The Tenable Master Agreement is the contract that “governs all Tenable products (including Tenable One, Tenable Vulnerability Management, Tenable Security Center, and Nessus) and services”.[2] The current published template is version 7, labelled 12.2025. It takes effect when the customer clicks to accept it, and it is legally binding on acceptance or on continued download, installation or use.[1] Three schedules are part of the Agreement: Schedule A for Software, Schedule B for Hosted Services and Schedule C for Professional Services. Hardware (Schedule D), artificial intelligence (Schedule E), data processing, technical support plans and the cloud service level agreement are separate documents on Tenable’s Software License Agreements page.[1][2] For a software asset manager, the Agreement matters for four reasons. It points to the Documentation for the metric, it defines how overages are settled, it contains the compliance review right, and it limits who may use the Products and for whose benefit. General background is in software license audit and license compliance.
Editions
The template has no editions. It names the Tenable contracting entity according to the customer’s location and type:[1]
| Customer | Tenable entity | Governing law and forum |
|---|---|---|
| Located in North or South America | Tenable, Inc. | Delaware law; courts of Howard County, Maryland and the US District Court for Maryland; jury trial waived |
| US federal, state or local government, or a federal systems integrator | Tenable Public Sector LLC | As above; Government Customer clause (48 C.F.R. 12.212) applies |
| Located outside the Americas | Tenable Network Security Ireland Limited | Irish law; arbitration in Dublin under the Arbitration Act 2010 |
The Agreement lasts until terminated. Each purchase has its own License Term, stated in the Ordering Document.[1]
Metrics
The Agreement does not define a licence metric. Licences follow “the applicable licensing model as set forth in the Documentation and/or the Ordering Document”. That model may limit Scan Targets, compute, storage, resource utilisation, License Term, users, seats, licences or modules.[1] The central defined term is the Scan Target, “the targets or subjects of a Scan”. Documentation means the product manuals at docs.tenable.com.[1] The Cloud Platform Licensing Policy links the two: “an asset is considered a scan target”.[3] For reseller purchases, the Ordering Document that Tenable issues “shall set forth all Products (and corresponding licensing metrics) purchased by Customer”. That makes it the entitlement record for an effective licence position.[1] Catalog proof: Licensing model set by Documentation and Ordering Document.
Counting / floors
Metering and overage (Master Agreement v.7, 12.2025). Tenable “shall use commercially reasonable efforts to meter resource utilization and assess likeness or uniqueness of Scan Targets”. If the customer exceeds its licence restrictions, it must buy an upgraded licence for all actual or additional usage. Tenable or the reseller may invoice the overage promptly, at no more than Tenable’s then-current rates.[1] Discrepancies in Scan Target or utilisation counts are “the sole responsibility of the Customer to resolve”.[1] The clause works as a standing true-up. Nothing in the template gives a grace allowance. The 30-day elasticity is in the Cloud Platform Licensing Policy, which treats anything longer as a violation of the licence agreement.[3] Catalog proof: Overage requires an upgraded licence at up to then-current rates.
Temporary limitation. If Tenable reasonably believes that usage “exceeds the limitations of the license”, it may temporarily limit access to the Products or to specific features. Where practical it gives prior notice, and email or in-product messaging is enough. Normal fees continue during the limitation.[1] The products implement this technically. Cloud products disable scanning and export after 30 days of overage,[4] and Security Center disables access once its limit is exceeded.[5] Catalog proof: Tenable may temporarily limit use that exceeds the licence.
Fees for access. In direct transactions, “Fees for Hosted Services are charged for access to the Host Environment (as defined herein), not actual usage”, and payment is due within 30 days of invoice. For reseller purchases, payment terms are agreed with the reseller.[1] Unused capacity is not refunded. Termination for convenience needs 60 days’ notice and brings no refund.[1] Catalog proof: Hosted Services fees are for access, not actual usage.
Audits and compliance
Compliance review (Schedule A §5). Tenable may, “by itself or through an independent third party, review Customer’s usage of the Software to confirm compliance with this Agreement or the applicable Ordering Document”. The clause sets three conditions. Tenable must give reasonable advance notice, may not request a review more than once a year, and must not unreasonably interfere with the customer’s business.[1] Catalog proof: Compliance review of Software usage at most once per year.
The clause has three features that matter for audit planning:
- Scope. It sits in the Software schedule, so it covers installed products such as Nessus, Security Center and on-premises OT Exposure. The Hosted Services schedule has no review clause. For cloud products, compliance evidence comes from Tenable’s own metering, its Technical Data rights and the temporary-limitation clause.[1]
- What is missing. No cost-shifting threshold, no records-retention period, no certification step and no deadline for paying findings is stated. Any shortfall found is settled through the overage clause at up to then-current rates.[1]
- Technical Data. Tenable may use data generated by the Products, which the Agreement defines to include “information regarding licensing metrics and product behavioral data”, for purposes including licence validation.[1]
Nessus activation codes. Tenable’s Nessus documentation warns that continuously transferring one activation code between several scanners to maintain concurrent deployments “may violate the Tenable End User License Agreement (EULA)”. It advises customers to hold enough licences for the number of scanners they operate.[7] Catalog proof: Nessus activation code cannot be shared between scanners.
Use rights and restrictions
Internal use (Schedules A and B §2). Software is licensed in object code, “solely for Customer’s or Customer’s Affiliates own internal business purposes”. Installation is limited to the registered machines, and one backup copy is allowed. Hosted Services give the same internal-use access to the modules on the Ordering Document.[1] Catalog proof: Internal business use only; install limited to registered machines.
Restrictions (§4(c)). The Agreement prohibits five kinds of use:
- reverse engineering;
- derivative works;
- service bureau or application service provider use without prior written consent;
- providing “any managed service to a third party” without signing the Managed Security Services Provider Addendum;
- competitive analysis.
Products may scan only targets owned or hosted by the customer or its Affiliates, or third parties that gave express authorisation.[1] Breach of §4(c) is carved out of the liability caps.[1] Tenable’s Licensing Guide adds that MSSPs get “simplified pricing” through their representative.[8] Catalog proof: Managed services to third parties need the MSSP Addendum.
Customer’s Agent (§12(a)). A third party may run the Products to provide security services, solely for the customer’s benefit and internal purposes. The customer is “fully responsible” for that party’s use, “including liability for any breach of this Agreement or use beyond the licensed quantities”. Tenable may withdraw its consent to a particular agent.[1] Catalog proof: Customer's Agent may scan on the customer's behalf.
Term, renewal, transfer and termination
- Renewal terms. If the Agreement was accepted by click-through, each renewal is governed by the terms then posted, and use at renewal counts as acceptance. A mutually signed Agreement continues to govern renewals.[1] Catalog proof: Click-through renewals take the then-current terms.
- Assignment. Assignment needs the other party’s consent, which may not be unreasonably withheld. Transfers to an Affiliate, or in a merger or sale of substantially all ownership units, are exempt. In every case the customer must complete Tenable’s License Assignment Request Form.[1] Catalog proof: Assignment needs consent and a License Assignment Request Form.
- Termination for cause. Either party may terminate after a 30-day cure period. The customer then removes all copies of the Products and certifies their return or destruction. If Tenable terminates for cause, the customer still owes payments for the rest of the License Term.[1] Catalog proof: On termination for cause, remove Products and certify destruction.
- Support. Standard support is included for term licences. Perpetual support is bought separately, and lapsed support is reinstated by paying for the lapsed period.[1] A support plan is required for all software deployments.[6] Catalog proof: Support included for term licences; perpetual support bought separately; Support plan required for all software deployments.
Intellectual property
Ownership and feedback. The Agreement transfers no title to the Products. Rights not expressly granted are reserved, and feedback the customer gives is assigned to Tenable.[1] For contracts with Tenable Network Security Ireland Limited, decompiling for interoperability is allowed to the extent local law permits, after first asking Tenable for the information.[1]
Indemnity (§9). Tenable defends and indemnifies the customer against third-party claims that the customer’s authorised use of the Products infringes or misappropriates intellectual property rights in a Berne Convention jurisdiction. If a claim arises, Tenable may modify or replace the Products, procure the right to keep using them, or terminate. On termination it refunds prepaid unused subscription fees. For perpetual Software or Hardware the refund is “a straight line depreciation of the license fee based on a three (3) year useful life”.[1] Exclusions cover customer modifications, combination with non-Tenable products, failure to install updates and use outside the Agreement. The customer in turn indemnifies Tenable against claims arising from its scans of third-party targets. The indemnities sit outside the liability cap, which otherwise equals the fees paid in the prior twelve months.[1] Catalog proof: Tenable IP infringement indemnity and remedies.
Programs
- Evaluation licences. Tenable grants these at its discretion. They carry no charge and no support, and expire at the end of the evaluation period. They may not be used on third-party targets or to serve the customer’s clients.[1] Catalog proof: Evaluation licences exclude third-party scanning and client services.
- NFR licences. These go to sales and Technology Partners for one year and renew automatically. They may not be used in production, on the partner’s own networks, in customer services or for customer evaluations.[1] Catalog proof: NFR licences are non-production.
- MSSP Addendum. Required before the Products are used to provide managed services. Its text is not published.[1]
Out of scope
- The Data Processing Addendum, security measures and the Service Level Agreement’s service credits.
- Schedule D (Hardware) and Schedule E (Artificial Intelligence).
- Signed enterprise agreements, public-sector contract vehicles and reseller terms, which may override the template.
- Court decisions and disputes about Tenable licence reviews or intellectual property. Tenable’s contract documents do not report any, and no vendor-published source was found.