

Qualys VMDR and FortiCNAPP compete in the cybersecurity sector, focusing on vulnerability management and threat prevention. Qualys VMDR appears to have an advantage in comprehensive vulnerability management and real-time tracking, while FortiCNAPP stands out with its network segmentation and integration capabilities.
Features: Qualys VMDR offers comprehensive vulnerability management, continuous monitoring, and accurate vulnerability identification. FortiCNAPP is recognized for its robust network segmentation, security policy enforcement, and seamless integration with SIEM solutions.
Room for Improvement: Qualys VMDR users note complex reporting, high costs, and slow support. There's also concern about its cloud dependency for small businesses. FortiCNAPP requires user interface enhancements and better data visibility and compliance metrics, especially in IAM security controls.
Ease of Deployment and Customer Service: Qualys VMDR provides flexible deployment for cloud and on-premises environments but is complex for larger setups. Its technical support gets mixed reviews. FortiCNAPP is available on both public and private clouds and receives more consistent feedback on its quick response times and stable performance.
Pricing and ROI: Qualys VMDR's pricing is considered high, particularly for smaller enterprises, though the value is justified for larger organizations in terms of improved security posture. FortiCNAPP offers a competitive pricing model with significant ROI through integration capabilities, resulting in risk reduction and time savings. Both solutions are seen as worthwhile investments, with FortiCNAPP's pricing noted for its clarity.
FortiCNAPP is a competitive and robust solution, the only one in the IT sphere that addresses all quadrants in the Gartner Quadrants.
We saw a return on investment through significant savings in time, money, and resources.
My technical teams do utilize integration with DevOps tools, as it performs significantly with automation regarding sophisticated challenges.
Fortinet's technical support is definitely helpful and responsive.
Technical support from Fortinet is good; I get feedback and responses quickly.
We usually get on calls with tech support, and they are very helpful.
The response time takes a while.
The technical support provided by Qualys is pretty good.
For complex large customers, global deployments, or large public sector customers, the process can take longer.
Scalability depends on the license and the number of assets being monitored.
Qualys VMDR can handle scalability, although increasing the inventory can raise the licensing costs.
Qualys VMDR's scalability is good, and the customer support is good.
They respond within the service level agreements and are proactive in their approach.
Qualys VMDR is stable.
The vulnerability part is not systematically organized; it is all clumsy in the web UI, and it is not user-friendly.
The solution could be more user-friendly and intuitive.
Policy implementation is quite complex, and the stability will take more time for the solutions.
It does not automate patching unless the patch management module is purchased separately.
If AI features were integrated, it could enhance the capabilities significantly.
One area where Qualys VMDR can be improved is the missing feature for deploying agents for over 1,000 assets, as we need to do it manually.
The pricing is a mediator compared to other products; it is not that much higher and not much lower than other products, making it a very affordable price.
I would rate the pricing between seven to eight out of ten.
I have a notion that Qualys might be more expensive than Rapid7.
Qualys offers better pricing and is feature-packed compared to other tools.
It functions as a proactive tool, enabling me to identify threats quickly and automate responses.
The machine learning capability in Lacework FortiCNAPP is used for threat detection.
FortiCNAPP definitely brings time-saving benefits.
The prioritization of vulnerabilities has improved our remediation efforts by around thirty to thirty-five percent.
It impacts my workflow overall, with the patch management features as it has the missing patches listed in detail, making it easier to get a comprehensive report and providing some dashboards that offer visual representation.
Qualys VMDR's continuous monitoring capabilities help us respond to emergent threats by enabling my team to reach out to the security engineers whenever there is any detection of a vulnerability, informing them about it, and creating an incident.
| Product | Mindshare (%) |
|---|---|
| Qualys VMDR | 4.2% |
| FortiCNAPP | 1.8% |
| Other | 94.0% |


| Company Size | Count |
|---|---|
| Small Business | 6 |
| Midsize Enterprise | 4 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 20 |
| Midsize Enterprise | 12 |
| Large Enterprise | 70 |
FortiCNAPP is a comprehensive cloud security platform focusing on ease of use and machine learning-driven anomaly detection. It offers robust compliance reporting, seamless integration, and continuous monitoring, making it an essential tool for organizations managing multi-cloud environments and security configurations.
FortiCNAPP provides significant capabilities in cloud security, compliance, and vulnerability management. Designed for organizations needing efficient monitoring, it enables detection of anomalies across cloud infrastructures while optimizing security posture and ensuring compliance with environments like AWS and GCP. The platform offers in-depth insights through scanning of IAC scripts, host systems, and cloud configurations. Recognized for effectively managing security posture, it safeguards Kubernetes and container environments, providing comprehensive threat detection and response. However, some areas like visibility, IAM security controls, and compliance metrics need improvement. Users face challenges with alert setup and lack intuitive design, alongside issues like FedRAMP authorization absence and complexity in the data model.
What are the key features of FortiCNAPP?FortiCNAPP is implemented extensively by industries needing reliable cloud security, such as finance, healthcare, and technology sectors. It supports organizations in enhancing cloud infrastructure protection, ensuring compliance, and strengthening vulnerability management. By integrating with platforms like AWS and GCP, businesses can optimize security posture in their cloud deployments.
Qualys VMDR is a comprehensive cybersecurity tool offering vulnerability management, patch management, and continuous monitoring with real-time asset discovery. It delivers scalable, cloud-based solutions that enhance security operations without additional infrastructure.
Qualys VMDR provides a robust platform for enterprise security, integrating vulnerability management, compliance, and asset inventory for full visibility across cloud and on-premises environments. It features a comprehensive dashboard with threat intelligence-driven prioritization and remediation capabilities. Users benefit from accurate assessments via agent-based scanning and appreciate the intuitive, customizable scanning and reporting interface. However, there's room for improvement in false positive reduction, UI simplification, and integration capabilities, along with enhancements in asset management for large-scale deployments and the vulnerability database. Enhancing technical support speed, patch management, compliance standards, and inter-module navigation would further enrich user experience.
What are the key features of Qualys VMDR?Qualys VMDR is widely used in industries needing stringent security and compliance measures, offering comprehensive vulnerability and compliance management. It is deployed to secure web applications, servers, and crucial assets, supporting a wide range of sectors by ensuring policy adherence and vulnerability tracking through its powerful cloud platform.
We monitor all Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.