LICENSEWARE

Qualys cloud and application security licensing

This article is about licensing Qualys TotalCloud (CSPM, Cloud Workload Protection, CDR, Kubernetes and Container Security, SSPM), Web Application Scanning and TotalAppSec. For VMDR and endpoint applications, see Qualys VMDR and endpoint asset counting.

On This Page

Qualys cloud and application security licensing covers two groups of Qualys applications: the TotalCloud cloud-native application protection platform (CNAPP) and the web application and API testing products Web Application Scanning (WAS) and TotalAppSec (TAS). TotalCloud is sold on Qualys Units (QLUs). Qualys says customers can “mix, match, and reallocate licenses across any CNAPP module”, naming CSPM, CWPP, CDR, KCS and SSPM, without repurchasing.[4] Each module counts a different cloud resource. Most modules average the count over a rolling 90 days instead of taking a 15-day peak.[1] The web application products count applications configured for scanning.[1] All of these remain Cloud Services under the Master Cloud Services Agreement. That agreement lists web applications and domain names among the Assets to which use is limited.[7]

Editions

Module Scope (vendor description) Counted unit 
Cloud Security Posture Management (CSPM) Cloud compute workloads on AWS, Azure, GCP and OCI scanned by CSPM[1] Cloud compute workload 
Cloud Workload Protection, agent-based Cloud VMs with Qualys agents; the documentation labels it “TotalCloud Agent-based CWP (VMDR)“[1] Cloud workload VM 
Cloud Workload Protection, FlexScan Cloud VMs scanned without agents (API-based or snapshot-based)[1] Cloud workload VM 
Cloud Detection and Response (CDR) Compute workloads on AWS, Azure and GCP with CDR threat scanners enabled[1] Cloud compute workload 
Kubernetes and Container Security (KCS) Nodes protected by container runtime security; image scans; serverless containers[1] Container node, image scan, serverless container instance 
SaaS Security Posture Management (SSPM) Users monitored across supported SaaS applications[1] SaaS user 
Web Application Scanning (WAS) Web application discovery and vulnerability detection[6] Web application 
TotalAppSec (TAS) Web applications and API endpoints onboarded in TAS[1] Web application or API endpoints 

Buying a TotalCloud licence for any one use case, such as CSPM, automatically enables the other modules (KCS, CWPP, CDR and others), with no separate trial request to the Technical Account Manager.[2] The WAS entry on the QLU Asset Definition page carries the note “Available for Fed High subscriptions only”. The page does not say how WAS is sold on other platforms, where it appears as a separate application.[1] The free Community Edition includes Web Application Scanning for one web app URL.[5]

Metrics

Published conversion ratios

For TotalCloud, Qualys publishes the conversion from resources to QLUs. The public calculator states that pricing “is based on the number of resource units used”, meaning compute units in the cloud such as virtual machines, serverless functions and container images. It explains that QLU counts vary between modules because of differences in “functionality, complexity, and overall value propositions”.[3]

Resource Resource units QLUs 
VM using Cloud Agents (CWP) 1 1 
VM using FlexScan (CWP) 1 2 
VM protected by CSPM 1 8 
Serverless functions protected by CSPM 100 8 
VM protected by CDR 1 8 
Serverless functions protected by CDR 100 8 
VM with containers, including CI/CD build nodes 1 30 
Container images in registries 100 8 
Serverless containers 15 30 
SaaS users (SSPM) 1 1 

Source: QLU calculator, retrieved 2026-09-27. The calculator says its estimates “are indicative only and follow the published conversion ratios”.[3] The TotalCloud documentation (last updated August 2026) presents the same figures as the minimum QLUs per resource.[2] The Asset Definition page uses other ratios in its worked examples, such as 12:1 for CSPM and 45:1 for Container Security, and states that they are for illustration only.[1] Where the calculator and a contract differ, the contract governs.

Counting / floors

CSPM and CDR

CSPM counts Cloud Compute Workloads, meaning virtual machines and serverless workloads on AWS, Azure, GCP and OCI that CSPM scans. Storage, network, IAM and database resources are excluded, as are decommissioned or deleted workloads.[1] The calculator lists S3 buckets, databases, load balancers, VPCs and subnets among the resources “covered at no additional cost”. Serverless functions are “counted in blocks of 100”.[3] One virtual machine is one asset, and 100 serverless functions are one asset. The daily unique count is averaged over a rolling 90-day lookback.[1] CDR uses the same weighting and method, for workloads with CDR threat scanners enabled on AWS, Azure and GCP.[1]

Cloud Workload Protection

Agent-based CWP counts unique cloud VMs on AWS, Azure, GCP and OCI where Qualys agents are deployed, minus assets with no open ports and no reported vulnerabilities. It is evaluated in 15-day intervals at the highest value, and customers must enable purge rules to avoid counting inactive and terminated assets.[1] FlexScan counts VMs monitored by agentless scanning as a 90-day rolling daily average. Where a VM is scanned both ways, “usage is attributed to agentless (FlexScan) scans for licensing purposes”.[1] At the published ratios, a FlexScan VM costs 2 QLUs against 1 QLU for an agent-based VM.[3] Adding agentless scanning to VMs that already have agents therefore raises consumption.

Containers

Container Security is licensed “per node, regardless of the number of containers, pods, or namespaces running on the node”, with no limit on containers per node. Individual containers, pods and namespaces are not counted.[1] A node is active while it sends regular heartbeats and must miss several consecutive heartbeats before it is treated as inactive. Utilization comes from hourly snapshots, averaged daily over a rolling 90 days, which suits environments where nodes are frequently created and destroyed.[1] Two further container units are metered separately:[1]

  • Container image scans. Initial scans and rescans are counted, aggregated over 90 days. Duplicate scans of the same image at several pipeline stages count once. Images analyzed by container runtime security are included with runtime licensing and consume no separate QLUs.
  • Serverless container instances. These are instances where node-level sensors cannot be deployed, observed through serverless runtime telemetry and averaged daily over 90 days. Nodes and containers already counted under node-based licensing are excluded.

The calculator counts serverless containers in blocks of 15 and registry images in blocks of 100.[3]

SSPM

SSPM counts users actively monitored across supported SaaS applications. Inactive or deactivated accounts and accounts not monitored by SSPM are excluded. The count is averaged daily over a rolling 90 days.[1] The published ratio is one QLU per SaaS user.[3]

Web Application Scanning

WAS counts web applications “configured and active for scanning”. Applications that remain configured “continue to contribute to QLU usage, even if scans are paused or executed infrequently”. Only removing an application from the WAS configuration stops the count. Usage is evaluated in 15-day intervals at the highest count.[1] Retired applications left in the WAS configuration are the main source of over-count.

TotalAppSec

TotalAppSec counts web applications and API endpoints onboarded in TAS. One web application is one asset, and ten API endpoints are one asset: “Each API endpoint represents 1/10 of an asset for QLU calculation purposes”. Onboarded items keep counting even when testing frequency is reduced. Usage is evaluated in 15-day intervals at the peak.[1] In Qualys’s illustrative example, 85 web applications and 200 API endpoints make 105 asset equivalents.[1]

Virtualization & partitioning

In TotalCloud, the virtual machine or node is the unit. There is no host, hypervisor or cluster-level alternative. Kubernetes nodes and standalone VMs running containers are both counted as a “Virtual Machine with Containers”.[2] Because most cloud modules use a 90-day rolling daily average, a short-lived burst of instances raises the average only in proportion to how long it lasts. This differs from the 15-day peak method used for VMDR.[1]

Cloud / BYOL

TotalCloud is a Qualys cloud service that connects to the customer’s cloud accounts. It is not software licensed onto the hyperscaler, so no BYOL rule applies. Cloud assets from AWS, Azure and GCP keep their cloud-native tracking method when they are activated in CSAM.[8] The MCSA prohibits scanning an Asset the customer has no right or consent to scan (§3.3(viii)). That restriction matters when third-party or client cloud accounts are connected.[7]

Programs

TotalCloud is sold through QFlex. Units can be moved within the TotalCloud portfolio, for example “shifting units from VMs to container nodes during app modernization”, and unused QLUs “can be transferred between applications”.[2] To use QLUs, a licence-based subscription must first be converted to a QLU-based subscription.[2] The general QFlex rules, including the 90-day reallocation interval and overuse indicators, are covered in Qualys QFlex and Qualys Units.

Out of scope

This article does not cover Web Application Firewall, which appears in the subscription page application list without published counting rules,[6] or TotalAI and other applications without published asset definitions. It also does not cover the price of a QLU.

References

  1. Asset Definition and Product-Specific QLU Usage CalculationCSPM, CWP agent-based and FlexScan, CDR, Container Security, Container Image Scanning, Serverless Containers, SSPM, TotalAppSec, WAS. Footer: Last updated June 2026.Retrieved 2026-09-27.
  2. Qualys Unit (QLU) - A Flexible Subscription Model (TotalCloud)Minimum QLUs per resource. Footer: Last updated August 2026.Retrieved 2026-09-27.
  3. Flexible Subscription Using Qualys Units (QLU)Public TotalCloud QLU calculator and conversion ratios. Undated.Retrieved 2026-09-27.
  4. Qualys TotalCloud (CNAPP)Product page; QLU licensing across CNAPP modules. Undated.Retrieved 2026-09-27.
  5. Community Edition: Free Qualys Security PlatformOne web application URL in the free edition. Undated.Retrieved 2026-09-27.
  6. Subscription Plans | Flexible Cybersecurity Solutions | QualysApplication list including WAS and WAF. Undated.Retrieved 2026-09-27.
  7. Qualys Master Cloud Services Agreement (Terms and Conditions)Version label [11.25v]; no effective date. §1 Assets; §3.3 Restrictions; §3.5 Usage Limits.Retrieved 2026-09-27.
  8. Activate Assets for Applications (CSAM)Cloud asset tracking methods.Retrieved 2026-09-27.

See also

Catalog Rows Cited

6Metrics1Programs

Esc