LICENSEWARE

Tenable Security Center, Nessus and OT licensing

This article is about Tenable's installed, on-premises products: Tenable Security Center, Security Center+ and Director, Tenable Nessus Professional, Expert and Essentials, Tenable One OT Exposure and Tenable Enclave Security. For the cloud products see Tenable Vulnerability Management and Web App Scanning licensing.

On This Page

Tenable Security Center, Nessus and OT licensing covers the Tenable products that customers install and run themselves. These are the Tenable Security Center vulnerability management console, the Tenable Nessus scanner, Tenable One OT Exposure for industrial networks, and the Tenable Enclave Security bundle for isolated environments. They are Software under Schedule A of the Tenable Master Agreement. The licence is non-exclusive and non-transferable, for internal business purposes during the License Term, and installation is “limited to use with the computers or machines for which the Software is registered for use”.[10] Licences can be perpetual or subscription.[10] Security Center and OT Exposure are sized by assets identified by IP address. Nessus is sold as a subscription rather than per asset, and each licence is tied to an activation code for one active scanner.[1][3] Schedule A also carries Tenable’s right to review Software usage once a year. See Tenable Master Agreement, audit and compliance.

Editions

Product Versions Licence types 
Tenable Security Center Security Center (Network Monitor in discovery mode, Nessus scanners); Security Center+ (adds Network Monitor vulnerability detection, Asset Exposure Score, Asset Criticality Rating); Director add-on Perpetual or subscription[1] 
Tenable Nessus Professional; Expert (adds web application and external attack surface scanning, infrastructure-as-code scanning) Annual subscription, 1 to 3 years[3][6] 
Nessus Essentials / Essentials Plus Non-commercial; 5 IPs (30 days) or 20 IPs (annual) Free or USD 199 a year[7] 
Tenable One OT Exposure Core platforms, sensors, Enterprise Manager as components Subscription or perpetual/maintenance[8] 
Tenable Enclave Security Security Center plus Tenable Container Security Per assessed host and per image:tag[9] 

Security Center Director manages several Security Center instances from one place. Customers cannot upgrade a Security Center licence to a Director licence, or downgrade in the other direction.[1]

Metrics

  • Asset by IP address or UUID (Security Center). Licences are “valid for specific hosts and a maximum number of active assets identified by IP address or UUID.”[1]
  • Nessus subscription. Nessus Professional is “A single subscription price”. A plugin feed activation code identifies the licensed version and, where applicable, how many IP addresses may be scanned, how many remote scanners linked and how many Agents linked to Nessus Manager.[3]
  • FQDN (Nessus Expert and Security Center Web App Scanning). Tracked by FQDN and port in Nessus Expert.[3]
  • Detected device IP address (OT Exposure). One licence for each IP address of a detected device.[8]
  • Image:tag combination (Container Security in Enclave Security).[9]

Counting / floors

Tenable Security Center

Assessment, not discovery (as retrieved 2026-09-27). Assets generally do not count until they have been assessed for vulnerabilities. With a 500-asset licence a customer “can perform host discovery on your network, but you cannot assess more than 500 assets”.[1] Catalog proof: Security Center: assets by IP or UUID, depending on repository type.

Repository type matters. In agent and IPv4 repositories, an IP address or UUID counts once, even if several scan methods found it or it is stored in several repositories. In universal repositories every asset with a UUID counts. The same host stored in an IPv4 repository without a UUID and in a universal repository with one “is counted twice”.[1] IP addresses found by an alternative port scanner count against the licence.[1]

Counted Not counted 
Assets from active scans Assets present only from imports to offline or remote repositories 
Assets from Network Monitor instances not in discovery mode Assets present only from Network Monitor in discovery mode 
UUIDs from Tenable One OT Exposure instances (not in Director) Offline or remote repositories downloaded with a different licence or instance 
Offline or remote repositories downloaded with the same instance or licence Excluded plugins, for example Nessus 10180, 10287, 11936, 19506, 112154, 161455, 179042; Network Monitor 0-132 list; LCE 800000-800099 

Source: How Assets are Counted, current version.[1] Older Security Center versions may exclude different plugins. The version-specific License Requirements topic in the user guide lists them.[2] Catalog proof: Discovery plugins excluded from licence counts.

Reclamation. The licence count updates when a repository is deleted, when a licence report runs, or when a new licence is uploaded. Aged-out assets are removed during nightly cleanup, and unresponsive hosts are removed at scan import if scan settings are configured to do so.[1]

Overage locks the console. Unlike the cloud products, Security Center does not stage overage over 30 days: “If you exceed your limit, Tenable disables your access to Tenable Security Center.”[1] The licensing service reports four statuses. They are Valid, Exceeded, Locked (the enforcement cluster or namespace ID does not match the deployment) and Expired.[1] Catalog proof: Security Center disables access when the licence limit is exceeded.

Included components. Subscription licences include, on request, “The same number of on-premises Tenable Agents as your licensed assets”. Perpetual customers must buy on-premises Agents separately. Director, additional consoles, the Lab License and the Lumin connector are subscription-only add-ons. Vulnerability Intelligence is included with subscriptions and is an add-on for perpetual licences.[1] Web App Scanning in Security Center scans up to the licensed number of FQDNs and is required for the on-premises version of Web App Scanning.[1][12] Catalog proof: Security Center subscriptions include on-premises Agents equal to licensed assets.

Expiry: perpetual versus subscription. After expiry a perpetual Security Center console “remains fully functional”, while a subscription console needs a new licence key. For perpetual Nessus, plugin updates stop when maintenance expires, and after 90 days Nessus stops working. Nessus scanners managed by Security Center then stop as well. Perpetual Network Monitor stops processing new data after 30 days without updates.[1] Catalog proof: Security Center expiry: perpetual consoles keep working, Nessus stops after 90 days.

Tenable Nessus

One code, one active scanner. The activation code “cannot be shared between scanners”. It must be used within 24 hours and is also needed to run Nessus offline.[4] In Nessus Professional and Expert the code can be transferred to another system. The newest system becomes the active instance, and the only one that receives plugin updates. Tenable says transfer is designed for permanent migrations. Continuously moving one code between scanners to keep concurrent deployments “may violate the Tenable End User License Agreement (EULA)”.[4] Catalog proof: Nessus activation code cannot be shared between scanners.

Managed scanners. Scanners linked to Tenable One Vulnerability Management are covered by that subscription, which includes unlimited Nessus scanners. Scanners managed by Security Center get their activation code and plugins from Security Center.[3] Tenable Agents are licensed through Nessus Manager or Vulnerability Management. Nessus Manager licences are sized to the deployment.[5]

Nessus Expert allowance. Nessus Expert includes five web applications and five external attack surface domains per rolling 90-day period, and more can be purchased. Each scanned URL, tracked by FQDN and port, consumes a licence for 90 days from its last scan. It cannot be released early by deleting scan data.[3] Catalog proof: Nessus Expert: five web apps and five EASM domains per rolling 90 days.

Non-commercial editions. Nessus Essentials (free, 30 days, 5 IPs) and Essentials Plus (annual, 20 IPs) “are for personal, educational and non-commercial purposes only”. Commercial deployments and consulting services require Nessus Professional.[7] Catalog proof: Nessus Essentials and Essentials Plus are non-commercial only.

Tenable One OT Exposure

The licence count equals the number of unique IP addresses, and assets are licensed from the moment they are detected. Modules behind live IP addresses do not count. In Tenable’s example, a PLC chassis with two live IPs and ten modules counts as two.[8] Licences are reclaimed in real time for hidden or removed assets and for assets offline more than 30 days. The limit is hard: “you can only use your allocated number of licenses unless you purchase more licenses.” When the limit is exceeded, non-administrators lose access and vulnerability plugin and IDS signature updates stop, but new assets are still detected. After expiry the product is disabled.[8] Catalog proof: OT Exposure: one licence per detected IP address, hard limit.

Tenable Enclave Security

Enclave Security licenses assessed Security Center hosts and unique Container Security image:tag combinations. Both may temporarily exceed the licensed count by 10%, beyond which the product is disabled.[9] Catalog proof: Enclave Security allows 10% temporary overage.

Virtualization & partitioning

No processor, core or partitioning rule applies. Virtual hosts are counted as IP addresses or UUIDs like physical hosts. Duplicates arise from repository design rather than from virtualization.[1] Security Center and Enclave Security licences are bound to a deployment. Security Center licence keys are generated for the installation’s hostname or install UUID, and a mismatched enforcement ID puts the licence into the Locked state.[1][9] Moving a virtual appliance therefore needs a re-applied licence.

Cloud / BYOL

These products are self-hosted. No licence mobility to Tenable’s cloud is published. Moving to the cloud means buying Tenable One Vulnerability Management or Tenable One, where Security Center+ is a companion licence under the ratio-based model.[1] Assets synchronised from Security Center to Vulnerability Management count toward both licences.[1]

Programs

Out of scope

  • Tenable hardware appliances under Schedule D.
  • Tenable Log Correlation Engine, which Tenable no longer supports.
  • The standalone Tenable Lumin SKUs, which reached End of Sale on 2025-03-31.
  • OT Exposure component prices and Security Center prices, which are quoted only.

References

  1. Tenable Security Center LicensingVersions, asset counting, components, reclamation, overage, expiry, statuses, licence keys.Retrieved 2026-09-27.
  2. License Requirements (Tenable Security Center 6.9.x User Guide)Version-specific licensing topic in the product user guide.Retrieved 2026-09-27.
  3. Tenable Nessus LicensingNessus Professional and Expert; activation code; Expert web app licensing.Retrieved 2026-09-27.
  4. Manage Activation Code (Tenable Nessus 10.12)Activation code properties; transfer.Retrieved 2026-09-27.
  5. Licensing Requirements (Tenable Agent 11.2.x User Guide)Agents licensed through Nessus Manager or Vulnerability Management.Retrieved 2026-09-27.
  6. Tenable and Nessus Pricing & Purchase OptionsNessus prices, Advanced Support, training.Retrieved 2026-09-27.
  7. Tenable Nessus Essentials Vulnerability ScannerEssentials and Essentials Plus.Retrieved 2026-09-27.
  8. Tenable One OT Exposure LicensingPer-IP-address device licensing; hard limit.Retrieved 2026-09-27.
  9. Tenable Enclave Security LicensingSecurity Center and Container Security in Enclave Security.Retrieved 2026-09-27.
  10. Tenable Master Agreement v.7§4(b), §5 Support; Schedule A Software (§2 licence, §5 compliance rights).Retrieved 2026-09-27.
  11. Tenable Technical Support PlansVersion v7-20-2025.Effective 2025-07-20. Retrieved 2026-09-27.
  12. Tenable One Web App Scanning LicensingOn-premises WAS requires Security Center.Retrieved 2026-09-27.

See also

Catalog Rows Cited

5Metrics11Rules2Programs8SKUs

Esc