The interface is pretty good, as all the instructions are clear enough. The way you can create groups or scheduling scans and reports is a very good feature, and the CSV reports have very good information.
Analista de Seguridad TI at a manufacturing company with 1,001-5,000 employees
It's worth the investment, but score calculation needs to be improved. I had to manually re-calculate scoring at times.
What is most valuable?
How has it helped my organization?
In this case, my last employer was a Qualys partner and the consultancy was extra. But, the reports and the way the information is, helped a lot. Also, with this information concise presentations were sent to the CIO every month.
What needs improvement?
I think the only area to improve it is the way the scores are calculated. That was the only problem I had and because of that, all scores had to be rectified manually.
For how long have I used the solution?
I was using both Multimedios Redes (Enterprise version) and Lamosa for three years. I also used PC, PCI, and WAS.
Buyer's Guide
Qualys VMDR
June 2025

Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
What was my experience with deployment of the solution?
No issues were encountered.
What do I think about the stability of the solution?
Maybe one or two times, but they were caused by scheduled windows, but these problems were fixed very quickly.
What do I think about the scalability of the solution?
No issues were encountered.
How are customer service and support?
Customer Service:
Very good! I think I would give them 10/10 because in Latin America the service was excellent.
Technical Support:Again, I would give them 10/10, as the documentation is so good and all is clear, but if you have a doubt, technical support was always concise and had a quick answer. Also the community helps a lot.
Which solution did I use previously and why did I switch?
I did not personally, but the technical contacts that worked for my customers tried another solutions, and they chose Qualys for the easy way it manages the processes.
How was the initial setup?
The initial setup was very easy, with no complications found when the instructions were followed. Also, this activity was done with a physical and virtual appliance, and both ways were very easy to follow.
What was our ROI?
I was the vendor team, but I can give you the answer from the actual companies I worked for. The administrators, before Qualys, did not care so much about security, patching, etc.; but, after Qualys they changed their minds. Security took a very important role and of course they reduced, a lot, the chances of being hacked or attacked. It also helped, at this point, to be verified by auditors.
What's my experience with pricing, setup cost, and licensing?
It's worth it, really, when you see the complete picture and see all the factors. It is a very good investment. Qualys is a very good tool and very easy to use and it is also better to have an annual subscription rather than paying for a scan.
Which other solutions did I evaluate?
My customers evaluated Foundstone and Rapid7, and possibly others.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager System Security at a comms service provider with 1,001-5,000 employees
The installation of the local hardware scanner appliance is easy, but the asset tagging needs lots of improvements.
What is most valuable?
- Vulnerability management
- Policy compliance
- Scalability
How has it helped my organization?
As a leading IT services organization, it is very important for us to have a proactive identification/assessment of vulnerabilities. We also need to be able to remedy them in a timely manner before they exploit our security configuration compliance, and then harden our security for both system/network devices and applications. We need to do this both before and after placing them in production environment.
With QualsyGuard we have been able to achieve this by utilizing its modules, such as vulnerability management, policy compliance, web scanning, malware detection, and asset tagging.
What needs improvement?
As users of Qualys for the last three years, we have identified and shared many areas where Qualys needed to have improvements, including --
- Vulnerability database having some false positives, although this is rare;
- Web scan module requires authentication to access basic web forms;
- Asset tagging needs lots of improvements as it's currently a complex technique; and
- For policy compliance, they need to add more leading IT standards with regards to all the leading IT service provides like Juniper, Cisco, Microsoft, etc.
For how long have I used the solution?
I've been using this product for the last three years.
What do I think about the stability of the solution?
This is a very stable product and we haven't faced any issues since its deployment apart from announced downtimes for upgrades and improvements.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
Support is available 24/7 via phone and e-mail. Remote session support is also available.
Technical Support:They have excellent expertise.
Which solution did I use previously and why did I switch?
No previous solution was used.
How was the initial setup?
It's easy as it is a SaaS, cloud-based service. The installation of the local hardware scanner appliance is also easy.
What about the implementation team?
We used a vendor team who was excellent.
What was our ROI?
I cannot give you the exact ROI on this, but as a large information and communication technology service provider, a 24/7 service availability that leads to customer satisfaction is our key goal. Regular VM and compliance assessment results in the complete hardening of our critical assets defending us against any exploits that leads to unavailability of our services.
Which other solutions did I evaluate?
No, because it was already in use at our parent company and it was providing good results for a low price as well.
What other advice do I have?
- Collect complete asset inventory details (asset type, service/application details, administrator details etc.).
- Provide awareness session to the support team about Qualys, its usage, and functionality.
- Prepare OLAs and SOPs for better co-ordination between the teams.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Qualys VMDR
June 2025

Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
Security Consultant at Cyber Intelligence Sdn Bhd
The reporting features needs to be improved, but you don't need to spend a lot of time on the deployment.
What is most valuable?
The fact that it's on the cloud, so there's no configuration whatsoever on my physical machine except for the VM scanner.
How has it helped my organization?
It now takes less time to run a vulnerability assessment for our client. I do not have to bring two laptops anymore to my clients sites.
What needs improvement?
Maybe the reporting features. It is too granular, so that if someone new wants to get familiar with it, they will have a hard time. A few more tutorials or guide on screen would also be appreciated.
For how long have I used the solution?
I've been using the consultant edition for two years.
What was my experience with deployment of the solution?
During the internal scanner deployment, but the issue was mostly not the product, but more the network architecture of our client.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
9/10
Technical Support:9/10
Which solution did I use previously and why did I switch?
Rapid 7 Nexpose. To use the software, it takes a whole laptop just to run it, and the results have too much redundancy. Additionally, the scan rate is very slow compared to Qualys, and furthermore it is too expensive when compared to Qualys.
How was the initial setup?
It's very straightforward. Basically you can scan anything external/internet facing within five minutes. For internal scans you have to deploy the internal scanner which can be done in five minutes if the network architecture is not too complex.
What about the implementation team?
It was done In-house, but the help we get from their Singapore support team is awesome.
Which other solutions did I evaluate?
- Nessus
- Nexpose
What other advice do I have?
Use it. It is a great product. Many people are sceptical that their scan results are in the cloud. But if you want something affordable and that works like a charm, go for Qualys. Less headaches and easy to achieve ROI as you don't spend much on the deployment or maintenance.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: We have been doing some road-shows, & conferences in Malaysia to introduce Qualys.
Customer Technical Leader for Galeries Lafayette at a tech company with 10,001+ employees
The GUI needs work, but the vulnerabilities are kept up to date.
What is most valuable?
The top one for me is that the vulnerabilities are kept up to date.
How has it helped my organization?
It has reduced the cost of ownership for the engineers who can launch scans on the customers’ networks.
What needs improvement?
I’m convinced it could be possible to do a simpler interface.
For how long have I used the solution?
I used it for about four years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
There is an issue with the web browser, but it's not an issue with the product itself.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
9/10.
Technical Support:8/10.
Which solution did I use previously and why did I switch?
I switched due to the cost.
How was the initial setup?
It was simple because it's only used for external scans.
What's my experience with pricing, setup cost, and licensing?
You have to find the best solution regarding functions and cost.
Which other solutions did I evaluate?
- Tripwire
- Nessus
- Accunetix
- OIpenvas
What other advice do I have?
- Take your time
- Study all the functionalities of the product
- Try to set it up in a lab first before your production environment.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager Information Security at a healthcare company with 10,001+ employees
There are some stability issues with reporting, but it's straightforward to implement.
What is most valuable?
Vulnerability management.
How has it helped my organization?
It has helped to automate the vulnerability management program, increasing the security posture and helped us to identify the security risks in our infrastructure.
What needs improvement?
Web application security model needs some work.
For how long have I used the solution?
I've been using it for four years, including including VM, PCI, WAS and MDS features.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
There's been a few times, related to reporting, that we've had issues, but overall it's stable.
How are customer service and technical support?
Customer Service:
Excellent, the Qualys support team always helps on a priority basis.
Technical Support:Excellent!
Which solution did I use previously and why did I switch?
No previous solution was used.
How was the initial setup?
It was straightforward.
What about the implementation team?
It was done in-house.
Which other solutions did I evaluate?
No other options were looked at.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Services Manager at a tech company with 10,001+ employees
It is very simple and yet an effective way to do vulnerability assessment.
What is most valuable?
- Vulnerability assessment
- Asset management
- WAS
How has it helped my organization?
Since this is a SaaS based solution, the vulnerability scan with the external scanners as well as the reporting has improved a lot. The reporting is very granular and you can please higher management with your reports.
What needs improvement?
None, as the product is great.
For how long have I used the solution?
I've used it for four years.
What do I think about the stability of the solution?
Stability of the product is very high, I have never seen it unavailable.
How are customer service and technical support?
Customer Service:
The support needs to improve a lot, their response is absolutely slow. I have had terrible experience with support over the years.
Technical Support:I would rate it great because of its improvement since I have had terrible experiences in the past.
Which solution did I use previously and why did I switch?
We used McAfee Vulnerability Manager/Foundstone and had to switch because this is a SaaS based solution and has more features/capabilities.
How was the initial setup?
The initial setup is very simple in terms of configuring the appliance.
What about the implementation team?
We installed it ourselves,
What other advice do I have?
I would definitely recommmend using this product, as this is very simple and yet an effective way to do vulnerability assessment.
.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Linux Administrator at a comms service provider with 501-1,000 employees
The users on the forums are very knowledgeable, but the reporting in the solution is lacking.
What is most valuable?
The reporting and vulnerability analysis features.
How has it helped my organization?
Vulnerability scans are easily managed and maintained using Qualys. What used to be a manual process is now automatic. When we have an issue, I can easily see what production systems are affected and I can easily pinpoint a solution to mitigate the issue.
What needs improvement?
The reporting is lacking a little, and it would be nice to have reports sent via email. Often times we have to manually generate the reports after a vulnerability is fixed and a scan has to be re-run.
For how long have I used the solution?
I've used it for three years.
What was my experience with deployment of the solution?
We did not.
What do I think about the stability of the solution?
Our Qualys box is hardware and it's very easy to set up and maintain. It's very little maintenance, and the most time consuming part is setting up everything initially, such as what subnets you want to scan, what reports you want to run, etc.
What do I think about the scalability of the solution?
We have over 15,000 devices and had no issues with scaling up our Qualys infrastructure.
How are customer service and technical support?
Customer Service:
I have never had to interact with them. I get most of the information on the forums, and even there the responses are lighting fast. As far as actually talking to someone, I personally have never had to speak to Qualys support.
Technical Support:It's great. The users on the forums are very knowledgeable and eager to help. If I need a quick answer I will always get one from the support forum.
Which solution did I use previously and why did I switch?
We used Nessus before. It was a manual process and very time consuming. I like Nessus, but it was very tedious to get it to function automatically.
How was the initial setup?
There are always complexities to every setup. I think the biggest issue was the learning curve. Having to learn all the new pieces and how they fit into our environment was probably the single biggest hurdle we had to face.
What about the implementation team?
We did it in-house.
Which other solutions did I evaluate?
We looked at Metasploit Expose but the price was too much for what we needed.
What other advice do I have?
Do your research and see how this product would best fit into your environment.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IT Security Analyst at a tech services company with 501-1,000 employees
The IT infrastructure needs work but WAF has improved our vulnerability identification.
What is most valuable?
WAF integration is valuable.
How has it helped my organization?
We can now perform vulnerability scans with WAF integration. The WAF has improved the vulnerability identification and reports to the SOC and CSO.
What needs improvement?
The IT infrastructure, especially server administration, needs to be improved.
For how long have I used the solution?
I've used it for two years.
What was my experience with deployment of the solution?
There was only one related, and that need work on our technology. As the solution is cloud based, we needed to adapt our internal policies.
What do I think about the stability of the solution?
There were no issues.
What do I think about the scalability of the solution?
This been done without a problem.
How are customer service and technical support?
Customer Service:
It's good.
Technical Support:It's good.
Which solution did I use previously and why did I switch?
There was no previous solution, but I did execute several POCs.
How was the initial setup?
It was a regular setup for the configuration, but the official training was necessary.
What's my experience with pricing, setup cost, and licensing?
We also looked at Nessus and GFI Languard.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Vulnerability Management IT Asset Management Configuration Management Databases Container Security Risk-Based Vulnerability ManagementPopular Comparisons
ServiceNow
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
SentinelOne Singularity Cloud Security
Tenable Nessus
Tanium
Tenable Security Center
CrowdStrike Falcon Cloud Security
Orca Security
Tenable Vulnerability Management
Rapid7 InsightVM
JFrog Xray
Acunetix
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Qualys VM vs Tenable Nessus: Comparison
- How does Tenable Nessus compare with Qualys VM?
- How does Pentera compare with Qualys VMDR?
- What are the main differences between Qualys VMDR and Tenable Nessus?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?
Yes, this review is helpful.