Qualys licensing is the set of terms under which Qualys, Inc. sells access to the Enterprise TruRisk Platform, a cloud-delivered suite of vulnerability management, compliance, asset inventory, patching, endpoint, cloud and application security applications. The governing contract is the Qualys Master Cloud Services Agreement (MCSA). It covers Qualys cloud services, hardware and software together, whether a subscription is bought directly from Qualys or from an authorized reseller.[1] The customer receives a limited, non-exclusive, non-transferable right to use the services during the Subscription Term, solely for its own internal business purposes.[1] Use is capped by the number of Assets in the Order Form. The MCSA defines Assets as the IP addresses, domain names, web applications and other assets to which the customer directs the Cloud Services.[1] Each application’s documentation then says exactly which assets count. Qualys also offers QFlex, a subscription model under which the customer buys a shared pool of Qualys Units (QLUs) and allocates it across applications, instead of buying product-specific licences.[3] For the general models, see subscription and consumption licensing and concurrent and device licensing.
Editions
Qualys does not publish a single edition ladder or a public price list. Its subscription page lists sensors, free inventory tools and applications, and asks buyers to request a quote.[2] The commercial offerings a software asset manager usually meets are:
| Offering | What it is (vendor description) | Licensed on |
|---|---|---|
| Vulnerability Management, Detection and Response (VMDR) | Asset and vulnerability management with TruRisk prioritization, plus unlimited virtual scanners, Cloud Agents, passive sensors, agent gateways and container sensors[5] | Unique assets assessed during the term[4] |
| Vulnerability Management (IP-based subscriptions) | Older subscriptions sized by purchased IP addresses[6] | IPs added to the subscription, not hosts scanned[6] |
| Policy Compliance / Policy Audit | Configuration assessment against internal policies and external regulations[2] | Unique assets assessed[4] |
| CyberSecurity Asset Management (CSAM) | Asset inventory and attack-surface management | Unique managed assets[4] |
| Enterprise TruRisk Management (ETM) | Risk aggregation across Qualys and non-Qualys findings | Unique assets with security findings[4] |
| Patch Management, Mitigation, Isolation (TruRisk Eliminate) | Remediation applications running on the Cloud Agent | Activated agents[4] |
| Multi-Vector EDR, File Integrity Monitoring | Endpoint detection and file change monitoring | Endpoints with an active EDR agent; FIM-enabled assets[4] |
| Web Application Scanning (WAS), TotalAppSec | Web application and API security testing | Web applications configured for scanning; ten API endpoints count as one asset[4] |
| TotalCloud (CNAPP) | Cloud posture, workload, detection and container security | Cloud VMs, serverless functions and container nodes, averaged over 90 days[4] |
| Small business packages | VMDR TruRisk, TruRisk FixIT (adds patching) and TruRisk ProtectIT (adds anti-virus)[9] | Not stated; no public prices |
| Community Edition | Free version of the platform[7] | 16 internal and 3 external assets, one web application URL[7] |
Some capabilities come with every subscription. Cloud Agent inventory and Qualys Passive Scanners are listed as “Included with all subscriptions”, and Global AssetView is described as free.[2] A subscription entitles the customer to an unlimited number of scans. Qualys also says “pay per scan” packages exist.[10] Deployment options include the shared cloud platforms, the Qualys Government Platform, which Qualys describes as FedRAMP High Authorized,[16] and a Private Cloud Platform installed in the customer’s own data centre.[15]
Metrics
Qualys uses one contractual unit and several documented counting units:
- Asset: the MCSA unit that every Order Form quantity is expressed against.[1]
- IP address (VM subscription): the unit of IP-based Vulnerability Management subscriptions. Help > Account Info > VM Summary shows IPs Purchased, IPs in Subscription and Unique Hosts Scanned.[6]
- Application-specific asset definitions published for QFlex: VMDR asset, Policy Audit asset, CSAM managed asset, ETM asset with findings, EDR endpoint, Patch Management activated agent, Web application (WAS), Cloud compute workload, Container node and others.[4]
- Qualys Unit (QLU): the pooled currency of QFlex. Consumption is the counted asset quantity multiplied by a QLU-to-asset ratio.[3]
The asset definitions were written for QFlex, but they are the most detailed statement Qualys publishes of what each application counts. Documentation examples that show QLU-to-asset ratios are marked as illustrative only. Actual consumption depends on the ratio in the customer’s subscription agreement.[4] See Qualys QFlex and Qualys Units.
Counting / floors
For most asset-based applications, Qualys measures use in 15-day intervals and records the highest unique count in each interval, “so licensing reflects peak usage”. Cloud-native applications instead use a daily average over a rolling 90-day window.[4] Three counting rules shape most VMDR positions (Qualys QFlex documentation, as published 2026-09-27):
- Assets are counted for the whole term. Every asset that has had a Qualys Agent installed and reported at any time in the subscription term counts once per Agent ID, regardless of its current status. Cloud instances terminated during the term are included.[4]
- Purge rules are the customer’s job. Customers must configure purge rules to remove inactive, terminated or unwanted assets, otherwise usage is inflated.[4]
- De-duplication is best effort. An asset scanned by both a Scanner Appliance and a Cloud Agent counts once. Devices with multiple IP addresses may not correlate and may count separately.[4]
Qualys publishes no minimum quantities. The only published caps are those of the free Community Edition: unlimited vulnerability scanning for up to 16 internal and 3 external assets, one virtual scanner appliance, and scanning of one web application URL.[7] The details are in Qualys VMDR and endpoint asset counting.
Commercial terms
The MCSA [11.25v] sets the commercial frame for direct purchases (no effective date stated; as published 2026-09-27):
- Fees are based on subscriptions purchased, not actual usage. Payment obligations are non-cancelable, fees are non-refundable, and quantities cannot be decreased during a Subscription Term (§5.1). Fees are invoiced in advance and due net 30 days (§5.2).[1]
- If the customer exceeds a usage limit, Qualys works with it to reduce usage. If the customer cannot or will not conform, it is liable for fees for the excess (§3.5).[1]
- Order Forms renew automatically for one-year terms unless either party gives notice at least 60 days before the term ends. On auto-renewal the per-unit price may not rise more than 8%, excluding Special Pricing. A change of service type or a volume reduction at renewal is not protected by the cap (§11.2).[1]
- For reseller purchases, fees, invoicing, renewal and payment terms are those agreed between the reseller and the customer (§5, §11.2).[1]
- Affiliates may use the customer’s subscriptions for their internal use, and the customer is liable for their breaches (§3.1).[1]
Virtualization & partitioning
Qualys publishes no host-based or hypervisor-level counting option. Each virtual machine, cloud instance or container node counts under the rules of the application that assesses it. The VMDR definition includes cloud instances discovered through AWS, Azure, GCP, OCI and Alibaba connectors, counted once per instance ID.[4] Container security is licensed per node “regardless of the number of containers, pods, or namespaces running on the node”.[4] Virtual scanner appliances are included without limit with VMDR.[5] Physical scanner appliances are rated by scanning capacity in units, and a VM scan uses two units per IP.[11]
Cloud / BYOL
The Enterprise TruRisk Platform is itself a cloud service, so there is no bring-your-own-licence construct for running Qualys software on a hyperscaler. Cloud workloads are covered by the TotalCloud applications, whose metrics and published QLU ratios are described in Qualys cloud and application security licensing.
Programs
- QFlex: a pooled QLU commitment. Tiered pricing gives higher discounts for larger QLU purchases, and allocations can be changed every 90 days.[3][14]
- Consulting Edition: subscriptions for consultants and MSPs that serve SMB/SME clients. Internal use is not allowed, and a network subscription must be bought for each client (MCSA §4).[1]
- Reseller purchases: the MCSA still governs use, but commercial terms move to the reseller agreement.[1]
- Community Edition and 30-day trials: free use, covered in Qualys scanners, free editions and contract terms.[7][8]
Audits and disputes
The MCSA contains no clause that lets Qualys audit the customer’s premises or records. Compliance with purchased quantities is enforced through the platform. The Order Form sets usage limits, and fees are owed for excess usage the customer cannot or will not reduce (§3.5).[1] Under QFlex, Qualys describes real-time consumption tracking, visual indicators and proactive alerts intended to prevent unexpected overages, and says teams can download and share consumption reports “for planning and audits”.[14] Standard support, including hardware replacement for scanner appliances, is described in the Cloud Services Support Policy.[12]
On intellectual property, Qualys agrees to defend the customer against third-party claims that the Cloud Services or Software infringe or misappropriate intellectual property rights. It may modify the service, obtain a licence, or terminate the affected subscription and refund prepaid fees, and the clause is the customer’s sole remedy for such claims (§9.1).[1] The customer in turn indemnifies Qualys against claims arising from scanning assets it had no right or consent to scan (§9.2, §3.3(viii)).[1]
Qualys has itself been a defendant in patent litigation over its products. On 2018-11-29, Finjan, Inc. filed a complaint against Qualys in the U.S. District Court for the Northern District of California (case 3:18-cv-07229). Finjan asserted seven U.S. patents against Qualys malware detection, web application firewall, web application scanning and vulnerability management solutions, including Qualys Cloud Platform products.[13] The cited filing records only the start of the case. For audit practice generally, see software license audit and license compliance.
Out of scope
This article does not cover the Qualys vulnerability knowledge base, CVE content or hardware specifications beyond scanner capacity. It also does not cover prices, which Qualys does not publish, or partner program commercial terms beyond those stated in the MCSA.