It is a SaaS solution with agents distributed at endpoints.
Principal at Cranny Group
Good return on investment, ease of deployment, and metrics
Pros and Cons
- "The Vulnerability Management and Patch Management features are the most valuable features of this solution."
- "Endpoint stability and fault resolution could be improved."
What is our primary use case?
How has it helped my organization?
Qualys VM has improved the way the organization functions.
What is most valuable?
The Vulnerability Management and Patch Management features are the most valuable features of this solution.
The most valuable qualities of Qualys VM are its ease of deployment and metrics.
What needs improvement?
Endpoint stability and fault resolution could be improved.
I would like to see the solution's footprint expanded to include iOS and iPads in the next release.
One example of how it could be better would be better handling of end-of-life systems and better feedback on job failures.
Buyer's Guide
Qualys VMDR
June 2025

Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
For how long have I used the solution?
We have been working with Qualys VM for just over two years.
It is a cloud platform. I'm not sure if a version is associated with that.
What do I think about the stability of the solution?
The stability of Qualys VM is quite good, but not fantastic. I would rate it an eight out of ten.
What do I think about the scalability of the solution?
The scalability of Qualys VM is very good.
This solution is used by five security or system administrators in our organization.
We have no plans to expand our usage; it is already widely deployed.
How are customer service and support?
The technical support is mediocre at best.
I would rate them a two out of five.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We were previously using Lansweeper, which was not scalable.
How was the initial setup?
I would rate the initial setup a three out of five.
It took several weeks to deploy.
What about the implementation team?
We completed the deployment in-house.
What was our ROI?
We have seen a return on investment.
What's my experience with pricing, setup cost, and licensing?
There are no additional fees in addition to the standard licensing fees.
What other advice do I have?
I would recommend identifying the right metrics to drive the program.
I would rate Qualys VM an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Manager, Info Security Planning & Architecture at a comms service provider with 10,001+ employees
A great help to improve and maintain security
Pros and Cons
- "The most valuable features are vulnerability scanning, policy compliance scanning, and tablet for web application scanning."
- "Sometimes the scanning can get overwhelmed and start to drag when a lot of users are trying to scan at once."
What is our primary use case?
I mainly use Qualys VM for vulnerability management to carry out vulnerability scans on IT assets to find out which are vulnerable and what is needed to patch them. We also use it for policy compliance scans and in tablet for web application scans.
How has it helped my organization?
Qualys VM has greatly helped us to improve and maintain our posture of security.
What is most valuable?
The most valuable features are vulnerability scanning, policy compliance scanning, and tablet for web application scanning.
What needs improvement?
Sometimes the scanning can get overwhelmed and start to drag when a lot of users are trying to scan at once. I think cloud-based solutions like Qualys VM should be prepared to throw more resources in to ensure they don't get overwhelmed like this.
For how long have I used the solution?
I've been using Qualys VM for about six years.
What do I think about the stability of the solution?
The stability and performance have been fine.
What do I think about the scalability of the solution?
Qualys VM is very easy to scale - that's one of the benefits of cloud-based solutions.
How are customer service and support?
Qualys' technical support is very responsive.
How was the initial setup?
Qualys VM is straightforward to set up.
What about the implementation team?
The deployment was done in-house.
What other advice do I have?
I would advise anybody looking into using Qualys to go online to also check on Gartner and Forrester. From a planning perspective, you need to look at your estate to determine what kind of tool you need. I would rate Qualys VM eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Qualys VMDR
June 2025

Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
Senior Manager Network Design at MEEZA, Managed IT Services Provider
Versatile features, highly scalable, and beneficial reports
Pros and Cons
- "The most valuable features of Qualys VM are its ability to do proper vulnerability assessment. It has a lot of updates for all the vulnerability databases from all over the globe. It's an amazing solution when it comes to the versatility of the features it has. Additionally, the reports are very good. It generates very detailed reports about the vulnerabilities inside the environment"
- "Qualys VM could improve by having more skilled support personnel."
What is our primary use case?
We use bother on-premise and cloud deployments of Qualys VM. For my clients in the cloud, we use a cloud solution, which is a bring your own license model. Additionally, We have our own deployment of Qualys VM.
We are using Qualys VM to provide a VM service.
What is most valuable?
The most valuable features of Qualys VM are its ability to do proper vulnerability assessment. It has a lot of updates for all the vulnerability databases from all over the globe. It's an amazing solution when it comes to the versatility of the features it has. Additionally, the reports are very good. It generates very detailed reports about the vulnerabilities inside the environment
For how long have I used the solution?
I have been using Qualys VM for approximately five years.
What do I think about the stability of the solution?
Qualys VM is a highly stable solution.
How are customer service and support?
Qualys VM could improve by having more skilled support personnel.
How was the initial setup?
The initial setup of Qualys VM is straightforward. The full implementation took us approximately one day.
What about the implementation team?
We have approximately 100 people who are part of our technical team. We did the implementation of this solution.
What's my experience with pricing, setup cost, and licensing?
There is a license for the use of this solution. We pay annually instead of monthly to receive a better discount on the price.
What other advice do I have?
I would recommend this solution to others.
I rate Qualys VM a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CIO at Oakmount
A powerful virtual scanner appliance that scans batch files, BIT files, and compact files.
Pros and Cons
- "This is one of the best products I have worked with so far. I like the power of Qualys, and it's a better solution because you can scan a compact file, a BIT file, or batch files. The product already knows what's happening inside, and you don't need to expand the package. Tenable will do the same thing, but you need to have a package issuance claim. With Qualys, we can immediately understand the file, even a compact file. If there's some kind of discovery or incident, you will know what happened in the environment."
- "Integration could be better. When you think about scanning, it's not used just with this product alone but with other Qualys products. If you think about the bundle, the product itself is good. But integration with other products and packages has space for improvement. They should also offer a better price for bundles."
What is our primary use case?
We use Qualys Virtual Scanner Appliance for the big scan.
What is most valuable?
This is one of the best products I have worked with so far. I like the power of Qualys, and it's a better solution because you can scan a compact file, a BIT file, or batch files. The product already knows what's happening inside, and you don't need to expand the package. Tenable will do the same thing, but you need to have a package issuance claim. With Qualys, we can immediately understand the file, even a compact file. If there's some kind of discovery or incident, you will know what happened in the environment.
What needs improvement?
Integration could be better. When you think about scanning, it's not used just with this product alone but with other Qualys products. If you think about the bundle, the product itself is good. But integration with other products and packages has space for improvement. They should also offer a better price for bundles.
For how long have I used the solution?
I have been using Qualys Virtual Scanner Appliance since I joined my company three years ago.
What do I think about the stability of the solution?
Qualys Virtual Scanner Appliance is very stable.
What do I think about the scalability of the solution?
Qualys Virtual Scanner Appliance is scalable.
How was the initial setup?
The initial setup is straightforward. You only need one technician to deploy and maintain this solution. However, it really depends on the size of the customer's environment.
What's my experience with pricing, setup cost, and licensing?
Qualys Virtual Scanner Appliance isn't expensive right now. But the price for their product bundles could be better.
What other advice do I have?
I would advise potential users to look into the environment and understand what they want to do before implementing this solution. They must understand how to communicate with the network and what kind of network they want to put together. Just read the manual first.
On a scale from one to ten, I would give Qualys Virtual Scanner Appliance a nine.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Vice President | Information Security at a financial services firm with 1,001-5,000 employees
Very intuitive, easy going and simple to use
Pros and Cons
- "Intuitive and easy to use."
- "Reports were lacking somewhat on the customization side."
What is our primary use case?
I used this solution for one of my clients and the primary use case was for the compliance mode and scanning. We are customers of Qualys and I am senior vice president information security.
What is most valuable?
I found the solution quite intuitive and easy going. I have worked with other similar tools and found this simple to use.
What needs improvement?
I felt hindered sometimes within reports in that they were lacking somewhat on the customization side in terms of making use of the data. The cloud user interface could be a little more responsive. It was a click and then a wait.
For how long have I used the solution?
I used this solution recently for about five months.
What do I think about the stability of the solution?
There were a couple of small bugs but the solution was stable.
What other advice do I have?
I would recommend this solution and rate it a nine out of 10.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Lead Cyber Security engineer at a manufacturing company with 10,001+ employees
Provides an overview of the inventory assessment process and can be accessed across the company
Pros and Cons
- "It gives a very good overview of the inventory assessment process, and it can be accessed across our company because it's a global tool."
- "It's not very user-friendly at times and requires in-depth understanding. So, a layman or someone new to Qualys won't be able to easily understand it. You need education to use the solution."
What is our primary use case?
We use Qualys Asset Inventory for doing infrastructure level scans or server inventory, or saving the server database or asset database.
How has it helped my organization?
Good Posture of Servers database. Gives easy access of all hardware details.
What is most valuable?
I think it's a good tracking mechanism, and it gives a good infrastructure level scan, which helps us to maintain the assets and the asset inventory or gives us a good understanding of both.
It gives a very good overview of the inventory assessment process.
IT Manages assets in your account that you want to scan for security and
compliance, define asset tags and AWS connectors.
Modules supported
VM, PC, SCA, CERTVIEW, CLOUDVIEW
It can be accessed across our company because it's a global tool.
What needs improvement?
One thing that can be improved is the flexibility and the fact that Qualys Asset Inventory provides too much detail, which makes it not very easy to understand. It's not very user-friendly at times and requires in-depth understanding. So, a layman or someone new to Qualys won't be able to easily understand it. You need education to use the solution.
As for additional features, the first thing would be providing call support whenever we require any kind of help with issues that have been identified. The second would be a simple reporting structure.
For how long have I used the solution?
I've been using Qualys Asset Inventory within the last 12 months.
What do I think about the stability of the solution?
Stability-wise, Qualys Asset Inventory is always stable, and for this particular asset inventory, it is a good tool. We have not had any kind of issues, and as of now, it's a stable environment.
What do I think about the scalability of the solution?
We currently have 50 plus users and have no plans to increase usage at present.
How are customer service and technical support?
Most of the time technical support has been through emails; calling is a back feature. It's not as easy compared to that of Veracode.
How was the initial setup?
The initial setup was quite complex and took two to three months, including customization and testing.
What's my experience with pricing, setup cost, and licensing?
The license is on a yearly basis.
What other advice do I have?
If you are familiar with or have hands on experience with Qualys Asset Inventory, this is a better tool. It will give you in-depth details of all the assets, and the managing inventory will be better. It will also give you advanced features compared to those of other inventory tools.
I would rate Qualys Asset Inventory at eight on a scale from one to ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. Manager, Vulnerability Management at a transportation company with 10,001+ employees
User-friendly, supports multiple platforms, and the VM DR capabilities are helpful
Pros and Cons
- "The features that are most valuable are the identification, scan features, and the identification of vulnerabilities."
- "I would like to see more accuracy in detections, better reporting capabilities, and better dashboard download capabilities."
What is our primary use case?
We are using Qualys VM, as our scanner tool. We also use it for Application Security and Policy Compliance.
We use it for the identification of vulnerabilities for all of our devices on the network. This includes Windows workstations, servers, and Linux machines. We also use it for cloud, and external use as well.
What is most valuable?
The features that are most valuable are the identification, scan features, and the identification of vulnerabilities. Recently, the VMDR additions and the threat protection has been useful.
It's pretty user-friendly.
What needs improvement?
The Patch Identifications, which are supersedence identifications, need improvement.
I would like to see more accuracy in detections, better reporting capabilities, and better dashboard download capabilities. These are things that are definitely needed.
For how long have I used the solution?
I have been using Qualys VM for more than 15 years.
We are using the latest version.
VMDR was added in July with newer enhancements.
What do I think about the stability of the solution?
It's a stable solution.
What do I think about the scalability of the solution?
It's very scalable for large networks. We have also used the agents and they work very well.
I have a team of five in our organization and external to it, there are approximately twenty-five.
How are customer service and technical support?
We engage with technical support often. There could be some improvements made.
How was the initial setup?
The initial setup is straightforward.
What's my experience with pricing, setup cost, and licensing?
It is different for every company, but for us, it's every three years. I will know more about the pricing in September because we are going to be looking at our pricing again.
We get a large volume discount, which is good.
What other advice do I have?
I would recommend this product to others who are interested in using it.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Global Infrastructure Architect at a energy/utilities company with 5,001-10,000 employees
Good technical support that is always there when you need them, but the prioritization of vulnerabilities needs to be improved
Pros and Cons
- "Technical support is great and we've never really had a problem."
- "We are moving away from Qualys to Defender ATP because I find that Defender ATP is much better at prioritizing the vulnerabilities that I should be looking at."
What is our primary use case?
We are currently using Qualys for vulnerability detection, as part of our security solution. We're moving towards Defender ATP because I am looking more at the Operational Technology (OT) side of things than I am at the Information Technology (IT) side.
What is most valuable?
What I like best about this product is that it does what it is supposed to do, which is vulnerability scanning.
What needs improvement?
We are moving away from Qualys to Defender ATP because I find that Defender ATP is much better at prioritizing the vulnerabilities that I should be looking at.
In general, I would like to see some better analytics and prioritization of vulnerabilities.
For how long have I used the solution?
We have been working with Qualys VM for three years.
What do I think about the stability of the solution?
Qualys VM is a stable solution.
What do I think about the scalability of the solution?
This is a stable product.
How are customer service and technical support?
Technical support is great and we've never really had a problem. They're always there if we need them.
Which solution did I use previously and why did I switch?
We did not work with another similar solution prior to Qualys.
How was the initial setup?
The initial setup is straightforward.
Our setup involved some on-premises deployments but ultimately, it uses the cloud.
What's my experience with pricing, setup cost, and licensing?
They have recently changed the pricing model, which is now better than it was before.
Which other solutions did I evaluate?
Right now, we don't have anything in our OT environment, and this is what I am particularly interested in. I am currently having discussions about new solutions with Qualys, Tenable, and Forescout.
What other advice do I have?
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Vulnerability Management IT Asset Management Configuration Management Databases Container Security Risk-Based Vulnerability ManagementPopular Comparisons
ServiceNow
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
SentinelOne Singularity Cloud Security
Tenable Nessus
Tanium
Tenable Security Center
CrowdStrike Falcon Cloud Security
Orca Security
Tenable Vulnerability Management
Rapid7 InsightVM
JFrog Xray
Acunetix
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Qualys VM vs Tenable Nessus: Comparison
- How does Tenable Nessus compare with Qualys VM?
- How does Pentera compare with Qualys VMDR?
- What are the main differences between Qualys VMDR and Tenable Nessus?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?