Tenable licensing is the set of terms and counting rules under which Tenable sells its exposure management platform, Tenable One, the products that make it up, the on-premises Tenable Security Center, and the Tenable Nessus vulnerability scanner. One click-through contract, the Tenable Master Agreement, governs every Tenable product, including Tenable One, Tenable Vulnerability Management, Tenable Security Center and Nessus.[2] The contracting entity depends on the customer. It is Tenable, Inc. in the Americas, Tenable Public Sector LLC for US federal, state and local government, and Tenable Network Security Ireland Limited everywhere else.[1] The Agreement does not fix a metric. Licences follow “the applicable licensing model as set forth in the Documentation and/or the Ordering Document”. That model can limit Scan Targets, compute, storage, License Term, users, seats or modules.[1] In practice the Documentation is the Tenable Licensing Guide on docs.tenable.com. It states that every Tenable product except Nessus is licensed per asset, and that Nessus is subscription-based.[3]
The result is a family of asset-style metrics. Each product defines its own asset, but the products share a 90-day assessment window, automatic licence reclamation, and a staged response to overage. For the general models, see concurrent and device licensing and subscription and consumption licensing.
Editions
Tenable no longer sells most products as separately named editions. New customers buy Tenable One in one of two packages, Tenable One Foundation or Tenable One Advanced. Point products such as Vulnerability Management, Web App Scanning, OT Exposure and Attack Surface Management are applications inside the package, and several further capabilities are add-ons.[8] Customers who bought Tenable One earlier stay on a ratio-based model, which converts each product’s resources into Tenable One assets.[9] The Licensing Guide also documents standalone licensing for most products.
| Offering | Delivery | Licensed on | Notes |
|---|---|---|---|
| Tenable One Foundation / Advanced | Cloud platform | Tenable One asset | Minimum 100 / 300 assets[8] |
| Tenable One Vulnerability Management | Cloud | Assessed asset in the past 90 days | Unlimited Nessus scanners, Agents and Network Monitors included[4] |
| Tenable One Web App Scanning | Cloud or on-premises | Unique FQDN | On-premises version requires Security Center[6] |
| Tenable Security Center / Security Center+ | On-premises | IP address or UUID | Director add-on for multi-instance management[5] |
| Tenable One OT Exposure | On-premises appliances | Detected device IP address | Subscription or perpetual/maintenance[10] |
| Tenable One Identity Exposure | Cloud or on-premises | Enabled user | AD and Entra ID identities deduplicated[11] |
| Tenable Nessus Professional / Expert | Installed scanner | Annual subscription per activation code | Expert adds web app and EASM scanning[7] |
Naming varies between documents. Licensing Guide topics use a “Tenable One” prefix, for example Tenable One OT Exposure and Tenable One Web App Scanning, but the same pages still use shorter forms such as Tenable Vulnerability Management.[4] Older contracts and SKUs may carry earlier names. The Licensing Guide explicitly leaves out Tenable One Cloud Exposure (Tenable Cloud Security) and refers customers to their Tenable representative.[3]
Metrics
| Tenable term | Catalog row | Where it applies |
|---|---|---|
| Asset (Tenable One) | Tenable One asset | The single pool purchased under Foundation, Advanced or the ratio-based model[8] |
| Licensed asset | Licensed asset (VM) | Assessed resources from the past 90 days, identified on scans or imported with vulnerabilities[4] |
| Asset by IP address or UUID | IP address or UUID | Tenable Security Center; counting depends on repository type[5] |
| FQDN | FQDN | Web App Scanning; also Nessus Expert web applications[6] |
| Enabled user | Enabled user | Identity Exposure[11] |
| Detected device with an IP address | OT device IP | OT Exposure[10] |
| Observable object | Observable object | Standalone Attack Surface Management[9] |
| PCI asset | PCI ASV asset | Unique IP addresses checked at attestation[17] |
| Nessus licence | Nessus subscription | One activation code per active scanner[15] |
The Cloud Platform Licensing Policy supplies the general vocabulary. An Asset is a physical or virtual device with an operating system, an active cloud resource, a web application with an FQDN, or a user of the identity products. An Assessed Asset has been scanned for a vulnerability, configuration or state. A Discovered Asset has only been identified by discovery plugins. A Licensed Asset is any asset assessed within the product’s metered billing term.[12] The practical rule is that discovery is free and assessment consumes licences. Other metrics in the catalog cover AI Exposure users, Tenable Hexa AI tokens, Cloud Exposure billable assets and container image:tag combinations.
Counting / floors
Asset-based pricing (Licensing Guide as of 2026-09-16). Customers buy licences for assets, and when the environment grows they buy more. Tenable uses progressive pricing, so the per-unit price falls as the quantity rises. Prices are quoted by the Tenable representative.[3] Catalog proof: All products except Nessus are licensed per asset with progressive pricing.
The 90-day window. In the cloud products an asset stays licensed while it has been assessed within the last 90 days. Licences are reclaimed within 24 hours of an asset’s deletion, after the Asset Age Out period configured for a network, or after 90 days without a scan.[4] The policy adds one caveat: assets deleted manually stay licensed until the end of the billing term, whereas assets removed by Asset Age Out are deleted immediately.[12] Catalog proof: VM licensed asset: assessed in the past 90 days; VM licence reclamation: 24 hours after deletion, age-out, or 90 days.
Count once. Tenable One deduplicates assets from its native sensors using a ranked hierarchy of identification attributes. A web application and the server it runs on are never merged, so they count as two assets.[8] Catalog proof: Count Once: native assets deduplicated by attribute hierarchy; Web application and its host are two licensed assets.
Floors. Tenable One Foundation needs at least 100 assets and Tenable One Advanced at least 300.[8] PCI ASV licences are sold at least 7 at a time.[17] Online purchases of Tenable One Vulnerability Management go up to 250 assets.[13] Catalog proof: Tenable One minimums: 100 assets Foundation, 300 assets Advanced; PCI ASV licence checked at attestation submission.
Overage. The contractual rule is the same for all products. A customer that exceeds its licence restrictions must buy an upgraded licence for all actual usage, invoiced at no more than Tenable’s then-current rates.[1] The technical response differs by product. Cloud products are elastic and reduce functionality in stages at 3, 15 and 30 days.[4] The policy treats more than 30 days over the licence as a violation of the licence agreement.[12] Security Center disables access when its limit is exceeded,[5] and OT Exposure cannot exceed its allocation at all.[10] Catalog proof: Overage requires an upgraded licence at up to then-current rates; Cloud products: elastic overage with staged reduction at 3, 15 and 30 days; Security Center disables access when the licence limit is exceeded.
Nessus. Nessus Professional is sold at a single subscription price, and Nessus Expert adds charges for web application and EASM domains beyond five per rolling 90-day period.[7] An activation code cannot be shared between scanners.[15] Catalog proof: Nessus activation code cannot be shared between scanners.
Virtualization & partitioning
Tenable metrics count scan targets, not processors or cores, so no hard or soft partitioning policy of the kind described in virtualization and partitioning applies. Virtual machines and containers are named examples of licensed assets in Vulnerability Management.[4] In practice virtualization affects the count through identity. Cloned virtual machines that carry the same Tenable agent UUID can merge into a single asset. Uncredentialed scans of hosts that already run an agent can create duplicates.[8] Container images in Tenable Enclave Security are licensed per unique image:tag combination.
Cloud / BYOL
The Tenable Cloud Platform hosts Vulnerability Management, Web App Scanning, Identity Exposure, Attack Surface Management and the Tenable One applications. The Master Agreement’s Hosted Services schedule gives the customer access to the modules on the Ordering Document for the License Term, and fees are charged for access, not actual usage.[1] No bring-your-own-licence mapping is published. Moving from Security Center to the cloud is a commercial change of product. Cloud workloads count as licensed assets. The policy’s asset definition includes active, non-terminated cloud resources, and assets terminated in a cloud platform free their licence after a nightly cleanup.[12]
Programs
- Tenable One Foundation and Tenable One Advanced. These are the two current packages, with add-ons such as identity security, patch management, PCI ASV and extra Tenable Hexa AI tokens.[8] See Tenable One licensing.
- Ratio-based Tenable One (legacy). Resources convert to Tenable One assets at published ratios, and licences can be reallocated once per 90 days.[9]
- Technical Support Plans (version 2025-07-20). Four plans are offered: Standard, Advanced, Premier and Elite. A support plan is required for all software deployments.[16]
- MSSP Addendum, evaluation and NFR licences. Contract-level programs in the Master Agreement.[1] See Tenable Master Agreement, audit and compliance.
- Nessus Essentials and Essentials Plus. Non-commercial licences limited to 5 and 20 IPs.[14]
Prices
Tenable publishes online prices only for Nessus, Tenable One Vulnerability Management and Tenable One Web App Scanning. Tenable One, Cloud Exposure and Security Center are sold by customised quote.[13] On 2026-09-27 the pricing page listed Nessus Professional at USD 4,790 for a one-year licence (Tenable Nessus Professional - 1 year) and Nessus Expert at USD 6,790 (Tenable Nessus Expert - 1 year), with two- and three-year options and a USD 400 Advanced Support add-on.[13] Nessus Essentials Plus costs USD 199 a year.[14] The same page showed two different one-year figures for Vulnerability Management (USD 3,700 on the product card, USD 3,500 for 100 assets in the purchase dialog). The catalog therefore records that online subscription without a list price.
Out of scope
- Tenable One Cloud Exposure (Tenable Cloud Security) packaging and prices, which the Licensing Guide does not cover.
- Tenable hardware appliances (Schedule D) and the AI schedule (Schedule E), except where they affect licensing.
- Signed enterprise agreements, public-sector contract vehicles, reseller price lists and cloud marketplace private offers, which were not retrievable.
- Tenable Patch Management and Tenable One AI Exposure beyond their licensing metric.
- Litigation arising from Tenable licence reviews or intellectual property disputes, which Tenable’s licensing documents do not address. The contractual audit and IP indemnity clauses are covered in Tenable Master Agreement, audit and compliance.