Veracode Static Analysis and SCA licensing covers the subscriptions that let a customer scan its own code with Veracode: Veracode Static Analysis, which analyses compiled binaries or bytecode, Veracode SCA (software composition analysis), which finds vulnerable and risky open-source libraries, and Veracode Fix, which generates suggested code changes. These products are sold under the Veracode End User Assessment Agreement. The Order Form states the quantity bought, and the customer pays for use above it.[17] How that quantity is consumed is set out in Veracode’s documentation of its license consumption reports.[1] For the platform-wide view, see Veracode licensing.
Editions
Veracode does not publish named editions of Static Analysis or SCA. Its role reference lists separate subscriptions instead: Veracode Static Analysis, Veracode SCA (also called Veracode Software Composition Analysis) and Veracode DAST. Most scanning roles require one of the three, and the Security Lead role also needs a base Veracode Platform subscription.[16] Within Static Analysis the documentation names several ways to scan, each tied to a licence:
| Scan method | What it does | Licence named in the documentation |
|---|---|---|
| Upload and Scan | Static Analysis and SCA in one operation, with results in the Veracode Platform[5] | An active Static Analysis or SCA licence. Both scans run by default, but results are visible only for the products licensed.[7] |
| Pipeline Scan | Faster static scans in IDEs, CI/CD pipelines and repositories. They do not scan open-source components and their data is not stored in the platform.[5] | An active Veracode Static Analysis licence.[6] |
| SCA agent-based scan | Open-source scanning in pipelines and repositories[5] | An SCA subscription, which includes a default workspace.[8] |
| Veracode Fix | Suggested fixes for Static Analysis flaws (Fix for SAST) and open-source issues (Fix for SCA)[12] | A Veracode Fix licence.[11] |
If an organisation has already run Static Analysis scans on an application, the SCA results become available as soon as it activates an SCA licence.[5] Some integrations carry no separate charge. The GitHub Workflow Integration needs no additional Veracode licence, although the customer must be licensed for the scan types it runs.[14]
Metrics
| Measure | Catalog row | Definition in Veracode documents |
|---|---|---|
| Licences used | Application | The largest scan of each application in the subscription year, divided by the application size definition.[1] |
| MB used | Megabytes of analysis size | The number of megabytes used during the subscription year, set against the megabytes purchased.[1] |
| Application profiles | Application profile (tier model) | In the License Used Tier Model report, quantities for Standard and Small reflect the number of application profiles.[1] |
| Contributing developers | Contributing developer | Members of SCM projects who contributed to a repository within the last 90 days.[10] |
The application itself is defined in the EUAA as a collection of logically related software components that perform a coordinated set of functions.[17] The application size definition used to convert scan size into licences is not published.
Counting / floors
Largest scan, not number of scans. The Largest Scan Report records, for each application, the largest scan in the subscription year. Licences used are that figure divided by the application size definition. The report also shows how many times each application was scanned.[1] On that formula, frequent rescans of an application do not add licences, but an application whose largest scan exceeds the size definition uses more than one. Catalog: Licences used equal the largest scan per application divided by the application size definition.
Annual reset. In a multi-year contract, consumption metrics start at 0 at the beginning of each subscription year.[1] Catalog: Consumption restarts each subscription year.
Tier model. Some contracts are counted in application profiles rather than megabytes. The License Used Tier Model report shows quantities purchased and used per SKU, and for Standard and Small these reflect application profiles.[1] Some Static Analysis licences limit the number of application profiles a customer can create.[4] Catalog: Tier model counts application profiles for Standard and Small; Some Static Analysis licences cap the number of application profiles.
Consumption is not reversed. Deleting an application profile and its scan results does not return a consumed licence.[3] Test scans count as well. The Static Analysis quickstart warns that scanning its sample application in a new profile uses a Veracode licence. Restoring it requires a request to Veracode Technical Support.[2] Catalog: Deleting an application profile does not return a consumed licence; A quickstart scan of a sample application uses a licence.
SDLC and third-party licences. Scan records carry a License Type of SDLC, for internal testing of first-party software, or third-party, for a supplier testing code it develops for the Veracode customer. The License Account field records which account paid for the scan.[15]
Floors. No minimum quantity is published.
Technical limits
Technical limits are separate from licence quantities but shape how much can be scanned:
- A single scan can analyse at most 5 GB of uploaded files and 50,000 files. The largest individual file is 2 GB.[5] Catalog: Upload limit of 5 GB analysed per scan.
- A customer can run a maximum of 10 concurrent sandbox scans.[9] Catalog: At most 10 concurrent sandbox scans.
- Each Pipeline Scan is limited to 60 minutes.[6]
Sandboxes let developers scan code in development before a policy scan, and they are not available to third-party vendors scanned on behalf of an enterprise.[9] The consumption reports cover Static Analysis and Dynamic Analysis scan activity.[1]
Developer counts
Veracode publishes a tool for counting developers. The Veracode CLI command veracode repository report reports all developers who contributed to a repository in the last 90 days. It identifies unique contributors by email address, counts an address used in several SCMs only once, and summarises unique contributors per SCM and in total.[10] Catalog: Contributing developers are counted over a 90-day window; A contributing developer is counted once across SCMs. The documentation does not state which subscriptions are priced on that count. A licence manager should check the Order Form before treating developer numbers as a contractual metric. The 90-day window means the count changes as people join or leave projects.
Virtualization & partitioning
Static Analysis and SCA are cloud services that analyse uploaded artifacts or repositories. Hardware, cores and virtualization play no part in the count.[17]
Cloud / BYOL
The Solutions run on Veracode’s Solution Platform as software as a service. Pipeline Scan and the CLI are clients of that service. They need an active Static Analysis licence[6] and do not license an on-premises scanner.
Audits and compliance
Users with the Security Lead or Administrator role can download the four consumption reports (License Used, Largest Scan, All Scans and License Used Tier Model) from Analytics > Data Exports.[1] These are the figures Veracode can use in its annual usage measurement under the EUAA.[17] Two practical controls follow from the counting rules. Customers should restrict who can create application profiles, because each new profile that is scanned consumes licences that deletion does not return. They should also watch for applications whose largest scan approaches the size definition. See software license audit.
Product changes
The static-only IDE plugins and extensions are being retired and reach end of life on 2026-12-31.[13] Catalog: Static-only IDE plugins reach end of life on 2026-12-31. Veracode Fix is used from IDEs and the CLI for Static Analysis flaws, and from the CLI and SCM for SCA.[12]
Out of scope
- The application size definition and megabyte quantities in individual contracts.
- Commercial terms of developer-based subscriptions, which are not published.
- Container Security and Package Firewall, whose commercial terms are not described in public licensing documents.