LICENSEWARE

Tenable licensing

This article is an overview of how Tenable licenses Tenable One, its vulnerability, web application, identity, OT and attack surface products, Tenable Security Center and Tenable Nessus. Deeper articles cover Tenable One packaging, cloud vulnerability and web application scanning, Security Center with Nessus and OT, and the Tenable Master Agreement. It is not legal advice.

On This Page

Tenable licensing is the set of terms and counting rules under which Tenable sells its exposure management platform, Tenable One, the products that make it up, the on-premises Tenable Security Center, and the Tenable Nessus vulnerability scanner. One click-through contract, the Tenable Master Agreement, governs every Tenable product, including Tenable One, Tenable Vulnerability Management, Tenable Security Center and Nessus.[2] The contracting entity depends on the customer. It is Tenable, Inc. in the Americas, Tenable Public Sector LLC for US federal, state and local government, and Tenable Network Security Ireland Limited everywhere else.[1] The Agreement does not fix a metric. Licences follow “the applicable licensing model as set forth in the Documentation and/or the Ordering Document”. That model can limit Scan Targets, compute, storage, License Term, users, seats or modules.[1] In practice the Documentation is the Tenable Licensing Guide on docs.tenable.com. It states that every Tenable product except Nessus is licensed per asset, and that Nessus is subscription-based.[3]

The result is a family of asset-style metrics. Each product defines its own asset, but the products share a 90-day assessment window, automatic licence reclamation, and a staged response to overage. For the general models, see concurrent and device licensing and subscription and consumption licensing.

Editions

Tenable no longer sells most products as separately named editions. New customers buy Tenable One in one of two packages, Tenable One Foundation or Tenable One Advanced. Point products such as Vulnerability Management, Web App Scanning, OT Exposure and Attack Surface Management are applications inside the package, and several further capabilities are add-ons.[8] Customers who bought Tenable One earlier stay on a ratio-based model, which converts each product’s resources into Tenable One assets.[9] The Licensing Guide also documents standalone licensing for most products.

Offering Delivery Licensed on Notes 
Tenable One Foundation / Advanced Cloud platform Tenable One asset Minimum 100 / 300 assets[8] 
Tenable One Vulnerability Management Cloud Assessed asset in the past 90 days Unlimited Nessus scanners, Agents and Network Monitors included[4] 
Tenable One Web App Scanning Cloud or on-premises Unique FQDN On-premises version requires Security Center[6] 
Tenable Security Center / Security Center+ On-premises IP address or UUID Director add-on for multi-instance management[5] 
Tenable One OT Exposure On-premises appliances Detected device IP address Subscription or perpetual/maintenance[10] 
Tenable One Identity Exposure Cloud or on-premises Enabled user AD and Entra ID identities deduplicated[11] 
Tenable Nessus Professional / Expert Installed scanner Annual subscription per activation code Expert adds web app and EASM scanning[7] 

Naming varies between documents. Licensing Guide topics use a “Tenable One” prefix, for example Tenable One OT Exposure and Tenable One Web App Scanning, but the same pages still use shorter forms such as Tenable Vulnerability Management.[4] Older contracts and SKUs may carry earlier names. The Licensing Guide explicitly leaves out Tenable One Cloud Exposure (Tenable Cloud Security) and refers customers to their Tenable representative.[3]

Metrics

Tenable term Catalog row Where it applies 
Asset (Tenable One) Tenable One asset The single pool purchased under Foundation, Advanced or the ratio-based model[8] 
Licensed asset Licensed asset (VM) Assessed resources from the past 90 days, identified on scans or imported with vulnerabilities[4] 
Asset by IP address or UUID IP address or UUID Tenable Security Center; counting depends on repository type[5] 
FQDN FQDN Web App Scanning; also Nessus Expert web applications[6] 
Enabled user Enabled user Identity Exposure[11] 
Detected device with an IP address OT device IP OT Exposure[10] 
Observable object Observable object Standalone Attack Surface Management[9] 
PCI asset PCI ASV asset Unique IP addresses checked at attestation[17] 
Nessus licence Nessus subscription One activation code per active scanner[15] 

The Cloud Platform Licensing Policy supplies the general vocabulary. An Asset is a physical or virtual device with an operating system, an active cloud resource, a web application with an FQDN, or a user of the identity products. An Assessed Asset has been scanned for a vulnerability, configuration or state. A Discovered Asset has only been identified by discovery plugins. A Licensed Asset is any asset assessed within the product’s metered billing term.[12] The practical rule is that discovery is free and assessment consumes licences. Other metrics in the catalog cover AI Exposure users, Tenable Hexa AI tokens, Cloud Exposure billable assets and container image:tag combinations.

Counting / floors

Asset-based pricing (Licensing Guide as of 2026-09-16). Customers buy licences for assets, and when the environment grows they buy more. Tenable uses progressive pricing, so the per-unit price falls as the quantity rises. Prices are quoted by the Tenable representative.[3] Catalog proof: All products except Nessus are licensed per asset with progressive pricing.

The 90-day window. In the cloud products an asset stays licensed while it has been assessed within the last 90 days. Licences are reclaimed within 24 hours of an asset’s deletion, after the Asset Age Out period configured for a network, or after 90 days without a scan.[4] The policy adds one caveat: assets deleted manually stay licensed until the end of the billing term, whereas assets removed by Asset Age Out are deleted immediately.[12] Catalog proof: VM licensed asset: assessed in the past 90 days; VM licence reclamation: 24 hours after deletion, age-out, or 90 days.

Count once. Tenable One deduplicates assets from its native sensors using a ranked hierarchy of identification attributes. A web application and the server it runs on are never merged, so they count as two assets.[8] Catalog proof: Count Once: native assets deduplicated by attribute hierarchy; Web application and its host are two licensed assets.

Floors. Tenable One Foundation needs at least 100 assets and Tenable One Advanced at least 300.[8] PCI ASV licences are sold at least 7 at a time.[17] Online purchases of Tenable One Vulnerability Management go up to 250 assets.[13] Catalog proof: Tenable One minimums: 100 assets Foundation, 300 assets Advanced; PCI ASV licence checked at attestation submission.

Overage. The contractual rule is the same for all products. A customer that exceeds its licence restrictions must buy an upgraded licence for all actual usage, invoiced at no more than Tenable’s then-current rates.[1] The technical response differs by product. Cloud products are elastic and reduce functionality in stages at 3, 15 and 30 days.[4] The policy treats more than 30 days over the licence as a violation of the licence agreement.[12] Security Center disables access when its limit is exceeded,[5] and OT Exposure cannot exceed its allocation at all.[10] Catalog proof: Overage requires an upgraded licence at up to then-current rates; Cloud products: elastic overage with staged reduction at 3, 15 and 30 days; Security Center disables access when the licence limit is exceeded.

Nessus. Nessus Professional is sold at a single subscription price, and Nessus Expert adds charges for web application and EASM domains beyond five per rolling 90-day period.[7] An activation code cannot be shared between scanners.[15] Catalog proof: Nessus activation code cannot be shared between scanners.

Virtualization & partitioning

Tenable metrics count scan targets, not processors or cores, so no hard or soft partitioning policy of the kind described in virtualization and partitioning applies. Virtual machines and containers are named examples of licensed assets in Vulnerability Management.[4] In practice virtualization affects the count through identity. Cloned virtual machines that carry the same Tenable agent UUID can merge into a single asset. Uncredentialed scans of hosts that already run an agent can create duplicates.[8] Container images in Tenable Enclave Security are licensed per unique image:tag combination.

Cloud / BYOL

The Tenable Cloud Platform hosts Vulnerability Management, Web App Scanning, Identity Exposure, Attack Surface Management and the Tenable One applications. The Master Agreement’s Hosted Services schedule gives the customer access to the modules on the Ordering Document for the License Term, and fees are charged for access, not actual usage.[1] No bring-your-own-licence mapping is published. Moving from Security Center to the cloud is a commercial change of product. Cloud workloads count as licensed assets. The policy’s asset definition includes active, non-terminated cloud resources, and assets terminated in a cloud platform free their licence after a nightly cleanup.[12]

Programs

Prices

Tenable publishes online prices only for Nessus, Tenable One Vulnerability Management and Tenable One Web App Scanning. Tenable One, Cloud Exposure and Security Center are sold by customised quote.[13] On 2026-09-27 the pricing page listed Nessus Professional at USD 4,790 for a one-year licence (Tenable Nessus Professional - 1 year) and Nessus Expert at USD 6,790 (Tenable Nessus Expert - 1 year), with two- and three-year options and a USD 400 Advanced Support add-on.[13] Nessus Essentials Plus costs USD 199 a year.[14] The same page showed two different one-year figures for Vulnerability Management (USD 3,700 on the product card, USD 3,500 for 100 assets in the purchase dialog). The catalog therefore records that online subscription without a list price.

Out of scope

  • Tenable One Cloud Exposure (Tenable Cloud Security) packaging and prices, which the Licensing Guide does not cover.
  • Tenable hardware appliances (Schedule D) and the AI schedule (Schedule E), except where they affect licensing.
  • Signed enterprise agreements, public-sector contract vehicles, reseller price lists and cloud marketplace private offers, which were not retrievable.
  • Tenable Patch Management and Tenable One AI Exposure beyond their licensing metric.
  • Litigation arising from Tenable licence reviews or intellectual property disputes, which Tenable’s licensing documents do not address. The contractual audit and IP indemnity clauses are covered in Tenable Master Agreement, audit and compliance.

References

  1. Tenable Master Agreement v.7Click-through master agreement labelled v.7 12.2025. §1 Definitions; §2 Orders; §3 Term; §4 Products and licensing model; §5 Support; §12 Other legal clauses; Schedules A-C.Retrieved 2026-09-27.
  2. Tenable Software License AgreementsIndex of current agreements and schedules. Undated.Retrieved 2026-09-27.
  3. Licensing Tenable Products (Tenable Licensing Guide)Overview topic of the Licensing Guide.Effective 2026-09-16. Retrieved 2026-09-27.
  4. Tenable One Vulnerability Management LicensingLicensed asset, counting, reclamation, overage, excluded plugins.Retrieved 2026-09-27.
  5. Tenable Security Center LicensingIP or UUID asset counting, components, lock-out, expiry.Retrieved 2026-09-27.
  6. Tenable One Web App Scanning LicensingFQDN licensing.Retrieved 2026-09-27.
  7. Tenable Nessus LicensingNessus Professional and Expert; activation code.Retrieved 2026-09-27.
  8. Tenable One Foundation / Tenable One Advanced LicensingCurrent Tenable One packaging, minimums, Count Once, Hexa AI tokens.Retrieved 2026-09-27.
  9. Tenable One Ratio-Based LicensingLegacy ratio-based model and asset value table.Retrieved 2026-09-27.
  10. Tenable One OT Exposure LicensingPer-IP-address device licensing.Retrieved 2026-09-27.
  11. Tenable One Identity Exposure LicensingEnabled-user licensing.Retrieved 2026-09-27.
  12. Tenable Cloud Platform Licensing PolicyDefinitions of Asset, Licensed Asset, Deleted Asset, License Size.Retrieved 2026-09-27.
  13. Tenable and Nessus Pricing & Purchase OptionsPublic online prices. Undated.Retrieved 2026-09-27.
  14. Tenable Nessus Essentials Vulnerability ScannerEssentials and Essentials Plus non-commercial licences.Retrieved 2026-09-27.
  15. Manage Activation Code (Tenable Nessus 10.12)Activation code properties and transfer.Retrieved 2026-09-27.
  16. Tenable Technical Support PlansVersion v7-20-2025.Effective 2025-07-20. Retrieved 2026-09-27.
  17. Tenable One PCI ASV LicensingPCI Standard and Enterprise tiers; 7-licence minimum.Retrieved 2026-09-27.

See also

Catalog Rows Cited

13Metrics11Rules8Programs3SKUs

Esc