Qualys VMDR and endpoint asset counting covers the rules Qualys publishes for counting assets in its infrastructure security, asset management and remediation applications. The central offering is Vulnerability Management, Detection and Response (VMDR). Qualys describes it as including asset and vulnerability management, TruRisk prioritization, patch detection, certificate inventory, PCI ASV assessments, and unlimited virtual scanners, Cloud Agents, passive sensors, agent gateways and container sensors.[3] VMDR usage is based on “the total number of unique assets assessed by VMDR during the subscription term”.[1] The contractual cap is the number of Assets in the Order Form under the Master Cloud Services Agreement.[11]
Editions
| Application | What it covers | Unit counted |
|---|---|---|
| VMDR | Vulnerability assessment and prioritization across hybrid IT[3] | VMDR asset |
| Vulnerability Management (IP-based) | Earlier subscriptions sized by purchased IPs[2] | IP address |
| VMDR Mobile | Mobile devices enabled through VMDR Mobile, Cloud Agent or the Intune Connector[1] | Mobile device |
| VMDR-OT | Operational technology assets[1] | Weighted OT asset |
| Policy Audit / Policy Compliance | Configuration and policy assessment. Policy Audit is described as an enhanced version of Policy Compliance[9] | Policy Audit asset |
| Audit Fix (PAF) | Remediation of failed Policy Audit controls. Needs an active Policy Audit subscription and a Cloud Agent[12] | Agents activated for PAF |
| CyberSecurity Asset Management (CSAM) | Managed asset inventory | CSAM managed asset |
| Enterprise TruRisk Management (ETM), ETM Identity | Risk aggregation; identity risk | Asset with findings; enabled identity |
| Patch Management, Mitigation, Isolation; TruRisk Eliminate | Remediation through the Cloud Agent | Activated agent |
| Multi-Vector EDR | Endpoint detection and response | EDR endpoint |
| File Integrity Monitoring (FIM) | File change monitoring | FIM-enabled asset |
| PCI Compliance | PCI ASV scanning | IP address or DNS entry |
For small businesses, Qualys sells three packages. VMDR TruRisk is enterprise VMDR functionality. TruRisk FixIT adds operating-system and third-party patching, and TruRisk ProtectIT adds anti-virus, incident response and threat hunting. No prices are published.[10]
Metrics
VMDR and Policy Audit
VMDR and Policy Audit share one counting method (Asset Definition page, as published 2026-09-27):[1]
- A1, all-time on-premises agents. Every unique asset that has had a Qualys Agent installed and has reported at any time in the subscription term, counted once per Agent ID “regardless of current status”.
- A2, scanner-discovered assets. Assets found by network or cloud scanning (IP-based discovery, DNS, NetBIOS, cloud instance discovery, and authenticated or unauthenticated scans) that are not already in A1.
- B, cloud service provider assets. Resources found through AWS, Azure, Google Cloud, OCI and Alibaba integrations, counted once per instance ID. Resources terminated or deleted during the term are included if they were discovered during it.
- C, ghost assets. Assets with no open ports and no reported vulnerabilities that result from transient scan artifacts, IP reuse or incomplete correlation. These are deducted.
Usage is (A + B − C) × QLU ratio, evaluated in 15-day intervals at the highest value observed.[1] Eligible assets include physical servers, virtual machines, cloud compute instances, desktops and laptops, container hosts, and “any other device or system assigned a unique hostname, IP address, Agent ID, instance ID, or other unique identifier”. Any asset scanned, assessed or reported during the term counts “regardless of scan frequency”.[1]
IP-based Vulnerability Management
In IP-licensed subscriptions, a manager can open Help > Account Info > VM Summary to see three figures: IPs Purchased, IPs in Subscription and Unique Hosts Scanned. The licence used is based on “the total IPs added to the license displayed in IPs in Subscription field but not on the basis of the total assets scanned”.[2] For a subscription with unlimited IPs, the IPs Purchased field always reads “Contact your Technical Account Manager”. Additional IPs are bought through the TAM.[2] The practical difference from VMDR is that an IP-based position is driven by what the customer adds to the subscription, not by what the platform discovers.
CSAM, ETM and identities
CSAM counts unique managed assets after de-duplication and normalization. Assets discovered only through External Attack Surface Management, Passive Sensor, Cloud Agentless Passive Sensor, Active Directory, VMware or CMDB integrations are excluded.[1] Activating an unmanaged asset in CSAM for VM, Policy Audit or Certificate View converts it into a managed asset, and “the license for those applications is used”.[9] ETM counts unique assets with security findings, whether the findings come from Qualys or non-Qualys sources. With a valid ETM subscription, CSAM is included, and no separate QLUs have to be bought or allocated for it.[1] ETM Identity counts unique enabled identities across identity providers such as Active Directory, Entra ID, Okta and Ping. Disabled and duplicate identities are excluded.[1]
Agents: Patch Management, EDR, FIM
Patch Management usage is based on agents activated for Patch Management, Isolation or Mitigation. Agents that remain activated continue to count “even when idle”. TruRisk Eliminate counts the highest asset count across those three modules, and each asset counts once.[1] The Patch Management entry on the QLU page carries the note “Available for Fed High subscriptions only”; the page does not say how Patch Management is sold on other platforms.[1] EDR counts endpoints on which the EDR agent is installed and active. An inactive endpoint stops counting only when the agent is removed or the endpoint is de-registered.[1] FIM counts agent-based assets with FIM enabled. Container runtime sensors and scanner-based assets count only if they sent FIM events in the last 30 days.[1]
Counting / floors
De-duplication
An asset scanned by both a Scanner Appliance and a Cloud Agent “is counted as one asset, provided it represents the same uniquely identifiable asset”. De-duplication depends on the identifiers available, however. Devices with multiple IP addresses may not correlate and “may be recognized as separate instances”.[1] Multi-homed servers, DHCP ranges and re-imaged hosts are therefore the usual sources of over-count in a VMDR position.
Purging
For VMDR and Policy Audit, decommissioned assets (inactive, terminated or unused) are excluded “only when purge rules are enabled”.[1] Purging also removes Cloud Agents. When a Cloud Agent is uninstalled, its host record and scan results are purged. If the host has been offline for more than 15 days, the record is deleted, and the agent is re-provisioned as a new Cloud Agent if the host comes back online.[8] Commentary: because A1 counts every agent that reported at any time in the term, the published definition implies that a purge lowers future counts but does not remove an agent already counted in the current term.
Patch Management overconsumption
In the Patch Management Licenses tab, one licence is consumed per asset. If more assets are activated than licences held, the Total Consumption counter exceeds 100%, and “licenses will be consumed based on the asset activation time stamp in ascending order”.[5] Isolation behaves differently. Activation and licence allocation are mapped 1:1, and “the license consumption never exceeds the license limit”.[6]
VMDR and Patch Management licence counts
VMDR includes a free Patch Management licence, with limited features, for assets enabled for VMDR. Full capability needs Patch Management licences. The Cloud Agent UI shows VMDR and Patch Management licences combined. In Qualys’s example, 100 VMDR and 50 Patch Management licences appear as 150 activations in Cloud Agent but 50 in Patch Management.[5] Reconciliations should take the Patch Management figure from the Patch Management UI.
Activation keys
Cloud Agent activation keys can be unlimited, which is the default, or limited by agent count, expiry date or both. When a limited key reaches its limit, it expires and cannot onboard new agents, but agents already installed “continue to function as expected”.[7] Key limits are therefore a deployment control, not a licence entitlement.
Included sensors
Cloud Agent inventory and Qualys Passive Scanners are “Included with all subscriptions”.[4] Sensors are not a separate licence line for VMDR: Qualys lists unlimited virtual scanners, Cloud Agents, passive sensors, agent gateways and container sensors as part of VMDR.[3]
Virtualization & partitioning
Virtual machines and container hosts are listed as eligible VMDR assets in their own right.[1] No hypervisor-level or host-based alternative is published. VMDR-OT uses weighting instead. Basic identification assets are inventoried but consume no QLUs, an enriched data asset counts as two-thirds of an asset, and an asset with vulnerabilities counts as one.[1]
Cloud / BYOL
Cloud instances found through cloud service provider connectors count toward VMDR (component B) once per instance ID, including instances terminated during the term.[1] Short-lived autoscaling instances can therefore add to the count even after they are gone. Agentless cloud workload scanning is licensed under TotalCloud, as described in Qualys cloud and application security licensing.
Programs
Patch Management add-ons
Windows Extended Security Update patching needs a separate ESU licence. The ESU licence is tailored to the Windows version, is “not part of the Patch Management subscription”, and must be enabled by the TAM. It supports Windows Server 2012 and 2012 R2, and may not be available in every region.[5] The TruRisk Eliminate MECM plugin needs a TruRisk Eliminate subscription. Its licence expires with that subscription.[5]
Trials
Isolation trial licences give all features for 30 days, and the trial “can be allocated a maximum of 6 times”.[6] Other trial and free-edition rules are covered in Qualys scanners, free editions and contract terms.
Out of scope
This article does not cover the vulnerability knowledge base, detection content or remediation effectiveness. It also does not cover QLU-to-asset ratios, which the documentation marks as illustrative and which are set per contract.