

Qualys Policy Compliance and RSA Archer are competitors in the compliance and GRC management space. While Qualys is noted for its comprehensive reporting and advanced automation, Archer stands out with its robust workflow capabilities and flexibility.
Features: Qualys Policy Compliance is renowned for its comprehensive compliance reports, customizable policies, and advanced automation capabilities. It is also praised for its seamless integration features. RSA Archer excels with its advanced workflow and data integration features. It offers strong reporting capabilities and is known for its flexibility in customization, which makes it a robust tool for managing enterprise-wide GRC modules.
Room for Improvement: For Qualys Policy Compliance, improvements are needed in enhanced detection features and alignment with industry standards like CIS. Users find Archer's interface and error reporting challenging, suggesting further customization options and better integration mechanisms. Archer's older-generation design and complexity in some workflow and API integration areas are also noted.
Ease of Deployment and Customer Service: Qualys Policy Compliance is praised for its deployment flexibility across public clouds and hybrids, with excellent customer support. RSA Archer offers various deployment options but gets mixed feedback on technical support, which can lack immediacy and responsiveness.
Pricing and ROI: Qualys Policy Compliance is considered cost-efficient, providing strong security features at a competitive price, with users reporting positive ROI. While RSA Archer offers extensive GRC functionalities, it is noted for higher costs, especially for smaller businesses, although it remains cost-effective for larger enterprises due to its comprehensive solutions.
It relates to the effectiveness of employees and the time taken to complete tasks manually versus using the RSA system.
They understood the scope, and we were ready to jump into the implementation phase in a day or two.
Qualys Policy Compliance customer support is very good.
The response time from RSA Archer's support team is not an issue; usually, there's no problem getting a timely response, but there could be more knowledgeable agents available.
They are responsive and perform well in technical support.
In terms of scalability with Qualys Policy Compliance, we did not face any issues. It was scalable.
Scalability depends on the number of servers, including web and service servers.
The level of scalability depends on customization and how skillful our customization team is.
Once everything is set and done with Qualys Policy Compliance, we did not face any performance issues or issues in terms of it being resource-friendly or utilizing any machine resources.
It is very rare to encounter performance issues, about 0.1 to 0.01%.
The tool has stability, and it allows me to automate whatever process I have.
Performance issues arise mainly since it is not a core service for most organizations, so the resources provided are fewer.
If there were some sort of reporting that fulfills auditor's requirements, particularly if there is an external audit and they ask us for any historical data like how long we have been compliant to the PCI framework, that would be valuable.
They need to improve the reporting part of the CI/CD pipelines and the ability to download scans from pods.
While the AI features are emerging and the cost is comparatively low, it's not yet up to the market standard.
A remaining area for improvement is integration. There should be built-in integration mechanisms, for example, for organizations switching from platforms like ServiceNow to Archer, instead of custom integrations for each client.
Dashboards are usually effective, but while visibility from the dashboard level is good, drill-down details may be difficult to access, as they don't seem to have direct support for this drill-down.
after comparing it with other products in the market, I would rate it around six or seven out of ten, as the price is relative.
In Qualys Policy Compliance, the best feature is that they keep their vulnerability database updated.
From the Qualys Policy Compliance, the best feature is that they have predefined templates for compliances, allowing easy application of compliance requirements against our products and providing clear reports on whether assets are compliant or not.
In the banking sector, Archer has been used to automate processes such as business continuity management, transitioning from manual processes to automated systems.
The helpful features of RSA Archer include providing an integrated overview of the landscape in the company, which leads the user to use the same inventory and other components, sharing the same set of references and objects we are working on.
This allows us to show end users and management where the issues lie and effectively demonstrate accountability and visibility in compliance.
| Product | Mindshare (%) |
|---|---|
| RSA Archer | 20.7% |
| Qualys Policy Compliance | 4.0% |
| Other | 75.3% |
| Company Size | Count |
|---|---|
| Small Business | 2 |
| Midsize Enterprise | 2 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 6 |
| Large Enterprise | 25 |
Qualys Policy Compliance offers seamless compliance management featuring real-time threat detection, policy customization, and integration with SIEM and ticketing tools. It supports both on-premises and cloud assets, ensuring comprehensive security management.
Qualys Policy Compliance provides a streamlined approach to compliance through its predefined templates and frequent vulnerability updates, supporting the compliance needs of organizations managing diverse infrastructures. Its interface allows effective management of security policies and straightforward compliance verification. Users benefit from enhanced security management with its automation features and asset scanning capabilities. Integration with cloud infrastructure and seamless policy management across platforms like Windows, Linux, and networking appliances make it indispensable for enterprises seeking minimal vulnerabilities.
What are the key features of Qualys Policy Compliance?Banks and organizations utilize Qualys Policy Compliance for server hardening and security configuration verification. Loading it with security policies, they ensure PCI compliance and effective vulnerability management. It's particularly effective across Windows, Linux, and networking appliances with basic scans for compliance checks.
RSA Archer provides robust risk management, compliance, and vendor management with intuitive features for customizable and streamlined governance tasks.
RSA Archer delivers integrated solutions supporting risk management and compliance tasks. Its adaptive interface and customizable options enhance workflows, making it valuable for organizations requiring automation, advanced workflows, and easy integration capabilities. While offering flexibility and configuration power, users note potential enhancements for integration, reporting, and interface updates.
What are the key features of RSA Archer?In the finance, public, and IT sectors, RSA Archer is utilized for managing risk and compliance. Organizations leverage its capabilities for third-party risk, policy management, and security assessments, providing tailored solutions for regulatory compliance and operational risk management. Integration with platforms like ServiceNow enhances its utility within enterprise environments.
We monitor all IT Governance reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.