LICENSEWARE

Tenable Master Agreement, audit and compliance

This article is about the contractual layer of Tenable licensing: the Tenable Master Agreement v.7, Tenable's compliance review right, overage and true-up, use restrictions, third-party and managed-service use, assignment, intellectual property indemnity, evaluations and NFR licences. For product counting rules see Tenable licensing.

On This Page

The Tenable Master Agreement is the contract that “governs all Tenable products (including Tenable One, Tenable Vulnerability Management, Tenable Security Center, and Nessus) and services”.[2] The current published template is version 7, labelled 12.2025. It takes effect when the customer clicks to accept it, and it is legally binding on acceptance or on continued download, installation or use.[1] Three schedules are part of the Agreement: Schedule A for Software, Schedule B for Hosted Services and Schedule C for Professional Services. Hardware (Schedule D), artificial intelligence (Schedule E), data processing, technical support plans and the cloud service level agreement are separate documents on Tenable’s Software License Agreements page.[1][2] For a software asset manager, the Agreement matters for four reasons. It points to the Documentation for the metric, it defines how overages are settled, it contains the compliance review right, and it limits who may use the Products and for whose benefit. General background is in software license audit and license compliance.

Editions

The template has no editions. It names the Tenable contracting entity according to the customer’s location and type:[1]

Customer Tenable entity Governing law and forum 
Located in North or South America Tenable, Inc. Delaware law; courts of Howard County, Maryland and the US District Court for Maryland; jury trial waived 
US federal, state or local government, or a federal systems integrator Tenable Public Sector LLC As above; Government Customer clause (48 C.F.R. 12.212) applies 
Located outside the Americas Tenable Network Security Ireland Limited Irish law; arbitration in Dublin under the Arbitration Act 2010 

The Agreement lasts until terminated. Each purchase has its own License Term, stated in the Ordering Document.[1]

Metrics

The Agreement does not define a licence metric. Licences follow “the applicable licensing model as set forth in the Documentation and/or the Ordering Document”. That model may limit Scan Targets, compute, storage, resource utilisation, License Term, users, seats, licences or modules.[1] The central defined term is the Scan Target, “the targets or subjects of a Scan”. Documentation means the product manuals at docs.tenable.com.[1] The Cloud Platform Licensing Policy links the two: “an asset is considered a scan target”.[3] For reseller purchases, the Ordering Document that Tenable issues “shall set forth all Products (and corresponding licensing metrics) purchased by Customer”. That makes it the entitlement record for an effective licence position.[1] Catalog proof: Licensing model set by Documentation and Ordering Document.

Counting / floors

Metering and overage (Master Agreement v.7, 12.2025). Tenable “shall use commercially reasonable efforts to meter resource utilization and assess likeness or uniqueness of Scan Targets”. If the customer exceeds its licence restrictions, it must buy an upgraded licence for all actual or additional usage. Tenable or the reseller may invoice the overage promptly, at no more than Tenable’s then-current rates.[1] Discrepancies in Scan Target or utilisation counts are “the sole responsibility of the Customer to resolve”.[1] The clause works as a standing true-up. Nothing in the template gives a grace allowance. The 30-day elasticity is in the Cloud Platform Licensing Policy, which treats anything longer as a violation of the licence agreement.[3] Catalog proof: Overage requires an upgraded licence at up to then-current rates.

Temporary limitation. If Tenable reasonably believes that usage “exceeds the limitations of the license”, it may temporarily limit access to the Products or to specific features. Where practical it gives prior notice, and email or in-product messaging is enough. Normal fees continue during the limitation.[1] The products implement this technically. Cloud products disable scanning and export after 30 days of overage,[4] and Security Center disables access once its limit is exceeded.[5] Catalog proof: Tenable may temporarily limit use that exceeds the licence.

Fees for access. In direct transactions, “Fees for Hosted Services are charged for access to the Host Environment (as defined herein), not actual usage”, and payment is due within 30 days of invoice. For reseller purchases, payment terms are agreed with the reseller.[1] Unused capacity is not refunded. Termination for convenience needs 60 days’ notice and brings no refund.[1] Catalog proof: Hosted Services fees are for access, not actual usage.

Audits and compliance

Compliance review (Schedule A §5). Tenable may, “by itself or through an independent third party, review Customer’s usage of the Software to confirm compliance with this Agreement or the applicable Ordering Document”. The clause sets three conditions. Tenable must give reasonable advance notice, may not request a review more than once a year, and must not unreasonably interfere with the customer’s business.[1] Catalog proof: Compliance review of Software usage at most once per year.

The clause has three features that matter for audit planning:

  • Scope. It sits in the Software schedule, so it covers installed products such as Nessus, Security Center and on-premises OT Exposure. The Hosted Services schedule has no review clause. For cloud products, compliance evidence comes from Tenable’s own metering, its Technical Data rights and the temporary-limitation clause.[1]
  • What is missing. No cost-shifting threshold, no records-retention period, no certification step and no deadline for paying findings is stated. Any shortfall found is settled through the overage clause at up to then-current rates.[1]
  • Technical Data. Tenable may use data generated by the Products, which the Agreement defines to include “information regarding licensing metrics and product behavioral data”, for purposes including licence validation.[1]

Nessus activation codes. Tenable’s Nessus documentation warns that continuously transferring one activation code between several scanners to maintain concurrent deployments “may violate the Tenable End User License Agreement (EULA)”. It advises customers to hold enough licences for the number of scanners they operate.[7] Catalog proof: Nessus activation code cannot be shared between scanners.

Use rights and restrictions

Internal use (Schedules A and B §2). Software is licensed in object code, “solely for Customer’s or Customer’s Affiliates own internal business purposes”. Installation is limited to the registered machines, and one backup copy is allowed. Hosted Services give the same internal-use access to the modules on the Ordering Document.[1] Catalog proof: Internal business use only; install limited to registered machines.

Restrictions (§4(c)). The Agreement prohibits five kinds of use:

  • reverse engineering;
  • derivative works;
  • service bureau or application service provider use without prior written consent;
  • providing “any managed service to a third party” without signing the Managed Security Services Provider Addendum;
  • competitive analysis.

Products may scan only targets owned or hosted by the customer or its Affiliates, or third parties that gave express authorisation.[1] Breach of §4(c) is carved out of the liability caps.[1] Tenable’s Licensing Guide adds that MSSPs get “simplified pricing” through their representative.[8] Catalog proof: Managed services to third parties need the MSSP Addendum.

Customer’s Agent (§12(a)). A third party may run the Products to provide security services, solely for the customer’s benefit and internal purposes. The customer is “fully responsible” for that party’s use, “including liability for any breach of this Agreement or use beyond the licensed quantities”. Tenable may withdraw its consent to a particular agent.[1] Catalog proof: Customer's Agent may scan on the customer's behalf.

Term, renewal, transfer and termination

Intellectual property

Ownership and feedback. The Agreement transfers no title to the Products. Rights not expressly granted are reserved, and feedback the customer gives is assigned to Tenable.[1] For contracts with Tenable Network Security Ireland Limited, decompiling for interoperability is allowed to the extent local law permits, after first asking Tenable for the information.[1]

Indemnity (§9). Tenable defends and indemnifies the customer against third-party claims that the customer’s authorised use of the Products infringes or misappropriates intellectual property rights in a Berne Convention jurisdiction. If a claim arises, Tenable may modify or replace the Products, procure the right to keep using them, or terminate. On termination it refunds prepaid unused subscription fees. For perpetual Software or Hardware the refund is “a straight line depreciation of the license fee based on a three (3) year useful life”.[1] Exclusions cover customer modifications, combination with non-Tenable products, failure to install updates and use outside the Agreement. The customer in turn indemnifies Tenable against claims arising from its scans of third-party targets. The indemnities sit outside the liability cap, which otherwise equals the fees paid in the prior twelve months.[1] Catalog proof: Tenable IP infringement indemnity and remedies.

Programs

Out of scope

  • The Data Processing Addendum, security measures and the Service Level Agreement’s service credits.
  • Schedule D (Hardware) and Schedule E (Artificial Intelligence).
  • Signed enterprise agreements, public-sector contract vehicles and reseller terms, which may override the template.
  • Court decisions and disputes about Tenable licence reviews or intellectual property. Tenable’s contract documents do not report any, and no vendor-published source was found.

References

  1. Tenable Master Agreement v.7Click-through template labelled v.7 12.2025; 13 pages.Retrieved 2026-09-27.
  2. Tenable Software License AgreementsCurrent agreements index; the Master Agreement governs all products.Retrieved 2026-09-27.
  3. Tenable Cloud Platform Licensing PolicyLicense Size: 30-day elasticity before a violation.Retrieved 2026-09-27.
  4. Tenable One Vulnerability Management LicensingOverage stages at 3, 15 and 30 days.Retrieved 2026-09-27.
  5. Tenable Security Center LicensingAccess disabled when licence exceeded.Retrieved 2026-09-27.
  6. Tenable Technical Support PlansVersion v7-20-2025.Effective 2025-07-20. Retrieved 2026-09-27.
  7. Manage Activation Code (Tenable Nessus 10.12)Activation code transfer and EULA caution.Retrieved 2026-09-27.
  8. Tenable One Foundation / Tenable One Advanced LicensingSimplified MSSP pricing note.Retrieved 2026-09-27.

See also

Catalog Rows Cited

17Rules3Programs

Esc