# SQL Server Standard Licensing Explained: Per Core or Server + CAL?

> SQL Server edition limits, how Server + CAL and per-core licensing differ, how licenses are counted in virtual machines, and how to pick between 2016, 2017 and 2019.

- Source: https://karincalisans.com/en/blog/sql-server-standard-licensing-guide-core-vs-cal/
- Published: 28 September 2026
- Author: Karınca Lisans

---

Short answer: **SQL Server Standard can be licensed in two ways: per core when you cannot count your users or the database serves an internet-facing application, and Server + CAL when a small, countable group of users works against a server with many cores.** The free Express edition is limited to 10 GB per database, one socket or four cores and roughly 1.4 GB of buffer-pool memory, which makes it suitable only for small applications.

This guide walks through the SQL Server 2019 editions and the capacity limits Microsoft documents for them, how the Server + CAL and per-core models work, how licenses are counted in virtual machines, how to choose between the 2016, 2017 and 2019 releases based on the support calendar, and what typical small-business setups look like. It is written for small and mid-sized businesses and the administrators setting up SQL Server for an ERP, accounting or e-commerce application for the first time. As of September 2026 the information is current; it is not legal licensing advice.

## Key Takeaways

- SQL Server Express is free, but according to Microsoft it is capped at 10 GB per database, 1 socket or 4 cores and 1,410 MB of buffer-pool memory.
- SQL Server 2019 Standard uses at most 4 sockets or 24 cores (whichever is lower) and 128 GB of buffer-pool memory per instance; Enterprise is limited only by the operating system.
- Under the per-core model every physical core in the server is licensed, at least 4 core licenses are required per physical processor, and no CALs are needed.
- Under Server + CAL each operating system environment needs a server license and every user or device that accesses SQL Server needs a CAL.
- Microsoft's lifecycle calendar shows support for 2016 ended in July 2026, 2017 runs to October 2027 and 2019 to January 2030.

## SQL Server Editions and Capacity Limits

SQL Server is a product family in which Microsoft sells the same database engine in several capacity and price tiers. Microsoft's [Editions and supported features of SQL Server 2019](https://learn.microsoft.com/en-us/sql/sql-server/editions-and-components-of-sql-server-2019?view=sql-server-ver15) page defines five main editions: Enterprise, Standard, Web, Developer and Express. Developer includes every Enterprise feature but is licensed for development and test only, never for a production server. Web is aimed at hosting providers. Express is free and can be upgraded to a higher edition when the need grows.

| Edition | Compute limit per instance | Buffer-pool memory | Max database size | Licensing |
| --- | --- | --- | --- | --- |
| Express | Lesser of 1 socket or 4 cores | 1,410 MB | 10 GB | Free |
| Web | Lesser of 4 sockets or 16 cores | 64 GB | 524 PB | Hosting providers only (SPLA) |
| Standard | Lesser of 4 sockets or 24 cores | 128 GB | 524 PB | Per core or Server + CAL |
| Enterprise | Operating system maximum | Operating system maximum | 524 PB | Per core only |
| Developer | Operating system maximum | Operating system maximum | 524 PB | Free, non-production |

The figures in the table come from Microsoft's 2019 editions page and apply to a single SQL Server instance. Microsoft's [compute capacity limits by edition](https://learn.microsoft.com/en-us/sql/sql-server/compute-capacity-limits-by-edition-of-sql-server?view=sql-server-ver15) article explains that these limits constrain one instance rather than the whole server, so several instances can run on the same physical machine. The same article notes that in a virtualized environment the limit is applied to logical processors, not cores. The 24-core cap for Standard applies to SQL Server 2022 and earlier; Microsoft raised it to 32 cores with SQL Server 2025.

## Is Express Enough?

SQL Server Express is genuinely enough when a single application's database will stay under 10 GB and concurrent load is low; single-user accounting installs, a small CRM or an intranet tool fall into that class. The trap with Express is that the 10 GB limit applies per database: once the application grows, inserts start failing and you are forced to move to Standard. According to Microsoft's edition table, Express also lacks SQL Server Agent, so scheduled backups and maintenance jobs have to be built by hand. Those two gaps are why most businesses keep Express for pilots and go to Standard in production.

## How the Server + CAL Model Works

Server + CAL is the model, available only for Standard edition, that combines a server license with client access licenses. According to Microsoft's SQL Server 2019 licensing guide, every operating system environment (physical or virtual) that runs SQL Server or any of its components needs a server license, and every user or device that accesses SQL Server needs a CAL. A CAL is not software; it is a license that grants access, and it comes in two forms:

- **User CAL:** assigned to a specific person, who may then connect from any device with a single CAL. Economical when you have fewer people than devices.
- **Device CAL:** assigned to a specific device, which any number of people may use with a single CAL. Required for shift-shared terminals and for devices not operated by humans.

Two warnings in the guide matter in practice. First, devices not operated by humans, such as automation systems that connect indirectly, require device CALs. Second, multiplexing or pooling users behind a middle tier does not reduce the number of CALs required: even if a web application connects to the database with one service account, every person using that application needs a CAL. The moment you can no longer count your users, this model stops working and you need to move to per-core licensing.

## How the Per-Core Model Works

Per-core licensing measures the processing power of the server and is independent of how many people connect. According to Microsoft's guide, when SQL Server runs in a physical operating system environment all physical cores in the server must be licensed, a minimum of four core licenses is required for each physical processor, and licenses are sold in packs of two. Hyper-threading does not change the number of core licenses required on a physical server. No CALs are purchased under this model; an unlimited number of users and devices may connect from inside or outside the organization.

Microsoft recommends the per-core model in four situations: when deploying Enterprise edition, for internet or extranet workloads, when users and devices cannot easily be counted, and whenever the total cost for Standard works out lower than Server + CAL. The practical rule of thumb: on a single-processor, four-core server, 4 core licenses open the door to unlimited users, so per core becomes cheaper than Server + CAL as headcount grows, while a five-user accounting server is usually cheaper under Server + CAL. For Microsoft's own summary of the two models, see the [SQL Server 2019 licensing datasheet](https://download.microsoft.com/download/0/5/c/05c60185-ebdd-4472-895a-3d8e8da55682/SQL_Server_2019_Licensing_Datasheet.pdf).

## Licensing in Virtual Machines

SQL Server licensing in virtual machines is counted in two different ways depending on the model you pick. Under per core, every virtual core allocated to the VM needs a core license, with a minimum of four core licenses per virtual machine; a VM with two virtual cores is still licensed with four. Microsoft states that licensing individual VMs is the only way to run Standard edition in a virtualized environment under the per-core model. Under Server + CAL, one server license per VM running SQL Server is enough regardless of how many virtual processors it has, and the CAL rule for every user and device remains unchanged.

With Enterprise edition, once all physical cores on the host are licensed, SQL Server may run in as many VMs as there are core licenses; adding Software Assurance extends that to an unlimited number of VMs. Most small businesses never reach that scenario, but on a Hyper-V host running two or three VMs it pays to settle "which VM holds SQL and how many virtual cores does it have" up front, because that keeps the license count simple. Remember that the host itself needs a separate operating system license; a [Windows Server 2022 Standard](https://karincalisans.com/en/product/windows-server-2022-standard-license-key/) license, for example, covers one physical server with rights to run 2 virtual machines and is bought separately from the SQL Server license.

## Choosing Between 2016, 2017 and 2019

For a new installation, the deciding criterion between releases is Microsoft's lifecycle calendar. According to Microsoft's lifecycle pages, extended support for [SQL Server 2016](https://learn.microsoft.com/en-us/lifecycle/products/sql-server-2016) ended on July 14, 2026, and Microsoft lists Extended Security Update periods for that release. [SQL Server 2017](https://learn.microsoft.com/en-us/lifecycle/products/sql-server-2017) is in extended support until October 12, 2027, and [SQL Server 2019](https://learn.microsoft.com/en-us/lifecycle/products/sql-server-2019) until January 8, 2030. In all three, Standard edition is capped at 4 sockets or 24 cores and 128 GB of buffer-pool memory; the differences are in features and support horizon.

| Release | End of extended support | Notable difference | For new installs |
| --- | --- | --- | --- |
| SQL Server 2016 Standard | July 14, 2026 (ended) | Query Store, Always Encrypted; Windows only | Only for existing apps tied to 2016 |
| SQL Server 2017 Standard | October 12, 2027 | Linux and container support, graph database | Linux deployments, short-term projects |
| SQL Server 2019 Standard | January 8, 2030 | Intelligent query processing, accelerated recovery, TDE in Standard | Recommended release |

One detail between Microsoft's 2017 and 2019 edition pages concerns small businesses in particular: Transparent Data Encryption (TDE) was Enterprise-only in 2017 but became available in Standard with 2019. For an installation that stores personal data and needs disk-level encryption, that alone is a reason to choose 2019. At Karınca Lisans the [SQL Server 2019 Standard](https://karincalisans.com/en/product/sql-server-2019-standard-license-key/) and [SQL Server 2017 Standard](https://karincalisans.com/en/product/sql-server-2017-standard-license-key/) licenses are delivered as a digital key for one server; according to the product pages the key must be used within 1 day of delivery, the activated key is valid for life on that server, and CALs are not included.

## Small-Business Scenarios

Small-business SQL Server needs usually fit one of three patterns. The first is an accounting or ERP server with 5 to 15 users: the users can be counted and the server has a single processor, so Server + CAL is the natural choice with one user CAL per person. The second is an internet-facing online store or customer portal: visitors cannot be counted, so per-core licensing is mandatory, and on a single-processor, four-core server the minimum of 4 core licenses is enough. The third is automation on a production line: if devices not operated by humans connect, device CALs are required, or per-core licensing is chosen instead.

In all three scenarios it helps to separate the license key from the license right. The key is the code you type into the setup wizard that unlocks the engine; the license right is the record of how many cores or users you paid for, and it is the latter that determines whether you comply with Microsoft's rules. If you are wondering why the same product sells at different prices through different channels, the mechanism is the same as with Windows; our article on [why Windows licenses sell at different prices](https://karincalisans.com/en/blog/why-windows-licenses-sell-at-different-prices/) explains volume licensing and channel differences in detail.

Our support team at Karınca Lisans helps dozens of businesses every month with SQL Server edition selection and setup. The situation we run into most often is a key ordered before the server is ready, so the 1-day redemption window expires before installation can happen. The second most common case is an application that started on Express, hit the 10 GB wall and moved to Standard in a hurry under data-migration pressure. The third is CALs: to customers who assume the key includes CALs, we explain every time that a CAL is a separate Microsoft license item that has to be planned by user count.

## Which Option Should You Choose?

- **One application, under 10 GB of data, low load:** start with SQL Server Express and move to Standard when you outgrow it.
- **A countable 5 to 20 users, one server:** SQL Server 2019 Standard under Server + CAL with user CALs.
- **Internet-facing application or uncountable users:** SQL Server 2019 Standard under per core (at least 4 core licenses per processor).
- **Linux deployment or a short-term project that ends before 2027:** SQL Server 2017 Standard.
- **Installation inside a virtual machine:** at least 4 virtual core licenses per VM (per core) or one server license per VM (Server + CAL), plus a Windows Server license for the host.

Once you have decided, every release in our [SQL Server licenses](https://karincalisans.com/en/product-category/server-software/sql-server-licenses/) category states its capacity limits, support date and key redemption window on the product page; if you are unsure which release fits, share your server's core and user counts with our WhatsApp support line.

## Frequently Asked Questions

### What is a SQL Server CAL, and does it come with the key?

A CAL (client access license) is the access right that every user or device connecting to SQL Server needs under the Server + CAL model; it is a license record, not software. The SQL Server keys sold at Karınca Lisans cover one server and do not include CALs, which are a separate Microsoft license item.

### My web app connects with a single database account; is one CAL enough?

No. Microsoft's licensing guide states explicitly that multiplexing users behind a middle tier does not reduce the number of CALs required. Every person using the application needs a CAL; if users cannot be counted, per-core licensing is the right model.

### What is the main difference between SQL Server Standard and Enterprise?

Standard is capped at 4 sockets or 24 cores and 128 GB of buffer-pool memory per instance; Enterprise uses whatever the operating system allows and offers the full high-availability set, such as Always On availability groups and online index operations. The vast majority of line-of-business applications fit within Standard's limits.

### Does SQL Server 2016 keep working now that support has ended?

Yes. After support ends the installation keeps running and the license stays valid, but Microsoft no longer publishes security updates. Microsoft lists Extended Security Update periods for 2016; for new installations, 2019 with support to 2030 is the more forward-looking choice.
