LICENSEWARE

Qualys licensing

This article is an overview of how Qualys licenses the Enterprise TruRisk Platform, its applications, sensors and free editions. Deeper articles cover the QFlex and Qualys Units model, VMDR and endpoint asset counting, cloud and application security metrics, and scanners, free editions and contract terms. It is not legal advice.

On This Page

Qualys licensing is the set of terms under which Qualys, Inc. sells access to the Enterprise TruRisk Platform, a cloud-delivered suite of vulnerability management, compliance, asset inventory, patching, endpoint, cloud and application security applications. The governing contract is the Qualys Master Cloud Services Agreement (MCSA). It covers Qualys cloud services, hardware and software together, whether a subscription is bought directly from Qualys or from an authorized reseller.[1] The customer receives a limited, non-exclusive, non-transferable right to use the services during the Subscription Term, solely for its own internal business purposes.[1] Use is capped by the number of Assets in the Order Form. The MCSA defines Assets as the IP addresses, domain names, web applications and other assets to which the customer directs the Cloud Services.[1] Each application’s documentation then says exactly which assets count. Qualys also offers QFlex, a subscription model under which the customer buys a shared pool of Qualys Units (QLUs) and allocates it across applications, instead of buying product-specific licences.[3] For the general models, see subscription and consumption licensing and concurrent and device licensing.

Editions

Qualys does not publish a single edition ladder or a public price list. Its subscription page lists sensors, free inventory tools and applications, and asks buyers to request a quote.[2] The commercial offerings a software asset manager usually meets are:

Offering What it is (vendor description) Licensed on 
Vulnerability Management, Detection and Response (VMDR) Asset and vulnerability management with TruRisk prioritization, plus unlimited virtual scanners, Cloud Agents, passive sensors, agent gateways and container sensors[5] Unique assets assessed during the term[4] 
Vulnerability Management (IP-based subscriptions) Older subscriptions sized by purchased IP addresses[6] IPs added to the subscription, not hosts scanned[6] 
Policy Compliance / Policy Audit Configuration assessment against internal policies and external regulations[2] Unique assets assessed[4] 
CyberSecurity Asset Management (CSAM) Asset inventory and attack-surface management Unique managed assets[4] 
Enterprise TruRisk Management (ETM) Risk aggregation across Qualys and non-Qualys findings Unique assets with security findings[4] 
Patch Management, Mitigation, Isolation (TruRisk Eliminate) Remediation applications running on the Cloud Agent Activated agents[4] 
Multi-Vector EDR, File Integrity Monitoring Endpoint detection and file change monitoring Endpoints with an active EDR agent; FIM-enabled assets[4] 
Web Application Scanning (WAS), TotalAppSec Web application and API security testing Web applications configured for scanning; ten API endpoints count as one asset[4] 
TotalCloud (CNAPP) Cloud posture, workload, detection and container security Cloud VMs, serverless functions and container nodes, averaged over 90 days[4] 
Small business packages VMDR TruRisk, TruRisk FixIT (adds patching) and TruRisk ProtectIT (adds anti-virus)[9] Not stated; no public prices 
Community Edition Free version of the platform[7] 16 internal and 3 external assets, one web application URL[7] 

Some capabilities come with every subscription. Cloud Agent inventory and Qualys Passive Scanners are listed as “Included with all subscriptions”, and Global AssetView is described as free.[2] A subscription entitles the customer to an unlimited number of scans. Qualys also says “pay per scan” packages exist.[10] Deployment options include the shared cloud platforms, the Qualys Government Platform, which Qualys describes as FedRAMP High Authorized,[16] and a Private Cloud Platform installed in the customer’s own data centre.[15]

Metrics

Qualys uses one contractual unit and several documented counting units:

The asset definitions were written for QFlex, but they are the most detailed statement Qualys publishes of what each application counts. Documentation examples that show QLU-to-asset ratios are marked as illustrative only. Actual consumption depends on the ratio in the customer’s subscription agreement.[4] See Qualys QFlex and Qualys Units.

Counting / floors

For most asset-based applications, Qualys measures use in 15-day intervals and records the highest unique count in each interval, “so licensing reflects peak usage”. Cloud-native applications instead use a daily average over a rolling 90-day window.[4] Three counting rules shape most VMDR positions (Qualys QFlex documentation, as published 2026-09-27):

  • Assets are counted for the whole term. Every asset that has had a Qualys Agent installed and reported at any time in the subscription term counts once per Agent ID, regardless of its current status. Cloud instances terminated during the term are included.[4]
  • Purge rules are the customer’s job. Customers must configure purge rules to remove inactive, terminated or unwanted assets, otherwise usage is inflated.[4]
  • De-duplication is best effort. An asset scanned by both a Scanner Appliance and a Cloud Agent counts once. Devices with multiple IP addresses may not correlate and may count separately.[4]

Qualys publishes no minimum quantities. The only published caps are those of the free Community Edition: unlimited vulnerability scanning for up to 16 internal and 3 external assets, one virtual scanner appliance, and scanning of one web application URL.[7] The details are in Qualys VMDR and endpoint asset counting.

Commercial terms

The MCSA [11.25v] sets the commercial frame for direct purchases (no effective date stated; as published 2026-09-27):

  • Fees are based on subscriptions purchased, not actual usage. Payment obligations are non-cancelable, fees are non-refundable, and quantities cannot be decreased during a Subscription Term (§5.1). Fees are invoiced in advance and due net 30 days (§5.2).[1]
  • If the customer exceeds a usage limit, Qualys works with it to reduce usage. If the customer cannot or will not conform, it is liable for fees for the excess (§3.5).[1]
  • Order Forms renew automatically for one-year terms unless either party gives notice at least 60 days before the term ends. On auto-renewal the per-unit price may not rise more than 8%, excluding Special Pricing. A change of service type or a volume reduction at renewal is not protected by the cap (§11.2).[1]
  • For reseller purchases, fees, invoicing, renewal and payment terms are those agreed between the reseller and the customer (§5, §11.2).[1]
  • Affiliates may use the customer’s subscriptions for their internal use, and the customer is liable for their breaches (§3.1).[1]

Virtualization & partitioning

Qualys publishes no host-based or hypervisor-level counting option. Each virtual machine, cloud instance or container node counts under the rules of the application that assesses it. The VMDR definition includes cloud instances discovered through AWS, Azure, GCP, OCI and Alibaba connectors, counted once per instance ID.[4] Container security is licensed per node “regardless of the number of containers, pods, or namespaces running on the node”.[4] Virtual scanner appliances are included without limit with VMDR.[5] Physical scanner appliances are rated by scanning capacity in units, and a VM scan uses two units per IP.[11]

Cloud / BYOL

The Enterprise TruRisk Platform is itself a cloud service, so there is no bring-your-own-licence construct for running Qualys software on a hyperscaler. Cloud workloads are covered by the TotalCloud applications, whose metrics and published QLU ratios are described in Qualys cloud and application security licensing.

Programs

Audits and disputes

The MCSA contains no clause that lets Qualys audit the customer’s premises or records. Compliance with purchased quantities is enforced through the platform. The Order Form sets usage limits, and fees are owed for excess usage the customer cannot or will not reduce (§3.5).[1] Under QFlex, Qualys describes real-time consumption tracking, visual indicators and proactive alerts intended to prevent unexpected overages, and says teams can download and share consumption reports “for planning and audits”.[14] Standard support, including hardware replacement for scanner appliances, is described in the Cloud Services Support Policy.[12]

On intellectual property, Qualys agrees to defend the customer against third-party claims that the Cloud Services or Software infringe or misappropriate intellectual property rights. It may modify the service, obtain a licence, or terminate the affected subscription and refund prepaid fees, and the clause is the customer’s sole remedy for such claims (§9.1).[1] The customer in turn indemnifies Qualys against claims arising from scanning assets it had no right or consent to scan (§9.2, §3.3(viii)).[1]

Qualys has itself been a defendant in patent litigation over its products. On 2018-11-29, Finjan, Inc. filed a complaint against Qualys in the U.S. District Court for the Northern District of California (case 3:18-cv-07229). Finjan asserted seven U.S. patents against Qualys malware detection, web application firewall, web application scanning and vulnerability management solutions, including Qualys Cloud Platform products.[13] The cited filing records only the start of the case. For audit practice generally, see software license audit and license compliance.

Out of scope

This article does not cover the Qualys vulnerability knowledge base, CVE content or hardware specifications beyond scanner capacity. It also does not cover prices, which Qualys does not publish, or partner program commercial terms beyond those stated in the MCSA.

References

  1. Qualys Master Cloud Services Agreement (Terms and Conditions)Version label [11.25v]; no effective date. §1 Definitions, §3 Ordering and use, §4 Consultants, §5 Fees, §9 Indemnification, §10 Liability, §11 Term, §12 General.Retrieved 2026-09-27.
  2. Subscription Plans | Flexible Cybersecurity Solutions | QualysSensors and applications; items included with all subscriptions. Undated.Retrieved 2026-09-27.
  3. Introduction to QFlex Subscription Model and Qualys Units (QLUs)Footer: Last updated June 2026.Retrieved 2026-09-27.
  4. Asset Definition and Product-Specific QLU Usage CalculationPer-application counting rules. Footer: Last updated June 2026.Retrieved 2026-09-27.
  5. Vulnerability Management, Detection and Response (VMDR)Product page; what VMDR includes. Undated.Retrieved 2026-09-27.
  6. Purchasing more IPs / licensesIP-based VM subscriptions. Footer: Last updated September 2026.Retrieved 2026-09-27.
  7. Community Edition: Free Qualys Security PlatformFree edition limits. Undated.Retrieved 2026-09-27.
  8. Platform Free Trials30-day use-case and product trials; free services. Undated.Retrieved 2026-09-27.
  9. Qualys VMDR TruRisk for Small BusinessSmall business packages; no prices published. Undated.Retrieved 2026-09-27.
  10. General FAQUnlimited scans; pay-per-scan packages. Undated.Retrieved 2026-09-27.
  11. Qualys Physical Scanner Appliance overviewQGSA models and scanning capacity.Retrieved 2026-09-27.
  12. Support Service Level Agreement (Cloud Services Support Policy)Qualys Standard Support. Undated.Retrieved 2026-09-27.
  13. Finjan Holdings, Inc. Form 8-K (complaint against Qualys Inc.)Filed with the U.S. Securities and Exchange Commission on 2018-12-03 by the plaintiff; not a Qualys document.Effective 2018-12-03. Retrieved 2026-09-30.
  14. Qualys Units (QLU) Frequently Asked QuestionsFooter: Last updated June 2026.Retrieved 2026-09-27.
  15. Private Cloud PlatformOn-premises deployment of the platform. Undated.Retrieved 2026-09-27.
  16. FedRAMP High-Authorized Qualys Government PlatformGovernment platform and its services. Undated.Retrieved 2026-09-27.

See also

Catalog Rows Cited

12Metrics5Programs

Esc