No more typing reviews! Try our Samantha, our new voice AI agent.

Vanta vs Xops comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
39
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (6th)
Vanta
Average Rating
8.6
Reviews Sentiment
5.5
Number of Reviews
10
Ranking in other categories
Compliance Consulting (1st), Data Governance (14th), Compliance Management (3rd)
Xops
Average Rating
9.0
Number of Reviews
4
Ranking in other categories
Cloud Cost Management (27th), Compliance Management (13th), AI Security (28th)
 

Featured Reviews

RO
IT Security Expert at Alior Bank S.A.
Unified risk scoring has improved our cloud visibility and simplifies remediation priorities
Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS. This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score. The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified. Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.
reviewer2585640 - PeerSpot reviewer
Consultant at a consultancy with 11-50 employees
Compliance workflows have become organized and automation supports ongoing healthcare audits
There are always tons of rooms for improvement for Vanta. I kind of exaggerated a little bit about the policy control. I don't really love the way they handle the revision management of that feature. If I'm on V1 of the policy document and I make some changes to it, then I get rid of V1 and then I re-upload V2. It's not that it keeps a running history of each of the different revisions. A little bit of an issue with that, but workable. I don't really have any negative complaint right now that would be worthwhile expressing. It's just that there's a lot of features. The UI is not super intuitive, but now that I've worked with it for a couple of years, I know how to navigate and get around. Initially, it was a little bit of a struggle understanding how these things would all work.
SS
CEO at Rexha Technologies
User interface needs refinement while providing robust security and cost management
Xops helps me with cloud finance management by allowing me to monitor my spending, and just a couple of months ago, I noticed that my AWS bill, which usually hovers around 50k monthly, spiked unexpectedly. I received an alert on the dashboard and via email about a sudden increase in usage, enabling me to rectify the actual problem and bring things back to normal. The best features of Xops, in my experience, include the FinOps component for checking unnecessary spending trends, the cloud security features, and the cybersecurity and workload security features that allow me to frequently check for vulnerabilities on images and websites. The cloud security feature of Xops stands out to me because it helps maintain compliance status by providing multiple compliance checks, including ISO and CIS benchmarks, and it is not limited to AWS, as it also includes Azure cloud scans and O365 cloud scans, allowing me to monitor security across various platforms. Other useful features of Xops include asset management tools and automation scripts, which help me check what assets I have across all regions, giving me a global view whenever I need it. Xops has positively impacted my organization by enabling me to save money and proactively detect issues, especially related to cloud spending, while also improving my routine security checks for any misconfigurations. While some metrics are difficult to quantify, I regularly run scans to catch security vulnerabilities that may arise due to changing user settings.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One of the features I appreciate is the ability to generate daily reports without relying on anyone else."
"I appreciate Qualys TotalCloud's ability to onboard any type of device with ease, including containers."
"If I had to say something positive about the product that brings me the biggest benefit, I would say it has accurate reports, gets new update CVEs, zero-day attack detection, and is easy to manage with its GUI."
"Qualys TotalCloud provides a single, prioritized view of risk, reducing the workload associated with consolidating multiple sources for risk prioritization."
"Qualys TotalCloud has significantly improved our organization by automating our reporting processes, reducing the time spent on report creation from two hours to less than fifteen to twenty minutes."
"With TotalCloud, we can scan through the API. If we are not able to deploy cloud agents on the machine, we can use the API."
"If someone were to ask me to review Qualys TotalCloud, I would summarize it as an end-to-end solution for cloud security with visibility and governance-grade controls without needing to manage multiple disconnected tools."
"The most valuable feature is extensibility."
"Vanta provides a necessary repository that any compliance expert will look at and recognize right away."
"The product has provided automated security controls for our cloud provider. It helps to automate security checks. Vanta offers a list of things that can be done to achieve ISO 27001 compliance."
"It helps us track the compliance of the components listed in our partner's directory. We can also check if the password manager, XML, and three log policies have been properly implemented on the desktop."
"After implementing those changes with Vanta, we tracked specific outcomes and metrics and improved compliance scores, which we can see in Vanta."
"They integrate into New Relic as a performance monitoring tool."
"Vanta has positively impacted my organization by streamlining the whole HITRUST R2 assessment process."
"The most valuable feature of Vanta is its prebuilt control frameworks."
"Task management and vendor assurance are the most valuable features. It is also an easy tool to use."
"Xops has positively impacted my organization by enabling me to save money and proactively detect issues, especially related to cloud spending, while also improving my routine security checks for any misconfigurations."
"The automated compliance monitoring reduced our manual security audits by 60%, allowing our team to focus on strategic initiatives rather than repetitive checks."
"Xops helped us mitigate the frequent external attacks that we have been trying to curb for a long time now, and more importantly, it helps with an easy-to-understand dashboard where I can monitor the services in use, optimizations, and ultimately the costs."
"The AWS cost optimization features have been game-changing - particularly the automated detection of idle EC2 instances and unattached EBS volumes that were silently draining our budget."
"X-Ops has significantly improved our organization by streamlining cloud cost governance and enhancing the security posture across our AWS trading environment."
"The most valuable aspects of the solution include the Cloud FinOps Dashboards and the vulnerability scans."
 

Cons

"Qualys' customer service provides quality answers, but the response time is long, even though it is within the SLA."
"The support process is inefficient due to the excessive number of replies required when submitting tickets."
"The main area needing improvement is integration. Although the team is strengthening TotalCloud, integration can be enhanced with SIEM, SOAR, ITSM, and other sources."
"It is already perfect, but they can bring some newer dashboards and customization options for the dashboard. It would be great to be able to include on-prem assets on the dashboard."
"The vulnerability part is good, but the policy compliance module needs improvement because it involves a lot of manual work. Specifically, the remediation part of the controls requires enhancements."
"Qualys's ticketing system can be confusing when assigning tasks to individuals, and support could be improved by offering instant call solutions with engineers in addition to ticket replies."
"To improve the user experience, reporting could be simplified for better comprehension by end users and project managers, facilitating issue resolution."
"Their customer support needs improvement."
"Currently, Vanta's user access review module is still in development, and we've been giving them continuous feedback to help them improve that."
"I would tell others looking into using Vanta to use it for HITRUST E1 and I1 assessments, as the R2 assessments are still a work in progress."
"There is a delay with customer support and they are unsure of the answers we need."
"Some of the tool's automated tests do not work the way it should."
"Failed tests for device CVEs seem to be cumulative, meaning I have to clear all CVEs before the test will pass, which makes it difficult to resolve the test before the next round of CVEs are published."
"Scalability could be improved."
"The main area for improvement in Vanta is the user interface's refresh rate."
"They have an AI generator for the system description for SOC 2, however, the outline is a little sketchy."
"While Xops delivers on core functionality, the platform could benefit from more mature AI models for anomaly detection."
"I do not have notes for improvements."
"I chose four out of five because I believe more UI enhancements and a cleaner UX navigation could elevate it to a perfect five."
 

Pricing and Cost Advice

"While Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive and may soon be considered overpriced."
"It isn't cheap, but it's reasonable. It helps us to manage things with very few resources."
"Qualys TotalCloud offers good pricing that is affordable and competitive with the market. Our partnership also provides us with additional benefits."
"Qualys TotalCloud offers competitive pricing given its comprehensive suite of features, including integration, assessment, remediation, and detection capabilities, all within a single platform."
"As a middle management member, I do not have direct pricing knowledge, but based on the knowledge from our meetings, its pricing is competitive."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"Qualys TotalCloud is expensive."
"Qualys TotalCloud offers cost-effective licensing flexibility."
"Vanta is expensive."
Information not available
report
Use our free recommendation engine to learn which Compliance Management solutions are best for your needs.
900,644 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
18%
Financial Services Firm
14%
Construction Company
7%
Comms Service Provider
7%
Computer Software Company
15%
Financial Services Firm
8%
University
8%
Outsourcing Company
8%
Construction Company
42%
Comms Service Provider
10%
Manufacturing Company
9%
Healthcare Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise3
Large Enterprise29
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise3
Large Enterprise1
No data available
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
Areas that need improvement in every solution include the remediation part. The remediation steps should be simple en...
What is your primary use case for Qualys TotalCloud?
Our use case involves the assets that we have under cloud, the assets exposed to the internet, and the internal appli...
What needs improvement with Vanta?
To improve Vanta, I suggest continuing to improve the areas of integration with the HITRUST CSF for R2 assessments. I...
What is your primary use case for Vanta?
My main use case is certification. I used Vanta to establish a HITRUST certification for a telecommunications organiz...
What advice do you have for others considering Vanta?
I would tell others looking into using Vanta to use it for HITRUST E1 and I1 assessments, as the R2 assessments are s...
What is your experience regarding pricing and costs for Xops?
I recommend ensuring you fully understand the pricing tiers and the features included at each level. You should evalu...
What needs improvement with Xops?
I would like to see built-in anomaly detection for trading patterns using machine learning. It would also be helpful ...
What is your primary use case for Xops?
I use X-Ops to monitor and optimize AWS infrastructure costs for our trading workloads. It helps me ensure continuous...
 

Comparisons

 

Also Known As

Qualys TotalCloud with FlexScan
No data available
No data available
 

Overview

 

Sample Customers

Information Not Available
Care Directives, Shortcut , Nayya, Heizenrader, Treasury Prime
Information Not Available
Find out what your peers are saying about Vanta vs. Xops and other solutions. Updated: April 2026.
900,644 professionals have used our research since 2012.