QFlex is the subscription model that Qualys uses for platform capabilities priced in Qualys Units (QLUs). With QFlex, the customer subscribes to a shared pool of QLUs and can allocate and reallocate it across Qualys products “without the need to purchase product-specific licenses”.[1] The Qualys FAQ describes a QLU as representing the customer’s “subscription investment across Qualys products”.[2] QFlex does not replace the Master Cloud Services Agreement. That agreement still limits use to the Assets in the Order Form and makes excess usage billable.[10] What QFlex changes is the way the quantity is expressed and moved between applications. The feature is not enabled by default: Qualys says it is available on request through the Technical Account Manager (TAM).[1] Customers with an existing licence-based subscription must convert it to a QLU-based subscription.[7]
Editions
QFlex is a commercial wrapper, not an edition. The All Products page lists every application supported under QFlex and shows its status: Purchased, Activate Trial, Recommended or Trial.[6] The Asset Definition page publishes counting rules for these QFlex applications: Enterprise TruRisk Management (ETM), CyberSecurity Asset Management (CSAM), ETM Identity, VMDR, VMDR Mobile, VMDR-OT, EDR, zLinux agents, Cloud Security Posture Management (CSPM), Cloud Workload Protection (agent-based and FlexScan), Cloud Detection and Response (CDR), Container Security, container image scanning, serverless containers, SaaS Security Posture Management (SSPM), TotalAppSec, Web Application Scanning (WAS), Policy Audit, Audit Fix, File Integrity Monitoring (FIM), PCI Compliance, Patch Management and TruRisk Eliminate.[3]
Pricing follows three principles. Customers buy a centralized pool of QLUs “at a single price point” and allocate it dynamically, and buying more QLUs “across QFlex-eligible products” unlocks higher discounts under a tiered pricing model.[1] Qualys does not publish the price of a QLU.
Metrics
The unit of account is the Qualys Unit (QLU). The platform calculates QLU consumption “from the asset count using a predefined QLU-to-asset ratio”, and consumption changes as assets are added or removed.[1] Each application brings its own asset metric:
| Application | Counted unit (catalog row) | Measurement |
|---|---|---|
| VMDR | VMDR asset: unique assets assessed during the term | 15-day peak |
| Policy Audit | Policy Audit asset | 15-day peak |
| CSAM | CSAM managed asset | 15-day peak |
| ETM | Asset with findings | 15-day peak |
| ETM Identity | Enabled identity | 15-day peak |
| EDR | Endpoint with active EDR agent | 15-day peak |
| Patch Management, Isolation, Mitigation | Activated agent | 15-day peak |
| FIM | FIM-enabled asset | 15-day peak |
| WAS | Web application configured for scanning | 15-day peak |
| TotalAppSec | Web application or ten API endpoints | 15-day peak |
| PCI Compliance | IP address or DNS entry | 15-day peak |
| VMDR-OT | Weighted OT asset | 15-day peak |
| VMDR Mobile | Mobile device | 15-day peak |
| CSPM, CDR | Cloud compute workload | 90-day rolling daily average |
| Cloud Workload Protection | Cloud workload VM | 15-day peak (agent), 90-day average (FlexScan) |
| Kubernetes and Container Security | Container node | 90-day rolling daily average |
| SSPM | SaaS user | 90-day rolling daily average |
The table summarizes the Asset Definition page as published on 2026-09-27.[3] Each row links to a catalog entry with the vendor’s definition and exclusions.
Counting / floors
Ratios
Consumption is the counted quantity multiplied by the ratio for that application. The worked examples on the Asset Definition page use ratios such as 1.5:1 for VMDR and 3:1 for ETM. Qualys states that “the QLU-to-asset ratio shown above is for illustration only” and that actual consumption depends on “the ratio defined in the applicable Qualys subscription agreement”.[3] An effective licence position under QFlex therefore needs two inputs from the contract, the pool size and the per-application ratio, and one input from the platform, the counted assets.
TotalCloud is the exception: Qualys publishes its ratios. The TotalCloud documentation lists the minimum QLUs per resource.[7] The public calculator gives the same conversion ratios and notes that its estimates “are indicative only”.[8]
| TotalCloud resource | QLUs |
|---|---|
| Virtual machine with Cloud Agent (CWP) | 1 per VM |
| Virtual machine with FlexScan (CWP) | 2 per VM |
| Virtual machine protected by CSPM or CDR | 8 per VM |
| Serverless functions (CSPM or CDR) | 8 per 100, counted in blocks of 100 |
| Virtual machine with containers, including CI/CD build nodes | 30 per VM |
| Container images in registries | 8 per 100 |
| Serverless containers | 30 per 15 |
| SaaS user (SSPM) | 1 per user |
Sources: TotalCloud QLU documentation (last updated August 2026) and the public QLU calculator, both retrieved 2026-09-27.[7][8]
Measurement windows
Most asset-based applications are evaluated in 15-day intervals. For each interval, Qualys records the highest unique asset count, a method that “ensures that licensing reflects peak usage”.[3] Cloud-native applications (CSPM, CWP FlexScan, CDR, Container Security, image scanning, serverless containers and SSPM) take a daily count. That count is averaged over a rolling 90-day period.[3] The My Subscription usage graph also updates every 15 days and shows the peak unit usage for each period.[4]
Purging
Assets that are no longer used keep consuming units until they are removed. Customers “must configure purge rules to remove inactive, terminated, or unwanted assets” to avoid inflated QLU usage.[3] The Purge Assets action on the QLU Management page opens the CSAM Asset Purge Rules tab. There, assets can be marked as purged to stop duplicate or unwanted assets from consuming units.[5]
Overuse
Qualys publishes no minimum QLU pool. The My Subscription page shows a QLU counter with the remaining balance. Each product card has a colour-coded bar: within limit, approaching limits (about 80% to 90% of purchased QLUs), or overutilization, meaning usage “has exceeded the purchased limits”. A CSV usage report can be downloaded.[4] The QLU documentation does not itself state the charge for overutilization. The MCSA provides that a customer who cannot or will not keep to a usage limit is liable for fees for the excess usage (§3.5).[10] Additional QLUs are requested from the TAM and are available for allocation as soon as they are purchased.[2]
Virtualization & partitioning
QFlex does not add a virtualization rule of its own. Virtual machines, cloud instances and container nodes are counted under each application’s definition. The TotalCloud documentation gives the example of moving units from VMs to container nodes during application modernization.[7] Per-application counting of virtual and cloud assets is covered in Qualys VMDR and endpoint asset counting and Qualys cloud and application security licensing.
Cloud / BYOL
Within TotalCloud, unused QLUs “can be transferred between applications”. Buying a TotalCloud licence for any one use case, such as CSPM, automatically enables the other modules (KCS, CWPP, CDR and others) in the platform.[7] Enabling a module is not the same as funding it. Consumption by the enabled modules still draws on the allocated units. No bring-your-own-licence construct applies, because the platform itself is the cloud service.
Programs
Allocation and reallocation
The QFlex program row records the following commercial rules:
- Who may allocate. By default, the Subscription (PoC) user and Super Users can access QLU Management. Other users need the QLU Manager role. With QLU.ALLOCATION they can allocate and reallocate units and start trials; with QLU.VIEW they can only view usage.[9]
- How often. Units can be reallocated “once every 90 days”. The Reallocate button shows the next available date.[5] The FAQ gives the same frequency.[2]
- Policy exceptions. The FAQ says the QLU model “replaces unlimited licensing with standardized and controlled policies” and that administrators may allow exceptions only with executive approval.[2]
- Sizing. Customers can estimate requirements with the QLU calculator in the Customer Support Portal or ask their TAM.[2]
Trials
A 30-day product trial can be started from Administration > Subscription > All Products without contacting support. Trials “run for a limited time and cover a restricted number of assets”, and purchased QLUs can be assigned during or after the trial.[2] Once a trial is activated, “it cannot be modified or restarted until the trial period is completed”.[6]
Records for audit
The platform keeps audit logs and a history of subscription status, allocation changes and QLU consumption. Administrators can export this data for compliance reviews.[2] These records are the evidence base for reconciling a QFlex position with the Order Form.
Out of scope
This article does not cover the per-QLU price, which Qualys does not publish, or discount tiers. It also does not cover contract-specific QLU-to-asset ratios for non-TotalCloud applications or Order Form terms that differ from the published documentation.