

Qualys VMDR and Pentera compete in the cybersecurity vulnerability management sector. Qualys VMDR seems to have the upper hand with its comprehensive feature set and broader coverage across various security aspects, including cloud-based scanning and patch management, while Pentera focuses on automated penetration testing and real-time validation.
Features: Qualys VMDR offers comprehensive vulnerability management with cloud-based scanning, patch management, and compliance features. It includes continuous monitoring, cloud agent deployment, and robust reporting capabilities. Pentera provides automated penetration testing, continuous vulnerability assessment, and AI-based reporting, offering a realistic approach to cybersecurity validation.
Room for Improvement: Qualys VMDR users suggest enhancements in cloud-based dependency management, simplification of report generation, and asset tagging. Better customer support and streamlined API functionalities are also desired. Pentera could improve its licensing model to accommodate smaller organizations and enhance dashboard usability. Both platforms could benefit from more tailored solutions and improved scalability.
Ease of Deployment and Customer Service: Qualys VMDR supports various deployment environments, including public and private clouds, on-premises, and hybrid setups. Its technical support receives mixed reviews, particularly concerning responsiveness. Pentera primarily supports on-premises and private cloud deployments with less complex infrastructure and is noted for effective technical support, highlighting a contrast in deployment flexibility.
Pricing and ROI: Qualys VMDR is priced high but offers various licensing models and discounts, with users acknowledging the comprehensive service justifies the investment. Pentera is also considered expensive but provides value in targeting overlooked vulnerabilities. Both platforms achieve significant ROI through vulnerability reduction and enhanced cybersecurity, though Qualys’s extensive service range might offer higher overall returns.
Some customers consider the ROI favorable, but facing difficulties now due to changes in the licensing model, which has made it more expensive compared to last year.
We saw a return on investment through significant savings in time, money, and resources.
We usually get on calls with tech support, and they are very helpful.
When reaching out via email, they reply quickly.
The response time takes a while.
Scalability depends on the license and the number of assets being monitored.
Qualys VMDR can handle scalability, although increasing the inventory can raise the licensing costs.
Qualys VMDR's scalability is good, and the customer support is good.
Qualys VMDR is stable.
When the IP is imported into a system, we cannot withdraw or revoke the license.
It does not automate patching unless the patch management module is purchased separately.
I would appreciate improvements in the query options in Qualys VMDR, specifically in the query-building process where I would need more features and operators.
If AI features were integrated, it could enhance the capabilities significantly.
I have a notion that Qualys might be more expensive than Rapid7.
Qualys offers better pricing and is feature-packed compared to other tools.
I would rate the pricing between seven to eight out of ten.
We can automate the Pentera processes by automatically creating scenarios to validate the system.
The prioritization of vulnerabilities has improved our remediation efforts by around thirty to thirty-five percent.
It impacts my workflow overall, with the patch management features as it has the missing patches listed in detail, making it easier to get a comprehensive report and providing some dashboards that offer visual representation.
Qualys VMDR's continuous monitoring capabilities help us respond to emergent threats by enabling my team to reach out to the security engineers whenever there is any detection of a vulnerability, informing them about it, and creating an incident.
| Product | Market Share (%) |
|---|---|
| Pentera | 24.9% |
| Cymulate | 17.0% |
| Picus Security | 14.6% |
| Other | 43.5% |
| Product | Market Share (%) |
|---|---|
| Qualys VMDR | 5.0% |
| Wiz | 7.5% |
| Tenable Nessus | 5.2% |
| Other | 82.3% |


| Company Size | Count |
|---|---|
| Small Business | 5 |
| Midsize Enterprise | 1 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 20 |
| Midsize Enterprise | 12 |
| Large Enterprise | 70 |
Pentera is the category leader for Automated Security Validation, allowing every organization to evaluate its security readiness, to know its real security risk at any given moment. Test all cybersecurity layers across the attack surface – inside and out – by safely emulating attacks & prioritize patching with a risk-based remediation roadmap.
Thousands of security professionals and service providers around the world use Pentera to guide remediation and close security gaps before they are exploited. For more info visit: pentera.io
Vulnerability Management, Detection, and Response (VMDR) is a cornerstone product of the Qualys TruRisk Platform and a global leader in the enterprise-grade vulnerability management (VM) vendor space. With VMDR, enterprises are empowered with visibility and insight into cyber risk exposure - making it easy to prioritize vulnerabilities, assets, or groups of assets based on business risk. Security teams can take action to mitigate risk, helping the business measure their actual risk exposure over time.
Qualys VMDR offers an all-inclusive risk-based vulnerability management solution to prioritize vulnerabilities and assets based on risk and business criticality. VMDR seamlessly integrates with configuration management databases (CMDB), Qualys Patch Management, Custom Assessment and Remediation (CAR), Qualys TotalCloud and other Qualys and non-Qualys solutions to facilitate vulnerability detection and remediation across the entire enterprise.
With VMDR, users are empowered with actionable risk insights that translate vulnerabilities and exploits into optimized remediation actions based on business impact. Qualys customers can now aggregate and orchestrate data from the Qualys Threat Library, 25+ threat intelligence feeds, and third-party security and IT solutions, empowering organizations to measure, communicate, and eliminate risk across on-premises, hybrid, and cloud environments.
We monitor all Breach and Attack Simulation (BAS) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.