LICENSEWARE

Rapid7 InsightVM, Nexpose and Exposure Command licensing

This article is about licensing Rapid7 vulnerability management: InsightVM, Nexpose and the Exposure Command packages that now include InsightVM. For the platform-wide overview, see Rapid7 licensing. It is not legal advice.

On This Page

InsightVM is Rapid7’s vulnerability risk management product. Nexpose is its on-premise vulnerability scanner.[1][9] Both are licensed by the number of unique assets whose vulnerability or policy assessment data is stored in the Security Console.[4][5] Rapid7 now presents InsightVM as the vulnerability management technology within Exposure Command. Exposure Command Essentials combines InsightVM with attack surface management. Exposure Command Ultimate adds cloud and application security.[1] Both products are Software under Schedule B of the Master Software and Services Agreement. InsightVM combines Rapid7-hosted components with components deployed on premises, while Nexpose is deployed on premises. Schedule B therefore applies its rules for both Cloud-Hosted and Distributed Software.[7]

Editions

Offering Contents (vendor description) Commercial notes 
InsightVM Vulnerability scanning with scan engines or agents, risk prioritisation and remediation guidance[12] Starts at $1.62 per asset per month for 500 assets[3]; still available, now part of Exposure Command[1] 
Nexpose On-premise scanner with Real Risk Score, Adaptive Security, policy assessment and remediation reporting[9] By quote 
Exposure Command Essentials InsightVM plus attack surface management; hybrid scanning, agent visibility, risk-based prioritisation and remediation workflows[2] By quote; demo-led[1] 
Exposure Command Ultimate Essentials plus multi-cloud and container assessment, IaC scanning, cloud threat detection and dynamic application security testing[2] By quote 
Managed Threat Complete MDR service that includes full access to InsightVM[8] Priced per MDR asset, not per InsightVM asset 

The public price point is recorded as InsightVM - starting price per asset. Commentary: $1.62 per asset per month for 500 assets works out to about $9,720 a year, before any discount. Existing InsightVM customers are told to take changes to their contract, timeline or deployment to their Rapid7 account team.[1] Customers who need hands-on access, an on-premise deployment or a smaller evaluation can still start an InsightVM trial.[12] See Exposure Command and InsightVM is sold as part of Exposure Command packages.

Metrics

Asset (unique assessed asset). InsightVM is licensed for unique assessed assets. An asset is assessed when its vulnerability or policy assessment data is stored in the Security Console.[4] Assets assessed by agents count toward the same total.[4] The contract term for this capacity is “unique assets”, one of the Volume Limitations in the MSSA.[7] The Nexpose documentation uses identical wording.[5]

Scan Engine (Max. Scan Engines) and hosted engine assets. The Security Console licence records several capacities alongside the asset maximum. Max. Scan Engines is the number of internal Scan Engines the customer may use. Max. Assets to Scan is the number of assets it may scan with internal engines. Max. Assets to Scan w/ Hosted Engine is the number it may scan with a Rapid7-hosted engine.[6]

Counting / floors

Assessed, not discovered (as retrieved 2026-09-30). The licence limits the number of assets that can be assessed and stored. It does not limit the number of assets that can be discovered on the network.[4] Commentary: discovery scans and asset inventory imports do not consume licences. The first vulnerability or policy result stored for an asset does. Catalog proof: InsightVM and Nexpose licence unique assessed assets, not discovered assets.

Correlation. Uniqueness is decided by correlation heuristics on UUIDs, hostnames, MAC addresses and IP addresses. A UUID match always correlates. Non-matching UUIDs do not prevent correlation if other attributes match.[4] Correlated assets are counted once, so an asset assessed by both an agent and a credentialed scan is not double-counted.[4] Commentary: assets that fail to correlate, for example unauthenticated scan results for agent-managed hosts, do count twice. Rapid7 points subscribers to its guidance on correlating agent assets with unauthenticated scans.[4] Catalog proof: Correlated assets counted once across agent and scan.

Thresholds and enforcement. The Security Console notifies users at three thresholds.[4]

Usage of licensed maximum What the console does 
Above 90% Orange notification 
Above 100% Red notification; temporary flexibility to scan above the limit 
Above 110% Red banner that cannot be dismissed; further scans may trigger automatic enforcement 
Enforcement New scan data is not retained and cannot be recovered later; ends when the count is back within the licence 

To avoid enforcement, the documentation says to clean up duplicate or stale assets, or to contact the customer success team to increase the licence.[4] Catalog proof: Above 110% of licensed assets new scan data may not be retained.

Contractual overage (effective 2025-10-24). Enforcement in the product is separate from the contract. Under Schedule B, excess usage is invoiced after a Notice Period at then-current list rates for the applicable tier, prorated for the rest of the Term.[7] Distributed Software may track or enforce its Volume Limitations. Rapid7 may also ask, no more than once every six months, for a signed certification of compliant use.[7] Catalog proof: Excess usage invoiced at then-current list rate for the tier, prorated; Distributed Software may enforce limits; signed usage certification at most every six months.

Who can see the count. Only global administrators can see the full licence limit, the usage bar and the licence details. Non-admin users see the overall and discovered asset counts for the assets they can access, along with the threshold notifications.[4]

Floors. No minimum quantity is published. The public starting price is expressed “for 500 assets”.[3]

Virtualization & partitioning

Rapid7 publishes no host-based, processor-based or hypervisor-based alternative. Each assessed virtual machine is an asset. The documentation does, however, set out three cases for elastic estates.[4]

  • AWS and Azure. Each instance or virtual machine counts as one asset until it is terminated. Rapid7’s discovery connections detect decommissioned instances and remove them from the licence count immediately, so stale cloud assets do not count against the limit.
  • Containers. Each container host counts as one asset, however many containers it runs. Per-image assessments, and the data they use, do not affect the licence count.
  • Other virtualization. On-premises virtual machines are not covered by an automatic removal rule. Commentary: stale virtual machines stay in the count until they are deleted from the console or aged out by the customer’s own retention settings.

Catalog proof: AWS and Azure instances count until terminated; container hosts count once.

Cloud / BYOL

InsightVM combines components Rapid7 hosts with components the customer deploys: scan engines and agents across on-prem and cloud-hosted infrastructure[12], managed from a Security Console.[6] The MSSA grants use of the Software within the Volume Limitations wherever it is deployed. It publishes no separate rule for installing Distributed Software in a public cloud.[7] In the Exposure Command packages, cloud resources are assessed by the cloud security component of Exposure Command Ultimate. That component covers AWS, Azure, GCP and Kubernetes, and extends to Oracle Cloud Infrastructure and Alibaba Cloud.[2] See Rapid7 Metasploit, AppSpider, InsightAppSec and InsightCloudSec licensing for how InsightCloudSec counts billable resources.

Licence activation and entitlement records

A Security Console is activated with a licence key from Rapid7, a string of 16 numbers and letters in four hyphen-separated groups. A console without internet access uses a .lic licence file instead, which lists the licensed features and scanning capacities.[6] The licence details show the licence status, the expiration date, the scan engine and asset maxima, and whether SCADA scanning, discovery scanning, PCI reporting and policy scanning are enabled. An active licence is needed to run scans and create reports.[6] On the Command Platform, the Subscription Management view lists each InsightVM or Nexpose subscription with its expiry and entitlements, together with Console Management.[10] Catalog proof: Security Console licence sets expiry, scan engines, asset maxima and features; Command Platform Subscription Management lists purchased entitlements and expiry.

Programs and legacy editions

Worked example

Commentary, illustrative only. A customer has 2,000 licensed InsightVM assets. It runs agents on 1,500 laptops and servers and credentialed scans on 700 servers, 400 of which also run the agent. It also holds 300 AWS instances, 120 of which were terminated during the quarter.

  1. Agents and scans together cover 1,500 + 700 - 400 = 1,800 hosts, provided the agent and scan records correlate.
  2. The 180 running AWS instances add 180, because terminated instances drop out through the discovery connection. That gives 1,980 assessed assets, or 99% of the licence.
  3. If 400 overlapping servers fail to correlate because scans are unauthenticated, the count rises to 2,380, or 119%. The console would then show the 110% banner, and new scan data could be withheld.
  4. The contractual exposure is the excess, invoiced at list rate for the relevant tier and prorated. The remedy is either to fix correlation and delete duplicates, or to buy up.

Out of scope

  • Surface Command licensing and the metric of the Exposure Command attack surface component. Neither is published.
  • Managed Vulnerability Management services, which are governed by Schedule A and a statement of work.
  • Metasploit integration with InsightVM, covered in the Metasploit article.
  • End-of-life dates for individual InsightVM integrations.

References

  1. InsightVM is now part of Exposure CommandProduct page and FAQ; the former InsightVM pricing URL redirects here. Undated.Retrieved 2026-09-30.
  2. Hybrid Exposure Management - Exposure CommandEssentials and Ultimate capability lists. Undated.Retrieved 2026-09-30.
  3. Rapid7 PricingInsightVM starting price. Undated.Retrieved 2026-09-30.
  4. Live Licensing - InsightVM documentationWhat counts as an asset; cloud and container assets; notifications; enforcement. Undated.Retrieved 2026-09-30.
  5. Live Licensing - Nexpose documentationNexpose version of the same page. Undated.Retrieved 2026-09-30.
  6. Managing versions, updates, and licenses - InsightVM documentationLicence activation and licence details. Undated.Retrieved 2026-09-30.
  7. Master Software and Services Agreement - Rapid7Volume Limitations, overage, usage verification. Last updated October 2025.Effective 2025-10-24. Retrieved 2026-09-30.
  8. Rapid7 MDR PackagesManaged Threat Complete FAQ on InsightVM inclusion. Undated.Retrieved 2026-09-30.
  9. On-Premise Vulnerability Scanner - NexposeNexpose product page. Undated.Retrieved 2026-09-30.
  10. Subscription Management - Command Platform documentationSubscriptions, entitlements and Console Management for InsightVM and Nexpose. Undated.Retrieved 2026-09-30.
  11. Rapid7 End User License Agreement (purchases before 2023-03-01)Nexpose MSSP and Consultant editions; records review. Last updated April 2021.Retrieved 2026-09-30.
  12. InsightVM TrialTrial page. Undated.Retrieved 2026-09-30.

See also

Catalog Rows Cited

1SKUs1Programs12Rules2Metrics

Esc