No more typing reviews! Try our Samantha, our new voice AI agent.

Qualys VMDR vs ServiceNow Security Operations comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys VMDR
Ranking in Risk-Based Vulnerability Management
1st
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
96
Ranking in other categories
IT Asset Management (3rd), Vulnerability Management (3rd), Configuration Management Databases (3rd), Container Security (10th)
ServiceNow Security Operations
Ranking in Risk-Based Vulnerability Management
12th
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
24
Ranking in other categories
Security Incident Response (1st), Security Orchestration Automation and Response (SOAR) (9th)
 

Mindshare comparison

As of August 2026, in the Risk-Based Vulnerability Management category, the mindshare of Qualys VMDR is 9.7%, down from 16.0% compared to the previous year. The mindshare of ServiceNow Security Operations is 1.6%, up from 1.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Risk-Based Vulnerability Management Mindshare Distribution
ProductMindshare (%)
Qualys VMDR9.7%
ServiceNow Security Operations1.6%
Other88.7%
Risk-Based Vulnerability Management
 

Featured Reviews

Vaibhav Ghule - PeerSpot reviewer
Soc Lead & Edr Administration at Persistent Systems
Continuous risk-based monitoring has strengthened incident response and vulnerability prioritization
I haven't explored Qualys VMDR's vulnerability lifecycle automation yet. One of my analysts mentioned that queries lack grouping operators in Qualys VMDR. From my experience, I would appreciate improvements in the query options in Qualys VMDR, specifically in the query-building process where I would need more features and operators. Additionally, we have been facing issues with Qualys on the cloud level. We cannot download the configuration profile from the cloud agent, and it is showing a pending action for download. During 2025, we noticed outages of Qualys a couple of times. I want to mention that there is an issue with receiving timely RCA deliveries. While this is not necessarily about the tool, it relates to support. The support has not been very responsive, and we are receiving RCAs a little delayed whenever we raise support cases or communicate with the TAMs. Additionally, the UI has a slight latency, which I and my team have experienced. They have also reported this latency issue when navigating through different pages.
Suhel Khan - PeerSpot reviewer
Senior Consultant (Siem Admin) at IBM
Precise incident handling has improved reporting and searching across complex security cases
I would like to see new features added, particularly regarding the incident upgrading part. For instance, if you have an instance and need to transfer it to a particular team, being able to show that the status is still in progress, which is currently in a beta version, would definitely help people to understand that the status has changed for the incident.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"If you are familiar with or have hands on experience with Qualys Asset Inventory, this is a better tool, as it will give you in-depth details of all the assets and the managing inventory will be better, and it will also give you advanced features compared to those of other inventory tools."
"Using the policy compliance module allowed this to be automated and saved time as well as generated more complete coverage of assets leading to greater assurance."
"This is one of the best products I have worked with so far."
"The most valuable feature is the QID part, especially of CentralList, which makes it easy to assess new critical vulnerabilities."
"The most recent is VMDR, which provides a comprehensive overview of how to detect, patch, and remediate specific vulnerabilities."
"Tech support is helpful."
"We can now perform vulnerability scans with WAF integration, and the WAF has improved the vulnerability identification and reports to the SOC and CSO."
"It is quite easy to implement."
"Reduces time to closure and closure metrics for vulnerabilities."
"It streamlines processes; it collects data, takes that data and turns it into information, and allows you to manage through dashboards and work lists, improving every facet of the overall process."
"The product's most valuable features include the no-code capability for workflows and flow design, which makes it user-friendly, and the ability to perform advanced configurations."
"ServiceNow Security Operations has helped me in getting more precise results."
"ServiceNow Security Operations should be mandatory for any organization to maintain data."
"The most valuable features are service management and case management, and ServiceNow Security Operations also takes care of problem management as well as GRC, governance, risk, and compliance, enabling it to provide risk assessment."
"The product has a very simple UI."
"The solution is available over the cloud and is easy to manage."
 

Cons

"I would like to have CSPM, a continuous scan-like cloud added to the solution."
"Support could be improved since the response can be slow."
"The ability to manage user accounts and give rights to the operator to know about abnormalities of applications is something that needs improvement."
"One of the biggest issues from the clients' perspective is that all Qualys computing is on the cloud."
"The customer support is very bad."
"The IoT scan is not great."
"Its integration with ServiceNow and other similar products is complicated and can be improved."
"Expanding the template library would be very useful."
"​Process framework and best practices for ease of integration between IT and security teams via incident, problem, and change.​"
"They should stick to the roadmap and continue to build plugins and integrations with other third parties, enhance the UI, and enhance the reporting. It's all good. They should just continue enhancing the releases."
"An area for improvement I observed in ServiceNow Security Operations is the need to maintain correct CMDB data because if you're unable to do this, you can't perfectly maintain the vulnerability data. CMDB data in ServiceNow Security Operations needs to be accurate. As I've been working on ServiceNow Security Operations for only seven months, I still need more time to try all its modules before I can give recommendations regarding additional features I'd like to see in the solution."
"You can't connect to anything. It doesn't interact with things very well."
"Report generation within ServiceNow can take some time. Additionally, there are occasional issues when raising a ticket, which can also consume time."
"The product of ServiceNow Security Operations needs more features. The product is called SecOps, but it is not security operations in terms of SIEM solutions."
"We'd like customization to be easier in terms of the UI and using the dashboards."
"There are limitations for the third-parties that are providing the inputs. They should increase the robustness of the solution."
 

Pricing and Cost Advice

"An annual license for a single scanner costs around $3,000."
"In Nigerian Naira, we spend about roughly four to five million to use this solution and this is expensive compared to solutions like Nessus."
"Qualys VM is quite expensive. It's a subscription-based license, and it's yearly. Right now, it's open for me, and I don't have any limitations or caps on the licenses. They are seeing if the product is viable for 4500 users. I can add as much as I want, and at the end of the subscription, they'll let me know how many licenses were actually used and bill me accordingly. On a scale from one to five, I would give their pricing a three. It's still expensive."
"They have recently changed the pricing model, which is now better than it was before."
"Qualys VM is reasonably priced."
"The product is more expensive than that of any other vendor."
"We have an annual contract for Qualys VMDR. I believe it's for either two years or five years."
"I used to work there, so I never paid for the product. As an employee, we get a lifetime license for personal use, and that's what I'm using. It is a comprehensive platform, so there is a lot more to it. There could be other solutions that are probably a little bit cheaper, but it depends on what people need. Different people have different needs. It offers many things on the same platform. If you add all the things up, it should be cheaper, but I have not done any analysis specifically."
"It is an expensive product."
"Compared to competitor tools, ServiceNow Security Operations is more affordable"
"If you're going to implement it on your own, there would be internal costs. If you're going to implement it through a contractor or consultant, you have to pay for that."
"This product is a good value for the money."
"The product is more expensive than other solutions."
"The solution is more expensive than BMC Remedy, the other ITSM tool available in the market."
report
Use our free recommendation engine to learn which Risk-Based Vulnerability Management solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Manufacturing Company
7%
Computer Software Company
6%
Construction Company
6%
Financial Services Firm
15%
Manufacturing Company
13%
Comms Service Provider
6%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business20
Midsize Enterprise12
Large Enterprise70
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise2
Large Enterprise17
 

Questions from the Community

What is your experience regarding pricing and costs for Qualys VMDR?
My experience with pricing, setup cost, and licensing shows that we can consider both time and money saved.
What needs improvement with Qualys VMDR?
I haven't explored Qualys VMDR's vulnerability lifecycle automation yet. One of my analysts mentioned that queries lack grouping operators in Qualys VMDR. From my experience, I would appreciate imp...
What advice do you have for others considering Qualys VMDR?
I have some understanding about PeerSpot, and I have visited the website. PeerSpot is similar to TrustRadius. It takes reviews from customers or end users who are using the tools and technologies i...
What is your experience regarding pricing and costs for ServiceNow Security Operations?
In my opinion, the pricing is quite affordable considering the features, and I do not find it expensive. I would not call it cheap; rather, I am looking at it as a product owner.
What needs improvement with ServiceNow Security Operations?
I would like to see new features added, particularly regarding the incident upgrading part. For instance, if you have an instance and need to transfer it to a particular team, being able to show th...
What advice do you have for others considering ServiceNow Security Operations?
For someone looking to use ServiceNow Security Operations, I recommend that they read about the documentation and spend one or two hours familiarizing themselves with FortiGating, and that will be ...
 

Also Known As

Qualys VM, QualysGuard VM, Qualys Asset Inventory, Qualys Container Security
No data available
 

Overview

 

Sample Customers

Agrokor Group, American Specialty Health, American State Bank, Arval, Life:), Axway, Bank of the West, Blueport Commerce, BSkyB, Brinks, CaixaBank, Cartagena, Catholic Health System, CEC Bank, Cegedim, CIGNA, Clickability, Colby-Sawyer College, Commercial Bank of Dubai, University of Utah, eBay Inc., ING Singapore, National Theatre, OTP Bank, Sodexo, WebEx
DXC Technology, Freedom Security Alliance, Prime Therapeutics, Seton Hall University, York Risk Services
Find out what your peers are saying about Qualys VMDR vs. ServiceNow Security Operations and other solutions. Updated: June 2026.
908,800 professionals have used our research since 2012.