Try our new research platform with insights from 80,000+ expert users

Qualys Policy Compliance vs RSA Archer comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on May 21, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.9
Qualys Policy Compliance improves data visibility and reliability, with many users noting efficiency despite challenges in ROI calculation.
Sentiment score
7.5
RSA Archer enhances risk management, automates processes, centralizes data, and offers customization, resulting in optimized operations and financial returns.
It relates to the effectiveness of employees and the time taken to complete tasks manually versus using the RSA system.
 

Customer Service

Sentiment score
8.1
Users commend Qualys Policy Compliance's responsive support, rating it highly, despite occasional challenges in providing necessary evidence.
Sentiment score
6.4
RSA Archer is praised for approachable support, active community, but needs quicker initial responses and deeper first-level assistance.
Qualys Policy Compliance customer support is very good.
They are responsive and perform well in technical support.
 

Scalability Issues

Sentiment score
7.7
Qualys Policy Compliance offers scalable solutions for complex environments, managing large IP volumes, despite minor web interface speed issues.
Sentiment score
7.2
RSA Archer is scalable and adaptable but demands significant resources and expertise, suitable for large and complex environments.
Scalability depends on the number of servers, including web and service servers.
The level of scalability depends on customization and how skillful our customization team is.
 

Stability Issues

Sentiment score
8.8
Qualys Policy Compliance is highly reliable, offering stability, excellent performance, and rare performance issues, earning a 9/10 rating.
Sentiment score
6.3
RSA Archer is stable, improving with updates, but may slow during resource-intensive tasks, large databases, or peak times.
It is very rare to encounter performance issues, about 0.1 to 0.01%.
Performance issues arise mainly since it is not a core service for most organizations, so the resources provided are fewer.
The tool has stability, and it allows me to automate whatever process I have.
 

Room For Improvement

Users seek improved reporting, support, customization, and educational resources in Qualys Policy Compliance for better industry alignment.
RSA Archer requires dashboard, UI, automation, integration improvements, and better functionality, support, pricing, and training to enhance usability.
They need to improve the reporting part of the CI/CD pipelines and the ability to download scans from pods.
While the AI features are emerging and the cost is comparatively low, it's not yet up to the market standard.
A remaining area for improvement is integration. There should be built-in integration mechanisms, for example, for organizations switching from platforms like ServiceNow to Archer, instead of custom integrations for each client.
 

Setup Cost

Qualys Policy Compliance pricing is device-based, viewed as mid-range, with value in security features and potential cost-effectiveness.
RSA Archer is cost-effective for large firms but may be prohibitively expensive for smaller companies despite flexible licensing.
after comparing it with other products in the market, I would rate it around six or seven out of ten, as the price is relative.
 

Valuable Features

Qualys Policy Compliance provides automated threat detection, customizable policies, robust reporting, and integrates well with tools like Confluence and Jira.
RSA Archer offers configurable modules, workflow automation, and robust risk management with user-friendly interfaces and flexible API integration.
From the Qualys Policy Compliance, the best feature is that they have predefined templates for compliances, allowing easy application of compliance requirements against our products and providing clear reports on whether assets are compliant or not.
In the banking sector, Archer has been used to automate processes such as business continuity management, transitioning from manual processes to automated systems.
This allows us to show end users and management where the issues lie and effectively demonstrate accountability and visibility in compliance.
The tool has stability, and it allows me to automate whatever process I have.
 

Categories and Ranking

Qualys Policy Compliance
Ranking in IT Governance
3rd
Average Rating
8.6
Reviews Sentiment
7.9
Number of Reviews
7
Ranking in other categories
No ranking in other categories
RSA Archer
Ranking in IT Governance
1st
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
41
Ranking in other categories
GRC (1st), IT Vendor Risk Management (4th)
 

Mindshare comparison

As of July 2025, in the IT Governance category, the mindshare of Qualys Policy Compliance is 2.5%, up from 1.9% compared to the previous year. The mindshare of RSA Archer is 33.9%, up from 32.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Governance
 

Featured Reviews

Bhupendra Nayak - PeerSpot reviewer
A VMDR solution that can be used to detect, block, and mitigate vulnerabilities
We use QualysGuard Policy Compliance for VMDR (Vulnerability Management, Detection and Response). We can use the solution to detect, block, and mitigate vulnerabilities The most valuable feature of QualysGuard Policy Compliance is the automation that can detect real-time threats and decrease…
IMRAN ALMARZOOQI - PeerSpot reviewer
Automates compliance management effectively but needs improved interface and dashboards
The tool basically automates whatever processes you already have, so I cannot specify improvements in that regard. However, my main issue with Archer is the graphics. The graphics have always been lacking. I always need to depend on another tool to read information from Archer to have better dashboards. It is like using Linux, and it has a Linux mindset and interface. I want to use Archer for top management and CEOs, but it looks too technical, and the dashboards are not really friendly. They are bulky, like opening an old Nintendo system from nineteen-ninety. The management agrees that Archer lacks in terms of presentation and dashboarding. It is complex, not user-friendly, and bulky. The interface just looks old.
report
Use our free recommendation engine to learn which IT Governance solutions are best for your needs.
860,168 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Healthcare Company
19%
Financial Services Firm
17%
Government
9%
Computer Software Company
8%
Educational Organization
23%
Financial Services Firm
18%
Insurance Company
9%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about QualysGuard Policy Compliance?
The most valuable feature of QualysGuard Policy Compliance is the automation that can detect real-time threats and decrease risks.
What is your experience regarding pricing and costs for QualysGuard Policy Compliance?
The product is very expensive, rated nine out of ten, however, it is worth trying and can potentially replace other platforms.
What needs improvement with QualysGuard Policy Compliance?
Some sort of education or knowledge base about the product would be beneficial for beginners. They could offer more training sessions for beginners who are new to the solution, as learning would be...
What do you like most about RSA Archer?
It has various valuable features. For example, showing us if a control aligns with specific standards or frameworks helps us understand it better and verify its compliance.
What needs improvement with RSA Archer?
If the user needs to fill data, they need to go to one page and then to the next page if they can reduce the number of clicks to perform some activities and would like RSA to improve in this area. ...
What is your primary use case for RSA Archer?
I perform all of our information security management governance and risk -related activities through Archer. My organization manages all types of audits and Enterprise risk activities using Archer.
 

Comparisons

No data available
 

Also Known As

No data available
Archer
 

Overview

 

Sample Customers

PDX, Cigna
T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Find out what your peers are saying about Qualys Policy Compliance vs. RSA Archer and other solutions. Updated: June 2025.
860,168 professionals have used our research since 2012.