Tenable Vulnerability Management and Web App Scanning licensing covers Tenable’s two cloud scanning products, now named Tenable One Vulnerability Management and Tenable One Web App Scanning, and the PCI ASV add-on that runs on them. Both products are Hosted Services under the Tenable Master Agreement. They grant access to the hosted environment and the modules on the Ordering Document for the License Term, and fees are charged “for access to the Host Environment (as defined herein), not actual usage”.[8] The metric is a count of assessed targets. Vulnerability Management assigns licences to assessed resources from the past 90 days, and Web App Scanning to unique fully qualified domain names.[1][3] Either product can be bought on its own or as an application within Tenable One. See Tenable One licensing.
Editions
| Offering | Metric | Included | Add-ons |
|---|---|---|---|
| Tenable One Vulnerability Management | Licensed asset | Unlimited Nessus scanners, unlimited Tenable Agents, unlimited Network Monitors with vulnerability detection, API access | PCI ASV; Attack Surface Management |
| Tenable One Web App Scanning (cloud) | FQDN | External scanning, OWASP Top 10, HTML5 crawling, integration with Vulnerability Management, API | Additional cloud scan concurrency |
| Tenable One Web App Scanning (on-premises) | FQDN | Runs through Nessus scanners in Security Center | Requires a Security Center licence |
| Tenable One PCI ASV | PCI ASV asset | Nessus and WAS PCI scan templates | Standard or Enterprise tier |
Sources: Vulnerability Management components;[1] Web App Scanning components;[3] PCI ASV tiers.[4]
The cloud version of Web App Scanning is sold only as a subscription. The on-premises version is available as a subscription or as a perpetual licence with maintenance, and “A Tenable Security Center license is required”.[3] Tenable Agents are licensed through the product that manages them, either Nessus Manager or Vulnerability Management. A Vulnerability Management subscription therefore covers its agents without separate agent licences.[6] Catalog proof: VM includes unlimited Nessus scanners, Agents and Network Monitors; On-premises Web App Scanning requires Security Center.
Metrics
The Cloud Platform Licensing Policy defines the terms that the licence agreement relies on:[2]
- Asset. A physical or virtual device with an operating system connected to a network; an active cloud resource; a web application with an FQDN; or a user of the identity products.
- Assessed Asset. Any asset scanned for a vulnerability, configuration or state.
- Discovered Asset. An asset identified by discovery plugins but not scanned.
- Licensed Asset. An asset assessed within the product’s metered billing term.
- Unlicensed Asset. An asset not assessed within the billing term but still inside the data retention period.
- License Size. The number of assets purchased that can be assessed or scanned.
The policy also states that “an asset is considered a scan target”, which ties these terms to the Master Agreement’s Scan Target.[2]
The catalog rows are Licensed asset (VM), FQDN and PCI ASV asset.
Counting / floors
Vulnerability Management
What counts (as retrieved 2026-09-27). A newly scanned asset is compared with previously discovered assets. It counts “if the new asset does not match a previously discovered asset and has been assessed for vulnerabilities”.[1] Matching uses the BIOS UUID, MAC address, NetBIOS name, FQDN and other attributes, together with the Tenable UUID that authenticated scanners and agents assign.[1]
| Counted | Not counted |
|---|---|
| Assets identified by an active scan or agent scan | Scans with the Host Discovery template or only discovery plugins |
| Asset imports containing vulnerabilities (for example Nessus Professional results) | Asset imports with no vulnerabilities (for example ServiceNow data) |
| Host and Web App Scanning assets whose last licensed scan was within 90 days | Network Monitor in discovery mode; discovery-only connectors until the asset is scanned |
| Assets from scans with plugin debugging enabled (delete them to stop counting) | Scanned Mobile Device Management assets; excluded plugin output |
Source: How Assets Are Counted.[1] Catalog proof: VM licensed asset: assessed in the past 90 days; Discovery-only data and connectors do not consume VM licences; Plugin-debugging scans create licensed assets.
Excluded plugins. Output from listed plugins does not count towards the licence. The list covers Nessus discovery plugins such as 10180 (Ping the remote host), 10335 (Nessus TCP scanner), 11219 (SYN scanner), 14274 (SNMP scanner) and 34277 (UDP scanner). It also covers informational plugins such as 45590 (CPE), 54615 (Device Type), 12053 (Host FQDN), 11936 (OS Identification), 19506 (Nessus Scan Information), 209654 and 204872, and Network Monitor plugins 0, 12, 18, 19, 20, 113 and 132.[1] Catalog proof: Discovery plugins excluded from licence counts.
Reclamation and age-out. The licence count is static for the contract unless more is purchased. Licences return to the pool in four ways:[1]
- Deleted assets are reclaimed within 24 hours.
- Aged-out assets are reclaimed after the period set under Settings > Sensors > Networks.
- Connector assets are reclaimed the day after the connector is terminated.
- All other assets are reclaimed after 90 days without a scan.
The policy qualifies deletion in two ways. First, assets deleted through the UI or API “remain licensed until the end of the billing term”. Second, assets removed by Asset Age Out are deleted immediately together with their vulnerability data.[2] Cloud assets flagged as terminated by a connector free their licence after a nightly cleanup.[2] Catalog proof: VM licence reclamation: 24 hours after deletion, age-out, or 90 days.
Overage. Licences are elastic, but overage reduces functionality in three stages. After three consecutive days over the licensed count a message appears. After 15 days a warning about reduced functionality appears. After 30 days scan and export features are disabled.[1] Tenable allows temporary elasticity “for no more than 30 days before it’s considered a violation of the license agreement”.[2] The Master Agreement then requires an upgraded licence covering all actual usage.[8] Tenable attributes many overages to poor scan hygiene or product misconfiguration.[1] Catalog proof: Cloud products: elastic overage with staged reduction at 3, 15 and 30 days; Overage requires an upgraded licence at up to then-current rates.
Expiry. A warning appears 30 days before expiry. After expiry the customer can no longer sign in to the Tenable platform.[1] Catalog proof: Cloud licence expiry blocks sign-in; 30-day warning.
Web App Scanning
Web App Scanning counts FQDNs “scanned for vulnerabilities in the past 90 days”. FQDNs are read as complete URLs with a hostname, parent domain and top-level domain.[3] If any component differs from a previously scanned target, the target is a separate asset. For example, en.example.com, ex-ample.com and example.org are three assets besides example.com. Paths under the same FQDN, such as /welcome/get-started, add nothing.[3] If only IP addresses are scanned, the IP addresses are licensed instead.[3] Catalog proof: WAS: one asset per unique FQDN; paths do not add assets.
A web application FQDN and the host that serves it are two licensed assets. Count Once deduplication does not merge the two asset classes.[3][7] Reclamation, overage stages and expiry follow the Vulnerability Management rules. Deleted assets are reclaimed within 24 hours and other assets after the age-out period or 90 days.[3] Catalog proof: Web application and its host are two licensed assets.
PCI ASV
The legacy model bundled PCI Basic with Vulnerability Management at no extra cost. PCI Basic covers one asset and one attestation every 90 days and is intended for testing. The legacy TIO-PCI-ASV SKU was not licensed by asset count.[4] The current SKUs, PCI Standard (12 attestations a year, 30-day SLA) and PCI Enterprise (unlimited, 14-day SLA), are licensed by asset count. They are checked “at the time of attestation submission”, not continuously.[4] FQDNs are resolved to IP addresses, and only unique IP addresses count. An attestation over the licensed count is blocked until assets are marked out of scope or more licences are bought. Licences are sold at least 7 at a time, and new customers must also hold at least a basic Vulnerability Management licence.[4] Tenable’s sizing guidance is to cover every public-facing IP address and to add a 10-20% buffer for internal scope.[4] Catalog proof: PCI ASV licence checked at attestation submission.
Virtualization & partitioning
The metric counts scan targets, so there is no processor, core or partition rule. Virtual machines and containers are named examples of licensed assets.[1] For short-lived virtual and cloud workloads, the count depends on reclamation. Terminated cloud assets free their licence nightly, while manually deleted assets stay licensed until the end of the billing term.[2] The policy states that licences “are calculated by the number of scanner type(s) applied per resource”. It does not give a worked example of how several scanner types on one resource are counted.[2]
Cloud / BYOL
Both products are Tenable-hosted. The Hosted Services schedule has no bring-your-own-licence or marketplace mapping. The customer chooses the Scan Data retention period within the limits in the Documentation.[8] Assets imported from an on-premises Security Center are synchronised assets. Synchronised assets that count toward the Security Center licence also count toward the Vulnerability Management licence.[9]
Programs and prices
Tenable publishes online prices for these two products only. On 2026-09-27 the pricing page offered Vulnerability Management “for up to 250 assets online”. The product card showed “1 year subscription / $3,700”. The purchase dialog showed USD 3,500 (1 year), 6,825 (2 years) and 9,975 (3 years) for 100 assets.[5] For Web App Scanning, the card showed USD 6,790 and the dialog USD 3,578 for 5 FQDNs.[5] Because the two figures differ, the catalog rows VM online subscription and WAS online subscription record the displayed values without a list price. The PCI Standard and Enterprise tiers and the evaluation licence are recorded as programs. Evaluation Products may not be used to scan third-party targets.[8] Tenable also offers simplified pricing to MSSPs through its representatives.[1]
Out of scope
- Tenable One packaging, the Count Once hierarchy and Hexa AI tokens, covered in Tenable One licensing.
- Scan configuration and scan tuning practices, except where they change the licence count.
- The Service Level Agreement’s availability credits.
- Tenable One Cloud Exposure, whose licensing the Licensing Guide does not cover.