Tenable One licensing covers Tenable’s exposure management platform. Several security applications share one pool of licences, and each application counts a different kind of resource against that pool. Customers “purchase licenses for assets: resources identified by - or managed in - your Tenable products”, and the asset type varies by product. In Web App Scanning an asset is a unique fully qualified domain name (FQDN). In Identity Exposure it is an enabled user in a directory service.[1] Tenable documents two generations of the model. New customers buy Tenable One Foundation or Tenable One Advanced. Earlier customers keep a ratio-based model, which weights each resource type before it is added to the pool.[2] Both generations sit under the Tenable Master Agreement. A customer that exceeds its licence restrictions must buy an upgraded licence for all actual usage.[10] For the general background, see subscription and consumption licensing.
Editions
Tenable offers two versions of Tenable One. Each has out-of-the-box applications and optional add-ons.[1]
| Tenable One Foundation | Tenable One Advanced | |
|---|---|---|
| Minimum purchase | 100 assets | 300 assets |
| Included | Vulnerability management, web application security, OT & IoT security, attack surface management, AI discovery, cloud workload protection, dashboards & reporting, asset inventory, integrated intelligence, ticketing, third-party data connectors | Everything in Foundation, plus AI workload and agent protection, cloud security posture management, Kubernetes security posture management, risk scores & benchmarks, workflow & mobilization, Attack Path Analysis |
| Add-ons | Cloud-native application protection; AI user & app governance; identity security; patch management; PCI ASV capabilities; additional Tenable Hexa AI tokens | Same add-on list |
Source: Tenable One Foundation / Advanced Licensing.[1] Foundation and Advanced no longer include the no-cost PCI Basic licence that came with earlier Vulnerability Management purchases.[9]
Ratio-based Tenable One (legacy). The earlier structure is still documented for customers whose contracts use ratios. It includes companion licences for Tenable One Vulnerability Management, Security Center+ with up to three consoles, on-premises Web App Scanning, OT Exposure, Attack Surface Management and Cloud Exposure. The add-ons were extra Security Center consoles, extra Web App Scanning concurrency, on-premises Identity Exposure, third-party connectors and daily ASM frequency.[2] Tenable states that all new Tenable One customers use the Foundation / Advanced structure.[2]
Metrics
The pool is counted in Tenable One assets. Under Foundation and Advanced, one asset of any supported type consumes one licence. The ratio-based model instead converts resources “to a number of Tenable One assets based on ratios”, so that a single price per Tenable One asset applies to every resource type.[2]
| Resource (product) | Tenable definition | Ratio-based value |
|---|---|---|
| Vulnerability Management asset | Scanned targets from the past 90 days, discovery excluded, or imported assets with vulnerabilities | 1 |
| Security Center+ IP address | 1 IP address | 1 |
| Web App Scanning FQDN | FQDNs assessed in the past 90 days, or IPs if only IPs are scanned | 1 |
| Identity (Identity Exposure) | Human or machine identities in the identity service | 0.50 |
| Cloud Exposure billable asset | Public cloud compute instances, container hosts or orchestrators, serverless assets, container repositories, on-premises container hosts | 3 (CIEM), 5 (Standard), 7.50 (Enterprise), 1 (Cloud Workload Protection) |
| OT device (OT Exposure) | Detected devices with IP addresses | 1.50 |
| Observable object (ASM) | Domain names, subdomains or IP addresses | 0.25 (fortnightly), 0.50 (daily) |
| Third-party application asset | Hosts, code projects, images, websites or cloud resources from a non-Tenable source | 0.50 |
Source: Tenable One Asset Values table.[2] Catalog proof: Legacy Tenable One ratios convert resources into Tenable One assets.
Two further units sit outside the asset pool. Tenable Hexa AI tokens are “the base unit of LLM compute within Tenable One”.[1] AI Exposure users are counted by a Highest Count method, described below.[5]
Counting / floors
Minimums. Customers must buy at least 100 assets for Foundation and 300 for Advanced.[1] The ratio-based calculator states that “You must buy at least 300 licenses at a time.”[2] Catalog proof: Tenable One minimums: 100 assets Foundation, 300 assets Advanced.
Count Once deduplication. Tenable uses a “count once” approach so that the same asset is never charged more than once. Assets from Nessus scanners, Nessus Agents and Vulnerability Management sensors are matched through a ranked hierarchy of Identification Attributes.[1] The ranking starts with cloud provider resource IDs, Active Directory identifiers, the Tenable agent or scanner UUID, third-party agent IDs (CrowdStrike, Qualys, BigFix, Carbon Black, Windows Defender), Entra ID device identifiers, network device serial numbers and the BIOS UUID. Below these come the MAC address, NetBIOS name, FQDN, IPv6 and IPv4. The last five are “network scoped”. The same IP address seen by scanners in two different Tenable networks is therefore two assets.[1] Catalog proof: Count Once: native assets deduplicated by attribute hierarchy.
Tenable’s guide lists failure modes that inflate the count:[1]
- An agent-covered laptop that is also scanned without credentials produces a second, IP-matched asset.
- DHCP reuse of an IP address is recognised as a new asset rather than merged.
- Cloned virtual machines that share an agent UUID can wrongly merge. The fix is to unlink the agent, delete the Tenable tag UUID and relink.
Tenable recommends credentialed scans, host tagging and correctly defined networks.
Asset classes do not merge. A web application scanned by Web App Scanning or ASM and the server it runs on, scanned by Vulnerability Management, are different asset classes. Together they count as two assets for licensing.[3] Catalog proof: Web application and its host are two licensed assets.
Third-party connectors. Customers must have available asset licences before they ingest assets from third-party connectors. Licences can be reallocated, or more can be purchased.[1] Under the ratio-based model, licences can be moved between products once per 90 days through the Tenable representative.[2]
Application-specific counting
- Identity Exposure. Each licence covers one unique identity. Accounts for the same identity in Active Directory and Entra ID count once, but identities that overlap across separate tenants are not deduplicated.[6] Catalog proof: Identity Exposure counts enabled users once across synced directories.
- Attack Surface Management. Within Tenable One, licensing counts only assets created by the ASM integration in Vulnerability Management. These are host assets for A and AAAA records, and web application assets where a web application is detected. They “are billable immediately upon creation”. The integration cannot be disabled, and exclusion rules are the only way to keep an asset out. The ASM inventory limit is twice the number of licences purchased.[4] Catalog proof: ASM within Tenable One: assets billable on creation in VM.
- AI Exposure. Billable users are the user count of the single AI application with the most users. In Tenable’s example, 2,000 ChatGPT Enterprise users and 300 GitHub Copilot users bill as 2,000. Billable users do not expire, and AI Exposure is an add-on to Foundation and Advanced.[5] Catalog proof: AI Exposure bills the largest single application user count.
- OT Exposure. Customers licensed through Foundation or Advanced can self-provision a Security Center companion licence, called a Reporting Console. Connecting a standalone OT Exposure purchase to Tenable One does not bring its assets into the Tenable One licence.[7]
Tenable Hexa AI tokens. Monthly token capacity comes with the subscription and rises with licensed assets. Under 1,000 assets it is 1.0M tokens on Foundation and 5.0M on Advanced. Above 250,000 assets it is 15.0M and 75.0M. Capacity resets on the first of each month without rollover. Additional capacity is sold in five tiers starting at 10M tokens a month.[1][8] Catalog proof: Hexa AI token capacity resets monthly without rollover.
Reclamation, overage and expiry
The purchased licence count stays fixed for the contract, but each application reclaims licences and reassigns them within the same product.[1]
- Vulnerability Management and Web App Scanning. Deleted assets are reclaimed within 24 hours. Other assets are reclaimed after the age-out period or after 90 days without a scan.
- Identity Exposure. Reclaimed in real time when an enabled user is deleted.
- OT Exposure. Reclaimed in real time for hidden assets and for assets offline more than 30 days.
- ASM. Reclaimed when assets are archived or when sources are removed or age out.
Overage is elastic. Tenable Exposure Management shows a message after three consecutive days over the licence, and a warning about reduced functionality after 15 days. After 30 days it disables scan and export features.[1] The Cloud Platform Licensing Policy treats elasticity beyond 30 days as a violation of the licence agreement.[8] Tenable warns 30 days before expiry. After expiry the customer “can no longer sign in to the Tenable One platform”.[1] Catalog proof: Cloud products: elastic overage with staged reduction at 3, 15 and 30 days; Cloud licence expiry blocks sign-in; 30-day warning.
Virtualization & partitioning
Tenable One has no processor or partition rules. Virtualization affects the count only through asset identity. Cloud provider resource IDs are the highest-confidence match. Cloned images that carry the same Tenable UUID can merge, and uncredentialed scans can duplicate agent-covered virtual machines.[1] Cloud Exposure counts compute instances, container hosts, serverless assets and container repositories as billable assets.[2]
Cloud / BYOL
Tenable One is a hosted service, so no bring-your-own-licence rule applies. Hosted Services fees are charged for access to the hosted environment, not actual usage.[10] Licences are provisioned in the Tenable Account Management portal, and each product’s activation code appears on its Products tab.[1]
Programs
- Tenable One Foundation and Tenable One Advanced: the current subscription tiers.[1]
- Ratio-based Tenable One: the legacy structure with 90-day reallocation.[2]
- PCI ASV tiers: an add-on licensed by asset count and checked at attestation.[9] See Tenable Vulnerability Management and Web App Scanning licensing.
- MSSP pricing is described as “simplified pricing” available through the Tenable representative.[1]
Out of scope
- Tenable One Cloud Exposure packaging beyond the ratio values, which the Licensing Guide does not cover.
- Per-asset prices, which Tenable does not publish for Tenable One.
- Patch Management and AI user & app governance add-ons, for which no metric is documented.
- Standalone Security Center, Nessus and OT Exposure purchases, covered in Tenable Security Center, Nessus and OT licensing.