Try our new research platform with insights from 80,000+ expert users

BigFix vs Qualys Patch Management comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

BigFix
Ranking in Patch Management
2nd
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
97
Ranking in other categories
Configuration Management (6th), Endpoint Protection Platform (EPP) (23rd), Unified Endpoint Management (UEM) (4th)
Qualys Patch Management
Ranking in Patch Management
4th
Average Rating
9.0
Reviews Sentiment
7.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2025, in the Patch Management category, the mindshare of BigFix is 7.9%, down from 12.6% compared to the previous year. The mindshare of Qualys Patch Management is 4.3%, up from 0.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Patch Management
 

Featured Reviews

Bella Yakoby - PeerSpot reviewer
Offers third-party patching feature, good scalability, and enhance endpoint management capabilities
From the perspective of the team that's handling the environment, it's not so user-friendly compared to other solutions, the competitors. We hire new teams from time to time, and they are complaining, look, although BigFix is very robust and cross-platform, it's not so fun to work with. The user interface for the technical teams is not so advanced. It's not so intuitive compared to SCCM, compared to ManageEngine. And this is the fact that they have, with the teams, because they have the rejection. The look and feel of the system are old-fashioned. For new employees, it's less easy to find someone I don't need to educate on how to work with BigFix. Although it's easy, it's not as intuitive as the other solutions, and the functionality of the other solutions is less advanced. Let's summarize: The user interface has to be changed from the perspective of the teams that are managing the product. It's old school.
Revathi VeeraRaghavan - PeerSpot reviewer
Provides a centralized platform for managing assets and vulnerabilities, enabling assessment, prioritization, and remediation
Qualys Patch Management system requires several improvements. Firstly, the inability to download asset patches and the lack of third-party application integration limit patch accessibility. Additionally, rollback options are unreliable, and pre-deployment patch testing is crucial. Reporting needs enhancement, particularly with group-based compliance percentages and clearer, VMDR-like reporting in the Patch Management module. Furthermore, detection speed should be improved, as patches are released 24 hours after QIDs are published. The user interface could be more functional, with dashboards for patch compliance visualization and simplified error code language. Finally, the Mac patch catalogue needs expansion, and automated workflows, policy enforcement, and testing procedures should be streamlined for seamless, user-independent operation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature for us is the ability to manage TWS, the relevance is really what sets it apart. Also, using it as a software deployment tool is the key for us."
"We've had no issues with stability."
"BigFix helped us to identify the compliance of devices and has also improved the way that we manage our software inventory for reporting to vendors."
"The most valuable feature is patch management, a must have, even for Linux and iOS."
"I think BigFix is a very good solution, and I rate it ten out of ten."
"Patch Management for a variety of operating systems makes it valuable as we can rely on a single tool for obtaining patch compliance of the entire compute infrastructure."
"We are able to go from patching thousands of machines by twenty to thirty people to one person."
"BigFix can manage lost devices, so you can wipe them remotely to ensure the IP doesn't get out in public. Unified endpoint security is a new perspective. I know that HCL is also collaborating with IBM, but I'm not sure if there is any cooperation between them and MaaS360 or other endpoint components."
"Automated features streamline patch deployment and ensure compliance, effectively mitigating risks and bolstering organizational security."
"We have seen about 60% to 70% improvement in the patch rate so far."
"Qualys Patch Management allows us to structure all the patches together and schedule patch management sessions."
"We can update the registry with special features such as Registry Update. We can also run scripts via the Patch Management module. These features are very helpful in our operations."
"Customer service is exceptional."
"Policy enforcement requires less time for my team because users cannot avoid applying updates. The user can skip two or three times or for a maximum of eight hours. After that, there is no way to avoid it. It helps us keep the environment safe."
"We've been able to reduce organizational risk by 50%."
"Qualys Patch Management is beneficial for addressing critical vulnerability alerts quickly, providing significant improvements in mitigating risk within our organization."
 

Cons

"The console interface is not friendly, and requires training before using it in production."
"There is no support for patch management on SLES on IBM pSeries (only the Intel platform is supported)."
"I would like the dashboard to be improved to show the problematic machines and good machines."
"To make it a ten they should improve the licensing. Second, if they could have one environment for everything it would be nice. For you to install compliance you need to install the server, and then you add the modules. For you to install inventory you install the server and then you add the modules. It's not easy to do. When I was doing it before I learned it, it was not straight forward."
"I would like to see API connectivity, built-in API connectors to the standard toolsets, whether it's for your ServiceNow or your Qualys. More API connectivity to make it easier to integrate to other tools."
"I self-taught for this online, so the initial setup was a little difficult to pick up at first. I had to create a couple of testing environments and destroy them in order to learn how to use it. There was a lot of trial and error, a lot of reading of the manuals."
"I would like to see different types of reporting and the ability to integrate closer with the cloud."
"The solution should have some kind of a local caching methodology, where the patches can be taken locally into a localized relay server, and from there, the patch can be applied, so that there is not much usage of the network required."
"A patch contract is a bundle of patches that we are going to roll out. I would like to reference those patches from separate jobs. They explained at a conference that it cannot be done, but that is my main complaint. I wish that the whole schema was a little bit clearer because there is a little bit of cloudiness around it."
"We dislike having to pay extra. We don't mind paying for additional modules like Certificate View."
"I struggled to see patch availability for some applications in the Qualys console, requiring me to use third-party repositories. If repositories could be integrated within the Qualys module, it would simplify the patching process for me."
"The patch status and patch completion information should be improved. If a patch fails due to some reason, such as a Windows error, the error code that gets published should be more detailed."
"The user interface could be more functional, with dashboards for patch compliance visualization and simplified error code language."
"They need to improve the user-friendliness of identifying how many devices are affected by a particular patch. It is not intuitive, and there should be clearer indicators or buttons to access this information easily."
"Reporting needs enhancement, particularly with group-based compliance percentages and clearer, VMDR-like reporting in the Patch Management module."
"Qualys could improve its randomized download feature and provide more detailed information about patch failures, including the reason for failure."
 

Pricing and Cost Advice

"We have a subscription-based contract with BigFix."
"It might be about $23 a client."
"I would stay with the Managed Virtual Server license model, which is a 1-to-1 license per OS whether it is virtual or physical."
"The price of BigFix could be lower. However, I am always seeking a lower price."
"So, the pricing is slightly more expensive than the others. I have to keep buying licenses every time I add a new device."
"You get what we call the Platform Edition, which you get for free. The patch service is maybe $0.50 per workstation per month. Then there's the basic server cost, which is about $1.50 per server per month. You also get into Lifecycle which does power management, OSD remote control, and those types of things, and that might be about 10 times the price - which works out to about $13 per server and, maybe $5 per workstation per month."
"I can estimate the reduced cost of servers maintenance to approximatively $500,000."
"The price of BigFix is better than the solutions. You are able to pay monthly or annually. There are not any hidden costs with BigFix. There is an additional cost for the SQL database."
"The licensing cost is more than 2,000 for the whole Americas region"
"Compared to other tools, the price of Qualys Patch Management is reasonable."
"While the cost of Qualys Patch Management is slightly high compared to alternative tools, it is not excessively expensive."
"Qualys Patch Management is a cost-effective solution for managing our 43,000-plus assets."
"Qualys Patch Management comes as part of a bundled package with several modules, making it a cost-effective deal for us."
"The pricing is reasonable and less expensive than the previous tool."
"I'm unaware of Qualys' exact price, but it's more expensive than Nessus. With technological products, you need to pay to get the best."
"Qualys Patch Management is expensive."
report
Use our free recommendation engine to learn which Patch Management solutions are best for your needs.
860,592 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
23%
Financial Services Firm
12%
Government
9%
Computer Software Company
8%
Computer Software Company
14%
Government
12%
Manufacturing Company
11%
Financial Services Firm
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about BigFix?
The most valuable features of the solution are Windows patching and the hardware and software inventory.
What is your experience regarding pricing and costs for BigFix?
The pricing is competitive, but not the most competitive.
What needs improvement with BigFix?
While performing integration, we face many issues with IBM solution. We need detailed information about those issues that can help users to mitigate them. The problem was related to the hardware co...
What is your experience regarding pricing and costs for Qualys Patch Management?
From a pricing perspective, I find Qualys to be a bit higher, but it is worth it. Compared to other tools, it is on the costly side, but I believe it is worth the investment.
What needs improvement with Qualys Patch Management?
Regarding improvements in Qualys Patch Management, I did not quite understand the downsides they were expecting. Initially, I was confused about where to find and how to use the available features....
What is your primary use case for Qualys Patch Management?
I am using Qualys Patch Management for two years, and everything is satisfactory from my side. Before purchasing Qualys Patch Management, we were already using Qualys VMDR and the cloud agent model...
 

Also Known As

Tivoli Endpoint Manager
No data available
 

Overview

 

Sample Customers

US Foods, Penn State, St Vincent's Health US Foods, Sabadell Bank, SunTrust, Australia Sydney, Stemac, Capgemini, WNS Global Services, Jebsen & Jessen, CenterBeam, Strauss, Christian Hospital Centre, Brit Insurance, Career Education Corporation
Information Not Available
Find out what your peers are saying about BigFix vs. Qualys Patch Management and other solutions. Updated: June 2025.
860,592 professionals have used our research since 2012.