We use Qualys VMDR for vulnerability management and operations, such as scanning assets to identify vulnerabilities and updating the reports for different teams.
System Engineer at a financial services firm with 1-10 employees
Enhanced vulnerability detection and scanning with valuable asset management options
Pros and Cons
- "Authenticated scans provide different options, including those using or not using the FactSet and adding option profiles."
- "It would be helpful to have features for better tracking, including options for adding relevant owners or supporting groups for each asset."
What is our primary use case?
How has it helped my organization?
We identified and resolved many vulnerabilities by using Qualys VMDR. It has been helpful in detecting externally facing asset vulnerabilities and coordinating patching or remediation with different teams.
What is most valuable?
I find the scans portion of VMDR to be valuable. Authenticated scans provide different options, including those using or not using the FactSet and adding option profiles. Another good feature is the Knowledge Base, which provides detailed information on vulnerabilities, period scores, solutions, issues, and mitigation.
What needs improvement?
I'd suggest improvements in asset management. It would be helpful to have features for better tracking, including options for adding relevant owners or supporting groups for each asset.
Buyer's Guide
Qualys Exposure Management
July 2026
Learn what your peers think about Qualys Exposure Management. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,563 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Qualys VMDR for about three years.
What do I think about the stability of the solution?
The solution is stable. I would rate it eight out of ten.
What do I think about the scalability of the solution?
Scalability is rated at 7.5 out of ten.
How are customer service and support?
When you raise a report, it will be generated in VMDR and shared with the respective team. Depending on client requests, reports can be in PDF or Excel format.
Which solution did I use previously and why did I switch?
I did not use any previous vulnerability solutions; I started directly with Qualys.
How was the initial setup?
The setup for Qualys VMDR is easy since it's a cloud tool. Access is provided through different inboxes, and deployment is straightforward.
What's my experience with pricing, setup cost, and licensing?
I am not aware of the actual cost or pricing as it is managed by the client.
Which other solutions did I evaluate?
Compared to other solutions like Nexus, Qualys provides more options and is a better tool.
What other advice do I have?
I recommend using Qualys as it offers many valuable features and options. It is better compared to solutions like Nexus.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Qualys Exposure Management Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Product Categories
Vulnerability Management IT Asset Management Configuration Management Databases Container Security Risk-Based Vulnerability ManagementPopular Comparisons
Check Point Cloud Firewall (formerly CloudGuard Network Security)
SentinelOne Singularity Cloud Security
Qualys TotalCloud
ServiceNow
Microsoft Defender for Cloud
Checkmarx One
Prisma Cloud by Palo Alto Networks
Zafran Security
TrendAI Vision One – Cloud Security
Orca Security
Buyer's Guide
Download our free Qualys Exposure Management Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Qualys VM vs Tenable Nessus: Comparison
- How does Tenable Nessus compare with Qualys VM?
- How does Pentera compare with Qualys VMDR?
- What are the main differences between Qualys VMDR and Tenable Nessus?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?
















