The primary use cases of this solution are as a scanner. We use it with Azure and AWS. For on-premises, we use physical scanners all over the globe. We have deployed our external scanners in approximately 70 regions.
Enterprise Security Architect at a energy/utilities company with 10,001+ employees
Vulnerability scanner with good dashboard presentation and clear reporting
Pros and Cons
- "What I like about Qualys VM is the dashboard presentation. It's very good."
- "If you are comparing Nexpose and Qualys, I would prefer Qualys."
- "The customer support is very bad."
- "The customer support is very bad; when we submit a ticket, we do not get a response immediately."
What is our primary use case?
What is most valuable?
What I like about Qualys VM is the dashboard presentation. It's very good.
The reporting capability and executive reporting are very good.
What needs improvement?
Customer support needs to be improved because it was not to our SLA standards.
Suddenly, the scan engine will go down. We don't know what the reason is, or how it goes down. Because of that, the business is impacted.
I had a look at the PCI reports (policy compliance reports) and I have heard that most memberships have been taken by Azure, although I was not aware of that. I would like to see more documentation or awareness.
For how long have I used the solution?
I have worked with Qualys VM for the last two years.
Buyer's Guide
Qualys Exposure Management
July 2026
Learn what your peers think about Qualys Exposure Management. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,563 professionals have used our research since 2012.
What do I think about the stability of the solution?
This solution is stable.
What do I think about the scalability of the solution?
The scalability is good.
How are customer service and support?
The customer support is very bad. When we submit a ticket, we do not get a response immediately.
Which solution did I use previously and why did I switch?
Previously, I have used Rapid 7 Nexpose. They are similar solutions although what Qualys is providing, it provides well but requires less. Qualys reporting is better.
Nexpose has upgraded too, and now their reporting is also very good.
How was the initial setup?
The initial setup was straightforward and we didn't have any issues with it.
What other advice do I have?
If you are comparing Nexpose and Qualys, I would prefer Qualys. The UI is good and whatever reports you are getting, are very clear. If you present it to management, the reports are good. They require an executive report that highlights the vulnerability and how many servers are affected. You can customize it also.
Nexpose is coming out with new features, but Qualys has already implemented them.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Solutions Architect at a tech services company with 10,001+ employees
A lightweight solution with good reporting, but multi-cloud support should be improved
Pros and Cons
- "The most valuable feature is that this solution is very lightweight."
- "I would like to see this solution simplified to work more easily in a multi-cloud environment."
What is our primary use case?
We are a solution provider and this is one of the products that we implement for our clients. We do a lot of work with containers. With respect to containerization, security is important for us and we regularly check the market to see what solutions are available in these areas.
This solution is primarily used for container security and compliance. Moving into any environment, in particular, one that is cloud-based, our clients want to make sure that things are okay from a compliance perspective. We generate reports and they can see whether there are any violations. If they see violations or security breaches during the audit then they have to be addressed.
What is most valuable?
The most valuable feature is that this solution is very lightweight.
What needs improvement?
I would like to see this solution simplified to work more easily in a multi-cloud environment. One of our customers has more than 3,000 servers across multiple regions, and they were asking about security and vulnerability checking in an automated fashion. This could be done with a cloud-based service that monitors all of the deployments, pulls the data from the containers, and checks for compliance.
For how long have I used the solution?
We have been dealing with Qualys for at least three years, which is when our container journey began. At that point, our proposals did not deal with security for containers because our customers did not ask for it, but now it is something that we recommend.
How are customer service and technical support?
The technical support for this solution is good. We are required to solve any kind of security issue whin two hours, so these are critical tickets. The entire instance usually has to come down until the fix is delivered.
Which other solutions did I evaluate?
We often demonstrate these types of tools to the enterprise architecture team, who will ultimately decide which solutions they are going to implement based on their environment and requirements.
We are completely agnostic with respect to which tools our customers decide to implement. As an engineering team, we implement what the customer wants. In the case of Qualys and other solutions, we download the information and pass it along to our customers. We also facilitate or set up communication between vendors and customers to best help our clients.
We do try to learn about who the providers are and what differentiates their solutions from others. Sometimes our customers do not know very much about the products, so we try to provide as much insight as possible to facilitate their decision making.
What other advice do I have?
A lot of our customers have a workload that is scattered across a multi-cloud environment. This means that some of the RFPs we answer are based on very large landscapes with distributed workloads.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Qualys Exposure Management
July 2026
Learn what your peers think about Qualys Exposure Management. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,563 professionals have used our research since 2012.
Sr. Manager, Vulnerability Management at a transportation company with 10,001+ employees
Assists us with vulnerability management and policy compliance across our network
Pros and Cons
- "The most valuable features are vulnerability detection and the scanning capability to enable identification of vulnerabilities across our network."
- "It's been the chosen solution year after year for vulnerability management and our vulnerability management program is centered around this tool."
- "I would like to see this solution more developed and competitive in the Cloud space."
What is our primary use case?
Our primary uses for this solution are security vulnerability detection and policy compliance.
How has it helped my organization?
It's been the chosen solution year after year for vulnerability management and our vulnerability management program is centered around this tool.
What is most valuable?
The most valuable features are vulnerability detection and the scanning capability to enable identification of vulnerabilities across our network.
What needs improvement?
I would like to see this solution more developed and competitive in the Cloud space.
For how long have I used the solution?
We have been using Qualys VM for fifteen years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technology Security Expert at T-Mobile Polska (Deutsche Telekom)
Identifies and helps to remedy vulnerabilities, has good certificate management
Pros and Cons
- "The most valuable feature is the certificate management."
- "This solution has provided information about existing vulnerabilities, and helped with quick remediation in case of global malware attacks."
- "The reporting in this solution can be improved."
What is our primary use case?
Our primary use case is vulnerability assessment.
How has it helped my organization?
This solution has provided information about existing vulnerabilities, and helped with quick remediation in case of global malware attacks.
What is most valuable?
The most valuable feature is the certificate management. The reason is the limited license provided by the mother company.
What needs improvement?
The reporting in this solution can be improved.
For how long have I used the solution?
I have been using this solution for five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Executive Officer at a consultancy with 1-10 employees
An excellent solution for vulnerability management that's highly scalable and very stable
Pros and Cons
- "Technical support is fantastic."
- "The way we can maintain a current actual registry of all the IP assets within it is very good."
- "It's quite complex on the way it is set up, so it takes a fair bit of time in order to get your head around it in order to deploy it. Once you've deployed it, then you're never confident on the versions of the browsers and the SSL certificates, etc. You have to always go back into Qualys and check."
What is our primary use case?
The primary use for the solution is vulnerability management.
What is most valuable?
The way we can maintain a current actual registry of all the IP assets within it is very good. The scanning of software assets on the endpoint machine is also useful. I've tried the scanning of similar asset vulnerabilities throughout different servers, including Unix and Windows. Qualys maintains a good intervention database. We have a service line that updates to the newest software, or whenever you set it up. The second service line has denominated my nodes across the globe. It's easy to deploy the solution.
What needs improvement?
The server application scanning has room for improvement.
It's quite complex on the way it is set up, so it takes a fair bit of time in order to get your head around it in order to deploy it. Once you've deployed it, then you're never confident on the versions of the browsers and the SSL certificates, etc. You have to always go back into Qualys and check.
They do talk about an agent-based scanning for non-IP machines. It sort of sits between server scanning and endpoint scanning. That's not very clear. If they can improve that and deploy, then it'll be such a nice package.
The solution should help its vendors more with renewals. For example, we had deployed the solution as a reseller to a client and then somebody else came along and we didn't end up getting the renewal licenses for the servers. I wasn't very happy about that. We put all the hard work to get it in, but the following years we didn't get the benefit of our low pricing in the first year.
They should integrate with the dashboard and provide a plugins link for data that's coming into API on the dashboard. When the users buy the license, they can turn it items on. So, that way you know you've got the full solution. What you don't pay for is not switched on, and what you pay for can get switched on immediately.
For how long have I used the solution?
I've been using the solution for since 2005.
What do I think about the stability of the solution?
The solution is very stable.
What do I think about the scalability of the solution?
The solution is highly scalable.
How are customer service and technical support?
Technical support is fantastic.
What other advice do I have?
I would advise others to always have a proof of concept version of the solution put into play. Then spend a good two months on it. Stabilize the solution and check out the features and then deploy it into production. Otherwise, you will spend money during the real project for what could have been done as a POC. Deploy the core solution, get the scanning done and all the critical components put it in a proof of concept and then move it into production.
I would rate the solution eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
Information Security Officer at Zamil
Threat detection tells us which machines are infected with a vulnerability
Pros and Cons
- "They also have threat detection which maps threats. There is a feed that comes from Qualys when a new vulnerability is found. It tells us which machines are infected with that vulnerability."
- "I would recommend Qualys because it's very easy to use."
- "What we have found is that the solution is not closely tied with the patch management. It is okay with newer ones, like Windows 10 machines; it gives the correct patch. But for Windows 7 or Windows Server 2008, it does not give us the correct patch so we have to manually identify the patches. This is a major problem."
What is most valuable?
The first thing we like is the scanner, the device which checks vulnerability management.
They also have threat detection which maps threats. There is a feed that comes from Qualys when a new vulnerability is found. It tells us which machines are infected with that vulnerability. If there is a new attack, we definitely know that it is happening, what is happening in our environment.
What needs improvement?
What we have found is that the solution is not closely tied with the patch management. It is okay with newer ones, like Windows 10 machines; it gives the correct patch. But for Windows 7 or Windows Server 2008, it does not give us the correct patch so we have to manually identify the patches. This is a major problem.
For how long have I used the solution?
This is the third year we are using Qualys. This year we included one more module, the patching module.
What do I think about the stability of the solution?
It's stable. Every month we scan more than 5,000 IP addresses and we are able to detect vulnerabilities.
How are customer service and technical support?
Our experience is that the problems we send them take too much time to resolve. For example, we opened a case for the problem I mentioned earlier, the vulnerabilities with Windows 7 and Server 2008 where it's trying the wrong patch. It took them a long time to even give us the correct explanation. So this is a problem.
How was the initial setup?
The initial setup was very easy. We just needed to download the virtual machine. There is a key and we just needed to provide a proxy setting. That's it.
We did all the configuration as a one-time job where we defined our subnet and mapped. We needed to schedule the scan and the map and we needed to schedule a group of, say, Windows. It was just a one-time job where needed to configure the query and run it. It created a report and sent it to the administrators. After that one-time job, everything happens automatically.
What about the implementation team?
We did it on our own.
What other advice do I have?
I would recommend Qualys because it's very easy to use. It does not require many specific skills. We are always on the latest version because Qualys provides automatic updates.
We have a virtual appliance in each site and that sends the logs to the cloud. We have the consoles on the cloud which enable us to query and scan. All this happens through the cloud.
We only have one administrator for the solution who monitors and checks if there is anything to be aware of. It sends the reports to all the different administrators, such as network, Linux, and Windows administrators and they take it from there.
We also have Qualys configuration management module. If there are any particular issues in any servers or in any network, it gives us a report to suggest and rectify the issues. It tells us what changes are needed to on that device.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Technology Analyst at Tata Consultancy Services
Patch supersedence has been an invaluable feature
Pros and Cons
- "Patch supersedence."
- "Representation of the total number of vulnerabilities (with name) vs. the number of patches (with name)."
What is our primary use case?
Datacenters which are in different locations.
How has it helped my organization?
- Asset discovery
- Asset sanitization
- Scan scheduling
- Patch supersedence.
What is most valuable?
Patch supersedence.
What needs improvement?
Representation of the total number of vulnerabilities (with name) vs. the number of patches (with name).
For how long have I used the solution?
One to three years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Works at Tata Consultancy Services
Generated more complete coverage of assets and saved time
Pros and Cons
- "Using the policy compliance module allowed this to be automated and saved time as well as generated more complete coverage of assets leading to greater assurance."
- "Expanding the template library would be very useful."
What is our primary use case?
The primary use case is using this as the infrastructure scanner for an enterprise vulnerability programme in a customer organization.
How has it helped my organization?
The customer was manually testing asset health by point-in-time audits. Using the policy compliance module allowed this to be automated and saved time as well as generated more complete coverage of assets leading to greater assurance.
What is most valuable?
The prebuilt CIS templates are very useful.
What needs improvement?
Expanding the template library would be very useful.
For how long have I used the solution?
Three to five years.
Disclosure: My company has a business relationship with this vendor other than being a customer. My company is a service provider that installs and operates solutions for customers.
Senior Information Security Engineer at a financial services firm with 501-1,000 employees
It is a stable product. Tech support is quick to respond to any inquiries.
Pros and Cons
- "Tech support is helpful."
- "There are fewer false positives when using this solution, and we are also cutting the need for news monitoring with this solution."
- "I do not like that all of the data is stored on the cloud."
What is our primary use case?
It mainly scans the model against all of our online websites.
How has it helped my organization?
There are fewer false positives when using this solution. We are also cutting the need for news monitoring with this solution.
What is most valuable?
We find all of the features useful.
What needs improvement?
One note for room for improvement is that all of the data is stored on the cloud. I think it would be better if they came up with a big box that could store the data and collect data from, it would be a huge improvement.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
It is an extremely impressive and stable product. I would give it a 99% out of 100%. It is very close to being perfect.
What do I think about the scalability of the solution?
I have had no issues with scalability. Initially, we had some issues with the dashboard, but eventually, it set and stabilized. There was an issue with the data dashing between the two models initially, but it was resolved.
How is customer service and technical support?
The tech support is helpful. When we initially open a ticket, we get response within five minutes. Then, they open a case and we receive input from tech support within 24-48 hours with a Q-ID.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Specialist at a manufacturing company with 10,001+ employees
This solution helps us fill out forms in a timely manner. It is more expensive than competitive products.
Pros and Cons
- "It is quite easy to implement."
- "I find most valuable to achieve a channel system and we can also use it to track when we actually close the ticketing of the sites, and in addition, it is quite easy to implement."
- "When you want to cover yourself for scalability, you will be charged for the number you place on the scan itself."
- "It is more expensive vs. other products on the market."
What is our primary use case?
My primary use case is to actually fill out forms, ensure that they are being closed in a timely manner. This is why we use these one point solutions.
What is most valuable?
I find most valuable to achieve a channel system and we can also use it to track when we actually close the ticketing of the sites.
In addition, it is quite easy to implement. We found it quite convenient.
What needs improvement?
I think it could improve asset imagery.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
I have not encountered issues with stability of the product.
What do I think about the scalability of the solution?
I have not encountered any issues of scalability function. We do have to pay extra according to the number we are placing on the scan. So, when you want to be covered for the scalability, you will have to pay more.
How was the initial setup?
The initial setup was straightforward. It was quite simple. We just needed to download the image from the website, and onto our service team.
What's my experience with pricing, setup cost, and licensing?
Qualys is considered more expensive versus other products on the market.
Which other solutions did I evaluate?
We were previously using McAfee. We had to switch because McAfee stopped producing the solution we needed. We considered Tenable Nessus, but we chose Qualys in the end.
What other advice do I have?
I advise that you see if this solution can fit your problems, and help your needs.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Qualys Exposure Management Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Product Categories
Vulnerability Management IT Asset Management Configuration Management Databases Container Security Risk-Based Vulnerability ManagementPopular Comparisons
Check Point Cloud Firewall (formerly CloudGuard Network Security)
SentinelOne Singularity Cloud Security
Qualys TotalCloud
ServiceNow
Microsoft Defender for Cloud
Checkmarx One
Prisma Cloud by Palo Alto Networks
Zafran Security
TrendAI Vision One – Cloud Security
Orca Security
Buyer's Guide
Download our free Qualys Exposure Management Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Qualys VM vs Tenable Nessus: Comparison
- How does Tenable Nessus compare with Qualys VM?
- How does Pentera compare with Qualys VMDR?
- What are the main differences between Qualys VMDR and Tenable Nessus?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?



















Publish!? Or