Tenable One vs Tenable Vulnerability Management, start with the module
Tenable.io is now Tenable One Vulnerability Management. Our advice to Norwegian mid-sized firms: buy the module, not the platform package.
Tenable.io was not discontinued. It was renamed twice, and the second rename is why so many buyers think they are choosing between two products when they are choosing between a module and the package it ships in.
My advice for most Norwegian mid-sized firms is short. Buy Tenable One Vulnerability Management on its own. Leave the platform package until you can pass the three-part test further down this page.
I ran eleven Tenable scoping calls in the last twelve months. Seven of them opened with some version of “we are comparing Tenable One against Tenable.io”. That is not a product comparison. It is a naming problem, and it has a price tag.
TL;DR: Tenable.io became Tenable Vulnerability Management in 2023, and Tenable’s own pages now brand it Tenable One Vulnerability Management. The product is the vulnerability module of the Tenable One platform, sold alone or inside the package. Most Norwegian firms running servers and laptops should buy the module and add surfaces later.
Tenable.io, Tenable Vulnerability Management and Tenable One are the same lineage
Tenable.io is the old name for the product Tenable sells today as Tenable One Vulnerability Management. Nothing was retired and nothing was replaced.
Tenable announced the first rename on 15 May 2023. Tenable.io became Tenable Vulnerability Management, Tenable.ad became Tenable Identity Exposure, Tenable.cs became Tenable Cloud Security, and Tenable.ot became Tenable OT Security. The dot-suffix names went away across the portfolio.
The second change is quieter, and it is the one causing the confusion in 2026. Tenable’s product page and its documentation now head the product as Tenable One Vulnerability Management, while the body text on those same pages still says Tenable Vulnerability Management. I have found no announcement for that one, the way there was in 2023. The docs are clear on what it means in practice: “Tenable One Vulnerability Management can be purchased alone or as part of the Tenable One Exposure Management Platform package.”
So the search “Tenable One vs Tenable.io” sets a 2023 name against a 2026 name for two things that are not alternatives: the vulnerability module on one side, the platform that contains it on the other. If Nessus is also on your shortlist, our three-way comparison of Nessus, Tenable Vulnerability Management and Tenable One sizes all three. This page is about the two that share a console.
What the platform package adds, and what it adds to your week
Tenable One now comes in two packages, Foundation and Advanced, announced on 28 April 2026 and applying to new Tenable One customers.
Tenable’s licensing guide lists what sits where. Foundation covers vulnerability management, web application security, OT and IoT security, attack surface management, AI discovery, cloud workload protection, asset inventory, ticketing and third-party data connectors. Advanced adds AI workload and agent protection, cloud and Kubernetes security posture management, risk scores and benchmarks, workflow and mobilization, and Attack Path Analysis.
Read that split twice, because it decides the buy. Attack Path Analysis is the feature that makes a platform worth more than the sum of its scanners, and it sits in Advanced. Identity security is in neither package. It is a paid add-on, alongside cloud-native application protection, AI user and app governance, and patch management. Tenable calls the whole thing an exposure management platform, and we have written before on why exposure management and vulnerability management are not the same discipline.
Now the part that costs you time. Tenable One licenses on assets, and an asset means something different in each surface. In Web App Scanning an asset is a fully qualified domain name. In Identity Exposure it is an enabled user in your directory. Tenable counts each asset once, so a machine carrying three sensors is not billed three times, which is fair. The counting work does not go away.
You cannot price the package until somebody counts domains and enabled accounts. In the two Foundation scopings I ran this spring, the asset count the customer gave me on the call and the count we agreed after two weeks of discovery differed by more than a third. Both times the real number was higher.
The test we use before recommending the platform
Three conditions decide it, and all three have to hold. Two out of three is a no.
First, a named person owns findings outside the server and laptop estate. Not “IT will look at it”. A name, in a job description, with hours in the week.
Second, you can count the assets in at least two more surfaces today. If nobody can tell you how many public domain names and enabled directory accounts you have, you are not ready to sign a per-asset contract across those surfaces.
Third, you want Attack Path Analysis specifically. That means Advanced, not Foundation. If the answer is “we would like better dashboards”, the module already gives you dashboards.
When all three hold, buy Advanced. When one or two hold, buy the module and add surfaces as you get owners for them. The console stays the same and the migration does not exist, which is the point of Tenable’s own line about buying the product alone or inside the package.
Where Nessus Professional sits in this
Nessus Professional is software you install, licensed per user, listed at $4,790 a year, with Nessus Expert at $6,790. Tenable One Vulnerability Management is priced per asset, and Tenable lists 100 assets at $3,500 for one year.
That surprises people. Below a few hundred assets the cloud product can list under the installed scanner, and it brings roles, history and an evidence trail the scanner does not have. Above that the per-asset math takes over and the comparison flips. Both figures are list prices, not quotes.
If Nessus is still in the running, read what Nessus is and where it fits in the Tenable portfolio first. This page assumes you have already ruled it out.
What we recommend for a typical Norwegian mid-sized firm
Buy Tenable One Vulnerability Management. One console, one definition of an asset, one owner, and a scan schedule that runs whether or not anybody logs in.
Then add a surface when you have a person for it. Web application scanning when someone owns the applications. Cloud when someone owns the cloud accounts. Identity security as an add-on when Active Directory has an owner. Each of those is a package change, not a project.
FM CyberSecurity runs vulnerability management as a service on Tenable, and we set up, tune and report on the platform for customers who buy the licence themselves. If you want to see the console before you decide, we can set you up with a free Tenable One tenant and run a first assessment against your real assets.
Next step
Count your assets in each surface before you ask for a quote. That number decides which package you can price, and it is the one job no vendor can do for you.
If this resonates:
- Read how we run the vulnerability program in Tenable One to see what the module looks like in daily use.
- Forward this to whoever signs the renewal, your IT manager or your CFO.
- Talk to Anders for a thirty-minute review of your real asset count before the quote lands.
FAQ
Is Tenable.io the same as Tenable Vulnerability Management?
Yes. Tenable renamed Tenable.io to Tenable Vulnerability Management on 15 May 2023, along with the rest of the dot-suffix portfolio. Any guide, tender document or console screenshot that says Tenable.io describes the same product. If a supplier still quotes you “Tenable.io” in 2026, ask which package they mean.
Is Tenable One Vulnerability Management a different product from Tenable Vulnerability Management?
No. Tenable’s product page and documentation now use Tenable One Vulnerability Management in the title and heading, while the body text on those same pages keeps the shorter form. Both names point at the same console and the same Nessus scanning engine. The documentation states the product can be bought alone or as part of the Tenable One platform package.
Can we move from the module to the full platform later?
Yes, and the change is commercial more than technical. You keep the console, the scan configuration, the asset history and the plugin set. What changes is which surfaces report into the same view, and what you pay per asset. Plan the asset count first, because that number moves more than the price does.
Drafted with AI assistance, reviewed and edited by Anders Helgesplass and the FM CyberSecurity editorial team.