We're primarily using the solution for vulnerability assessment of internal server as well as the external server.
AVP - Information Security at a financial services firm with 10,001+ employees
Easy to use and scalable but needs to be priced more competitively
Pros and Cons
- "It is very easy to use and there are lots of options. We can usually easily go through it and all of the things we want to configure, and we can configure everything to our specifications very easily."
- "Sometimes we face a problem with accessing the tool and not getting an expected result. From a technology point of view, they need to look into this."
What is our primary use case?
What is most valuable?
The solution, overall, is very useful for our organization.
It is very easy to use and there are lots of options. We can usually easily go through it and all of the things we want to configure, and we can configure everything to our specifications very easily.
What needs improvement?
Sometimes we face a problem with accessing the tool and not getting an expected result. From a technology point of view, they need to look into this.
They need to consider how they can improve tool usability and different scanning options.
Sometimes we are facing issues while performing a scan and things are not correctly shown on the GUI. Even as we are doing a task, it may show up as completed, and then something is not visible. Sometimes we face other technical problems. For example, sometimes we can't go to the next page. It's limiting any positive results.
The solution needs to be easier to understand and configure.
The pricing is a bit on the higher side compared to other products in the industry.
For how long have I used the solution?
I've been dealing with the solution for the last five or six years now. It's been a while.
Buyer's Guide
Qualys VMDR
June 2025

Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
What do I think about the stability of the solution?
I haven't had any issues with stability. It's been okay.
What do I think about the scalability of the solution?
I don't see any issues with scalability. When we do multiple IP scans, when we require an increase in the number of IPs, we won't have any problem doing so.
How are customer service and support?
The technical support has been fine. We're getting the required support we need when we need it. I'd say we're pretty satisfied in that regard.
What's my experience with pricing, setup cost, and licensing?
I find the pricing to be a bit high, especially compared to the competition.
Which other solutions did I evaluate?
While we didn't evaluate other options previously, currently, we are looking at all sorts of vulnerability management solutions and that's including Kenna and RiskSense.
Although Qualys has come up with the model, I've not really looked that far into their other offerings. There is the possibility of upgrading the model on the part of vulnerability management. We'll see if we change solutions or decide to upgrade instead.
We've also looked at Tenable, which is easier to understand and configure.
What other advice do I have?
We are a Qualys customer. We aren't a reseller or partner.
Overall I'd rate the solution seven out of ten.
We are currently looking at other options, to see if there's a better solution out there. This one has pretty good technical support and is easy to use, however, there are other issues associated with it.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Enterprise Security Architect at a energy/utilities company with 10,001+ employees
Vulnerability scanner with good dashboard presentation and clear reporting
Pros and Cons
- "What I like about Qualys VM is the dashboard presentation. It's very good."
- "The customer support is very bad."
What is our primary use case?
The primary use cases of this solution are as a scanner. We use it with Azure and AWS. For on-premises, we use physical scanners all over the globe. We have deployed our external scanners in approximately 70 regions.
What is most valuable?
What I like about Qualys VM is the dashboard presentation. It's very good.
The reporting capability and executive reporting are very good.
What needs improvement?
Customer support needs to be improved because it was not to our SLA standards.
Suddenly, the scan engine will go down. We don't know what the reason is, or how it goes down. Because of that, the business is impacted.
I had a look at the PCI reports (policy compliance reports) and I have heard that most memberships have been taken by Azure, although I was not aware of that. I would like to see more documentation or awareness.
For how long have I used the solution?
I have worked with Qualys VM for the last two years.
What do I think about the stability of the solution?
This solution is stable.
What do I think about the scalability of the solution?
The scalability is good.
How are customer service and technical support?
The customer support is very bad. When we submit a ticket, we do not get a response immediately.
Which solution did I use previously and why did I switch?
Previously, I have used Rapid 7 Nexpose. They are similar solutions although what Qualys is providing, it provides well but requires less. Qualys reporting is better.
Nexpose has upgraded too, and now their reporting is also very good.
How was the initial setup?
The initial setup was straightforward and we didn't have any issues with it.
What other advice do I have?
If you are comparing Nexpose and Qualys, I would prefer Qualys. The UI is good and whatever reports you are getting, are very clear. If you present it to management, the reports are good. They require an executive report that highlights the vulnerability and how many servers are affected. You can customize it also.
Nexpose is coming out with new features, but Qualys has already implemented them.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Qualys VMDR
June 2025

Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
DevOps Engineer at a financial services firm with 501-1,000 employees
Detailed reports and the remediation, but interface needs improvements
Pros and Cons
- "The most valuable feature of Qualys Container Security is the detailed information in the reports and the remediation. This is done to make sure there are no vulnerabilities."
- "Qualys Container Security can improve the interface. It could be easier to navigate and be enriched."
What is our primary use case?
Qualys Container Security scans similar to a runtime container and it scans the entire cluster.
What is most valuable?
The most valuable feature of Qualys Container Security is the detailed information in the reports and the remediation. This is done to make sure there are no vulnerabilities.
What needs improvement?
Qualys Container Security can improve the interface. It could be easier to navigate and be enriched.
In a future release, it would be beneficial if the network and port policies we provided with some kind of automation AML script files. Having configuration files related to Kubernetes environments would be helpful.
For how long have I used the solution?
I have been using one year.
What do I think about the stability of the solution?
Qualys Container Security is stable.
What do I think about the scalability of the solution?
The scalability of Qualys Container Security is good.
How are customer service and support?
I have used the support from Qualys Container Security and they could improve their knowledge.
I rate the support from Qualys Container Security a two out of five.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have not used another similar solution prior to Qualys Container Security.
How was the initial setup?
The initial setup of Qualys Container Security is complex. The documentation could improve.
I rate the initial setup of Qualys Container Security a three out of five.
What other advice do I have?
I rate Qualys Container Security a six out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
President and CEO at a non-profit with 11-50 employees
Excellent intelligence and real-time inventory of vulnerabilities
Pros and Cons
- "Qualys VM has allowed us to know the vulnerabilities we need to prioritize based on the threat levels and the possible impact if there's an intrusion."
- "Qualys VM's machine learning and artificial intelligence features could be improved."
What is our primary use case?
I mainly use Qualys VM for CSAM, to complement vulnerability management on our assets, and to check for intrusions through our email gateways.
How has it helped my organization?
Qualys VM has allowed us to know the vulnerabilities we need to prioritize based on the threat levels and the possible impact if there's an intrusion. It also provides a view of inventories and vulnerabilities in the containers running on my infrastructure, which helps me to do better roadmapping on where I need to put my resources.
What is most valuable?
Qualys VM's best features are its machine-learning-backed intelligence, real-time inventory of vulnerabilities, backup, threat intelligence exposure database, and that it doesn't hold on to infrastructure resources like memory.
What needs improvement?
Qualys VM's machine learning and artificial intelligence features could be improved.
For how long have I used the solution?
I've been using Qualys VM for over a year.
What do I think about the stability of the solution?
I've had no issues with Qualys VM's stability.
What do I think about the scalability of the solution?
Qualys VM is scalable.
How are customer service and support?
Qualys has an impeccable, readily available technical support team.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is very simple - it's just a deploy-and-run.
What's my experience with pricing, setup cost, and licensing?
Qualys VM is reasonably priced.
What other advice do I have?
I would rate Qualys VM as nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Country Sales Lead at securic systems
Vulnerability management tool that integrates well with other products
Pros and Cons
- "The integrations for this solution are very good. I use a different product for virtual patching of vulnerabilities and Qualys integrates well with that product."
- "Qualys does have an on-prem solution, but it is very expensive."
What is most valuable?
The integrations for this solution are very good. I use a different product for virtual patching of vulnerabilities and Qualys integrates well with that product.
What needs improvement?
Qualys does have an on-prem solution, but it is very expensive.
For how long have I used the solution?
I have used this solution for six months.
What other advice do I have?
I would rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
GM Network Information Security at a tech services company with 1,001-5,000 employees
Helpful support and scalable
Pros and Cons
- "Qualys VM had a recent upgrade and the newer version is supporting the cloud."
- "The reporting and dashboards could improve in Qualys VM. However, they have improved since the previous versions."
What is most valuable?
Qualys VM had a recent upgrade and the newer version is supporting the cloud.
What needs improvement?
The reporting and dashboards could improve in Qualys VM. However, they have improved since the previous versions.
For how long have I used the solution?
I have been using Qualys VM for approximately 10 years.
What do I think about the scalability of the solution?
Qualys VM is highly scalable.
How are customer service and support?
The technical support was very good from Qualys VM.
What was our ROI?
Qualys VM helps to identify the vulnerabilities on a timely basis. It helps the companies to upgrade their networks and apply patches. In the latest version, it has added the patching capability, it's very useful.
What other advice do I have?
My advice to others is this is one of the top solutions in its category. However, they can evaluate many solutions to see for themselves.
I would recommend this solution to others to implement it in their network.
I rate Qualys VM an eight out of ten
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director for global support at a tech vendor with 1,001-5,000 employees
A comprehensive, scalable, and easy-to-deploy platform with a nice UI
Pros and Cons
- "The vulnerability management feature is what I used the most. It is a good SaaS product. It is easy to use. It has a nice UI where you can see all the assets and vulnerabilities."
- "Certain integration factors between different options could be improved."
What is our primary use case?
It is for vulnerability management. I used it in my previous company, and I also used it for my home network.
It is a SaaS platform. So, there is always the latest version.
What is most valuable?
The vulnerability management feature is what I used the most. It is a good SaaS product. It is easy to use. It has a nice UI where you can see all the assets and vulnerabilities.
What needs improvement?
Certain integration factors between different options could be improved.
For how long have I used the solution?
I worked with this solution for two years.
What do I think about the stability of the solution?
Its stability and performance are good.
What do I think about the scalability of the solution?
People use it for hundreds and thousands of assets, so it is definitely scalable.
How are customer service and support?
I used to run technical support there. So, I didn't need to go for support.
How was the initial setup?
It is easy and straightforward to set it up. It takes 5 to 10 minutes to set up a new asset.
What's my experience with pricing, setup cost, and licensing?
I used to work there, so I never paid for the product. As an employee, we get a lifetime license for personal use, and that's what I'm using.
It is a comprehensive platform, so there is a lot more to it. There could be other solutions that are probably a little bit cheaper, but it depends on what people need. Different people have different needs. It offers many things on the same platform. If you add all the things up, it should be cheaper, but I have not done any analysis specifically.
What other advice do I have?
It is a good product. I would recommend it to others. It had whatever I needed for my personal use case. There are a lot of features that I have not explored. Some of the features are applicable for corporate networks, and they can't be used for personal use cases.
I would rate it a nine out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Professional services team lead at a tech services company with 1,001-5,000 employees
The reporting and GUI need improvement but it's reliable
Pros and Cons
- "Qualys VM is very stable."
- "The reporting and the GUI need improvements."
What is our primary use case?
It was responsible for vulnerability scanning. It enforces vulnerability management websites.
What needs improvement?
The reporting and the GUI need improvements. Tenable dominated in these two areas: reporting and graphical user interface.
For how long have I used the solution?
Qualys VM was used once for one of our customers.
We were using the latest version.
What do I think about the stability of the solution?
Qualys VM is very stable.
What do I think about the scalability of the solution?
I didn't have all of the necessary information regarding the scalability or how to scale this solution, but all vulnerability management solutions have the same idea.
I believe that it is easy to scale.
How are customer service and support?
I did not contact technical support.
Which solution did I use previously and why did I switch?
I have also used Rapid7, which is very similar to Qualys VM.
Scaling is more difficult with Rapid7. When it comes to scaling, Rapid7 is not my first choice.
How was the initial setup?
I did not implement this solution, I performed one scan for our client.
What other advice do I have?
We have regulations in place in Saudi Arabia and Egypt that require all vulnerability management solutions to be implemented on-premise.
I would recommend this solution to others but Tenable is my preferred option.
I would rate Qualys VM a five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Vulnerability Management IT Asset Management Configuration Management Databases Container Security Risk-Based Vulnerability ManagementPopular Comparisons
ServiceNow
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
SentinelOne Singularity Cloud Security
Tenable Nessus
Tanium
Tenable Security Center
CrowdStrike Falcon Cloud Security
Orca Security
Tenable Vulnerability Management
Rapid7 InsightVM
JFrog Xray
Acunetix
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Qualys VM vs Tenable Nessus: Comparison
- How does Tenable Nessus compare with Qualys VM?
- How does Pentera compare with Qualys VMDR?
- What are the main differences between Qualys VMDR and Tenable Nessus?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?