Try our new research platform with insights from 80,000+ expert users

Qualys Policy Compliance vs RSA Archer comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on May 21, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.7
Qualys Policy Compliance improves data visibility and reliability, with many users noting efficiency despite challenges in ROI calculation.
Sentiment score
7.1
RSA Archer streamlines operations by automating processes, centralizing data, and enhancing risk management for high ROI and cost savings.
It relates to the effectiveness of employees and the time taken to complete tasks manually versus using the RSA system.
Information Security Specialist at Dubai Health Authority
 

Customer Service

Sentiment score
8.1
Users commend Qualys Policy Compliance's responsive support, rating it highly, despite occasional challenges in providing necessary evidence.
Sentiment score
6.3
Users experience varied satisfaction with RSA Archer support, appreciating prompt assistance but sometimes requiring escalation for complex issues.
They understood the scope, and we were ready to jump into the implementation phase in a day or two.
Information Security Analyst at a tech services company with 11-50 employees
Qualys Policy Compliance customer support is very good.
Technical Security Solutions Architecture at a tech vendor with 10,001+ employees
The response time from RSA Archer's support team is not an issue; usually, there's no problem getting a timely response, but there could be more knowledgeable agents available.
SW tester / Support, Helpdesk / Test Manager at ICZ a.s.
They are responsive and perform well in technical support.
 

Scalability Issues

Sentiment score
7.8
Qualys Policy Compliance offers scalable solutions for complex environments, managing large IP volumes, despite minor web interface speed issues.
Sentiment score
7.1
RSA Archer offers scalable solutions for multiple organizations, though effectiveness varies with strategy, deployment, and resource management.
In terms of scalability with Qualys Policy Compliance, we did not face any issues. It was scalable.
Information Security Analyst at a tech services company with 11-50 employees
Scalability depends on the number of servers, including web and service servers.
Information Security Specialist at Dubai Health Authority
The level of scalability depends on customization and how skillful our customization team is.
 

Stability Issues

Sentiment score
8.3
Qualys Policy Compliance is highly reliable, offering stability, excellent performance, and rare performance issues, earning a 9/10 rating.
Sentiment score
6.1
RSA Archer is stable and improved, though performance varies with resources and user load, rating around seven to eight.
Once everything is set and done with Qualys Policy Compliance, we did not face any performance issues or issues in terms of it being resource-friendly or utilizing any machine resources.
Information Security Analyst at a tech services company with 11-50 employees
It is very rare to encounter performance issues, about 0.1 to 0.01%.
Technical Security Solutions Architecture at a tech vendor with 10,001+ employees
The tool has stability, and it allows me to automate whatever process I have.
Head OT Risk Management & Compliance at Abu Dhabi National Oil Company
Performance issues arise mainly since it is not a core service for most organizations, so the resources provided are fewer.
Information Security Specialist at Dubai Health Authority
 

Room For Improvement

Users seek improved reporting, support, customization, and educational resources in Qualys Policy Compliance for better industry alignment.
RSA Archer struggles with outdated interface, complex workflows, costly updates, and lacks intuitive design and efficient integrations.
If there were some sort of reporting that fulfills auditor's requirements, particularly if there is an external audit and they ask us for any historical data like how long we have been compliant to the PCI framework, that would be valuable.
Information Security Analyst at a tech services company with 11-50 employees
They need to improve the reporting part of the CI/CD pipelines and the ability to download scans from pods.
Technical Security Solutions Architecture at a tech vendor with 10,001+ employees
While the AI features are emerging and the cost is comparatively low, it's not yet up to the market standard.
Information Security Specialist at Dubai Health Authority
A remaining area for improvement is integration. There should be built-in integration mechanisms, for example, for organizations switching from platforms like ServiceNow to Archer, instead of custom integrations for each client.
Dashboards are usually effective, but while visibility from the dashboard level is good, drill-down details may be difficult to access, as they don't seem to have direct support for this drill-down.
SW tester / Support, Helpdesk / Test Manager at ICZ a.s.
 

Setup Cost

Qualys Policy Compliance pricing is device-based, viewed as mid-range, with value in security features and potential cost-effectiveness.
RSA Archer is costly but valued for flexibility and functionality, appealing more to large enterprises than smaller ones.
after comparing it with other products in the market, I would rate it around six or seven out of ten, as the price is relative.
 

Valuable Features

Qualys Policy Compliance provides automated threat detection, customizable policies, robust reporting, and integrates well with tools like Confluence and Jira.
RSA Archer enhances governance, risk, and compliance with configurable modules, automation, robust security, and strong reporting, appealing to users.
In Qualys Policy Compliance, the best feature is that they keep their vulnerability database updated.
Information Security Analyst at a tech services company with 11-50 employees
From the Qualys Policy Compliance, the best feature is that they have predefined templates for compliances, allowing easy application of compliance requirements against our products and providing clear reports on whether assets are compliant or not.
Technical Security Solutions Architecture at a tech vendor with 10,001+ employees
In the banking sector, Archer has been used to automate processes such as business continuity management, transitioning from manual processes to automated systems.
The helpful features of RSA Archer include providing an integrated overview of the landscape in the company, which leads the user to use the same inventory and other components, sharing the same set of references and objects we are working on.
SW tester / Support, Helpdesk / Test Manager at ICZ a.s.
This allows us to show end users and management where the issues lie and effectively demonstrate accountability and visibility in compliance.
Information Security Specialist at Dubai Health Authority
 

Categories and Ranking

Qualys Policy Compliance
Ranking in IT Governance
3rd
Average Rating
8.8
Reviews Sentiment
7.3
Number of Reviews
8
Ranking in other categories
No ranking in other categories
RSA Archer
Ranking in IT Governance
1st
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
42
Ranking in other categories
GRC (1st), IT Vendor Risk Management (4th)
 

Mindshare comparison

As of January 2026, in the IT Governance category, the mindshare of Qualys Policy Compliance is 3.6%, up from 2.7% compared to the previous year. The mindshare of RSA Archer is 26.3%, down from 32.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Governance Market Share Distribution
ProductMarket Share (%)
RSA Archer26.3%
Qualys Policy Compliance3.6%
Other70.1%
IT Governance
 

Featured Reviews

reviewer1906245 - PeerSpot reviewer
Information Security Analyst at a tech services company with 11-50 employees
Facilitates continuous compliance monitoring and simplifies vulnerability tracking for distributed cloud assets
Regarding improvements I would like to see in Qualys Policy Compliance, there are a couple of vulnerabilities where the metrics that are already there and the way Qualys measures those metrics and labels them as critical, high, or low does not align with my understanding from a user standpoint. Every time, I have to put in a false positive. Since I have been doing that for the past one year, the same vulnerability tends to pop up and they mark it as critical. Qualys needs to update and rediscover those weaknesses and re-label them. I understand what the company design and what the tool does, but it takes some time for us to manage those things. In terms of missing features that I would like to see included in Qualys Policy Compliance, I do not think there are any. The feature does what we require and does the job. If there were some sort of reporting that fulfills auditor's requirements, particularly if there is an external audit and they ask us for any historical data like how long we have been compliant to the PCI framework, that would be valuable. Having reporting that shows historical data that we have been compliant from the date of inception, for example, from 2023 to 2025 onwards, would bring value to what we are reporting.
CJ
Information Security Specialist at Dubai Health Authority
Centralized management strengthens compliance with good look and feel
From my perspective as a customer and end user, Archer has an impressive look and feel, but the most adaptive feature is its ease of configuration which helps to enhance our process according to our maturity. It's more about our organization getting centralized with an integrated approach that focuses on risk governance and compliance. When can provide a detailed dashboards to management with the details of risks from top-down or bottom-up prioritizing actions based on its criticality or necessity. This allows us to show end users and management where the issues lie and effectively demonstrate accountability and visibility in compliance.
report
Use our free recommendation engine to learn which IT Governance solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Financial Services Firm
20%
Insurance Company
12%
Manufacturing Company
8%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise2
Large Enterprise4
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise6
Large Enterprise25
 

Questions from the Community

What is your experience regarding pricing and costs for QualysGuard Policy Compliance?
I was involved in the purchasing of Qualys Policy Compliance in my previous company, where the costs are based on the number of devices and features, with enterprise level pricing which I cannot sp...
What needs improvement with QualysGuard Policy Compliance?
Regarding improvements I would like to see in Qualys Policy Compliance, there are a couple of vulnerabilities where the metrics that are already there and the way Qualys measures those metrics and ...
What is your primary use case for QualysGuard Policy Compliance?
I have been working with Qualys Policy Compliance for the past four years. Our complete infrastructure is on cloud and we have assets distributed across Asia and North America. We have a couple of ...
What needs improvement with RSA Archer?
While it provides benefits in terms of security, the pricing is a bit higher than customers typically expect. It would be helpful if RSA Archer had the capability for two-way integration because, i...
What is your primary use case for RSA Archer?
Regarding the compliance, risk, and governance tools, I am comfortable discussing the tools in the GRC category. The specific module from ServiceNow is the ServiceNow Compliance, Risk, and Governan...
What advice do you have for others considering RSA Archer?
I have been in touch with about three companies who use RSA Archer actively in the compliance area. These companies use RSA Archer for nearly all purposes, including governance, internal risk, and ...
 

Also Known As

No data available
Archer
 

Overview

 

Sample Customers

PDX, Cigna
T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Find out what your peers are saying about Qualys Policy Compliance vs. RSA Archer and other solutions. Updated: December 2025.
881,082 professionals have used our research since 2012.