fixed UTC time and the platform does not enforce the entitlement.[25]

For the Privileged Basic User licence the documentation adds a use restriction rather than a count: the licence is not licensed to perform Privileged Session Manager connections, so permissions that allow it must be removed.[7]

Virtualization and partitioning

Only one product has a published virtualization rule. For Endpoint Privilege Manager, sets of non-persistent virtual desktops are checked by the number of concurrent active agents, while full protection and credentials rotation sets are checked by the number of registered agents.[10] The documents retrieved contain no processor, core or hypervisor-based rules for the self-hosted products, whose limits come from the licence file and the Order.[9]

Cloud and self-hosted

CyberArk does not publish a bring-your-own-licence programme for public cloud. The deployment choice is between SaaS and self-hosted. For SaaS, access ends with the Subscription Term and data is deleted within the period stated in the documentation or, if none, within 60 days of termination or expiry, with no obligation to retain it beyond 40 days.[5] For services on the shared services platform, an expired entitlement leads to suspension, and the service and its data are retained for a minimum of seven days before permanent removal.[4] PAM - Self-Hosted runs on a licence file installed in the Vault, with supported versions defined by an end-of-life policy.[3]

A subscription Self-Hosted or SaaS licence includes support unless the Order says otherwise.[2] Customers converting perpetual self-hosted licences to subscription or SaaS licences see the perpetual licences and their associated support terminated under the terms of the Order.[2][5]

Programs

  • Support options. Production, Premium, Platinum and Trusted (US only) set different response times; a customer that does not renew an enhanced option reverts to Production Support.[26]
  • Managed Services Provider licence. An amending agreement under which a provider operates the software for a designated Tenant.[27]
  • Self-Hosted end-of-life policy. Long Term Support and Standard Term Support versions with fee-based extension of the support period for LTS versions.[3]
  • Trials. Trial Versions and Trial Services are for internal evaluation only.[2][5]
  • Indirect Orders. Orders placed with a Channel Partner are priced between the partner and the customer.[2]

Details for these programmes are in CyberArk contract, support and lifecycle terms.

Audits and compliance

The Software License Agreement lets CyberArk review use of Self-Hosted Software against fee requirements, licensing parameters and metrics, and, not more than once per year on reasonable notice, request licence usage reports if they are reasonably accessible. If CyberArk reasonably determines that the customer used more than the purchased number or type of licences, CyberArk or its Channel Partner invoices the additional use.[2] For SaaS, a customer that exceeds licensed quantities must cooperate to resolve the non-compliance, which may include paying overages at then-current rates.[5] The product-level self-assessment tools are the Privilege Cloud user licences report, the Vault License Capacity report, the EPM licence page and the Certificate Manager - SaaS Licensing page.[6][9][10][28]

Out of scope

This overview does not cover pricing, discounts or part numbers, none of which CyberArk publishes. It does not cover Palo Alto Networks products, which are described in Palo Alto Networks licensing. Workforce Identity, Identity Governance, Secrets Manager, Secrets Hub and Credential Providers are named above without a metric because the public pages retrieved on 2026-10-07 state none.

References

  1. Palo Alto Networks Completes Acquisition of CyberArk to Secure the AI EraCompletion of the acquisition, dated 2026-02-11.Effective 2026-02-11. Retrieved 2026-10-07.
  2. CyberArk Software License Agreement (Global), Rev. 10 September 2026Sections 1 (licence, review, restrictions), 2 (payment, Indirect Orders), 8, 9, 10, 12 and 18. Rev. 10 September 2026.Effective 2026-09-10. Retrieved 2026-10-07.
  3. Self-hosted products end-of-life policy (Idira Docs)Support Period, Development Period, LTS and STS. Dates as shown on 2026-10-07.Retrieved 2026-10-07.
  4. Check capacity and licensing (Setup space, Idira Docs)Licence usage page and service entitlement lifecycle. Undated.Retrieved 2026-10-07.
  5. CyberArk SaaS Terms of Service (Global), Rev. 10 September 2026Sections 1, 2, 13 and definitions. Rev. 10 September 2026.Effective 2026-09-10. Retrieved 2026-10-07.
  6. Privilege Cloud user licenses report (Idira Docs)Licence types and when a licence is in use. Undated.Retrieved 2026-10-07.
  7. Review ISPSS user roles (Idira Docs)Role to licence mapping; Basic, Lite and External licences. Undated.Retrieved 2026-10-07.
  8. Understand user and group management (PAM - Self-Hosted, Idira Docs)Vault user types defined by the licence. Undated.Retrieved 2026-10-07.
  9. Manage the Idira License (PAM - Self-Hosted, Idira Docs)Licence file, monitoring thresholds, License Capacity report. Undated.Retrieved 2026-10-07.
  10. Manage your EPM license (Idira Docs)Workstation and Server licences, usage, overuse, expiry. Undated.Retrieved 2026-10-07.
  11. Manage licensing (Remote Access, Idira Docs)Tenant licence details and consumption rules. Undated.Retrieved 2026-10-07.
  12. Understanding licensing in Certificate Manager - SaaS (Machine Identity Security Docs)SCI metric, entitlement, plan, 2024 model change. Undated.Retrieved 2026-10-07.
  13. Certificate Manager - SaaS packages and add-ons (Machine Identity Security Docs)Standard and Enterprise packages and add-ons. Undated.Retrieved 2026-10-07.
  14. About licensing in Zero Touch PKI (Machine Identity Security Docs)Active certificate metric. Undated.Retrieved 2026-10-07.
  15. Venafi Trust Protection Platform 25.1 Installation and Upgrade GuideTrust Force licence; licence telemetry. Version 25.1.Retrieved 2026-10-07.
  16. Venafi Trust Protection Platform 25.1 Product Overview GuideUnassigned certificates and the Licensing Report. Version 25.1.Retrieved 2026-10-07.
  17. Idira Secrets Management product pageDeployment options for Secrets Manager. Undated.Retrieved 2026-10-07.
  18. Idira Application Credentials Delivery product pageCredential Providers platform coverage. Undated.Retrieved 2026-10-07.
  19. Idira Unified Secrets Governance product pageSecrets Hub capabilities. Undated.Retrieved 2026-10-07.
  20. Idira Workforce Password Management product pageWorkforce Password Management capabilities. Undated.Retrieved 2026-10-07.
  21. Idira Identity and Access Management product pageWorkforce identity capabilities. Undated.Retrieved 2026-10-07.
  22. Idira Identity Governance product pageIdentity governance capabilities. Undated.Retrieved 2026-10-07.
  23. Secrets Manager - SaaS documentation: workload identity and fetching secrets (Idira Docs)Workload identity concepts; Usage page for secrets. Undated.Retrieved 2026-10-07.
  24. CyberArk rebranding updates (Machine Identity Security Docs)Venafi to CyberArk product names. Undated.Retrieved 2026-10-07.
  25. How license usage is calculated using Secured Certificate Instances (Machine Identity Security Docs)What counts as an SCI; enforcement notes. Undated.Retrieved 2026-10-07.
  26. CyberArk Support Terms (Global), 10 October 2025Severity levels, renewal, Annex 1 support options. Dated 10 October 2025.Effective 2025-10-10. Retrieved 2026-10-07.
  27. CyberArk Managed Services Provider (MSP) License Agreement (Global), Rev. April 2022Sections 1, 4 and 5. Rev. April 2022; no day stated.Retrieved 2026-10-07.
  28. Viewing your license entitlements and usage (Machine Identity Security Docs)Licensing page fields and daily refresh. Undated.Retrieved 2026-10-07.

See also

Catalog Rows Cited

11Metrics

Esc