Netskope CASB API, DSPM and posture licensing covers the Netskope services that connect to SaaS applications, cloud accounts and data repositories through their APIs rather than inspecting live traffic. The Netskope Subscription Service Charges Document sets the units and true-up rules for the SKU families NK-P-CBAPI- (CASB API and API Introspection), NK-SSPM- (SaaS security posture management), NK-DSPM- (data security posture management), NK-IAAS-SS- (IaaS storage scan), NK-P-IAASPRT-PRF and NK-CSPM-ACT (IaaS Protection and cloud security posture management per Account) and NK-CSPM- (CSPM per Resource).[1] CASB API also has its own licensing terms in Netskope’s documentation, last modified September 28, 2026, which add a per-User option and detailed measurement rules,[2] and a tenant usage report explains how billable users are calculated for each SaaS application.[3]
Editions
| Service | SKU family | Unit | Catalog SKU |
|---|---|---|---|
| CASB API and API Introspection | NK-P-CBAPI- | Seat or User, plus TB of retroactive scan | CASB API and API Introspection |
| SSPM | NK-SSPM- | Seat | SSPM Seat |
| DSPM | NK-DSPM- | Data store (40,000 objects) | DSPM data store |
| IaaS Storage Scan | NK-IAAS-SS- | GB consumed | IaaS Storage Scan |
| IaaS Protection | NK-P-IAASPRT-PRF | Account (1 TB scanning) | IaaS Protection Professional |
| CSPM | NK-CSPM-ACT; NK-CSPM- | Account; Resource | CSPM per Account, CSPM per Resource |
The CASB API licensing terms describe the service as out-of-band data protection, threat detection and user behavioural anomaly detection for sanctioned SaaS applications through direct API integrations.[2] Netskope runs two CASB API platforms, Classic API Data Protection and Next Generation API Data Protection; the Classic platform’s end of life was announced on May 1, 2026 and it is decommissioned on June 1, 2027 (rule).[4] Usage reporting for retroactive scans and billable users covers Next Generation apps only.[3]
Metrics
Seat
The Service Charges Document defines a Seat as “a subscription for a Netskope API-enabled service to monitor a single User (as defined below) accessing a single third party SaaS application”.[1] The CASB API licensing terms phrase it as a subscription for an API-enabled service instance “to monitor a single app instance of service or user account for the protected SaaS app”, and state that each User-to-application-instance relationship counts as one Seat.[2] The catalog records the metric as Seat.
Seats multiply: two users monitored in three SaaS application accounts need six Seats, and “Two Netskope instances concurrently connected to the same SaaS application account with 1K app users, are treated as 2K user Seats” (rule).[2] A seat-based customer buys a fixed number of Seats that can be applied to any number of application instances as long as the total used does not exceed the entitlement.[2]
User option
CASB API can alternatively be entitled per User. Each User-based unit entitles one User “with access to unlimited non-Generative AI applications” (rule).[2] Commentary: the per-User model removes the multiplication by application count, but generative AI applications are outside the unlimited allowance, so their API coverage needs to be checked separately in the quotation.
TB of retroactive scan
Retroactive scans (deep scans of existing content) are measured in terabytes processed (TB of Retroactive Scan).[2] Each API service includes 1 TB per year, plus 1 TB per year for every 100 Seats, and further TB can be bought (rule).[1] The usage report explains that usage is based on data actually processed, not merely discovered: entities that do not match a retroactive policy, or policies that only raise alerts without DLP or threat inspection, do not count.[3]
Data store (DSPM)
DSPM is “charged on a per data store basis with a total limit on object-count”, a data store being a connected repository such as a database, data warehouse, object store bucket, file share or data instance, and an object being a database field or a file.[1] Each data store entitles up to 40,000 objects under management (rule).[1] The DSPM product enforces the object capacity: once reached, no further data stores can be connected until capacity is increased or data stores are archived, although already connected stores on an auto-scan schedule continue to be scanned.[5] An optional Query Analysis product is licensed by the number of data stores with Data In Use Monitoring enabled.[5]
Account, Resource and GB
An Account is a cloud services container such as an AWS account, Azure subscription or GCP project; a Resource is “a billable resource (akin to host-based pricing)” for supported compute instances, storage buckets and databases; and GB measures data scanned.[1] IaaS Protection and CSPM Account units each include one Account and up to 1 TB of data scanning.[1]
Counting / floors
CASB API measurement
Netskope “measures usage based on the number of unique Users or Seats observed daily at the Customer’s account level”, following an application-specific billable-user methodology; retroactive scan TB are cumulative over the annual Subscription Period (rule).[2] Unused allocations do not roll over, and entitlements are pooled across the customer’s tenants.[2] Customers can view usage per application in the CASB API dashboard at tenant level.[2]
Billable users per application
The CASB API Usage page lists, for each supported application, which user types count (rule).[3] Examples:
| Application | Counted | External users |
|---|---|---|
| Atlassian Confluence (Next Gen only) | Active users; deleted and API-only users excluded; a user in two organisations of one enterprise counted once | Not included |
| Atlassian Jira | Active users | Included |
| Box (Next Gen and Classic) | Active and suspended users, including service accounts (“app users”) | Not included |
| ChatGPT Enterprise | Active users only | Not included |
Source: CASB API Usage, Billable Users table.[3] Commentary: because Box service accounts and suspended users are billable, a Seat reconciliation against an HR headcount will under-count; the reconciliation needs the SaaS application’s own user list filtered by Netskope’s per-application rules.
Overage
If CASB API usage exceeds the entitlement, Netskope may limit functionality, “including the cessation of protection”, and the customer must within 30 days of notification either purchase additional Users, Seats or TB or cease the excess use.[2] SSPM Seats and DSPM data stores follow the same 30-day remedy in the Service Charges Document.[1] Customers may be required to provide system data, audit logs or written confirmation of Users and Seats on reasonable request.[2]
Quarterly true-up for cloud scanning
IaaS Storage Scan, IaaS Protection and CSPM use a prepaid base with quarterly measurement (rule).[1] GB consumed and Accounts or Resources in use are measured every three months after the service start date. Accounts and Resources are trued up on the average number in use during the quarter, and each additional quantity is bought with its own 12-month term starting on the true-up date unless Netskope quotes another period.[1] Commentary: this produces a staggered set of end dates across a CSPM estate, which must be reconciled at renewal.
Virtualization & partitioning
Posture products are counted per cloud Account or per Resource, not per host processor. A Resource is described as “akin to host-based pricing” and covers compute instances, storage buckets and databases identified in the product documentation.[1]
Cloud / BYOL
The services scan customer SaaS and IaaS environments; the SSA requires the customer to hold all licences needed to use the third-party services that Netskope monitors or scans, naming Microsoft Office 365 as an example (rule).[6] There is no BYOL model.
Programs
No separate program applies. Support and evaluation terms are those of the SSA and the Support Terms; see Subscription agreement, support and lifecycle.
Out of scope
Inline CASB (Cloud Inline) is licensed per User with the other inline services; see Subscription units and true-up. DataSec Command Center, which aggregates data security signals from these services, is covered in AI security licensing.