> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/understand-license-plans.md).

# Understand license plans

Cortex Cloud Posture Management and Cortex Cloud Runtime Security licensing is provided via an annual subscription, based on the number and type of cloud resources protected. The fundamental metric for consumption is the protected workload. You must procure a license capacity sufficient to cover the total number of workloads you intend to secure.

Licensing is subject to a metering system or Fair Usage policy. This mechanism defines how usage is tracked and what happens when the average consumption of protected workloads exceeds the purchased license capacity. Cortex Cloud accounts for workload utilization based on a 90-day average to smooth spikes and drops in usage of highly ephemeral workloads. Exceeding capacity often triggers a notification, but usually does not immediately disable security functions to ensure your workloads don't lose their protection.

To view the product license and add-ons associated with your tenant, go to **Settings** → **Cortex License** .

### Protected workloads

A workload represents any active compute entity that requires protection. These workloads count toward your Cortex Cloud license usage. Examples include:

Table 1. Billable Workload Units

<table data-header-hidden><thead><tr><th width="320"></th><th></th></tr></thead><tbody><tr><td><strong>Workload Type</strong></td><td><strong>Billable Units</strong></td></tr><tr><td>VMs not running containers</td><td>1 VM</td></tr><tr><td>VMs running containers</td><td>1 VM</td></tr><tr><td>Endpoint</td><td>1 Endpoint</td></tr><tr><td>CaaS (Container As A Service</td><td>10 Agent Protected Managed Containers</td></tr><tr><td>Cloud Buckets</td><td>10 Cloud Buckets</td></tr><tr><td>Managed Cloud Database (PaaS)</td><td>2 PaaS Databases</td></tr><tr><td>DBaaS TB Stored</td><td>DBaaS 1TB Stored</td></tr><tr><td>SaaS Users</td><td>10 SaaS Users</td></tr><tr><td>On-Premise Data assets</td><td>1 Connection</td></tr><tr><td>Cloud ASM – Service</td><td>4 Unmanaged Assets</td></tr><tr><td>Container Images in Registries</td><td><p><strong>Free quota</strong>:10 container image scans per deployed workload (VM/CaaS)</p><p><strong>Beyond free quota</strong>:10 container image scans</p></td></tr><tr><td>CLI Image Scans</td><td>-</td></tr></tbody></table>

Cortex Cloud Posture Management and Cortex Cloud Runtime Security are available in multiple license configurations, either individually or as part of a bundled package. For more information on bundling options with other Cortex products, see [Cortex XSIAM product licenses](https://app.gitbook.com/s/AEIjuYE3RXcIfmuQnBbm/cortex-xsiam-product-licenses).

<table data-header-hidden><thead><tr><th width="284"></th><th></th></tr></thead><tbody><tr><td><strong>License</strong></td><td><strong>Configuration</strong></td></tr><tr><td>Cloud Posture Management</td><td><p>Agentless comprehensive visibility across your cloud environment. Includes the following:</p><ul><li>Cloud Security Posture Management (CSPM)</li><li>Cloud Infrastructure Entitlement Management (CIEM)</li><li>Application Security Posture Management (ASPM)</li><li>Data Security Posture Management (DSPM)</li><li>Artificial Intelligence Security Posture Management (AI-SPM)</li><li>Cloud Attack Surface Management (ASM)</li><li>Kubernetes Security Posture Management (KSPM)</li><li>CI/CD Posture Management</li><li>Agentless Workload Scanning</li></ul></td></tr><tr><td>Cloud Runtime Security</td><td><p>Full cloud protection, detection, and response. Includes the following:</p><ul><li>Cloud Posture Management</li><li>Cloud Workload Protection (CWP)</li><li>Web Application &#x26; API Security (WAAS)</li></ul></td></tr></tbody></table>

### Add-ons

* **Security add-ons**: You can purchase security add-ons to expand the core capabilities of your Cortex Cloud Posture Management and Cortex Cloud Runtime Security licenses.
  * Data Ingestion
  * Application Security (IAC Security, SCA, Secrets Security)
  * Enterprise Runtime Security (XDR)
  * Identity Threat Detection and Response (IDTR)
  * Forensics investigation
  * Host Insights
  * Extended Threat Hunting (XTH)
  * Advanced Email Security
  * Data Loss Prevention (DLP) - Beta
* **Capacity add-ons**: You can purchase capability add-ons to extend the duration that security and telemetry data are retained for investigation and compliance purposes
  * Data Retention: Cortex Cloud Posture Management and Cortex Cloud Runtime Security retention per dataset.
  * Query Capacity (compute units): A single Compute Unit add-on.

### License usage and overflow rules

Cortex tracks license usage to ensure that your purchased capacity is used efficiently. The system distinguishes between different workload types and applies clear rules to avoid double-counting and handle usage that exceeds purchased limits.

Cortex categorizes workloads as follows:

* **Cloud Posture Workloads** – Total workloads purchased with a Cloud Posture Management license, including any security add-ons.
* **Cloud Runtime Workloads** – Total workloads purchased with a Cloud Runtime license.

{% hint style="info" %}

### Note

A Cloud Runtime license includes both Posture Scanning and Runtime Protection on the same asset. Usage, including any overflow, is tracked automatically to ensure accurate reporting across both licenses without duplicate counting.
{% endhint %}

#### Overflow rules

The following table outlines how the system counts workloads based on your purchased licenses and current usage:

| Licenses purchased                   | Usage scenario                                        | License counter display                                                                       | Overflow behaviour                                                                                                                                                                        |
| ------------------------------------ | ----------------------------------------------------- | --------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cloud Posture Only                   | Total posture workloads exceed quota.                 | All usage counts are shown under Cloud Posture Workload                                       | All workload usage, including over-quota workloads, counts toward the Posture license.                                                                                                    |
| Cloud Runtime Only                   | Total runtime workloads exceed quota.                 | All usage counts are shown under Cloud Runtime Workload                                       | All workload usage, including over-quota workloads, counts toward the Runtime license.                                                                                                    |
| Both Cloud Posture and Cloud Runtime | Workloads are within quota limits.                    | <p>Posture: Counts toward Posture quota.</p><p>Runtime: Counts toward Runtime quota.</p>      | No workload overflow. Counters show usage within purchased quotas.                                                                                                                        |
| Both Cloud Posture and Cloud Runtime | Posture exceeds quota, Runtime has remaining capacity | <p>Posture: 100% full usage.</p><p>Runtime: Partial or full usage count due to spillover.</p> | Spillover occurs only from Posture to Runtime; it does not occur in reverse. Excess Posture workloads use the available Runtime quota until it’s full.                                    |
| Both Cloud Posture and Cloud Runtime | Runtime quota full                                    | <p>Posture: Total usage (including excess).</p><p>Runtime: Total usage (over-quota)</p>       | Spillover only occurs from Posture to Runtime; it does not occur in the reverse. Excess Posture workloads are added back to the Posture counter, and any over-quota usage is shown there. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/get-started/understand-license-plans.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
