Our use cases are primarily on-premises vulnerability management and remediation, external attack surface management and vulnerability scanning.
Head: Cloud Platform Security at BCX Namibia
Helped us quickly remediate vulnerabilities thanks to its automation and ease of use
Pros and Cons
- "The biggest benefit is from a security operations perspective, where we are able to drive our security posture upwards by remediating any discovered vulnerabilities."
- "If anything, I would like to see the user interface modernized a bit more."
What is our primary use case?
How has it helped my organization?
The benefits I've seen are twofold. The biggest benefit is from a security operations perspective, where we are able to drive our security posture upwards by remediating any discovered vulnerabilities. We can also automate the remediation process. The other big benefit is executive reporting because it's very easy to produce trends over time to report on risk.
What is most valuable?
The most valuable features are vulnerability detection, patching capabilities, and remediation. Cloud security posture management is also very valuable. I find these features valuable because getting a unified view of your cloud security posture across different environments is not always easy. For example, you might have most of your resources sitting in Azure, but you might have a couple of workloads in AWS. Naturally, there are different tools that report on that, so it's invaluable to have those pulled into a single dashboard so you can drive your remediation from a single platform.
What needs improvement?
If anything, I would like to see the user interface modernized a bit more. Also, there are a lot of various modules, and if they could be consolidated into fewer options, it would make the buying experience easier.
Buyer's Guide
Qualys VMDR
June 2026
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,838 professionals have used our research since 2012.
For how long have I used the solution?
I've been working with Qualys VMDR for the last three years or so.
What do I think about the stability of the solution?
We haven’t faced any issues, the solution is very stable.
What do I think about the scalability of the solution?
Because the management sits in the cloud, you don't have to worry about management appliances or anything like that on-premise, so the solution is very scalable. You can split your assets into asset groups and delegate management to different teams. Around 1,000 users are using Qualys in my organization across 60 locations.
How are customer service and support?
We've had very few technical issues, and the customer support team has quickly resolved issues we've had.
How was the initial setup?
In the first step, Qualys provisions your cloud-based management instance. From there, you get a small, lightweight agent deployed by deployment technology like Microsoft Intune, in our case, SCCM, or any deployment technology.
We worked with BCX Namibia and the Qualys team in South Africa while deploying the solution. It took two weeks to deploy the solution. The solution is not difficult to maintain because the management component is cloud-based and is taken care of by Qualys. Any agent upgrades that might be necessary are very seamless.
What was our ROI?
We have seen an ROI using Qualys. Most breaches nowadays are because of a vulnerability that is exploited. By virtue of being able to identify and remediate these vulnerabilities, I believe we are significantly driving our cybersecurity risk downwards.
What's my experience with pricing, setup cost, and licensing?
The pricing is very competitive, especially because Qualys is integrated and does vulnerability management and remediation patching in one solution, so there's no need for a separate patching solution. You can also get very granular with the amount of IP addresses you can cover. You can go from as few as 16 IP addresses to many more. And the Qualys team is also willing to work with organizations to make the solution make commercial sense. The prices are fixed. We have a yearly subscription model based on the number of IP addresses we’re scanning.
Which other solutions did I evaluate?
We evaluated vulnerability management in Microsoft Defender, but we found the reporting and functionality lacking compared to Qualys. And then the Microsoft licensing costs were also a bit of a dealbreaker.
What other advice do I have?
If you're considering implementing Qualys in your organization, work with a strong pre-sales partner. Evaluate the product, make sure it does what you need, make sure you buy the features that you need, and make sure to use the training and onboarding material that Qualys has made available on its website so you can leverage the solution's full capability from the start. I rate Qualys VMDR a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Engineer at a consultancy with 10,001+ employees
Automated reporting enhances vulnerability management capabilities
Pros and Cons
- "I like the automated report generation and vulnerability report generation."
- "Using this product, we now have a vulnerability management cycle wherein VMDR plays a major role."
- "The response time of technical support takes a while."
What is our primary use case?
We use it for vulnerability management and report generation mostly. I am trying to solve the issue wherein the stakeholders can get automated vulnerability reports to their mailbox.
How has it helped my organization?
Using this product, we now have a vulnerability management cycle wherein VMDR plays a major role. It has greatly increased the capability on the detection aspect of the vulnerability and improved our scope and visibility on all other endpoints.
What is most valuable?
I like the automated report generation and vulnerability report generation.
What needs improvement?
I don't have any improvement requests on top of my mind right now. The response time of technical support takes a while.
For how long have I used the solution?
It's been more than two years now.
What do I think about the stability of the solution?
I would rate the stability as nine out of ten. It's quite stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
My rating for the technical support for Qualys is six out of ten. The response time takes a while.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I personally didn't use a different solution before Qualys.
How was the initial setup?
Although I was not present during the initial deployment process, it's pretty straightforward. It's just an agent installation, which automatically connects it to the cloud platform, so the implementation won't take as long.
What other advice do I have?
I would recommend Qualys VMDR to the other stakeholders because it already has its place in the market, and it's very reliable.
I'd rate the solution eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Qualys VMDR
June 2026
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,838 professionals have used our research since 2012.
Information Security Engineer at a university with 1,001-5,000 employees
Efficient automation feature and provides us with a comprehensive security solution
Pros and Cons
- "The most valuable feature is automation."
- "Qualys VMDR is basically susceptible to false positives, and false negatives."
What is our primary use case?
Qualys VMDR is a vulnerability management and detection response tool. It belongs to the first generation of vulnerability assessment tools. It enables us to manually identify vulnerable keys and fix them. It is built as a cutting-edge continuous platform where we can detect and protect. With this product, we can respond to specific vulnerabilities, going beyond just using artificial intelligence features. We have implemented VMDR across our cloud, physical interfaces, endpoints, and log servers. It's a good digital product for our organization.
How has it helped my organization?
It has improved our organization in many ways. We needed to have a security solution that focuses on different types of things. We discussed budgeting for the cloud and the need for an alternative to taking care of malware. Additionally, we have to consider various attacks. Therefore, Qualys VMDR is a great tool that helps us improve.
What is most valuable?
The most valuable feature is automation.
What needs improvement?
Qualys VMDR is basically susceptible to false positives, and false negatives. We receive a lot of false positives in there. VMDR can be considered a complex solution, especially for enterprises with limited resources or organizations. It requires extensive knowledge as an engineer. So, when using this tool, you need to utilize other tools to remediate the false security issues.
So maybe it should also have the ability to automatically identify and address false positives. In additional features, an automated process for remediating false positives. We might be looking for new types of signatures that can help us identify and address specific issues.
For how long have I used the solution?
I have been using Qualys VMDR for one last year.
What do I think about the stability of the solution?
I would rate the stability an eight out of ten.
What do I think about the scalability of the solution?
I would rate the scalability an eight out of ten.
How was the initial setup?
It took us one month to set up.
What was our ROI?
I have seen an ROI.
What's my experience with pricing, setup cost, and licensing?
The price is very reasonable, so you can definitely go with all the endpoints it offers.
What other advice do I have?
Just consider the licenses we have within VMware. They could replicate some of these features, which are used for premium customers. So, it might be useful to include those features in the subscription plans.
Overall, I would rate the solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Expert at a insurance company with 10,001+ employees
The solution is efficient, with easy implementation, and simple to use
Pros and Cons
- "The most valuable feature of the solution is the external channel."
- "I would like to have CSPM, a continuous scan-like cloud added to the solution."
What is our primary use case?
Qualys VM is used for vulnerability scans for the internet and applications using application exchange. There are many applications. We also use the solution for asset management per team, and the network scan to discover the devices on our network.
How has it helped my organization?
We have an excellent relationship with the vendor, so we use the solution in our company and in two other companies. We have a communication program. Japanese people can't speak English, but most of the tools have only English support, Qualys VM offers support in other languages which are essential for our company.
What is most valuable?
The most valuable feature of the solution is the external channel. The cloud-based channel within the AWS, which we implement accordingly.
The vulnerability cycle feature of the solution is valuable.
What needs improvement?
I would like to have CSPM, a continuous scan-like cloud added to the solution.
For how long have I used the solution?
I have been using the solution for one year.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
We have 25,000 storage devices that are currently using the solution.
Which solution did I use previously and why did I switch?
We previously used an AWS scanner but switched to Qualys VM because of the Japanese support and the cost.
How was the initial setup?
The initial setup is straightforward.
Qualys environment is implemented very easily, within one or two months. However, setting up the standard devices, such as opening a firewall, and preparing the network can take up to four or five months. The entire deployment takes about six months.
What about the implementation team?
The implementation was completed in-house.
What other advice do I have?
I give the solution an eight out of ten.
The maintenance is not difficult and we don't have any problems or concerns.
Implementation of the solution is very easy, using the solution is very easy, and it is very efficient.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Manager at a outsourcing company with 51-200 employees
Accurate and effective with good reporting
Pros and Cons
- "The reporting functionality is great."
- "In a world of the hybrid workforce and work from home, if you're looking for a more effective vulnerability management tool, you have to go to the agent-based vulnerability management tools that are out there, and we've been extremely happy with Qualys."
- "They're still evolving their platform in terms of reporting capabilities."
- "Every time they make a change, it's not always super smooth, and it's a little quirky with bugs sometimes."
What is our primary use case?
We do vulnerability management mostly with the agents and sometimes with the scanner.
We use it to install for around 20 or 30 clients right now so that we can remotely monitor their vulnerability status and help them improve their patch management processes. When certain critical things come up, we help clients with the Log4J, identifying where they need to remediate some of the super trendy critical things that come out and identifying end-of-life operating systems and software that need to be updated.
What is most valuable?
The reporting functionality is great. The most prominent feature that made us move from Nessus Professional was the scanner-based scanning to the Qualys agent-based scanning to move to work from home and remote.
If somebody's not connected to the network, you're not going to catch them with an appliance-based scan. However, if you have the agent on, as long as they're on the network, they're constantly checking in and constantly scanning.
It's more accurate and effective to get a picture of what the vulnerabilities are in a more distributed workforce.
The reporting capabilities that are available in Qualys are a work in progress. I know they're still evolving, and it's not always perfect. However, we only have so much flexibility to pinpoint a specific thing that we want to follow or monitor across all of our clients. We can set it up in a dashboard or report and do it quickly.
What needs improvement?
They're still evolving their platform in terms of reporting capabilities. Every time they make a change, it's not always super smooth, and it's a little quirky with bugs sometimes. That said, they've been really responsive at helping resolve issues that we find. We've got a pretty close relationship with them and our account managers there. We’re working on it.
For how long have I used the solution?
We've been using it as a service provider for about a year or so.
What do I think about the stability of the solution?
The solution can sometimes be buggy.
The agent itself is stable. The reporting platform seems to go through quite a bit of change that they're trying to make it more robust and developing more things, and so we'll make customizations, and they make it update, and the customizations wipe out. I wouldn't say the reporting platform is super stable at the moment. However, it more than meets our needs far beyond what we had with Nessus Professional. The ability to monitor has been stable.
What do I think about the scalability of the solution?
It's incredibly scalable. We've got it across 20 or 30 clients, and so we're pretty happy with how scalable it is from that aspect of a multi-client platform as an MSTP of that type of service.
However, the reporting doesn't seem to be as scalable. The more clients we add to it, the slower it runs with the reporting and dashboards.
Most of our clients are small and medium-sized businesses, so each of those clients has maybe anywhere from 30 to 1,000 agents.
We do plan to increase usage. We're only a year in. We touch a couple of hundred clients a year, so we're just learning the capabilities of it and growing with Qualys as we go. We're definitely all in with Qualys at this point.
How are customer service and support?
I maybe had one meeting trying to understand how to build the dashboards, however, my colleague is the one that was selected to handle the solution and works closely with technical support. From what I heard, they've been great.
Which solution did I use previously and why did I switch?
We previously used Nessus Professional. We switched when we could no longer go use our paid scanner on a client environment due to COVID and not actually going to client offices and nobody being there. Therefore, at that time, it wouldn't have been an effective vulnerability scan, and we had to look at other options. While one of our larger clients does have Nessus iOS through the city government, and it's a great tool, the pricing model was just cost prohibitive for our users across so many clients, and so that's why we were looking at other tools.
How was the initial setup?
It's straightforward as long as the clients have any technical know-how or central management of their devices.
The agents update themselves. There isn’t maintenance necessary once it is deployed.
What's my experience with pricing, setup cost, and licensing?
I’m not clear on the pricing. We don't use it as an in-house tool, and we use it more as a managed service provider. We provide information security consulting services for many companies. When they don't have vulnerability management, we'll offer to support Qualys for them. We've got the MSP platform, and so it's not the typical pricing structure or platform. Therefore, I can’t speak to the exact pricing or typical licensing.
What other advice do I have?
We pay for the Qualys platform, and we will maintain the vulnerability management for our clients until they get their own vulnerability management solution.
I’d recommend the solution to others.
In a world of the hybrid workforce and work from home, if you're looking for a more effective vulnerability management tool, you have to go to the agent-based vulnerability management tools that are out there, and we've been extremely happy with Qualys. We were also delighted with Nessus in terms of their ability to identify things. However, an agent-based scanner is above an appliance base for known devices. Ideally, you have both of them together so you can scan your network for devices that might have an agent on it. However, for known devices, we definitely have been switching and really appreciate the switch to agent-based in Qualys.
I’d rate the solution eight out of ten. The only downside is that reporting can be slow, knowing that we're dealing with trying to load dashboards with 20,000 to 30,000 agents.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Manager -Cloud Security at Capgemini
Continuous endpoint monitoring and amazing dashboards
Pros and Cons
- "Qualys has a continuous endpoint monitoring feature for agent-based scanning. Once you deploy the solution, it monitors everything that is happening every 30 minutes. Then, if there are any vulnerabilities, they are reported."
- "The advantage with Qualys is that you get a lot of features because it has been a market leader for quite a long time."
- "Qualys should improve their customer experience. They need to improve the tech support experience and the turnaround time."
- "I am not happy with the technical support because I had a very bad experience with them."
What is most valuable?
Qualys has a continuous endpoint monitoring feature for agent-based scanning. Once you deploy the solution, it monitors everything that is happening every 30 minutes. Then, if there are any vulnerabilities, they are reported. Plus, the dashboards are amazing. There are so many dashboards and things in the console that you can explore, which I think other solutions, Tenable.io for example, are still working on.
What needs improvement?
They have everything covered as far as features are concerned, but Qualys should improve their customer experience. They need to improve the tech support experience and the turnaround time.
For how long have I used the solution?
I've been working with this solution for one to two years.
What do I think about the stability of the solution?
This solution is definitely stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
I am not happy with the technical support because I had a very bad experience with them. On a scale of one to five, I would give Qualys tech support a two.
How would you rate customer service and support?
Neutral
How was the initial setup?
There were a few challenges. I had an integration issue with Qualys where they had to enable the data privacy from the back end because I couldn't integrate it with the SIEM.
What was our ROI?
The ROI is definitely good for this solution.
What's my experience with pricing, setup cost, and licensing?
Qualys is a pay-as-you-go model, so there's flexibility to the pricing.
What other advice do I have?
Everything is well-documented by Qualys. Their white paper is published and they have much visibility across the globe and on different platforms. If you look into their educational YouTube channel, you get a lot of information. There are a lot of seminars and talks on Qualys VMDR features.
The advantage with Qualys is that you get a lot of features because it has been a market leader for quite a long time. The solution has an agent-based approach and I think it is highly evolved when compared to Tenable, for example. However, Qualys is a bit highly priced so if you're looking strictly at pricing, I think you will get a better value with Tenable.
I would rate this solution as a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Has tagging system and scanners, that doesn't overload
Pros and Cons
- "I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagging system is good for tagging. We can still use QualysAgent task ID tools even if tags aren't made."
- "There's a need to upgrade or fix the potential vulnerability rate. Around 20,000 potential vulnerabilities were showing in Qualys VMDR, but none of the other tools showed them. When we checked, it wasn't the case. Support explained that even small issues were being counted as vulnerabilities, causing issues in our audit. So, the security features could be improved to identify vulnerabilities accurately."
What is our primary use case?
In our DLP operations, we use the tool to address stability issues and implement fixes suggested by it. This helps manage risk levels and decide whether to fix issues or implement workarounds.
What is most valuable?
I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagging system is good for tagging. We can still use QualysAgent task ID tools even if tags aren't made.
The asset inventory management feature has improved our security posture, which is good. It was introduced recently, and we've just started using it. In terms of management, I believe it's better than what we were using before.
Qualys VMDR is good at handling vulnerability management trends, especially with its policy module. Qualys VMDR offers customizable labels that fit the organization's needs, unlike other tools. This is important for enhancing security and meeting compliance requirements.
What needs improvement?
There's a need to upgrade or fix the potential vulnerability rate. Around 20,000 potential vulnerabilities were showing in Qualys VMDR, but none of the other tools showed them. When we checked, it wasn't the case. Support explained that even small issues were being counted as vulnerabilities, causing issues in our audit. So, the security features could be improved to identify vulnerabilities accurately.
For how long have I used the solution?
I have been working with the product for two years.
What do I think about the stability of the solution?
The stability is generally good, but we did face issues during the pandemic due to connectivity problems with Qualys VMDR servers. There were syncing issues, and agents weren't getting updated. However, we later realized it was our issue because our software needed updating. We had to manually update the proxy settings, which Qualys VMDR should have done. We managed to tackle the challenge with the help of another team.
How are customer service and support?
Support should be faster and more customer-friendly. We often have to review a lot of documentation for issues we're already aware of and follow basic steps repeatedly. Additionally, we must wait for Qualys VMDR personnel to move scans into debug mode, which can be time-consuming. Getting notifications or updates on these processes more quickly would be helpful.
How was the initial setup?
Setting up the tool doesn't take long and doesn't require many people.
What's my experience with pricing, setup cost, and licensing?
We have an annual contract for Qualys VMDR. I believe it's for either two years or five years.
What other advice do I have?
I haven't personally done any integration, so I can't comment on it. However, I believe some integration was happening between Qualys VMDR and ServiceNow. Our asset management tool was also trying to integrate with Qualys VMDR, but I'm unsure about the details or how it works. I rate the overall product an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Risk & Security Admin at Goodyear Tire & Rubber Company
It is scalable and has efficient features for scanning and detecting vulnerabilities
Pros and Cons
- "It is a stable solution."
- "We face issues while scanning multiple assets."
What is our primary use case?
We use the solution for vulnerability management.
What is most valuable?
The solution's best features are scanning and vulnerability management. By using them, we can obtain all critical reports.
What needs improvement?
They should improve the solution's pricing. Also, they should enhance the authentication feature. Presently, we face issues while scanning multiple assets. In cases of heavy workloads, it must scan assets properly.
For how long have I used the solution?
We have been using the solution for more than six years.
What do I think about the stability of the solution?
It is a stable solution.
What do I think about the scalability of the solution?
It is a scalable solution. We have more than 50,000 solution users in our organization globally.
How are customer service and support?
The solution's technical support is excellent and responsive.
How was the initial setup?
The solution's initial setup is straightforward.
What about the implementation team?
We have over 30 administrators managing the solution in our organization. In addition to installing the solution internally, we receive assistance from other vendors.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive.
What other advice do I have?
I recommend the solution to others. It is excellent. We can detect and mitigate all the vulnerabilities using it.
I rate the solution as an eight.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Consultant at Tata Consultancy
Great support, good training, and lots of great features
Pros and Cons
- "It's stable and quite reliable."
- "Almost all of the features are great."
- "There needs to be better documentation."
- "There needs to be better documentation. Maybe their price scheduler could be made simpler. It's expensive."
What is our primary use case?
Qualys has many products. However, the prominent one is for scanning the vulnerabilities on endpoints, including servers and desktops. The other can be for using multiple other products, like taking the certificate, inventory, and software inventory of endpoints through scanning.
Additionally, we use the solution for web application scanning. When they have web applications, they can scan applications for various vulnerabilities and give recommendations.
What is most valuable?
Almost all of the features are great. We use Qualys for vulnerability scanning of servers and web application scanning. These are the two prominent features that we often use.
The initial setup is very straightforward.
It's stable and quite reliable.
The product can scale.
Technical support is helpful, and the product provides a good amount of training.
What needs improvement?
Qualys has evolved a lot. It is one of the services that has evolved a lot, and we do recommend Qualys to the specs tent.
However, their products are very modular, so for customers, they need to provide some roadmap on how the customer can utilize their products. For example, starting with vulnerability scanning, they need to show how they can extend their products for multiple other use cases. They need to do a better job of educating customer more.
There needs to be better documentation.
Maybe their price scheduler could be made simpler.
It's expensive.
For how long have I used the solution?
We've been using Qualys for a long time. I've used it for more than five years.
What do I think about the stability of the solution?
It is stable. It is reliable. The solution doesn't have any bugs or glitches, and it doesn't crash or freeze.
What do I think about the scalability of the solution?
It's scalable. It's easy to expand.
Many people use the solution. There are likely more than 10,000 users.
The usage is based on the business requirements. It all depends on the service offering.
How are customer service and support?
They do offer a lot of support in the form of training for users. They also offer labs. The technical teams are reachable. Technical support is quite good with them.
How would you rate customer service and support?
Positive
How was the initial setup?
This is an easy product to set up. It's not very complex to implement.
The deployment was very fast. We could do it in about a week's time. It can be done very quickly. There are just some configurations on the cloud, and you can handle the agent deployment using some deployment tools.
What's my experience with pricing, setup cost, and licensing?
We pay an annual licensing fee.
Prices do vary. If it is for a standard solution, they are the best. If a company goes for some advanced solutions, like web scanning, it does become pricey. However, the basic solution is good. It's just the advanced solutions that drive up the price.
What other advice do I have?
I am a consultant.
I'd recommend the solution to others.
I would rate the product ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Cloud based service that offers insight into security and the vulnerability management of assets
Pros and Cons
- "The most valuable feature is the ability to run different capabilities with the same agent, and with only one agent, we can have EDR, vulnerability management, compliance and some basic SaaS security capabilities."
- "This solution could be improved by extending the agent capabilities to different operating systems including Mac and Linux. We would also like the capability to easily check for vulnerability in assets in the IOTs."
- "For a company with over 100,000 assets, there are challenges with scalability."
What is our primary use case?
We use this solution to manage compliance and to verify the gap between the policy defined by the company and the ones that are implemented in the system. We also use Qualys for vulnerability management of assets in the cloud or on-prem.
What is most valuable?
The most valuable feature is the ability to run different capabilities with the same agent. With only one agent, we can have EDR, vulnerability management, compliance and some basic SaaS security capabilities.
What needs improvement?
This solution could be improved by extending the agent capabilities to different operating systems including Mac and Linux. We would also like the capability to easily check for vulnerability in assets in the IOTs.
They have been adding additional features such as attack surface monitoring and intelligence to help managers detect additional risks. Adding intelligence is one of the most important features that we need.
For how long have I used the solution?
We have been using this solution for two years.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
For a company with over 100,000 assets, there are challenges with scalability.
How are customer service and support?
We haven't often needed support from Qualys but when we have needed it, they have been quick to respond and resolve our issues.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
If we compare Qualys VM to other vulnerability management solutions like Tenable, Qualys is only for agents. Their on-prem capabilities are pretty limited so it is very easy to manage assets that are cloud connected, but if they are not cloud connected, it is challenging. Tenable is better at managing non-cloud connected agents.
How was the initial setup?
The initial setup is straightforward. After the cloud tenant is available and the agents are installed, the first scans can be done in one to two days.
There is maintenance required for the agents but it is completely controlled by the cloud and is done automatically. There is a necessity for human intervention when there is a new agent or new feature that must be tested before it is implemented.
What about the implementation team?
We implemented the solution in-house.
What was our ROI?
Return of investment is difficult to assess because it's a tool that helps to reduce risks but doesn't have a direct feature on ROI.
What's my experience with pricing, setup cost, and licensing?
It is a high cost product. Compared to the other solutions, it is around 15 to 20% higher in cost. Qualys VMDR has multiple features in addition to vulnerability management and there is an additional cost for these features.
What other advice do I have?
The initial setup is not straightforward and it's important to have the agent connectivity linked to the cloud and available all the time.
If you have assets that are not connected to the cloud, you will need help from a service provider or integrator because the introduction of passive scanning is not straightforward.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Vulnerability Management IT Asset Management Configuration Management Databases Container Security Risk-Based Vulnerability ManagementPopular Comparisons
ServiceNow
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Checkmarx One
Prisma Cloud by Palo Alto Networks
Tanium
NinjaOne
TrendAI Vision One – Cloud Security
Orca Security
CrowdStrike Falcon Cloud Security
Tenable Nessus
Zafran Security
Qualys TotalCloud
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Qualys VM vs Tenable Nessus: Comparison
- How does Tenable Nessus compare with Qualys VM?
- How does Pentera compare with Qualys VMDR?
- What are the main differences between Qualys VMDR and Tenable Nessus?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?





















