In Nessus 10.12, how do Essentials, Essentials Plus, Professional and Expert differ, and how is a host limit counted?
answer
- free tier versus subscriptions
- five, twenty, thirty-two
- a delayed feed on the free tier
- discovery hosts and the 90-day window
basics
~20 sIn Nessus 10.12, Essentials scans up to 5 hosts with a 30-day-delayed feed, Essentials Plus 20 with a real-time feed, and neither has compliance. Professional adds compliance, Expert adds web app, attack-surface and IaC scanning. Discovery-only hosts never count.
solid answer
~40 s**Nessus Essentials** is the free tier: up to 5 hosts, a 30-day delayed plugin feed and no scan exports or reports. **Essentials Plus** raises the limit to 20, gets real-time plugin updates, PDF and HTML reports and concurrent scans. Neither offers compliance templates or custom audit files. **Professional** is a subscription with vulnerability and compliance scanning and Live Results; a Professional trial is capped at 32 hosts. **Expert** adds web application scanning and external attack-surface scanning (five apps or domains per rolling 90 days) and IaC scanning. On the capped tiers the limit applies per scan and to unique hosts across all scans; hosts found only by a host discovery scan do not count, and a host unscanned for 90 days drops out. The often-quoted 16-IP Essentials limit is stale.
go deeper
Recall the 5, 20 and 32 host limits and that compliance starts at Professional.
Explain the per-scan and cumulative counting, the discovery exemption and the 90-day drop-out, and why the 16-IP figure is stale.
Choose an edition from the requirement: delayed feed tolerance, compliance auditing, reports, web apps or attack surface.
Weigh standalone scanners against a managed or cloud-hosted platform by who needs results and how many scanners must share policies.
## Why the edition matters in an interview Edition questions are practical: a candidate who has set up a lab or proposed a purchase knows what the free tier cannot do, and why a scan that worked last month now refuses a target. The figures below are from the Nessus 10.12 user guide; older blog posts still quote numbers that no longer apply. ## The editions side by side | Edition | Host limit | Plugin feed | Notable limits or additions | |---|---|---|---| | Nessus Essentials | 5 | 30-day delay | Free tier; no scan exports or reports; no compliance | | Nessus Essentials Plus | 20 | real-time | PDF and HTML reports, concurrent scans; no compliance | | Nessus Professional trial | 32 | — | Trial of Professional | | Nessus Professional | no limit listed on the License Utilization page | daily by default (standalone) | Vulnerability and compliance scanning, Live Results | | Nessus Expert | no limit listed on the License Utilization page | daily by default (standalone) | Adds web app scanning, attack-surface scanning, IaC scanning | The License Utilization page in 10.12 lists exactly three host limits: **20** for Essentials Plus, **5** for Essentials and **32** for a Professional trial. The frequently repeated "Essentials scans 16 IPs" figure is **stale**; current Essentials is 5. ## Professional against Expert Both are subscriptions and both include Live Results, vulnerability scanning and compliance scanning. Expert adds: - **DAST web application scanning**: five web applications per rolling 90-day period, licensed by FQDN and port; a licence is released only after 90 days without a scan, and deleting scan data does not release it early; - **external attack surface scanning**: five domains per rolling 90-day period; - **Infrastructure as Code scanning**. The web app templates appear only in Expert, and the `Attack Surface Discovery` template is Expert-only too. ## How a host limit is counted On Essentials, Essentials Plus and the Professional trial, the host limit applies two ways at once: 1. the **number of hosts per scan**, and 2. the **number of unique hosts scanned cumulatively across all scans**. Two rules soften the cumulative count: - hosts found only by a **host discovery scan** do not count towards the limit, so you can map a network first and then pick targets; - a host **not scanned for 90 days** stops counting. The License Utilization view shows which hosts currently count and when each was last scanned. This is why a lab user can hit the limit after scanning a few different subnets, and recover simply by waiting out the 90-day window or rescanning the same hosts. ## Managed and hosted options Beyond the standalone editions, Nessus scanners can be run under a manager: - **Nessus Manager** is no longer sold as of February 1, 2018; Tenable still supports it for existing customers and provisions it for managing Tenable Agents. Agent templates exist only there. - **Tenable One Vulnerability Management** is Tenable's cloud-hosted platform. It can link unlimited Nessus scanners, push policies and schedules, and collect results; linked scanners take plugins and software updates from `cloud.tenable.com`. - **Tenable Security Center** manages scanners on premises and supplies their activation code and plugins. Every installation needs a **plugin feed activation code**, which identifies the licensed version and, where applicable, how many IP addresses it can scan. ## Activation codes and managers The activation code is entered where Nessus is managed. A standalone subscription manages it in Nessus itself; a scanner managed by Tenable Security Center gets its activation code and plugins from Security Center, and is registered with **Managed by SecurityCenter** so that it starts without a code of its own. On Essentials and Professional trials, a wizard walks a new user through the host discovery scan and the follow-up scan of chosen hosts, which is the workflow the discovery exemption is designed for. ## Picking an edition - Learning at home on a handful of machines: Essentials, accepting the delayed feed. - A small lab needing current plugins and reports: Essentials Plus. - Any CIS or STIG configuration auditing: Professional at minimum. - Web applications, external attack surface or IaC in the same tool: Expert.
- A Nessus Essentials user says the scanner refuses new targets after scanning several subnets this month. Why, and what helps?The 5-host limit counts unique hosts cumulatively across all scans, not just per scan. Hosts found only by a host discovery scan do not count, and a host not scanned for 90 days drops out, so map with discovery first and keep rescanning the same targets.
- Why might Nessus Essentials miss a vulnerability that Professional detects on the same day?Nessus Essentials receives plugin feed updates on a 30-day delay, so a plugin released recently is not in its set yet. Essentials Plus gets real-time plugin updates, and a standalone Professional scanner checks the feed every 24 hours by default.
saying these in an interview costs you the question
- Nessus Essentials scans up to 16 IP addresses.
- Hosts found by a host discovery scan use up Essentials licence slots.
- Essentials Plus includes compliance templates and custom audit files.
- The Essentials host limit only counts hosts within a single scan.
- Nessus Manager is still sold as the standard way to buy Nessus.