Try our new research platform with insights from 80,000+ expert users

BigFix vs Qualys Patch Management comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

BigFix
Ranking in Patch Management
3rd
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
97
Ranking in other categories
Configuration Management (6th), Endpoint Protection Platform (EPP) (26th), Unified Endpoint Management (UEM) (4th)
Qualys Patch Management
Ranking in Patch Management
4th
Average Rating
9.0
Reviews Sentiment
7.5
Number of Reviews
33
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2025, in the Patch Management category, the mindshare of BigFix is 7.5%, down from 12.6% compared to the previous year. The mindshare of Qualys Patch Management is 4.3%, up from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Patch Management
 

Featured Reviews

Bella Yakoby - PeerSpot reviewer
Offers third-party patching feature, good scalability, and enhance endpoint management capabilities
From the perspective of the team that's handling the environment, it's not so user-friendly compared to other solutions, the competitors. We hire new teams from time to time, and they are complaining, look, although BigFix is very robust and cross-platform, it's not so fun to work with. The user interface for the technical teams is not so advanced. It's not so intuitive compared to SCCM, compared to ManageEngine. And this is the fact that they have, with the teams, because they have the rejection. The look and feel of the system are old-fashioned. For new employees, it's less easy to find someone I don't need to educate on how to work with BigFix. Although it's easy, it's not as intuitive as the other solutions, and the functionality of the other solutions is less advanced. Let's summarize: The user interface has to be changed from the perspective of the teams that are managing the product. It's old school.
Revathi VeeraRaghavan - PeerSpot reviewer
Provides a centralized platform for managing assets and vulnerabilities, enabling assessment, prioritization, and remediation
Qualys Patch Management system requires several improvements. Firstly, the inability to download asset patches and the lack of third-party application integration limit patch accessibility. Additionally, rollback options are unreliable, and pre-deployment patch testing is crucial. Reporting needs enhancement, particularly with group-based compliance percentages and clearer, VMDR-like reporting in the Patch Management module. Furthermore, detection speed should be improved, as patches are released 24 hours after QIDs are published. The user interface could be more functional, with dashboards for patch compliance visualization and simplified error code language. Finally, the Mac patch catalogue needs expansion, and automated workflows, policy enforcement, and testing procedures should be streamlined for seamless, user-independent operation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Almost every feature is wonderful in BigFix. It is very stable, and we can rely on it. It is an awesome tool."
"The architecture for patching and the 100% correct reporting makes BigFix stand apart from other solutions."
"DOWNLOADING-PATCHES; It has also helped to reduce network traffic when it comes to downloading patches. By only having to download the patch once to the central location and then utilizing the relay structure to then download the patch to a specific site and then everything gathering at local, it greatly reduces the bandwidth of multiple endpoints."
"BigFix is a great product. The flexibility of putting together your own relevance and retrieving custom data from any one of your agents is a valuable feature. It is one of my favorite features because if a boss asks me, "How many of these devices do we have?", I can put together a report in two seconds."
"It is for multiple use cases. A lot of people are looking at it just for security, and that's really endpoint security. The endpoint management part of it in terms of being able to constantly do patching for Windows, Unix, macOS, Cloud, Raspberry, VMware, and all Linux flavors is important, and they are very good at that. They have support for virtually every OS on the market."
"All the vendor patches are synchronized automatically."
"We rely on BigFix as part of our consulting engagements. It's more efficient from a visibility and discovery standpoint on the initial phase, the consulting engagement. It also increases our efficiencies on the remediation phase of our engagements."
"It allows us to quickly deploy capabilities that we need, whether it be security or non-security. We use it to keep systems up to date, deploy new drivers, find the information we need in the case of security incidents. The capability allows us to gather a lot of information very quickly and it also allows us to have a centralized reporting feature and a centralized deployment capability which is nice."
"Qualys Patch Management excels with its user-friendly interface and comprehensive reporting features."
"Automated features streamline patch deployment and ensure compliance, effectively mitigating risks and bolstering organizational security."
"The most valuable feature in Patch Management is the Qualys query language for set-it-and-forget-it patching for our preapproved patches, and our preapproved schedules, That is extremely helpful compared to the old days of patching."
"Qualys Patch Management has saved significant resources."
"We've been able to reduce organizational risk by 50%."
"Qualys Patch Management significantly improved our patch rates by 80 percent, scanning for vulnerabilities every four hours via the Qualys agent."
"My overall rating for Qualys Patch Management is a ten out of ten."
"Qualys Patch Management offers excellent features, most notably the Qualys Gateway Service, which caches patches and distributes them to agents, minimizing bandwidth consumption."
 

Cons

"I would like to see more emphasis on using the web console, to have the same power as the full fat client console that they do they now. It's a lighter way to log in and it would be faster for our operators to do their work. The console tends to take a long time for a large number of clients."
"I would like to see the integration of user security between the different products to be improved. There's separate security for compliance, separate security for web reports, and the console, and you have to manage those things separately."
"The product lacks AI, ML, and IIT."
"While performing integration, we face many issues with IBM solution. We need detailed information about those issues that can help users to mitigate them."
"In-place and OS upgrades can be improved."
"Sometimes there is a lag time for our users."
"BigFix can improve the way machines report back to the console. In the external relay management environment, it has become more of a hybrid environment with most of the machines not being on-site. The need of having public-facing reporting items interconnected is becoming more and more crucial. In general, the reporting could use some enhancement."
"The sub-capacity licensing was a challenge for some of it. We had trouble getting it to calculate right."
"We dislike having to pay extra. We don't mind paying for additional modules like Certificate View."
"This authentication requirement blocks some patches from being pushed through Qualys, leaving them in a locked state."
"The GUI has areas that need improvement, particularly in the accuracy of results when adding dashboards and running queries."
"The user interface could be more functional, with dashboards for patch compliance visualization and simplified error code language."
"A common area for improvement in Patch Management, both within our environment and others I've encountered, is the lack of built-in driver updates."
"Qualys's current response time for releasing solutions to zero-day vulnerabilities, which takes approximately 12 to 16 hours, needs improvement."
"Its implementation is too recent to make any judgments about areas needing improvement. In terms of pricing, of course, it is not free. Cheaper is always better."
"False positives were the biggest concern."
 

Pricing and Cost Advice

"Compliance, inventory, and licensing are really pricey. They should lower the price. It discourages users from getting onboard."
"You get what we call the Platform Edition, which you get for free. The patch service is maybe $0.50 per workstation per month. Then there's the basic server cost, which is about $1.50 per server per month. You also get into Lifecycle which does power management, OSD remote control, and those types of things, and that might be about 10 times the price - which works out to about $13 per server and, maybe $5 per workstation per month."
"The price is reasonable, but our customers find it expensive."
"I can estimate the reduced cost of servers maintenance to approximatively $500,000."
"So, the pricing is slightly more expensive than the others. I have to keep buying licenses every time I add a new device."
"The price of the solution is high. There are not any additional fees from the standard license."
"The price of BigFix is better than the solutions. You are able to pay monthly or annually. There are not any hidden costs with BigFix. There is an additional cost for the SQL database."
"The product is less costly when compared to other solutions, and this is a good solid solution for what we have paid."
"Qualys Patch Management offers a moderate price point, neither cheap nor expensive, considering its comprehensive functionality."
"While the cost of Qualys Patch Management is slightly high compared to alternative tools, it is not excessively expensive."
"Qualys Patch Management is a cost-effective solution for managing our 43,000-plus assets."
"I'm unaware of Qualys' exact price, but it's more expensive than Nessus. With technological products, you need to pay to get the best."
"Qualys is fairly priced."
"Qualys Patch Management is expensive."
"The pricing is reasonable and less expensive than the previous tool."
"It is affordable, but they should provide features as per the rate they are charging. We have a big infrastructure with about 80,000 licenses. We expect better support from the Qualys team. So, it is affordable, but more features should be there, and the support should be better."
report
Use our free recommendation engine to learn which Patch Management solutions are best for your needs.
865,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Government
10%
Manufacturing Company
9%
Computer Software Company
9%
Computer Software Company
12%
Government
12%
Manufacturing Company
11%
Financial Services Firm
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about BigFix?
The most valuable features of the solution are Windows patching and the hardware and software inventory.
What is your experience regarding pricing and costs for BigFix?
The pricing is competitive, but not the most competitive.
What needs improvement with BigFix?
While performing integration, we face many issues with IBM solution. We need detailed information about those issues that can help users to mitigate them. The problem was related to the hardware co...
What is your experience regarding pricing and costs for Qualys Patch Management?
From a pricing perspective, I find Qualys to be a bit higher, but it is worth it. Compared to other tools, it is on the costly side, but I believe it is worth the investment.
What needs improvement with Qualys Patch Management?
Regarding improvements in Qualys Patch Management, I did not quite understand the downsides they were expecting. Initially, I was confused about where to find and how to use the available features....
What is your primary use case for Qualys Patch Management?
I am using Qualys Patch Management for two years, and everything is satisfactory from my side. Before purchasing Qualys Patch Management, we were already using Qualys VMDR and the cloud agent model...
 

Also Known As

Tivoli Endpoint Manager
No data available
 

Overview

 

Sample Customers

US Foods, Penn State, St Vincent's Health US Foods, Sabadell Bank, SunTrust, Australia Sydney, Stemac, Capgemini, WNS Global Services, Jebsen & Jessen, CenterBeam, Strauss, Christian Hospital Centre, Brit Insurance, Career Education Corporation
Information Not Available
Find out what your peers are saying about BigFix vs. Qualys Patch Management and other solutions. Updated: July 2025.
865,295 professionals have used our research since 2012.