

Qualys VMDR and FortiCNAPP compete in the cybersecurity sector, focusing on vulnerability management and threat prevention. Qualys VMDR appears to have an advantage in comprehensive vulnerability management and real-time tracking, while FortiCNAPP stands out with its network segmentation and integration capabilities.
Features: Qualys VMDR offers comprehensive vulnerability management, continuous monitoring, and accurate vulnerability identification. FortiCNAPP is recognized for its robust network segmentation, security policy enforcement, and seamless integration with SIEM solutions.
Room for Improvement: Qualys VMDR users note complex reporting, high costs, and slow support. There's also concern about its cloud dependency for small businesses. FortiCNAPP requires user interface enhancements and better data visibility and compliance metrics, especially in IAM security controls.
Ease of Deployment and Customer Service: Qualys VMDR provides flexible deployment for cloud and on-premises environments but is complex for larger setups. Its technical support gets mixed reviews. FortiCNAPP is available on both public and private clouds and receives more consistent feedback on its quick response times and stable performance.
Pricing and ROI: Qualys VMDR's pricing is considered high, particularly for smaller enterprises, though the value is justified for larger organizations in terms of improved security posture. FortiCNAPP offers a competitive pricing model with significant ROI through integration capabilities, resulting in risk reduction and time savings. Both solutions are seen as worthwhile investments, with FortiCNAPP's pricing noted for its clarity.
FortiCNAPP is a competitive and robust solution, the only one in the IT sphere that addresses all quadrants in the Gartner Quadrants.
We saw a return on investment through significant savings in time, money, and resources.
My technical teams do utilize integration with DevOps tools, as it performs significantly with automation regarding sophisticated challenges.
Fortinet's technical support is definitely helpful and responsive.
Technical support from Fortinet is good; I get feedback and responses quickly.
We usually get on calls with tech support, and they are very helpful.
The response time takes a while.
The technical support provided by Qualys is pretty good.
For complex large customers, global deployments, or large public sector customers, the process can take longer.
Scalability depends on the license and the number of assets being monitored.
Qualys VMDR can handle scalability, although increasing the inventory can raise the licensing costs.
Qualys VMDR's scalability is good, and the customer support is good.
They respond within the service level agreements and are proactive in their approach.
Qualys VMDR is stable.
The vulnerability part is not systematically organized; it is all clumsy in the web UI, and it is not user-friendly.
The solution could be more user-friendly and intuitive.
Policy implementation is quite complex, and the stability will take more time for the solutions.
It does not automate patching unless the patch management module is purchased separately.
If AI features were integrated, it could enhance the capabilities significantly.
One area where Qualys VMDR can be improved is the missing feature for deploying agents for over 1,000 assets, as we need to do it manually.
The pricing is a mediator compared to other products; it is not that much higher and not much lower than other products, making it a very affordable price.
I would rate the pricing between seven to eight out of ten.
I have a notion that Qualys might be more expensive than Rapid7.
Qualys offers better pricing and is feature-packed compared to other tools.
It functions as a proactive tool, enabling me to identify threats quickly and automate responses.
The machine learning capability in Lacework FortiCNAPP is used for threat detection.
FortiCNAPP definitely brings time-saving benefits.
The prioritization of vulnerabilities has improved our remediation efforts by around thirty to thirty-five percent.
It impacts my workflow overall, with the patch management features as it has the missing patches listed in detail, making it easier to get a comprehensive report and providing some dashboards that offer visual representation.
Qualys VMDR's continuous monitoring capabilities help us respond to emergent threats by enabling my team to reach out to the security engineers whenever there is any detection of a vulnerability, informing them about it, and creating an incident.
| Product | Mindshare (%) |
|---|---|
| Qualys VMDR | 4.9% |
| FortiCNAPP | 1.8% |
| Other | 93.3% |


| Company Size | Count |
|---|---|
| Small Business | 6 |
| Midsize Enterprise | 4 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 20 |
| Midsize Enterprise | 12 |
| Large Enterprise | 70 |
FortiCNAPP is a comprehensive cloud security platform focusing on ease of use and machine learning-driven anomaly detection. It offers robust compliance reporting, seamless integration, and continuous monitoring, making it an essential tool for organizations managing multi-cloud environments and security configurations.
FortiCNAPP provides significant capabilities in cloud security, compliance, and vulnerability management. Designed for organizations needing efficient monitoring, it enables detection of anomalies across cloud infrastructures while optimizing security posture and ensuring compliance with environments like AWS and GCP. The platform offers in-depth insights through scanning of IAC scripts, host systems, and cloud configurations. Recognized for effectively managing security posture, it safeguards Kubernetes and container environments, providing comprehensive threat detection and response. However, some areas like visibility, IAM security controls, and compliance metrics need improvement. Users face challenges with alert setup and lack intuitive design, alongside issues like FedRAMP authorization absence and complexity in the data model.
What are the key features of FortiCNAPP?FortiCNAPP is implemented extensively by industries needing reliable cloud security, such as finance, healthcare, and technology sectors. It supports organizations in enhancing cloud infrastructure protection, ensuring compliance, and strengthening vulnerability management. By integrating with platforms like AWS and GCP, businesses can optimize security posture in their cloud deployments.
Vulnerability Management, Detection, and Response (VMDR) is a cornerstone product of the Qualys TruRisk Platform and a global leader in the enterprise-grade vulnerability management (VM) vendor space. With VMDR, enterprises are empowered with visibility and insight into cyber risk exposure - making it easy to prioritize vulnerabilities, assets, or groups of assets based on business risk. Security teams can take action to mitigate risk, helping the business measure their actual risk exposure over time.
Qualys VMDR offers an all-inclusive risk-based vulnerability management solution to prioritize vulnerabilities and assets based on risk and business criticality. VMDR seamlessly integrates with configuration management databases (CMDB), Qualys Patch Management, Custom Assessment and Remediation (CAR), Qualys TotalCloud and other Qualys and non-Qualys solutions to facilitate vulnerability detection and remediation across the entire enterprise.
With VMDR, users are empowered with actionable risk insights that translate vulnerabilities and exploits into optimized remediation actions based on business impact. Qualys customers can now aggregate and orchestrate data from the Qualys Threat Library, 25+ threat intelligence feeds, and third-party security and IT solutions, empowering organizations to measure, communicate, and eliminate risk across on-premises, hybrid, and cloud environments.
We monitor all Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.