HomeField Notes › Fortify · On Demand
Fortify · On Demand

Fortify on Demand subscription audit considerations

Fortify on Demand changes the audit conversation because it is a subscription service rather than software the buyer installs and runs. The metrics are different, the data sits with the vendor, and the questions a buyer must ask shift accordingly. Knowing the Fortify on Demand subscription audit considerations before a finding arrives lets a buyer verify the vendor's own usage numbers rather than accepting them, which is the central discipline whenever consumption is measured on the vendor's side.

This article explains how Fortify on Demand is licensed, what an audit of it looks like, and how a buyer verifies the numbers. It supports our Fortify and AppSec audit defense practice and links up to the complete OpenText audit defense playbook for 2026.

How Fortify on Demand is licensed

Fortify on Demand is a hosted application security testing service. Rather than purchasing seats for software the buyer operates, the buyer subscribes to assessment capacity, typically expressed in units tied to applications or assessments over a term. Because the service runs on the vendor's infrastructure, the usage records originate with the vendor, which inverts the normal audit dynamic. In a traditional on premises audit the buyer holds the usage data and the vendor seeks to measure it. With a subscription service, the vendor holds the data and the buyer must verify it.

The inversion

On premises, you prove your usage. With Fortify on Demand, the vendor asserts your usage and you verify it. The defensive posture is verification, not disclosure, and it starts with understanding the assessment unit.

The assessment unit and why it matters

The most important thing to pin down is the unit the subscription is measured in. Is an assessment counted per application, per scan, per release, or per some other boundary. The answer determines whether the vendor's usage figure is even calculated correctly. A finding that counts each release of one application as a separate assessment, when the subscription was scoped per application, would overstate consumption by the number of releases. We treat this unit question in Fortify on Demand assessment unit counting, and it is the first thing to verify.

What a Fortify on Demand audit looks like

Because the data is hosted, a subscription audit usually takes the form of a usage reconciliation: the vendor presents its record of assessments consumed against the capacity purchased and claims any overage. The buyer's task is to test that record against its own understanding of what was submitted. The relevant questions are whether the counted assessments match the applications and releases the buyer actually submitted, whether evaluation or duplicate submissions were counted, and whether the assessment unit was applied consistently with the subscription terms. Each of these is a place where the vendor's number can be high.

Verifying the numbers

Verification draws on whatever records the buyer holds about its own submissions: tickets and approvals for assessment requests, release records, and the application inventory that defines what was in scope. The buyer reconciles its submission record against the vendor's consumption record and challenges any line where they diverge. This is reconstruction work adapted to a subscription context, and the same principle applies as everywhere else in a Fortify defense, which is that the buyer should never accept a vendor asserted number without independent verification. The general approach is in reconciling Fortify entitlements before an audit.

The term and renewal angle

Subscriptions also raise term and renewal questions that an on premises perpetual estate does not. Capacity that lapses, rolls over, or is consumed unevenly across the term all affect what overage means and when it is measured. A finding that measures peak consumption at the wrong point in the term, or that ignores unused capacity earlier in the period, can overstate the overage. These are negotiable on the same terms as any other component of a finding.

A representative outcome

In a recent engagement involving hosted assessment capacity, the vendor presented a consumption record that exceeded the subscribed capacity and claimed an overage. By reconciling the buyer's own submission and release records against the vendor's count, we identified assessments that had been counted at the wrong unit boundary and duplicate submissions that should not have entered the total. The verified consumption sat much closer to the subscribed capacity, and the overage claim fell substantially. The reduction was in the range we see across Fortify matters, consistent with the seat overclaim work in our E-02 case file even though the metric was a subscription unit rather than a developer seat.

The posture to take

With Fortify on Demand the buyer's strongest move is to treat the vendor's usage figure as a claim to be verified, not a fact to be accepted. Pin down the assessment unit, reconcile against your own submission records, and contest the term and renewal assumptions. For the broader measurement picture across the Fortify portfolio, see how OpenText measures Fortify usage in an audit.

Negotiating the renewal after a finding

A Fortify on Demand overage claim rarely arrives in isolation. It usually surfaces near a renewal, because that is when the vendor reconciles consumption against the capacity sold. This timing is leverage the buyer can use. Once the overage is verified down to its defensible size, the renewal becomes the vehicle for settling it on the buyer's terms rather than paying a separate penalty at list. A buyer who treats the verified overage and the renewal as one negotiation can fold the disputed consumption into a forward subscription priced and scoped sensibly, instead of accepting a backward looking charge and then renewing on top of it.

The protections worth securing in that renewal mirror the ones that prevent the dispute from recurring. The assessment unit should be defined explicitly, so there is no later argument about whether a release counts as a new assessment. Capacity terms should address rollover and uneven consumption across the period, so that unused capacity early in a term is not ignored when a peak is measured later. And the reconciliation method should be agreed in advance, so the next renewal starts from a shared view of consumption rather than from a vendor asserted figure the buyer must again verify from scratch. Handled this way, a subscription finding becomes an opportunity to convert an ambiguous arrangement into a clean one, which is the same Resolve discipline we apply across every Fortify matter. The buyer who verifies the number and then negotiates the renewal as a single move consistently lands in a better forward position than one who pays the overage and renews separately.

Verify the vendor's usage record

With a hosted subscription, the vendor holds the data. We reconcile it against your own submission records and contest every overstated assessment. Open a case to begin.

Open a case →

For the seat counting methodology behind the reconstruction, read the Fortify seat counting white paper.

If an OpenText or Micro Focus audit notice has reached your desk, the first seven days carry more weight than any week that follows. OpenText Audit Defense is an independent, buyer side practice founded in 2020 by former vendor compliance leadership. We have defended more than 200 audits, brought the average finding down by 68 percent, and mitigated more than $90M in claims against vendor positions. We do not resell OpenText software and we are not affiliated with OpenText Corporation. To open a case, use the contact form on this site.