Qualys cloud and application security licensing covers two groups of Qualys applications: the TotalCloud cloud-native application protection platform (CNAPP) and the web application and API testing products Web Application Scanning (WAS) and TotalAppSec (TAS). TotalCloud is sold on Qualys Units (QLUs). Qualys says customers can “mix, match, and reallocate licenses across any CNAPP module”, naming CSPM, CWPP, CDR, KCS and SSPM, without repurchasing.[4] Each module counts a different cloud resource. Most modules average the count over a rolling 90 days instead of taking a 15-day peak.[1] The web application products count applications configured for scanning.[1] All of these remain Cloud Services under the Master Cloud Services Agreement. That agreement lists web applications and domain names among the Assets to which use is limited.[7]
Editions
| Module | Scope (vendor description) | Counted unit |
|---|---|---|
| Cloud Security Posture Management (CSPM) | Cloud compute workloads on AWS, Azure, GCP and OCI scanned by CSPM[1] | Cloud compute workload |
| Cloud Workload Protection, agent-based | Cloud VMs with Qualys agents; the documentation labels it “TotalCloud Agent-based CWP (VMDR)“[1] | Cloud workload VM |
| Cloud Workload Protection, FlexScan | Cloud VMs scanned without agents (API-based or snapshot-based)[1] | Cloud workload VM |
| Cloud Detection and Response (CDR) | Compute workloads on AWS, Azure and GCP with CDR threat scanners enabled[1] | Cloud compute workload |
| Kubernetes and Container Security (KCS) | Nodes protected by container runtime security; image scans; serverless containers[1] | Container node, image scan, serverless container instance |
| SaaS Security Posture Management (SSPM) | Users monitored across supported SaaS applications[1] | SaaS user |
| Web Application Scanning (WAS) | Web application discovery and vulnerability detection[6] | Web application |
| TotalAppSec (TAS) | Web applications and API endpoints onboarded in TAS[1] | Web application or API endpoints |
Buying a TotalCloud licence for any one use case, such as CSPM, automatically enables the other modules (KCS, CWPP, CDR and others), with no separate trial request to the Technical Account Manager.[2] The WAS entry on the QLU Asset Definition page carries the note “Available for Fed High subscriptions only”. The page does not say how WAS is sold on other platforms, where it appears as a separate application.[1] The free Community Edition includes Web Application Scanning for one web app URL.[5]
Metrics
Published conversion ratios
For TotalCloud, Qualys publishes the conversion from resources to QLUs. The public calculator states that pricing “is based on the number of resource units used”, meaning compute units in the cloud such as virtual machines, serverless functions and container images. It explains that QLU counts vary between modules because of differences in “functionality, complexity, and overall value propositions”.[3]
| Resource | Resource units | QLUs |
|---|---|---|
| VM using Cloud Agents (CWP) | 1 | 1 |
| VM using FlexScan (CWP) | 1 | 2 |
| VM protected by CSPM | 1 | 8 |
| Serverless functions protected by CSPM | 100 | 8 |
| VM protected by CDR | 1 | 8 |
| Serverless functions protected by CDR | 100 | 8 |
| VM with containers, including CI/CD build nodes | 1 | 30 |
| Container images in registries | 100 | 8 |
| Serverless containers | 15 | 30 |
| SaaS users (SSPM) | 1 | 1 |
Source: QLU calculator, retrieved 2026-09-27. The calculator says its estimates “are indicative only and follow the published conversion ratios”.[3] The TotalCloud documentation (last updated August 2026) presents the same figures as the minimum QLUs per resource.[2] The Asset Definition page uses other ratios in its worked examples, such as 12:1 for CSPM and 45:1 for Container Security, and states that they are for illustration only.[1] Where the calculator and a contract differ, the contract governs.
Counting / floors
CSPM and CDR
CSPM counts Cloud Compute Workloads, meaning virtual machines and serverless workloads on AWS, Azure, GCP and OCI that CSPM scans. Storage, network, IAM and database resources are excluded, as are decommissioned or deleted workloads.[1] The calculator lists S3 buckets, databases, load balancers, VPCs and subnets among the resources “covered at no additional cost”. Serverless functions are “counted in blocks of 100”.[3] One virtual machine is one asset, and 100 serverless functions are one asset. The daily unique count is averaged over a rolling 90-day lookback.[1] CDR uses the same weighting and method, for workloads with CDR threat scanners enabled on AWS, Azure and GCP.[1]
Cloud Workload Protection
Agent-based CWP counts unique cloud VMs on AWS, Azure, GCP and OCI where Qualys agents are deployed, minus assets with no open ports and no reported vulnerabilities. It is evaluated in 15-day intervals at the highest value, and customers must enable purge rules to avoid counting inactive and terminated assets.[1] FlexScan counts VMs monitored by agentless scanning as a 90-day rolling daily average. Where a VM is scanned both ways, “usage is attributed to agentless (FlexScan) scans for licensing purposes”.[1] At the published ratios, a FlexScan VM costs 2 QLUs against 1 QLU for an agent-based VM.[3] Adding agentless scanning to VMs that already have agents therefore raises consumption.
Containers
Container Security is licensed “per node, regardless of the number of containers, pods, or namespaces running on the node”, with no limit on containers per node. Individual containers, pods and namespaces are not counted.[1] A node is active while it sends regular heartbeats and must miss several consecutive heartbeats before it is treated as inactive. Utilization comes from hourly snapshots, averaged daily over a rolling 90 days, which suits environments where nodes are frequently created and destroyed.[1] Two further container units are metered separately:[1]
- Container image scans. Initial scans and rescans are counted, aggregated over 90 days. Duplicate scans of the same image at several pipeline stages count once. Images analyzed by container runtime security are included with runtime licensing and consume no separate QLUs.
- Serverless container instances. These are instances where node-level sensors cannot be deployed, observed through serverless runtime telemetry and averaged daily over 90 days. Nodes and containers already counted under node-based licensing are excluded.
The calculator counts serverless containers in blocks of 15 and registry images in blocks of 100.[3]
SSPM
SSPM counts users actively monitored across supported SaaS applications. Inactive or deactivated accounts and accounts not monitored by SSPM are excluded. The count is averaged daily over a rolling 90 days.[1] The published ratio is one QLU per SaaS user.[3]
Web Application Scanning
WAS counts web applications “configured and active for scanning”. Applications that remain configured “continue to contribute to QLU usage, even if scans are paused or executed infrequently”. Only removing an application from the WAS configuration stops the count. Usage is evaluated in 15-day intervals at the highest count.[1] Retired applications left in the WAS configuration are the main source of over-count.
TotalAppSec
TotalAppSec counts web applications and API endpoints onboarded in TAS. One web application is one asset, and ten API endpoints are one asset: “Each API endpoint represents 1/10 of an asset for QLU calculation purposes”. Onboarded items keep counting even when testing frequency is reduced. Usage is evaluated in 15-day intervals at the peak.[1] In Qualys’s illustrative example, 85 web applications and 200 API endpoints make 105 asset equivalents.[1]
Virtualization & partitioning
In TotalCloud, the virtual machine or node is the unit. There is no host, hypervisor or cluster-level alternative. Kubernetes nodes and standalone VMs running containers are both counted as a “Virtual Machine with Containers”.[2] Because most cloud modules use a 90-day rolling daily average, a short-lived burst of instances raises the average only in proportion to how long it lasts. This differs from the 15-day peak method used for VMDR.[1]
Cloud / BYOL
TotalCloud is a Qualys cloud service that connects to the customer’s cloud accounts. It is not software licensed onto the hyperscaler, so no BYOL rule applies. Cloud assets from AWS, Azure and GCP keep their cloud-native tracking method when they are activated in CSAM.[8] The MCSA prohibits scanning an Asset the customer has no right or consent to scan (§3.3(viii)). That restriction matters when third-party or client cloud accounts are connected.[7]
Programs
TotalCloud is sold through QFlex. Units can be moved within the TotalCloud portfolio, for example “shifting units from VMs to container nodes during app modernization”, and unused QLUs “can be transferred between applications”.[2] To use QLUs, a licence-based subscription must first be converted to a QLU-based subscription.[2] The general QFlex rules, including the 90-day reallocation interval and overuse indicators, are covered in Qualys QFlex and Qualys Units.
Out of scope
This article does not cover Web Application Firewall, which appears in the subscription page application list without published counting rules,[6] or TotalAI and other applications without published asset definitions. It also does not cover the price of a QLU.