We have been using Qualys Patch Management alongside vulnerability management. We utilize it to manage high and critical vulnerabilities by prioritizing patches based on asset value and vulnerability score. We rate our asset with an asset value. Along with that, once we have a vulnerability score, we prioritize patches and servers that are high and critical. That is how we utilize both vulnerability management and patch management.
Security Portfolio Manager at a tech vendor with 10,001+ employees
Comprehensive dashboard makes it easy to apply patches and monitor pending updates
Pros and Cons
- "We have all the information on one page. The dashboard provides comprehensive information on one page, making it easy to apply patches and monitor pending updates."
- "Overall, I would rate Qualys Patch Management a nine out of ten."
- "It is pretty good. However, it would be good to have more widgets and AI-generated reports. I have not seen anything related to AI with Qualys. It would be beneficial for Qualys to incorporate AI-generated tools for Patch Management and VMDR. This could assist in managing risks, providing AI-generated reports, and creating risk letters for clients, which can streamline communication."
- "However, it would be good to have more widgets and AI-generated reports. I have not seen anything related to AI with Qualys."
What is our primary use case?
How has it helped my organization?
The risk-based approach provides a better way of patching. It helps identify criticalities based on asset value, enhancing decision-making.
Qualys Patch Management has helped us reduce the overall risk in our environment by integrating with vulnerability management and VMDR, allowing us to address risks based on asset value and risk levels. It is important for us that it is integrated with VMDR so that we are aware of the vulnerabilities in our system and can apply patches as per the associated risk, asset value, and threat to the environment. It is very important to integrate these tools. It helps reduce vulnerabilities through diligent patch application and improves overall efficiency.
TruRisk score is helpful for us, but we still have to ensure the security team is involved in the governance process to ensure that we are taking care of the entire environment. We include the security team on the governance side but the implementation and the activity can be done without them.
There has been an improvement in our patch rate. The efficiency in our environment increased by 30% over three years, compared to the tool we used previously. The duration of patching decreased in the environment.
The Risk Reduction Recommendation Report is good. It gives an overview of what can be remediated soon. It gives a good understanding of which patch can remediate the majority of the risks in the environment. It helps us see which vulnerabilities would reduce the most risk within our organization.
What is most valuable?
We have all the information on one page. The dashboard provides comprehensive information on one page, making it easy to apply patches and monitor pending updates. It helps a lot from the governance point of view to see what exactly is missing and what exactly has been applied.
What needs improvement?
They have already covered most of the things. I do not see a lot of opportunities for improvement. It is pretty good. However, it would be good to have more widgets and AI-generated reports. I have not seen anything related to AI with Qualys. It would be beneficial for Qualys to incorporate AI-generated tools for Patch Management and VMDR. This could assist in managing risks, providing AI-generated reports, and creating risk letters for clients, which can streamline communication.
Buyer's Guide
Qualys Patch Management
January 2026
Learn what your peers think about Qualys Patch Management. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Qualys Patch Management for more than three years.
What do I think about the stability of the solution?
We did not encounter any significant stability issues, except during a notified period when they were transitioning to another cloud vendor or fixing an issue.
How are customer service and support?
Customer service is responsive and effective. They are pretty fast. They generally respond to inquiries and provide a resolution within a couple of hours. So far, I have not seen a case where the resolution was not provided within 48 hours.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used BigFix. We switched to Qualys because BigFix moved from IBM to HCL, and we wanted a tool certified for PCI compliance. Qualys is PCI compliant.
How was the initial setup?
We have a hybrid deployment model. It was an easy process because we knew what we needed to configure the firewall rules and ports. The documentation and other information was provided by the Qualys partner. It did not take us a long time to get it deployed and test it out. We did a PoC, and everything worked fine.
Overall, the setup process was straightforward, and with good documentation and support, we deployed it within our change management framework in about two weeks.
It does not require any maintenance, but we need to ensure that we get rid of the licenses when not required or request licenses when we have more devices planned to be onboarded. That is something we need to look into. When we do not have a device or we do not need a scanner in a particular location, we can get rid of it, so from a maintenance point of view, there is not much.
What about the implementation team?
This deployment also involved integration with vulnerability management. We had a project manager coordinating efforts with the vendor, a documentation coordinator, and a team to handle change management and firewall configurations. Overall, we had three people. Effort-wise, it did not require a lot. They had to coordinate a couple of times for two to three hours.
What's my experience with pricing, setup cost, and licensing?
Its price is competitive in the market. Compared to other solutions like Rapid7, Qualys offers a favorable price point and robust features.
What other advice do I have?
Overall, I would rate Qualys Patch Management a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Engineer at a consultancy with 10,001+ employees
Streamlines vulnerability remediation with VMDR integration
Pros and Cons
- "Patch Management offers pre-action and post-action features, which provide the ability to execute scripts during the installation or uninstallation of software. This helps me make changes from Qualys itself."
- "We have seen about 60% to 70% improvement in the patch rate so far."
- "They should focus on increasing the list of supported patches. New software or data is continuously released, and it would be beneficial if patches were updated in the knowledge base more quickly."
- "Not all patches are supported, so there are some restrictions. Some remediations require script-level changes which Qualys does not support."
What is our primary use case?
We primarily use Patch Management in our organization for remediating vulnerabilities for which patches are supported by Qualys.
How has it helped my organization?
There is a zero-touch mechanism in Qualys for patch management. For example, if we have a product for which frequent patches are released, we do not have to manually initiate a patch. It can be initiated automatically when a new patch is available.
The integration between Qualys VMDR and Patch Management allows us to monitor job statuses and ensures timely remediation. Previously, we had only the VMDR solution from Qualys. For remediation, we had to go to a different solution. There was a delay in the syncing process. With the integration of Qualys VMDR and Patch Management, we have more real-time and comprehensive data. We can see information about the status of the job and other things in a single console. We have a faster view of the remediation effort.
We also have the ability to view and select patches based on the assets. There might be hundreds of patches available in the knowledge base. It gives us patches available only for the selected assets. This saves time and reduces risk.
For vulnerability management, Qualys serves as a single source of truth, but for patch management, we have to use some more tools because Qualys does not support certain scenarios.
We have seen about 60% to 70% improvement in the patch rate so far. It has reduced the organization's risk.
What is most valuable?
Patch Management offers pre-action and post-action features, which provide the ability to execute scripts during the installation or uninstallation of software. This helps me make changes from Qualys itself.
What needs improvement?
Not all patches are supported, so there are some restrictions. Some remediations require script-level changes which Qualys does not support. We have to manually create those scripts.
They should focus on increasing the list of supported patches. New software or data is continuously released, and it would be beneficial if patches were updated in the knowledge base more quickly. Sometimes, there are delays of three to four days, which should be addressed.
For how long have I used the solution?
I have been using Qualys Patch Management for more than one and a half years.
What do I think about the stability of the solution?
I would rate the stability a nine out of ten. Occasionally, I need to change patches for certain software like Google Chrome, but overall, it is stable.
What do I think about the scalability of the solution?
The scalability is good. It handles the requirements effectively.
We are using it at multiple locations. We have about 300k users.
How are customer service and support?
I would rate their customer support a nine out of ten. Although there can be some delays, overall, the support is satisfactory.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used a different patch management solution previously. We switched to Qualys because it integrates seamlessly with VMDR, which makes it easier to manage vulnerabilities and patching in a single console.
How was the initial setup?
The initial setup was easy. We had already deployed the agent. It involved selecting the asset and enabling the module.
It does not require any maintenance from our side. It is a SaaS platform. Everything is handled by Qualys.
What other advice do I have?
I would recommend Qualys Patch Management if you are integrating it with VMDR. If you are using a different solution for vulnerability management and considering Qualys solely for patch management, it might not be the best choice.
I would rate Qualys Patch Management a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Qualys Patch Management
January 2026
Learn what your peers think about Qualys Patch Management. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
Manager Information Security at a consultancy with 10,001+ employees
Remediated nearly 25 million vulnerabilities within our organization, significantly reducing our overall vulnerability count
Pros and Cons
- "Qualys Patch Management offers excellent features, most notably the Qualys Gateway Service, which caches patches and distributes them to agents, minimizing bandwidth consumption."
- "Qualys Patch Management has reduced our organizational risk by 99.9 percent."
- "One area for improvement in Qualys Patch Management is knowing whether patches have been completely downloaded in a particular QGS appliance."
- "One area for improvement in Qualys Patch Management is knowing whether patches have been completely downloaded in a particular QGS appliance."
What is our primary use case?
We primarily use Qualys Patch Management for deploying Microsoft's monthly security updates, released every second Tuesday. To mitigate vulnerabilities, we promptly create patch jobs for all endpoints and servers upon release and inform stakeholders of the urgent need for deployment. We adhere to strict SLAs, ensuring the entire patch cycle is completed within one to two weeks.
We implemented Qualys Patch Management to efficiently patch our endpoints, and servers.
How has it helped my organization?
Qualys' risk-based approach to automation is helpful for addressing vulnerabilities. We utilize TruRisk management for a comprehensive risk overview, employing a tag-based system to assign criticality scores. This allows us to prioritize patching through Qualys Vulnerability Management, Detection, and Response based on the severity of risks.
The integration of Qualys Patch Management and VMDR is critical for automating the deployment of relevant patches and configurations to remediate vulnerabilities. Within our organization's 343,000 assets, multiple entities and tags allow us to leverage VMDR to identify critical vulnerabilities and prioritize patching for high-value machines. This integration enables us to proactively push patches to all server and endpoint agents, effectively mitigating vulnerabilities.
The implementation of Qualys Patch Management has resulted in the remediation of nearly 25 million vulnerabilities within our organization, significantly reducing our overall vulnerability count.
TruRisk automation allows us to address vulnerabilities without involving our security team, as we can directly assess their criticality levels.
Qualys Patch Management provides a single source of truth for managing assets and vulnerabilities, enabling assessment, prioritization, and remediation. Its comprehensive view of each asset streamlines collaboration between security and IT teams, facilitating efficient vulnerability management.
The single source of truth helped reduce costs by 95 percent.
We have improved our patch rate to over 86 percent by implementing Qualys Patch Management. Previously, patches were managed through both Microsoft Intune and SCCM, which proved less effective.
The risk reduction report allows us to split the remediation based on criticality.
The risk reduction report provides recommendations on how to remediate vulnerabilities. Once a fix is available, the corresponding patch can be deployed to all assets based on the associated CVE identifier.
Qualys Patch Management has reduced our organizational risk by 99.9 percent.
What is most valuable?
Qualys Patch Management offers excellent features, most notably the Qualys Gateway Service, which caches patches and distributes them to agents, minimizing bandwidth consumption. The platform provides comprehensive visibility into patch status across endpoints and servers, supporting Linux and macOS in addition to Windows. Qualys has been instrumental in our vulnerability remediation efforts, enabling us to address nearly 25 million vulnerabilities.
What needs improvement?
One area for improvement in Qualys Patch Management is knowing whether patches have been completely downloaded in a particular QGS appliance. If a platform owner could verify that patches are downloaded on the appliance side, it would be possible to push them through to all agents confidently.
For how long have I used the solution?
I have been using the Patch Management solution for more than four years.
What do I think about the stability of the solution?
We did not encounter any significant stability issues. Control level issues can arise, but these can be addressed through support cases.
What do I think about the scalability of the solution?
I rate the scalability of Qualys Patch Management ten out of ten.
How are customer service and support?
I am completely satisfied with Qualys' customer service.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We are using SCCM and Intune, but they are not able to achieve the same Qualys patch percentages.
How was the initial setup?
The initial setup was straightforward. Since Patch Management is not a separate module, it is integrated with the overall Qualys deployment, allowing us to enable licenses for VMDR and PM automatically.
To deploy on one machine it takes ten minutes.
What about the implementation team?
To begin, we'll deploy the Qualys agent using an external tool on a separate system. Once the agent appears in the Qualys console, we can proceed by differentiating tags, assigning activation keys, verifying reported machines, and creating multiple vulnerability-based jobs.
What was our ROI?
We have achieved significant time savings of 90 percent, primarily due to comprehensive oversight and visibility of security issues. This streamlined approach reduces time spent addressing vulnerabilities and ensures efficient mitigation of any threats. Consequently, our robust security posture remains uncompromised, yielding substantial benefits.
What's my experience with pricing, setup cost, and licensing?
Qualys Patch Management is a cost-effective solution for managing our 43,000-plus assets. Its efficiency and effectiveness in vulnerability remediation justify the associated expenses.
What other advice do I have?
I would rate Qualys Patch Management ten out of ten.
To enhance visibility, we will utilize the TruRisk features more effectively in the future.
Our organization has 342,000 assets and over 150 people with access to Qualys, which is deployed across the entire organization.
No maintenance is required from our end.
I recommend Qualys Patch Management due to its comprehensive features. It saves time and provides significant tools for identifying vulnerabilities, pushing patches, and providing pre and post-action capabilities. Virtual patching is available to mitigate many vulnerabilities.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Senior Information Security Analyst at a tech vendor with 1,001-5,000 employees
Has enabled me to patch Windows workstations from detection to remediation in one place
Pros and Cons
- "Qualys Patch Management gives me a single source of truth for assets and vulnerabilities that need to be assessed, prioritized, and remediated."
- "I find the stability of Qualys Patch Management to be inconsistent; sometimes it works fine, while other times when I try to show a colleague something quickly, it takes considerable time to respond."
What is our primary use case?
My use cases for Qualys Patch Management are primarily for Windows workstations.
What is most valuable?
My favorite feature of Qualys Patch Management is being able to go from detection to patching in a single platform.
Qualys Patch Management helps me remediate vulnerabilities without needing to involve the security team because I am the security team. It helps me get context of what's going on.
What needs improvement?
One downside is that I've always wanted a dark mode in Qualys Patch Management. Because Qualys is so bright, if you're working in there for a while, you feel blind after extended time. Having a dark mode would be fantastic.
For how long have I used the solution?
I have been using Qualys Patch Management since the end of 2023.
What do I think about the stability of the solution?
I find the stability of Qualys Patch Management to be inconsistent; sometimes it works fine, while other times when I try to show a colleague something quickly, it takes considerable time to respond.
What do I think about the scalability of the solution?
The scalability of Qualys Patch Management seems good.
How are customer service and support?
I contact their technical support or customer support frequently.
The quality and speed of their support could be better.
I would rate their support a five out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial deployment of Qualys Patch Management is difficult.
I wasn't involved with the company during the initial deployment, which occurred approximately ten years ago. However, newer modules and connector configurations always seem more difficult than they should be.
What was our ROI?
Regarding pricing for Qualys Patch Management, if you can get a good deal, the value is there. It's on the pricier side, but it provides value if you can utilize it effectively.
Which other solutions did I evaluate?
I have used alternatives such as Tenable.
I prefer Qualys over Tenable.
The biggest difference between Qualys and Tenable is reporting, as the quality of reports from Qualys is much better received than those from Tenable.
What other advice do I have?
I use Qualys Patch Management with VMDR.
This integration with VMDR is important for me.
Qualys Patch Management gives me a single source of truth for assets and vulnerabilities that need to be assessed, prioritized, and remediated.
I use the Risk Reduction Recommendation report in Qualys Patch Management.
The Risk Reduction Recommendation report is helpful.
Qualys Patch Management helps me streamline remediation and gives me a good starting point.
If the risk-based approach to automation is set up correctly, it performs excellently.
For newer deployments of Qualys Patch Management, typically one person handles the implementation.
I maintain Qualys Patch Management consistently, so it requires minimal effort on my end.
My advice for new users of Qualys Patch Management is to spend time at the training center. A streamlined initial video guide would be beneficial.
I rate Qualys Patch Management an eight out of ten overall.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Oct 23, 2025
Flag as inappropriateSr Info security analyst at a tech services company with 51-200 employees
Significantly improves patch coverage and provides the ability to schedule jobs
Pros and Cons
- "Qualys Patch Management has helped reduce our organization's risk by 20%, and we have seen an improvement in our patch rates."
- "For those patches that I have to download for Patch Management, I would prefer if I could upload them to a repository instead of having to download them every time."
What is our primary use case?
Our use case for Qualys Patch Management is patching and updating. We use it for adding and removing local admin to the machines, along with various other tasks.
How has it helped my organization?
Qualys Patch Management helps the IT and security teams work together by enabling the IT team to handle Patch Tuesday and Microsoft patches. With Patch Management, I can monitor when patches have not been applied and help ensure 100% coverage on Patch Tuesday for the desktop team.
Qualys Patch Management has helped reduce our organization's risk by 20%, and we have seen an improvement in our patch rates.
What is most valuable?
The best feature of Qualys Patch Management is the ability to schedule jobs. I have browser updates that run automatically every day to update the three browsers, and I don't have to worry about it.
What needs improvement?
For those patches that I have to download for Patch Management, I would prefer if I could upload them to a repository instead of having to download them every time.
For how long have I used the solution?
I have been using the solution for about eight months.
What do I think about the stability of the solution?
I haven't experienced any bugs, glitches, or downtime, so I would rate Qualys Patch Management a ten out of ten for stability.
What do I think about the scalability of the solution?
For scalability, I would rate it a ten out of ten. We have approximately 8 to 10 users using this solution.
How are customer service and support?
I would rate the vendor support a ten out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We had another patch management solution, but we were using Qualys for VMDR and moved everything into Qualys Patch Management for the simplicity of the user interface and because we had an existing relationship with Qualys. That way we can not only manage our vulnerabilities, but if the vulnerability requires a patch, it's very easy to fix it in Qualys. We were using BigFix for patch management.
How was the initial setup?
The deployment was easy.
The agents self-update, and by using Qualys Cloud, that's all handled by the vendor, so the maintenance aspect requires little to no interaction from our end.
What was our ROI?
It has improved our patch rate by 40%.
What's my experience with pricing, setup cost, and licensing?
Regarding the single source of truth, it really at this juncture has not reduced costs as of yet.
What other advice do I have?
I would recommend this product to other users because it's very user-friendly. I can't speak to the pricing aspect, but from a user standpoint, it's a very good product.
I would rate it a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Oct 18, 2025
Flag as inappropriateSenior Information Security Engineer at a consultancy with 10,001+ employees
Seamlessly integrated vulnerability detection with automated script-based patching
Pros and Cons
- "Qualys Patch Management has significantly reduced our organizational risks."
- "Qualys could improve its randomized download feature and provide more detailed information about patch failures, including the reason for failure."
What is our primary use case?
We use Qualys Patch Management to remediate vulnerabilities. Qualys synchronizes with both the Vulnerability Management, Detection, and Response module and the Patch Management module. This provides a unified view of which vulnerabilities can be patched through Qualys and allows patching to be initiated directly from the VMDR module.
Most Windows security patches are released on Patch Tuesdays and become available to us through Qualys the following day. Once available, we can initiate patching to reduce vulnerabilities within our infrastructure. This process primarily addresses critical security updates from Microsoft and other third-party applications, allowing us to mitigate vulnerabilities using Qualys proactively.
How has it helped my organization?
Qualys Patch Management effectively mitigates risks through its risk-based automation, enabling rapid vulnerability remediation.
The integration of Qualys Patch Management with Qualys VMDR allows us to use the same device identification ID for both patch management and vulnerability identification. This enables us to easily determine which vulnerability a patch addresses, access CVE information, and validate patches based on product or product family. For instance, if we have Google applications with vulnerabilities, we can efficiently identify and patch them without searching for specific versions or missions. By selecting assets in Patch Management, we can automatically patch QID-based or family-based vulnerabilities identified by VMDR. This integration streamlines the patching process and provides clear visibility into the vulnerability status of our assets.
Our previous patch management products had communication issues with their agents. Qualys Patch Management utilizes the same agent as their vulnerability management system, streamlining the process. Security agents are more reliable than standard IT solutions, and because our IT team prioritizes agent uptime, patching is more accessible, and risk is reduced within our infrastructure. Qualys Patch Management offers immediate benefits. If a patch requires a reboot, Qualys allows users to initiate one within a specified timeframe automatically. Upon rebooting, the machine reports to the Qualys console and is automatically scanned. If the patch is successfully installed, the console reflects the update within 20 to 30 minutes. This streamlined process ensures efficient patch management and reduces vulnerabilities.
Qualys Patch Management's TruRisk automation allows us to prioritize patching vulnerabilities with available patches. This prioritization helps us focus on critical vulnerabilities and quickly remediate them, improving our security posture. The TruRisk score provides a clear metric to demonstrate the effectiveness of our remediation efforts to leadership, showing how quickly we address critical vulnerabilities and enhance our security.
TruRisk automation enhances data accuracy across business units. Leveraging the Vulnerability Management Tool for Remediation within TruRisk, patching can be initiated based on a risk score mechanism query, which provides the TruRisk score for a specific business unit. A subsequent query determines patch dispatchability, triggering a patch job if applicable. This process can be streamlined using Patch Query Language to efficiently retrieve data and execute accurate patching, reducing risk based on TruRisk scores.
Initially, the IT team resisted using Qualys Patch Management for vulnerability remediation due to its critical importance. However, after we demonstrated how integrating Patch Management with Vulnerability Management provides a single report and effectively reduces vulnerabilities, we convinced them to adopt it. This consolidated approach enhances efficiency and streamlines patch management throughout our organization.
Qualys Patch Management significantly improved our patching rates. Qualys provides access to exclusive security patches and boasts a comprehensive knowledge base covering a wide range of applications, including third-party software like Google Chrome, Edge browsers, and SQL. As Qualys expands its knowledge base, our patch management rates continue to improve. Furthermore, the Qualys support team has been instrumental in helping us resolve patching issues, such as installation failures, by efficiently identifying the root cause, whether it stemmed from network problems or the Qualys platform itself. With their assistance and the robust Qualys product, we have successfully mitigated these challenges.
Qualys Patch Management has significantly reduced our organizational risks. Previously, when using other solutions, our patch percentage was low, resulting in high risk. Qualys Patch Management, integrated with VMDR, immediately improved our patch percentage. Features like patch initiation, recurring patches, scheduling, and randomized patch downloading have been crucial in mitigating risk, especially for employees working from home with network issues. The randomized download option ensures patches are successfully downloaded even with interruptions, resuming automatically when the network connection is restored. These capabilities ensure Qualys Patch Management effectively reduced our organizational risk by 88 percent.
What is most valuable?
My favorite feature of Qualys Patch Management is its flexibility in executing scripts before and after patching. This is particularly useful for third-party or enterprise applications that require registry modifications to address vulnerabilities. We leverage this functionality to deploy scripts that adjust registry values, effectively patching vulnerabilities and enhancing the security of our machines. The ability to automate these tasks through Qualys Patch Management streamlines our workflow and improves our overall security posture.
What needs improvement?
Qualys could improve its randomized download feature and provide more detailed information about patch failures, including the reason for failure. This could include specifying whether the failure is related to a file download error, network interruption, application crash, or installer error based on the operating system. These enhancements would offer more insights into the patch management process and improve overall functionality.
For how long have I used the solution?
I have been using Qualys Patch Management for the last two years.
What do I think about the stability of the solution?
The stability of Qualys Patch Management is a nine out of ten. While it's generally stable, there have been occasional issues, particularly when new patches for Linux have been introduced.
What do I think about the scalability of the solution?
Qualys Patch Management's scalability is a ten out of ten. It scales efficiently across different machines globally, ensuring patches are deployed smoothly.
How are customer service and support?
Qualys' technical support has been excellent. Their team has effectively resolved various issues, including some that originated within our network.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was straightforward, leveraging the existing vulnerability management tool, which facilitated easy integration of Patch Management.
Deploying software to a single machine takes approximately one minute. However, in an organization with 1,000 machines, a traditional push deployment method could take up to four days to complete.
What other advice do I have?
I would rate Qualys Patch Management ten out of ten. Qualys Patch Management has significantly benefited our security and remediation efforts.
Qualys Patch Management is deployed across multiple locations and time zones in various countries. While most of the IT team has access to view Qualys Patch Management, only a few individuals can initiate patching. Those with view access can assess the patching capabilities and compliance of specific machines, while a limited number of authorized personnel can deploy the patches.
Qualys Patch Management requires minimal maintenance, primarily involving updating the agent software on managed devices.
I would recommend Qualys Patch Management to those using a vulnerability management solution as it helps significantly in reducing risks. It provides various options such as using third-party repositories for patches, which are beneficial for comprehensive patch management.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Senior Information Security Engineer at a consultancy with 10,001+ employees
Allowed us to install agents on all endpoints, enabling automatic patching over the internet
Pros and Cons
- "Automated features streamline patch deployment and ensure compliance, effectively mitigating risks and bolstering organizational security."
- "Qualys Patch Management significantly improved our patch rates by 80 percent, scanning for vulnerabilities every four hours via the Qualys agent."
- "Qualys Patch Management would benefit from enhanced integration to address its current limitations in patching new features."
- "Qualys Patch Management's pricing could be more competitive, as it presents a significant obstacle for many companies who find it unaffordable."
What is our primary use case?
We primarily use Qualys Patch Management for our endpoint machines. This solution automatically pushes patches to all machines, regardless of whether they are connected to the network, and allows them to update and reboot automatically.
How has it helped my organization?
The risk-based approach to automation in Qualys Patch Management helps us meet our strict SLA timelines by prioritizing critical vulnerabilities. Most vulnerabilities can be patched directly through Qualys, although some require additional external component upgrades. While we generally address critical vulnerabilities within the SLA timeframe, occasional delays necessitate quarantining affected systems from the network to mitigate risk. This automated process significantly reduces our overall security risk.
We had a large number of assets, making it challenging to push patches to all machines, especially those off the network. Qualys Patch Management allowed us to install agents on all endpoints, enabling automatic patching over the internet, regardless of network connection. Upon reconnecting to the Infosys network, any missed patches are applied, and the machine is automatically rebooted. This eliminates downtime for endpoints, except servers, and ensures timely vulnerability remediation, significantly reducing complaints and associated risks. We saw the benefits of Qualys Patch Management within a month.
What is most valuable?
Patch Management's integration capabilities are highly valuable, enabling precise targeting and prioritization of vulnerabilities. Automated features streamline patch deployment and ensure compliance, effectively mitigating risks and bolstering organizational security.
Qualys Patch Management serves as a single source of truth for identifying and addressing vulnerabilities in our assets. We utilize this tool extensively for various purposes, including VMDR, CSAM, and our own internal compliance efforts. Additionally, we are anticipating the release of Total AI and plan to integrate it into our workflow once available.
Before implementing Qualys, we lacked a comprehensive inventory view and relied on the support team to manage most machines. With Qualys Patch Management, we established a single source of truth for asset payment requests, providing clarity on server and endpoint counts. This allowed us to accurately assess vulnerabilities through scans and create dashboards for each device. By leveraging this data, we successfully eliminated one million unnecessary fees within six months.
Qualys Patch Management significantly improved our patch rates by 80 percent, scanning for vulnerabilities every four hours via the Qualys agent. Once identified, patches are automatically deployed and await system reboot, with an option to skip the reboot twice. This process effectively addresses most vulnerabilities identified in our call list. However, some vulnerabilities may require additional features or intervention from the project team, potentially involving coaching or further action, which can lead to delays. Despite these exceptions, Qualys Patch Management successfully deploys all required patches.
Our IT support team uses Qualys Patch Management with a configuration management database. Qualys Patch Management has significantly reduced our vulnerability count by enabling faster ticket resolution. This efficiency has allowed us to address vulnerabilities across thousands of machines, drastically reducing the number of vulnerabilities from millions to a manageable level.
Qualys Patch Management has helped reduce our organization's risk by 80 percent.
What needs improvement?
Qualys Patch Management's pricing could be more competitive, as it presents a significant obstacle for many companies who find it unaffordable.
Qualys Patch Management would benefit from enhanced integration to address its current limitations in patching new features.
For how long have I used the solution?
I have been part of the team using Qualys Patch Management for one and a half years.
What do I think about the stability of the solution?
I would rate the stability of Qualys Patch Management nine out of ten.
What do I think about the scalability of the solution?
I would rate the scalability of Qualys Patch Management nine out of ten.
How are customer service and support?
The technical support received from Qualys is excellent. We have a dedicated person to resolve any issues quickly.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial deployment was straightforward and was completed in two to three months.
What about the implementation team?
What was our ROI?
The implementation of Qualys Patch Management has resulted in an eighty percent reduction in vulnerabilities across the organization, which suggests a significant positive ROI.
What's my experience with pricing, setup cost, and licensing?
Qualys Patch Management is expensive.
What other advice do I have?
I would rate Qualys Patch Management nine out of ten.
Our security team is divided into two groups. The IT support team uses Qualys Patch Management to handle automated patching and maintenance. My team addresses issues that cannot be fixed automatically. We handle vulnerabilities that have been pending for a long time, escalating them and seeking remediation. If these issues remain unresolved, we quarantine the affected vulnerabilities.
We have 300 people from my team using Qualys Patch Management.
Maintenance from our end is minimal as we get comprehensive support from the Qualys team. They provide all necessary support, enabling us to effectively manage the solution.
I would recommend Qualys Patch Management, especially considering its integration capabilities and the support it provides in managing and automating patching processes, substantially reducing vulnerabilities and risks.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Senior Security Consultant at a tech consulting company with 11-50 employees
Enables swift patch deployment on a large number of devices and improves confidence in our security
Pros and Cons
- "The features I find most valuable in Qualys Patch Management include the ability to manage registry changes and run scripts both pre and post-patching. We have been able to apply workarounds for zero-day vulnerabilities efficiently."
- "Customer service is exceptional."
- "They need to improve the user-friendliness of identifying how many devices are affected by a particular patch. It is not intuitive, and there should be clearer indicators or buttons to access this information easily."
- "They need to improve the user-friendliness of identifying how many devices are affected by a particular patch."
What is our primary use case?
We are using the Qualys Patch Management and VMDR solution at a client location.
We primarily use Qualys Patch Management for the company's infrastructure. We utilize the core Patch Management module to remediate and manage patches. We mainly use it to address zero-day vulnerabilities and swiftly deploy patches across a large number of devices.
How has it helped my organization?
Whenever Microsoft releases any zero-day vulnerabilities, they provide a workaround. We are able to push that workaround from the Patch Management module. We can push the registry key changes or use the PowerShell script. We push changes to almost 600 devices in ten minutes. It helps us ensure our infrastructure security.
Qualys Patch Management has significantly improved our visibility into vulnerability remediation and patch severity. The solution has enabled us to remediate a large number of vulnerabilities and reduce our attack surface effectively.
We can track live updates and present dashboards to management, which has increased their confidence in our security posture. We can see the progress while pushing the patches. We have VMDR dashboards and reports. The reports are user-friendly, and everyone can understand these reports. We could also present them to the management. They were also happy to see the progress. They had visibility.
We have not implemented much automation. We are still in the early stages of this solution and testing out the possibilities. We had an issue because of the requirement that every server should be connected to the Internet before downloading the patches, but QGS was very helpful with that. QGS helps to ensure that we are able to patch devices that are not connected to the Internet.
We are able to prioritize the vulnerabilities and remediation. We did not see any discrepancies. With some of the other tools I have used, I have seen so many discrepancies between the vulnerability and the patching.
It helped our teams to work together. We created a separate team for vulnerability remediation. We also could help the patching team and support them in automating patch management. Previously, they were doing it manually on each server.
With Qualys Patch Management, there is an increase in vulnerability remediation. We have remediated almost 100,000 vulnerabilities. That is a huge count. Previously, we used a formula to identify critical vulnerabilities, and we could remediate only a limited number of vulnerabilities. With Qualys Patch Management, we could remediate all the vulnerabilities. We did not exclude any of the vulnerabilities.
There is also an increase in the patch rate. Previously, we could only cover 30% patching, whereas with Qualys Patch Management, within one and a half months, we could achieve 70% to 80% patching. The remaining ones are not included in the initial phase because of certain dependencies. We pushed data to almost 2,000 devices. It took some time for us to do the testing. We tested on ten production devices. After that, we pushed the patches to other devices.
We can download reports and customize the report templates based on the information we need. Our management could clearly see where we are now as compared to before. They could see our progress. They could see that we have fixed all high-priority ones within a month. The remaining ones are of medium and low priority. Even if we do not remediate them, it will be fine.
The Risk Reduction Recommendation Report helped us see which vulnerabilities would reduce the most risk within our organization.
What is most valuable?
The features I find most valuable in Qualys Patch Management include the ability to manage registry changes and run scripts both pre and post-patching. We have been able to apply workarounds for zero-day vulnerabilities efficiently.
Being able to create patch groups based on QIDs is also valuable. We can identify vulnerabilities using the QID and create a patch group. After that, we can push the patches.
What needs improvement?
They need to improve the user-friendliness of identifying how many devices are affected by a particular patch. It is not intuitive, and there should be clearer indicators or buttons to access this information easily. Currently, we have to go to the Patch Management module within an asset to see the information but not many people are aware of it. It is not intuitive in terms of seeing how many patches are pending on an asset. Other than that, it has everything we need.
For how long have I used the solution?
I have been using Qualys Patch Management for approximately one year.
What do I think about the stability of the solution?
We faced an issue once due to a cloud-related problem that slowed down the console and presented device status inconsistencies, but it was resolved within four hours.
What do I think about the scalability of the solution?
We have not encountered any scalability issues. We operate across multiple locations and have not faced any lags.
We have almost 125,000 users. We are a multinational company. We have offices in about 15 states in India. We are also in two or three other countries. This is why our asset count is high.
How are customer service and support?
Customer service is exceptional. The support team is experienced and responsive, providing solutions quickly without delay. I would rate them a ten out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before Qualys, we used Microsoft SCCM, which was not effective in progress tracking and vulnerability remediation. The tool was basic, the licensing cost was high, and we were only able to address 30% to 40% of vulnerabilities.
We proposed the Qualys Patch Management module. Its cost was almost similar but we got many more features. After implementing it, we could see the progress in vulnerability remediation and patching.
Qualys Patch Management also provided us with a variety of dashboards or criteria. We could see the number of patches done, pending, and failed. Microsoft SCCM did not give us that information. We could also export reports with Qualys Patch Management. This option was not available with Microsoft SCCM.
In terms of user-friendliness, Microsoft SCCM is more user-friendly. It has fewer features and is very easy. Even a beginner can use Microsoft SCCM, which is not the case with Qualys Patch Management.
How was the initial setup?
It is a cloud solution, so everything required is provided by Qualys.
It does not require any maintenance from our end.
What about the implementation team?
We required assistance from the Qualys team for the initial setup and configuration as we were not familiar with setting up and configuring QGS at the time.
What was our ROI?
It has saved us resources. We now have only two people for patch management.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable and competitive. We get many more features at the same price as other solutions such as Microsoft SCCM.
It is worth the money considering the services and features it has. Their support team is also awesome.
Which other solutions did I evaluate?
We evaluated Rapid7 as an alternative to Qualys but found it lacking in some features that Qualys offered.
What other advice do I have?
I would recommend Qualys Patch Management to every organization looking for better patch management and remediation. I would recommend opting for the cloud version of Qualys Patch Management as it is easier and faster to use compared to an on-premises solution.
I would rate Qualys Patch Management a ten out of ten. It makes my job easy.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: MSP
Buyer's Guide
Download our free Qualys Patch Management Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Patch ManagementPopular Comparisons
Microsoft Configuration Manager
Kaseya VSA
Vicarius vRx
ManageEngine Patch Manager Plus
Microsoft Windows Server Update Services
Ivanti Security Controls
Patch My PC
Ivanti Patch for Endpoint Manager
PDQ Deploy
Buyer's Guide
Download our free Qualys Patch Management Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Why is patch management important for cybersecurity?
- When evaluating Patch Management, what aspect do you think is the most important to look for?
- What patch management solution do you recommend?
- What solution should we use for upgrading and patching OS to remediate vulnerabilities?
- Why is Patch Management important for companies?
- What are Pros and Cons of Cloud-based Patch Management?















