Cybersecurity
Vulnerability Management
We quote the scanner subscription and supply the appliance or server it runs on, sized against your asset count. The scanning cadence and the remediation queue stay with your security team.

- Category
- Authenticated and unauthenticated scanning across the asset estate
- What we quote
- Scanner subscriptions and renewals, plus the hardware they run on
- Sizing
- By licensed asset count and scan window, not by site
- Boundary
- The scanning program and remediation stay yours to run
Buying a scanner is one afternoon; running the program is the job
Almost every framework a federal or state buyer works to asks for the same thing in different words — know what is on the network, know what is wrong with it, and show that the queue is going down. The scanner is the easy purchase. What makes it work is a licensed asset count that matches reality, a place to run the scanner that can reach the segments being scanned, credentials that let it authenticate rather than guess, and somebody who owns the remediation backlog. We quote the first three: the subscription band, the appliance or server, and the staging work to get it into your rack. The fourth is yours, and any supplier telling you their product substitutes for it is describing a report, not a program.
What decides the size of the license
Vulnerability-management licensing is counted in assets, and the definition of an asset is where budgets go wrong. A license band bought against the server count will not cover the workstation estate; one bought against the DHCP scope will cover addresses that have never existed. Reconcile the count before the quote — physical hosts, virtual machines, containers where they are in scope, and network devices — and buy the band above it rather than the one you exactly fill, because the count only ever moves one way.
Placement is the second decision. A scanner has to reach the segments it scans, which in a properly segmented environment means either a scanner per zone or firewall rules that partly defeat the segmentation. Distributed scanners reporting to a central manager is the usual answer, and it changes the license and the hardware bill: several modest appliances rather than one large one. Authenticated scanning needs credential management your team controls, and it is the difference between a useful report and a port list.
Subscriptions are sourced through authorized US distribution rather than held on a shelf, so stock language does not apply to them; what matters is the term, the seat band and the co-termination date.
Scanner licensing and the hardware behind it
The named line below is the one the hub catalog genuinely prices. Other platforms in this market are sourced on request through authorized US distribution. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.
Tenable
Nessus scanner and manager subscriptions, on-premises entitlements and the renewals against them — quoted per asset band against your anniversary. Where a program runs distributed scanners into a central manager, each scanner entitlement is quoted with it rather than assumed.
The server it runs on
A scanner is a compute and storage workload with a very uneven duty cycle — idle most of the week, saturated during the window. Sized against the asset count and the scan window, quoted as a rack server or workstation-class host, and staged with firmware baselining before it reaches your rack.
What stays yours to run
We do not run scans, interpret findings, write the remediation plan or represent your posture to an assessor or an authorizing official. Those are program functions inside your organization. A finding is only closed when somebody with authority over the asset patches it, mitigates it, or documents an accepted risk — and none of those three are things a supplier can do on your behalf.
We also make no compliance-outcome claim. Scanning appears in most control frameworks, but running a scanner does not satisfy a control on its own, and no purchase — hardware, license or service — confers a certification. What we supply is the tooling and the hardware behind the requirement.
Vulnerability management questions
How is vulnerability scanning licensed?
By asset count, in bands, on an annual or multi-year term. Some products count active assets seen in a rolling window rather than a static inventory, which behaves differently in an environment with a lot of ephemeral hosts. Reconcile the count before the quote, and buy the band above your current figure — the number only grows.
Do we need a scanner in each network segment?
That depends on your segmentation. A scanner can only assess what it can reach, so either you deploy distributed scanners reporting to a central manager, or you punch holes in the segmentation that partly undo it. Most segmented environments choose distributed scanners, which changes both the licensing and the hardware bill — so it is worth deciding before the quote.
Do you perform the scanning for us?
No. We supply the subscription, size and stage the hardware, and hand it over ready to run. We are not an assessment provider and we do not operate a scanning service — running the program, triaging the findings and closing them out stays with your security team.
What is the difference between a scan and a penetration test?
A scan is automated, broad and repeatable: it enumerates hosts and compares what it finds against a vulnerability database. A penetration test is a human exercise that chains findings into demonstrated impact. Frameworks generally expect scanning on a cadence; testing is a separate, usually periodic engagement, and it is not something we sell.
The solutions atlas
Every solution, one accountable partner.
UniQ platforms
By technology
By customer
- TAA & NDAA-889 Compliance Screening
- CMMC & CUI Solutions
- Federal & DoD
- State, Local & Education
- Healthcare
- Enterprise
- Rapid Procurement & GPC Buys
- Multi-Vendor Integration Projects
- eProcurement & Custom Catalogs
- FISMA Modernization
- CJIS-Compliant Justice Cloud & Local AI
- Federal Storage Modernization
- Government ERP & Business Systems Infrastructure
- Managed Procurement
- Secure AV & Conferencing
- Fiber Network Infrastructure
- Satellite & Resilient Connectivity
- Wavelength & Optical Transport
- Decentralized Data Centers
- Data Center Design & Build
Size a scanner against your asset count
Send the reconciled asset count, the segments in scope and the scan window you have to fit inside. We return a subscription quote with the scanner hardware sized alongside it and the staging work priced.