LICENSEWARE

Veracode Static Analysis and SCA licensing

This article covers how Veracode Static Analysis (SAST), Veracode SCA and Veracode Fix are licensed and how their consumption is counted. For the contract, see Veracode End User Assessment Agreement; for DAST and training, see Veracode DAST, training and platform subscriptions.

On This Page

Veracode Static Analysis and SCA licensing covers the subscriptions that let a customer scan its own code with Veracode: Veracode Static Analysis, which analyses compiled binaries or bytecode, Veracode SCA (software composition analysis), which finds vulnerable and risky open-source libraries, and Veracode Fix, which generates suggested code changes. These products are sold under the Veracode End User Assessment Agreement. The Order Form states the quantity bought, and the customer pays for use above it.[17] How that quantity is consumed is set out in Veracode’s documentation of its license consumption reports.[1] For the platform-wide view, see Veracode licensing.

Editions

Veracode does not publish named editions of Static Analysis or SCA. Its role reference lists separate subscriptions instead: Veracode Static Analysis, Veracode SCA (also called Veracode Software Composition Analysis) and Veracode DAST. Most scanning roles require one of the three, and the Security Lead role also needs a base Veracode Platform subscription.[16] Within Static Analysis the documentation names several ways to scan, each tied to a licence:

Scan method What it does Licence named in the documentation 
Upload and Scan Static Analysis and SCA in one operation, with results in the Veracode Platform[5] An active Static Analysis or SCA licence. Both scans run by default, but results are visible only for the products licensed.[7] 
Pipeline Scan Faster static scans in IDEs, CI/CD pipelines and repositories. They do not scan open-source components and their data is not stored in the platform.[5] An active Veracode Static Analysis licence.[6] 
SCA agent-based scan Open-source scanning in pipelines and repositories[5] An SCA subscription, which includes a default workspace.[8] 
Veracode Fix Suggested fixes for Static Analysis flaws (Fix for SAST) and open-source issues (Fix for SCA)[12] A Veracode Fix licence.[11] 

If an organisation has already run Static Analysis scans on an application, the SCA results become available as soon as it activates an SCA licence.[5] Some integrations carry no separate charge. The GitHub Workflow Integration needs no additional Veracode licence, although the customer must be licensed for the scan types it runs.[14]

Metrics

Measure Catalog row Definition in Veracode documents 
Licences used Application The largest scan of each application in the subscription year, divided by the application size definition.[1] 
MB used Megabytes of analysis size The number of megabytes used during the subscription year, set against the megabytes purchased.[1] 
Application profiles Application profile (tier model) In the License Used Tier Model report, quantities for Standard and Small reflect the number of application profiles.[1] 
Contributing developers Contributing developer Members of SCM projects who contributed to a repository within the last 90 days.[10] 

The application itself is defined in the EUAA as a collection of logically related software components that perform a coordinated set of functions.[17] The application size definition used to convert scan size into licences is not published.

Counting / floors

Largest scan, not number of scans. The Largest Scan Report records, for each application, the largest scan in the subscription year. Licences used are that figure divided by the application size definition. The report also shows how many times each application was scanned.[1] On that formula, frequent rescans of an application do not add licences, but an application whose largest scan exceeds the size definition uses more than one. Catalog: Licences used equal the largest scan per application divided by the application size definition.

Annual reset. In a multi-year contract, consumption metrics start at 0 at the beginning of each subscription year.[1] Catalog: Consumption restarts each subscription year.

Tier model. Some contracts are counted in application profiles rather than megabytes. The License Used Tier Model report shows quantities purchased and used per SKU, and for Standard and Small these reflect application profiles.[1] Some Static Analysis licences limit the number of application profiles a customer can create.[4] Catalog: Tier model counts application profiles for Standard and Small; Some Static Analysis licences cap the number of application profiles.

Consumption is not reversed. Deleting an application profile and its scan results does not return a consumed licence.[3] Test scans count as well. The Static Analysis quickstart warns that scanning its sample application in a new profile uses a Veracode licence. Restoring it requires a request to Veracode Technical Support.[2] Catalog: Deleting an application profile does not return a consumed licence; A quickstart scan of a sample application uses a licence.

SDLC and third-party licences. Scan records carry a License Type of SDLC, for internal testing of first-party software, or third-party, for a supplier testing code it develops for the Veracode customer. The License Account field records which account paid for the scan.[15]

Floors. No minimum quantity is published.

Technical limits

Technical limits are separate from licence quantities but shape how much can be scanned:

Sandboxes let developers scan code in development before a policy scan, and they are not available to third-party vendors scanned on behalf of an enterprise.[9] The consumption reports cover Static Analysis and Dynamic Analysis scan activity.[1]

Developer counts

Veracode publishes a tool for counting developers. The Veracode CLI command veracode repository report reports all developers who contributed to a repository in the last 90 days. It identifies unique contributors by email address, counts an address used in several SCMs only once, and summarises unique contributors per SCM and in total.[10] Catalog: Contributing developers are counted over a 90-day window; A contributing developer is counted once across SCMs. The documentation does not state which subscriptions are priced on that count. A licence manager should check the Order Form before treating developer numbers as a contractual metric. The 90-day window means the count changes as people join or leave projects.

Virtualization & partitioning

Static Analysis and SCA are cloud services that analyse uploaded artifacts or repositories. Hardware, cores and virtualization play no part in the count.[17]

Cloud / BYOL

The Solutions run on Veracode’s Solution Platform as software as a service. Pipeline Scan and the CLI are clients of that service. They need an active Static Analysis licence[6] and do not license an on-premises scanner.

Audits and compliance

Users with the Security Lead or Administrator role can download the four consumption reports (License Used, Largest Scan, All Scans and License Used Tier Model) from Analytics > Data Exports.[1] These are the figures Veracode can use in its annual usage measurement under the EUAA.[17] Two practical controls follow from the counting rules. Customers should restrict who can create application profiles, because each new profile that is scanned consumes licences that deletion does not return. They should also watch for applications whose largest scan approaches the size definition. See software license audit.

Product changes

The static-only IDE plugins and extensions are being retired and reach end of life on 2026-12-31.[13] Catalog: Static-only IDE plugins reach end of life on 2026-12-31. Veracode Fix is used from IDEs and the CLI for Static Analysis flaws, and from the CLI and SCM for SCA.[12]

Out of scope

  • The application size definition and megabyte quantities in individual contracts.
  • Commercial terms of developer-based subscriptions, which are not published.
  • Container Security and Package Firewall, whose commercial terms are not described in public licensing documents.

References

  1. View and download reports (license consumption reports)License Used, Largest Scan, All Scans and License Used Tier Model reports. Last updated on Sep 2, 2026. Catalog: View and download reports (license consumption reports)Effective 2026-09-02. Retrieved 2026-10-07.
  2. Static Analysis quickstartSample application scan uses a licence. Last updated on Sep 2, 2026. Catalog: Static Analysis quickstartEffective 2026-09-02. Retrieved 2026-10-07.
  3. Delete an application profileLast updated on Sep 2, 2026. Catalog: Delete an application profileEffective 2026-09-02. Retrieved 2026-10-07.
  4. Managing application profilesLast updated on Sep 2, 2026. Catalog: Managing application profilesEffective 2026-09-02. Retrieved 2026-10-07.
  5. Scan code (Static Analysis overview and upload limits)Upload and Scan, Pipeline Scan, packaged artifact limits. Last updated on Sep 8, 2026. Catalog: Scan code (upload limits)Effective 2026-09-08. Retrieved 2026-10-07.
  6. Veracode Pipeline ScanPrerequisites; 60-minute limit. Last updated on Sep 30, 2026. Catalog: Veracode Pipeline ScanEffective 2026-09-30. Retrieved 2026-10-07.
  7. Veracode Upload and ScanLast updated on Sep 9, 2026. Catalog: Veracode Upload and ScanEffective 2026-09-09. Retrieved 2026-10-07.
  8. SCA Agent-based Scan quickstartLast updated on Sep 9, 2026. Catalog: SCA Agent-based Scan quickstartEffective 2026-09-09. Retrieved 2026-10-07.
  9. Manage sandboxesLast updated on Sep 2, 2026. Catalog: Manage sandboxesEffective 2026-09-02. Retrieved 2026-10-07.
  10. veracode repository reportAbout contributing developers. Last updated on Apr 28, 2025. Catalog: veracode repository reportEffective 2025-04-28. Retrieved 2026-10-07.
  11. Scan for VS CodeVeracode Fix licence prerequisite. Last updated on Sep 30, 2026. Catalog: Scan for VS CodeEffective 2026-09-30. Retrieved 2026-10-07.
  12. About Veracode FixFix interfaces for SAST and SCA. Last updated on Sep 10, 2026.Effective 2026-09-10. Retrieved 2026-10-07.
  13. Static-only IDE pluginsEnd of life 2026-12-31. Last updated on May 25, 2026. Catalog: Static-only IDE pluginsEffective 2026-05-25. Retrieved 2026-10-07.
  14. Roll out Veracode GitHub Workflow AppLast updated on Jul 1, 2026. Catalog: Roll out Veracode GitHub Workflow AppEffective 2026-07-01. Retrieved 2026-10-07.
  15. Scans explore data dictionaryLicense Account and License Type fields. Last updated on Jul 7, 2026. Catalog: Scans explore data dictionaryEffective 2026-07-07. Retrieved 2026-10-07.
  16. UI user rolesLicensing column for each role. Last updated on Oct 2, 2026. Catalog: UI user rolesEffective 2026-10-02. Retrieved 2026-10-07.
  17. Veracode End User Assessment Agreement (20240610)s.1 Application definition; s.4.4 excess use. Catalog: End User Assessment Agreement (20240610)Effective 2024-06-10. Retrieved 2026-10-07.

See also

Catalog Rows Cited

4Metrics11Rules3SKUs

Esc