LICENSEWARE

Qualys VMDR and endpoint asset counting

This article is about how Qualys counts assets for VMDR, IP-based Vulnerability Management, Policy Compliance, CSAM, ETM, Patch Management, EDR and FIM. For cloud-native and web application metrics, see Qualys cloud and application security licensing.

On This Page

Qualys VMDR and endpoint asset counting covers the rules Qualys publishes for counting assets in its infrastructure security, asset management and remediation applications. The central offering is Vulnerability Management, Detection and Response (VMDR). Qualys describes it as including asset and vulnerability management, TruRisk prioritization, patch detection, certificate inventory, PCI ASV assessments, and unlimited virtual scanners, Cloud Agents, passive sensors, agent gateways and container sensors.[3] VMDR usage is based on “the total number of unique assets assessed by VMDR during the subscription term”.[1] The contractual cap is the number of Assets in the Order Form under the Master Cloud Services Agreement.[11]

Editions

Application What it covers Unit counted 
VMDR Vulnerability assessment and prioritization across hybrid IT[3] VMDR asset 
Vulnerability Management (IP-based) Earlier subscriptions sized by purchased IPs[2] IP address 
VMDR Mobile Mobile devices enabled through VMDR Mobile, Cloud Agent or the Intune Connector[1] Mobile device 
VMDR-OT Operational technology assets[1] Weighted OT asset 
Policy Audit / Policy Compliance Configuration and policy assessment. Policy Audit is described as an enhanced version of Policy Compliance[9] Policy Audit asset 
Audit Fix (PAF) Remediation of failed Policy Audit controls. Needs an active Policy Audit subscription and a Cloud Agent[12] Agents activated for PAF 
CyberSecurity Asset Management (CSAM) Managed asset inventory CSAM managed asset 
Enterprise TruRisk Management (ETM), ETM Identity Risk aggregation; identity risk Asset with findings; enabled identity 
Patch Management, Mitigation, Isolation; TruRisk Eliminate Remediation through the Cloud Agent Activated agent 
Multi-Vector EDR Endpoint detection and response EDR endpoint 
File Integrity Monitoring (FIM) File change monitoring FIM-enabled asset 
PCI Compliance PCI ASV scanning IP address or DNS entry 

For small businesses, Qualys sells three packages. VMDR TruRisk is enterprise VMDR functionality. TruRisk FixIT adds operating-system and third-party patching, and TruRisk ProtectIT adds anti-virus, incident response and threat hunting. No prices are published.[10]

Metrics

VMDR and Policy Audit

VMDR and Policy Audit share one counting method (Asset Definition page, as published 2026-09-27):[1]

  • A1, all-time on-premises agents. Every unique asset that has had a Qualys Agent installed and has reported at any time in the subscription term, counted once per Agent ID “regardless of current status”.
  • A2, scanner-discovered assets. Assets found by network or cloud scanning (IP-based discovery, DNS, NetBIOS, cloud instance discovery, and authenticated or unauthenticated scans) that are not already in A1.
  • B, cloud service provider assets. Resources found through AWS, Azure, Google Cloud, OCI and Alibaba integrations, counted once per instance ID. Resources terminated or deleted during the term are included if they were discovered during it.
  • C, ghost assets. Assets with no open ports and no reported vulnerabilities that result from transient scan artifacts, IP reuse or incomplete correlation. These are deducted.

Usage is (A + B − C) × QLU ratio, evaluated in 15-day intervals at the highest value observed.[1] Eligible assets include physical servers, virtual machines, cloud compute instances, desktops and laptops, container hosts, and “any other device or system assigned a unique hostname, IP address, Agent ID, instance ID, or other unique identifier”. Any asset scanned, assessed or reported during the term counts “regardless of scan frequency”.[1]

IP-based Vulnerability Management

In IP-licensed subscriptions, a manager can open Help > Account Info > VM Summary to see three figures: IPs Purchased, IPs in Subscription and Unique Hosts Scanned. The licence used is based on “the total IPs added to the license displayed in IPs in Subscription field but not on the basis of the total assets scanned”.[2] For a subscription with unlimited IPs, the IPs Purchased field always reads “Contact your Technical Account Manager”. Additional IPs are bought through the TAM.[2] The practical difference from VMDR is that an IP-based position is driven by what the customer adds to the subscription, not by what the platform discovers.

CSAM, ETM and identities

CSAM counts unique managed assets after de-duplication and normalization. Assets discovered only through External Attack Surface Management, Passive Sensor, Cloud Agentless Passive Sensor, Active Directory, VMware or CMDB integrations are excluded.[1] Activating an unmanaged asset in CSAM for VM, Policy Audit or Certificate View converts it into a managed asset, and “the license for those applications is used”.[9] ETM counts unique assets with security findings, whether the findings come from Qualys or non-Qualys sources. With a valid ETM subscription, CSAM is included, and no separate QLUs have to be bought or allocated for it.[1] ETM Identity counts unique enabled identities across identity providers such as Active Directory, Entra ID, Okta and Ping. Disabled and duplicate identities are excluded.[1]

Agents: Patch Management, EDR, FIM

Patch Management usage is based on agents activated for Patch Management, Isolation or Mitigation. Agents that remain activated continue to count “even when idle”. TruRisk Eliminate counts the highest asset count across those three modules, and each asset counts once.[1] The Patch Management entry on the QLU page carries the note “Available for Fed High subscriptions only”; the page does not say how Patch Management is sold on other platforms.[1] EDR counts endpoints on which the EDR agent is installed and active. An inactive endpoint stops counting only when the agent is removed or the endpoint is de-registered.[1] FIM counts agent-based assets with FIM enabled. Container runtime sensors and scanner-based assets count only if they sent FIM events in the last 30 days.[1]

Counting / floors

De-duplication

An asset scanned by both a Scanner Appliance and a Cloud Agent “is counted as one asset, provided it represents the same uniquely identifiable asset”. De-duplication depends on the identifiers available, however. Devices with multiple IP addresses may not correlate and “may be recognized as separate instances”.[1] Multi-homed servers, DHCP ranges and re-imaged hosts are therefore the usual sources of over-count in a VMDR position.

Purging

For VMDR and Policy Audit, decommissioned assets (inactive, terminated or unused) are excluded “only when purge rules are enabled”.[1] Purging also removes Cloud Agents. When a Cloud Agent is uninstalled, its host record and scan results are purged. If the host has been offline for more than 15 days, the record is deleted, and the agent is re-provisioned as a new Cloud Agent if the host comes back online.[8] Commentary: because A1 counts every agent that reported at any time in the term, the published definition implies that a purge lowers future counts but does not remove an agent already counted in the current term.

Patch Management overconsumption

In the Patch Management Licenses tab, one licence is consumed per asset. If more assets are activated than licences held, the Total Consumption counter exceeds 100%, and “licenses will be consumed based on the asset activation time stamp in ascending order”.[5] Isolation behaves differently. Activation and licence allocation are mapped 1:1, and “the license consumption never exceeds the license limit”.[6]

VMDR and Patch Management licence counts

VMDR includes a free Patch Management licence, with limited features, for assets enabled for VMDR. Full capability needs Patch Management licences. The Cloud Agent UI shows VMDR and Patch Management licences combined. In Qualys’s example, 100 VMDR and 50 Patch Management licences appear as 150 activations in Cloud Agent but 50 in Patch Management.[5] Reconciliations should take the Patch Management figure from the Patch Management UI.

Activation keys

Cloud Agent activation keys can be unlimited, which is the default, or limited by agent count, expiry date or both. When a limited key reaches its limit, it expires and cannot onboard new agents, but agents already installed “continue to function as expected”.[7] Key limits are therefore a deployment control, not a licence entitlement.

Included sensors

Cloud Agent inventory and Qualys Passive Scanners are “Included with all subscriptions”.[4] Sensors are not a separate licence line for VMDR: Qualys lists unlimited virtual scanners, Cloud Agents, passive sensors, agent gateways and container sensors as part of VMDR.[3]

Virtualization & partitioning

Virtual machines and container hosts are listed as eligible VMDR assets in their own right.[1] No hypervisor-level or host-based alternative is published. VMDR-OT uses weighting instead. Basic identification assets are inventoried but consume no QLUs, an enriched data asset counts as two-thirds of an asset, and an asset with vulnerabilities counts as one.[1]

Cloud / BYOL

Cloud instances found through cloud service provider connectors count toward VMDR (component B) once per instance ID, including instances terminated during the term.[1] Short-lived autoscaling instances can therefore add to the count even after they are gone. Agentless cloud workload scanning is licensed under TotalCloud, as described in Qualys cloud and application security licensing.

Programs

Patch Management add-ons

Windows Extended Security Update patching needs a separate ESU licence. The ESU licence is tailored to the Windows version, is “not part of the Patch Management subscription”, and must be enabled by the TAM. It supports Windows Server 2012 and 2012 R2, and may not be available in every region.[5] The TruRisk Eliminate MECM plugin needs a TruRisk Eliminate subscription. Its licence expires with that subscription.[5]

Trials

Isolation trial licences give all features for 30 days, and the trial “can be allocated a maximum of 6 times”.[6] Other trial and free-edition rules are covered in Qualys scanners, free editions and contract terms.

Out of scope

This article does not cover the vulnerability knowledge base, detection content or remediation effectiveness. It also does not cover QLU-to-asset ratios, which the documentation marks as illustrative and which are set per contract.

References

  1. Asset Definition and Product-Specific QLU Usage CalculationVMDR, VMDR Mobile, VMDR-OT, EDR, zLinux, ETM, CSAM, ETM Identity, Policy Audit, Audit Fix, FIM, PCI, Patch Management, TruRisk Eliminate. Footer: Last updated June 2026.Retrieved 2026-09-27.
  2. Purchasing more IPs / licensesIP-based VM subscriptions. Footer: Last updated September 2026.Retrieved 2026-09-27.
  3. Vulnerability Management, Detection and Response (VMDR)What VMDR includes. Undated.Retrieved 2026-09-27.
  4. Subscription Plans | Flexible Cybersecurity Solutions | QualysItems included with all subscriptions. Undated.Retrieved 2026-09-27.
  5. Manage TE LicensesPatch Management, Mitigation and Isolation licence consumption; ESU licence; MECM plugin. Footer: Last updated September 2026.Retrieved 2026-09-27.
  6. Viewing Isolation LicensesFull and Trial Isolation licences. Footer: Last updated September 2026.Retrieved 2026-09-27.
  7. Cloud Agent Activation KeyUnlimited and limited keys. Footer: Last updated September 2026.Retrieved 2026-09-27.
  8. Purge Rule BehaviorCloud Agent host record removal. Footer: Last updated September 2026.Retrieved 2026-09-27.
  9. Activate Assets for Applications (CSAM)Activation consumes the application licence.Retrieved 2026-09-27.
  10. Qualys VMDR TruRisk for Small BusinessVMDR TruRisk, FixIT and ProtectIT packages. Undated.Retrieved 2026-09-27.
  11. Qualys Master Cloud Services Agreement (Terms and Conditions)Version label [11.25v]; no effective date. §1 Assets; §3.5 Usage Limits.Retrieved 2026-09-27.
  12. Activate Cloud Agent for PAFPolicy Audit Fix prerequisites. Footer: Last updated September 2026.Retrieved 2026-09-27.

See also

Catalog Rows Cited

12Metrics1SKUs

Esc