No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2388546 - PeerSpot reviewer
Server Services Operation Head at a logistics company with 10,001+ employees
Real User
Top 20
Jul 18, 2024
Has robust vulnerability detection capabilities and good technical support services
Pros and Cons
  • "The platform's most valuable features include its robust vulnerability detection capabilities and automated remediation workflows."
  • "While Qualys VMDR is comprehensive, improvements in asset management functionality would be beneficial."

What is our primary use case?

Our primary use case of the product is comprehensive vulnerability management and asset inventory across a hybrid environment consisting of both cloud and on-premises deployments. We manage approximately 45,000 endpoints spread across multiple geographical locations.

What is most valuable?

The platform's most valuable features include its robust vulnerability detection capabilities and automated remediation workflows. These features not only help us identify vulnerabilities promptly but also enable us to prioritize and remediate them efficiently.

What needs improvement?

While Qualys VMDR is comprehensive, improvements in asset management functionality would be beneficial. Additionally, reducing dependency on multiple agents for data collection across different endpoints could simplify management and resource utilization.

In the next release, enhancements in reporting and analytics would be appreciated. Advanced analytics capabilities for trend analysis and predictive insights could further empower proactive decision-making in cybersecurity management.

For how long have I used the solution?

I have been using Qualys VMDR for approximately two years now.

Buyer's Guide
Qualys VMDR
June 2026
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,838 professionals have used our research since 2012.

What do I think about the stability of the solution?

The product is stable. I rate the stability a seven. 

What do I think about the scalability of the solution?

I rate the product scalability an eight. 

How are customer service and support?

The technical support services are good. 

How was the initial setup?

The initial setup was relatively straightforward. They provided comprehensive documentation and support during deployment, which helped streamline the process. 

I would rate the process a seven or eight. 

What about the implementation team?

We implemented the product with the help of in-house resources and support from Qualys.

Which other solutions did I evaluate?

We evaluated other options such as Tenable and Rapid7.

What other advice do I have?

I rate Qualys VMDR a nine out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Koketso Ditlhage - PeerSpot reviewer
Information Communication Technology Specialist at UNIVERSITY OF JOHANNESBURG
Real User
Top 5Leaderboard
Jul 4, 2024
Simplifies asset discovery and management, ensuring comprehensive scanning and reporting
Pros and Cons
  • "The product's patch management is excellent for keeping our critical servers and third-party applications updated efficiently."
  • "One area of the product that could be improved is the management of vulnerabilities detected on disabled applications."

What is our primary use case?

I primarily use Qualys VMDR for daily scans, onboarding assets, scanning, reporting, and managing the entire vulnerability management process, including test management.

How has it helped my organization?

VMDR has significantly improved our organization by simplifying asset discovery and management. We can easily identify and categorize assets, ensuring comprehensive scanning and reporting.

What is most valuable?

Qualys Patch Management is excellent for keeping our critical servers and third-party applications updated efficiently.


What needs improvement?

One area of the product that could be improved is the management of vulnerabilities detected on disabled applications. We currently face challenges with unnecessary alerts for Microsoft Defender, which we do not use. Additionally, enhancing the alerts for agent communication failures would be beneficial.

For how long have I used the solution?

I have been using Qualys VMDR for approximately three years.

What do I think about the stability of the solution?

The product has been very reliable in our day-to-day operations.

What do I think about the scalability of the solution?

I would rate the product scalability a ten. It easily scales with our organization's growth, allowing us to add new assets and expand our coverage seamlessly. We are considering expanding our deployment to include 500 assets next year.

How was the initial setup?

The initial setup was straightforward, taking less than a week to configure and generate reports. The deployment process was smooth, and we were able to integrate it effectively into our hybrid environment.

What was our ROI?

Within three months of deployment, we began seeing improvements in vulnerability management. This helped us significantly reduce vulnerabilities and streamline our patch management processes, providing a notable return on investment.

What's my experience with pricing, setup cost, and licensing?

The solution is reasonably priced for the value it provides. Our contract renewal was approximately 2.5 million ZAR for three years, including managed services.

Which other solutions did I evaluate?

Before selecting Qualys VMDR, we evaluated other options but ultimately chose Qualys due to its comprehensive features and effective proof of concept.

What other advice do I have?

We integrate Qualys VMDR with our infrastructure, conducting weekly scans and generating reports based on the findings. This provides daily views of vulnerabilities, and we use Qualys' patch management to deploy patches promptly, starting with the most severe vulnerabilities, thus reducing our threat exposure. Conducting a thorough proof of concept is essential to evaluate its effectiveness in your environment and to see how it integrates with your existing systems and handles your specific security needs.

I rate it a ten out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Qualys VMDR
June 2026
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,838 professionals have used our research since 2012.
IT Team Lead at a consultancy with 10,001+ employees
Real User
Top 20
Oct 21, 2024
Efficient risk assessment with critical vulnerability prioritization and an easy setup
Pros and Cons
  • "The most valuable feature is the QID part, especially of CentralList, which makes it easy to assess new critical vulnerabilities."
  • "Support could be improved since the response can be slow."

What is our primary use case?

The primary use case for Qualys VMDR is for infrastructure vulnerability management. It assists devices, including all infrastructure devices like serverless network devices and development environments.

How has it helped my organization?

The solution has improved the organization significantly because it helps in assessing and prioritizing risk. Based on the results from Qualys, I can prioritize remediations with the remediation teams, thereby reducing the volume of vulnerabilities.

What is most valuable?

The most valuable feature is the QID part, especially of CentralList, which makes it easy to assess new critical vulnerabilities. It saves a lot in assessing and prioritizing risks to the organization.

What needs improvement?

Support could be improved since the response can be slow. There is always room for improvement to align with the latest content and technologies.

For how long have I used the solution?

I have used the solution for three years.

What do I think about the stability of the solution?

The solution is stable. Anytime there is downtime or maintenance, Qualys ensures that we are well-informed with priority communications.

What do I think about the scalability of the solution?

Scalability would be rated nine or nine point five out of ten. We have high satisfaction with this aspect.

How are customer service and support?

Technical support response can sometimes be slow, leading to a rating of eight or nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I previously used a different tool. I switched to Qualys as it didn't have the same feature set.

How was the initial setup?

The initial setup was straightforward. Deployment took two to three days.

What about the implementation team?

The deployment was done by a different team, so I do not have specific details about the implementation team size.

Which other solutions did I evaluate?

I have used RapidSky before Qualys.

What other advice do I have?

I would recommend Qualys VMDR because it ensures comprehensive coverage, including aspects like vulnerability management and PCI, providing good inputs and improvements over time.

I'd rate the solution nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Venkata Kalla - PeerSpot reviewer
Information & Security Engineer at Infosys
MSP
Top 20
Oct 22, 2024
Efficient automated scans and good reliability with room for vulnerability detection improvement
Pros and Cons
  • "Continuous monitoring is a crucial feature that we use more frequently."
  • "There are scenarios where a vulnerability is reported once yet not in subsequent scans, even if we have not fixed it."

What is our primary use case?

We use continuous monitoring to schedule scans for all the applications in our organization. We create a parent tag and sub-tags for each application and schedule scans based on our requirements, such as every alternate day, weekly, or monthly. This helps us identify vulnerabilities in the web applications, especially those that are public-facing.

How has it helped my organization?

Since implementing Qualys, we have seen a reduction in the time required to scan applications, as it automates the process. This efficiency is one of the key improvements we have noticed. Additionally, the tool is effective compared to others, particularly for automated scans.

What is most valuable?

In Qualys VMDR, there are multiple valuable features such as Continuous Monitoring, SFU Connector, and WebVPN. Continuous monitoring is a crucial feature that we use more frequently.

What needs improvement?

There are scenarios where a vulnerability is reported once yet not in subsequent scans, even if we have not fixed it. Sometimes, Qualys is unable to crawl certain URLs due to unspecified issues. Additionally, the report download option occasionally has problems.

For how long have I used the solution?

I have been using Qualys for two years.

What do I think about the stability of the solution?

I would rate the stability as nine out of ten, indicating no significant issues with stability.

What do I think about the scalability of the solution?

The scalability of Qualys is rated as eight to nine out of ten, and there are no problems with scalability.

How are customer service and support?

The customer support system could be improved. While they respond, it takes them two to three days to address a concern, which is an issue. Overall, I would rate customer service as five or six.

How would you rate customer service and support?

Neutral

How was the initial setup?

The setup process was not within my involvement, as it was part of the project I had joined and it was already set up.

What other advice do I have?

I recommend Qualys VMDR as it effectively reduces the time required for vulnerability management and operates well with fewer people.

I'd rate the solution seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Vikram Chakravarthy - PeerSpot reviewer
Cyber Security Engineer II (Vulnerability & Threat Management) at FICO
Real User
Top 5Leaderboard
Sep 17, 2024
Efficient patch management and compliance tracking with ability to mitigate vunerabilities
Pros and Cons
  • "The best features of Qualys VMDR are its patch management capabilities and the ability to mitigate vulnerabilities automatically."
  • "The user interface (UI) is quite complicated."

What is our primary use case?

Qualys VMDR is used as a vulnerability management tool. We have more than a thousand users in our company, and we have integrated Qualys with their machines to help update software and measure known or unknown risks, prioritize them, and patch the devices. We monitor and mitigate alerts, and we find vulnerabilities in specific machines or systems, which we then address.

How has it helped my organization?

Before implementing Qualys, we used third-party companies to conduct vulnerability audits and paid them separately for mitigation. With Qualys, we now conduct our vulnerability management and mitigation internally, saving both time and money since we can monitor every system and threat without requiring manual processes or third-party involvement. This has resulted in significant ROI and reduced the risk of breaches.

What is most valuable?

The best features of Qualys VMDR are its patch management capabilities and the ability to mitigate vulnerabilities automatically. The report export feature allows us to see how many incidents have been mitigated and which ones still need attention. The compliance dashboard helps us track and fix threats efficiently, ensuring all machines comply with security standards.

What needs improvement?

The user interface (UI) is quite complicated. Initial-stage engineers or analysts might miss something due to the complexity. Also, for hybrid users, the agent might get disconnected, requiring users to revisit the office to reinstall the agent. Additionally, the reports could be more interactive.

For how long have I used the solution?

I have had five years of experience with cybersecurity platforms and have been using Qualys VMDR for that duration.

What do I think about the stability of the solution?

I would rate the stability of the solution nine out of ten. It is a robust platform that provides consistent performance.

What do I think about the scalability of the solution?

For scalability, I would rate it nine or 9.5 out of ten. The cloud-based architecture allows us to deploy it across multiple locations seamlessly.

How are customer service and support?

The technical support provided by Qualys is good. Queries are responded to promptly, and if needed, we can contact the TAM or any POCs directly. I would rate their support nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Before using Qualys, we used a third-party solution for vulnerability audits and mitigations. However, we switched to Qualys because it allows us to handle everything internally, avoiding the need for additional external services.

How was the initial setup?

The initial setup is agent-based and straightforward, especially if you have necessary tools like Active Directory. Given the cloud-based nature of Qualys, deployment can be completed within a day with appropriate resources.

What was our ROI?

We have seen a significant ROI with Qualys, which is estimated to be around twenty to thirty percent. It has saved a lot of time and money by allowing us to mitigate issues without user interaction and preventing breaches.

What's my experience with pricing, setup cost, and licensing?

Compared to Tenable, Qualys is quite expensive. However, its performance justifies the cost, making it a worthwhile investment.

Which other solutions did I evaluate?

We also use Tenable Solutions for vulnerability management. However, Tenable requires manual processes for mitigation, whereas Qualys allows for automated mitigation of vulnerabilities and threats.

What other advice do I have?

I would definitely recommend Qualys to other users. Depending on the number of users and specific needs, Qualys is a good vulnerability management product that offers efficient solutions. I'd rate the solution nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
KiranReddy - PeerSpot reviewer
Head of IT at a manufacturing company with 10,001+ employees
Real User
Dec 3, 2023
Has an effective tagging system and authentication mechanism compared to other tools
Pros and Cons
  • "The process of defining and discovering scans is organized efficiently."
  • "Qualys could improve the inbuilt dashboards."

What is our primary use case?

We use the product for enterprise network infrastructure scanning.

What is most valuable?

The product has multiple valuable areas. The process of defining and discovering scans is organized efficiently. It has an effective tagging system and authentication mechanism compared to other tools. Its integration with AD helps us a lot. Additionally, I like the report generation feature.

What needs improvement?

Qualys could improve the inbuilt dashboards. They could be advanced compared to competitors like Rapid7 and Tenable. They should include a faster reverse integration process. They could enhance its integration with ServiceNow CMDB to ensure that mapping IP addresses, domains, and net bias names is consistent and accurate.

For how long have I used the solution?

We have been using Qualys VMDR for nearly two and a half years.

What do I think about the stability of the solution?

I rate the product's stability a nine out of ten. I have rarely seen any stability issues with Qualys.

What do I think about the scalability of the solution?

I rate the product's scalability an eight out of ten. We only recommend some people use Qualys in our organization. It is a limited audience. It is used by the vulnerability management team and a few critical resources from different parts of the cybersecurity department. We have 50 users in total. They should provide role-based access for managers, reviewers, and scanners.

How was the initial setup?

The initial setup process is simple as I have prior experience working on two full-time projects with it. I find it simple as I have enough background knowledge of it.

What's my experience with pricing, setup cost, and licensing?

The product is more expensive than that of any other vendor.

Which other solutions did I evaluate?

I did work on Tenable's POC and some other vendors. It has some limitations in detecting different types of vulnerabilities or false positives. Qualys is on the higher side when compared to the other tools.

What other advice do I have?

I rate the product an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
LUKEMONYUSSUF - PeerSpot reviewer
Information Technology Security Analyst at Culina Group Limited
Real User
Jun 27, 2023
With an interesting dashboard, the solution offers stability and scalability
Pros and Cons
  • "I find the solution's dashboard interesting...The response time is fine. You can pull up reports without dragging or consuming bandwidth."
  • "It is a struggle to be able to pull our report and to be able to do onboarding using automated tools."

What is our primary use case?

Using the solution, I go through the reports and advise my organization on what needs to be done and how to go about it.


What is most valuable?

I find the solution's dashboard interesting since we get a proper view to streamline our findings and assist in prioritizing the schedule for patching or any other related incidents we believe have already been worked on.

What needs improvement?

Presently, I am more of the technical part. I am allowed to just go through the details of the report, which has been very interesting. It is a struggle to be able to pull our report and to be able to do onboarding using automated tools. So basically, the aforementioned aspect of the report needs improvement.

Presently, whatever I'm working on has been quite fantastic to the best of my knowledge.

For how long have I used the solution?

I have been using Qualys VMDR. I have been using it on my own site as a client. I am just a consultant. I work with Qualys VMDR due to my understanding of the product so that I can help my clients check one or two things that can help improve the digital infrastructure part.

What do I think about the stability of the solution?

The stability of the tool is okay. Most of the time, you need to do the updates online to be able to get off from any vulnerability. As long as you are online since it's on the cloud, it's just as software of which the update has been handled on the cloud as well.

The response time is fine. You can pull up reports without dragging or consuming bandwidth.

What do I think about the scalability of the solution?

The scalability of the tool is okay. Scalability-wise, I rate the solution an eight out of ten. I have not been able to have the solution function at a large scale. Hence, I will be able to categorically say that everything is fantastic.

How are customer service and support?

Presently on my own part, I've not been able to experience the support, but I can search the technical algorithm of which I've not yet got any reports. 

How was the initial setup?

The initial setup phase has been quite interesting because of our experience when we had to use the agents on most of the endpoints, which means it was okay for us.

The solution is deployed on the cloud.

What other advice do I have?

I would tell those planning to use it that it is definitely not about the technology. However, at the same time, if you have the technology, make sure you have the right person with the ability to assist you in addressing the advantages of the product.

I rate the overall product an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Nabhanyu Halgeri - PeerSpot reviewer
Cyber Security Specialist at a tech services company with 51-200 employees
Real User
Top 20
Oct 21, 2024
Effortless asset management, fast support, and an easy setup
Pros and Cons
  • "I value the scheduling of scans and reports as per the desired timeframes."
  • "The reporting section needs improvement as running reports can take several hours."

What is our primary use case?

The use cases would be for scanning purposes, for identifying assets, identifying and viewing assets, and setting up scan schedules. I use it primarily as a vulnerability management and scanning tool.

How has it helped my organization?

When you have everything in one place, the job is very easy. Qualys VMDR having a Russian nesting doll sort of environment does take a steep learning curve, but having everything in one place is quite neat.

What is most valuable?

The most valuable feature is the asset view where I can find individual assets and take a deeper dive into their information gathering section, potential vulnerabilities, and confirmed vulnerabilities. I also value the scheduling of scans and reports as per the desired timeframes.

What needs improvement?

The reporting section needs improvement as running reports can take several hours. A more intuitive way to configure reports settings to reduce run time would be helpful. Improvements are needed for sorting QIDs and findings during the reporting section without downloading the entire report. 

Additionally, there is a need to address the issue of retaining report sections when they exceed one or two GBs. For asset management, adding a notification for unscanned assets or those missing CVE ratings would help.

For how long have I used the solution?

I have been using it for close to three and a half to four years now.

What do I think about the stability of the solution?

There are rarely any stability issues. Discrepancies are usually anticipated due to the downtime and maintenance window provided in advance. It's a technological tool, and random anomalies may happen, but they are manageable.

What do I think about the scalability of the solution?

Qualys offers one of the best scalability capabilities for large-scale deployments. Its tools and solutions work effectively with large corporations. VMDR helps club multiple vulnerabilities into one QID, which assists with remediation cycles.

How are customer service and support?

Customer support is fast, although there can be a lot of back and forth. However, the overall service is satisfactory and of great quality.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used Nessus and Burp Suite, however, Burp Suite isn't in close proximity with Qualys for scanning purposes. Microsoft Defender offers some advantages with real-time, agent-based scanning that consumes fewer resources.

How was the initial setup?

The initial setup was quite simple and straightforward. Setting up Qualys was fairly easy with clear documentation and guidance.

What's my experience with pricing, setup cost, and licensing?

I am not familiar with the pricing side as I am not a part of that aspect. However, it is on the higher side, but it provides large-scale scalability for vulnerability management.

Which other solutions did I evaluate?

I have evaluated Nessus and Microsoft Defender for vulnerability management.

What other advice do I have?

Users should go through the training offered by Qualys for all VMDR modules and take an introductory call on how to use and schedule tasks. Setting up one thing at a time and testing the desired results before moving on is advised.

I'd rate the solution eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
VIKAS KUMAR YADAV - PeerSpot reviewer
Solutions Architect at a consultancy with 10,001+ employees
Real User
Top 20
Oct 9, 2024
Enhancing security with precise vulnerability assessments and remediation steps
Pros and Cons
  • "The most valuable feature is the vulnerability assessment."
  • "Qualys VMDR could improve in reducing the occurrences of false positive vulnerabilities."

What is our primary use case?

I am working for an IT firm where I use Qualys VMDR for my clients. I specifically use it for vulnerability detection and vulnerability remediation as part of our vulnerability assessment team. We scan all the assets for vulnerabilities, both servers and client-side, and then share the vulnerability reports with the relevant teams for remediation planning.

How has it helped my organization?

The continuous scanning for vulnerabilities, especially the notifications for zero-day vulnerabilities, greatly aids in keeping our systems secure. The accurate vulnerability assessments and the remediation plans they provide enhance our workflow and effectiveness in vulnerability management.

What is most valuable?

The most valuable feature is the vulnerability assessment. Qualys VMDR is precise in its assessments and categorizes vulnerabilities by severity from one to five. Additionally, they provide detailed reports and possible remediation steps, such as updating from Java version 3.4 to a more secure version.

What needs improvement?

Qualys VMDR could improve in reducing the occurrences of false positive vulnerabilities. Enhancing this aspect would make the tool even more effective.

For how long have I used the solution?

I have been using Qualys VMDR for two years.

What do I think about the stability of the solution?

There are no issues with stability. They notify us of any scheduled downtime a week in advance, usually planning it for weekends to avoid disrupting business operations.

What do I think about the scalability of the solution?

Qualys VMDR handles scalability very well. It offers extensive features and facilities to create groups for assets or servers, making it easy to add new environments or data centers for scanning.

How are customer service and support?

I have heard that their technical support team is very responsive and takes quick action when needed. However, I have never interacted with them personally.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We have used ZixSense, also known as Ivanti Neurons. ZixSense is more user-friendly than Qualys, however, the latter provides more comprehensive and accurate vulnerability assessments.

How was the initial setup?

The initial setup of Qualys VMDR was easy. We just had to open the Qualys tool, add the IP addresses of the respective servers or hostnames, and start scanning. Access to vulnerability assessment is only provided via IP addresses, not hostnames.

What about the implementation team?

Any changes or maintenance required are managed by the Qualys team following change requests from our upper management.

What other advice do I have?

New users should complete two training programs from the Qualys training center: Qualys Foundation and Qualys VMDR. These certifications provide the necessary knowledge to set up and use Qualys effectively. Qualys also provides a demo trial account for new users.

I'd rate the solution nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2561502 - PeerSpot reviewer
Senior Application Security Engineer at a real estate/law firm with 501-1,000 employees
Real User
Top 10
Sep 29, 2024
Quick threat detection and comprehensive vulnerability management with a good knowledge base
Pros and Cons
  • "Qualys VMDR provides us with a quick response to threat findings through regular scheduled scanning, which improves our security operations."
  • "Qualys VMDR should improve authenticated scanning capabilities."

What is our primary use case?

We use Qualys VMDR to scan our public websites and products, anywhere that is publicly available. We deploy it through Qualys's cloud scanner.

How has it helped my organization?

Qualys VMDR provides us with a quick response to threat findings through regular scheduled scanning, which improves our security operations. It also offers an impressive knowledge base for quick research results and coverage of all vulnerabilities.

What is most valuable?

The knowledge base is the most impressive feature because it provides quick research results and coverage of all vulnerabilities. Additionally, the real-time threat detection feature provides quick responses to threat findings.

What needs improvement?

Qualys VMDR should improve authenticated scanning capabilities. It currently only allows basic authorization tokens and preset parameters. In contrast, Burp's in-built browser works more like a proxy, which makes security testing easier and more accurate. Pricing is also an issue; it's high enough to deter mid-sized to small companies. Moreover, the technical support is slow and tends to just reference documentation rather than providing real technical assistance.

For how long have I used the solution?

I have been using it personally for five years, while my company has been using it for three years.

How are customer service and support?

The technical support is slow to respond. Most likely, they just provide reference links for documentation instead of offering in-depth technical guidance. This level of support doesn't compare well to others like Cisco, Juniper, or Avaya, which offer more hands-on assistance.

How would you rate customer service and support?

Neutral

What was our ROI?

This goes beyond my scope of responsibilities and is managed by my superior.

What's my experience with pricing, setup cost, and licensing?

The pricing for Qualys products is too high, and the licensing model involves paying for the whole bundle, which may not be affordable for mid-sized to small companies.

Which other solutions did I evaluate?

We are currently looking for alternatives to Qualys by researching competitor products on the market.

What other advice do I have?

For midsize to small-size companies, Qualys might not be the best choice if you don't have enough funding for security due to its high pricing. Qualys VMDR is still recommended for comprehensive vulnerability management but be prepared for slow technical support.

I'd rate the solution nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2026
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.