// scanner: rapid7-insightvm
Rapid7 InsightVM pricing 2026: quote-only via Exposure Command
Insight Agent + Live Dashboards + Remediation Projects. Per-asset pricing, now quoted through Exposure Command.
author: Oliver Wakefield-Smith · verified 2026-06-26
// direct-answer
What does Rapid7 InsightVM cost in 2026?
Quote only. Rapid7 moved InsightVM pricing into its Exposure Command packages and no longer lists a per-asset rate on the product or pricing page. Partner-reported figures put it near ~$1.75/asset/month (~$21/asset/year) at scale. Insight Agent, Live Dashboards, and Remediation Projects are included.
Pricing snapshot
- InsightVMQuote-only via Exposure Command; partner-reported ~$1.75/asset/month at scale
- InsightAppSec (DAST)Separate SKU, quote-only
- Insight Platform bundleQuote-only when combined with InsightIDR / InsightCloudSec
What scales, what does not
- Insight Agent is included; agent-based coverage avoids the credential-management overhead of authenticated network scans.
- Remediation Projects is the most operationally useful differentiator versus Tenable Workbenches.
- InsightAppSec is mandatory if you want web coverage; bundle pricing is a separate negotiation.
Where it hits the ceiling
Strong mid-market and enterprise on-prem story; cloud-native CNAPP is via Rapid7 InsightCloudSec, sold separately.
// faq
FAQ
- Is Rapid7 InsightVM pricing public?No longer. Rapid7 folded InsightVM pricing into its Exposure Command packages, and neither the InsightVM nor the Exposure Command pricing page lists a per-asset rate any more (checked 2026-07-27). It is now quote-only; partner-reported figures put it near ~$1.75/asset/month (~$21/asset/year) at scale.
- Is there a free tier of Rapid7 InsightVM?No formal free tier. Trials and PoCs are common.
- Does Rapid7 InsightVM cover web application scanning?Limited; for serious web DAST coverage pair with Burp Enterprise, Invicti, or Acunetix.
- Does Rapid7 InsightVM produce PCI ASV evidence?Yes. Rapid7 is a PCI Approved Scanning Vendor, so InsightVM can back the attested quarterly external ASV scan required by PCI DSS 11.3.2.
- How often does Rapid7 InsightVM update its vulnerability content?Daily for commercial scanners (Tenable plugins, Qualys signatures, Rapid7 recog). Open-source OpenVAS NVT feed is daily but lags commercial coverage by hours to days.