No more typing reviews! Try our Samantha, our new voice AI agent.
it_user1189266 - PeerSpot reviewer
Consultant at a tech services company with 11-50 employees
Reseller
Jan 14, 2021
Provides excellent security for scanning, flexible with good integration
Pros and Cons
  • "Great web application security for scanning."
  • "I like the solution's web application security for scanning, the solution is flexible with good integration."
  • "I'd like to see additional security for the app."

What is our primary use case?

We are consultants and resellers of Qualys VM. 

What is most valuable?

I like the solution's web application security for scanning, the solution is flexible with good integration. 

What needs improvement?

I'd like to see additional security for the app. The product lacks integrations for third party solutions or automation integration for other tools.

For how long have I used the solution?

I've been using this solution for six months. 

Buyer's Guide
Qualys VMDR
June 2026
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,838 professionals have used our research since 2012.

What do I think about the stability of the solution?

The product is 100% stable. There are five users in the company who deal with operations and security analysis. There are four people in the company who deploy and provide support.

How are customer service and support?

I've never used the technical support. Documentation is simple and complete. 

Which solution did I use previously and why did I switch?

I've previously worked with Tenable IO and Rapid 7. We switched because of Qualys's web application feature.

How was the initial setup?

The initial setup is straightforward. Initial deployment takes between two and four hours. We did it ourselves. 

What other advice do I have?

I would recommend this solution. 

I would rate this solution a 10 out of 10. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
reviewer1460919 - PeerSpot reviewer
Global Infrastructure Architect at a energy/utilities company with 5,001-10,000 employees
Real User
Dec 4, 2020
Good technical support that is always there when you need them, but the prioritization of vulnerabilities needs to be improved
Pros and Cons
  • "Technical support is great and we've never really had a problem."
  • "What I like best about this product is that it does what it is supposed to do, which is vulnerability scanning."
  • "We are moving away from Qualys to Defender ATP because I find that Defender ATP is much better at prioritizing the vulnerabilities that I should be looking at."

What is our primary use case?

We are currently using Qualys for vulnerability detection, as part of our security solution. We're moving towards Defender ATP because I am looking more at the Operational Technology (OT) side of things than I am at the Information Technology (IT) side.

What is most valuable?

What I like best about this product is that it does what it is supposed to do, which is vulnerability scanning.

What needs improvement?

We are moving away from Qualys to Defender ATP because I find that Defender ATP is much better at prioritizing the vulnerabilities that I should be looking at.

In general, I would like to see some better analytics and prioritization of vulnerabilities.

For how long have I used the solution?

We have been working with Qualys VM for three years.

What do I think about the stability of the solution?

Qualys VM is a stable solution.

What do I think about the scalability of the solution?

This is a stable product.

How are customer service and technical support?

Technical support is great and we've never really had a problem. They're always there if we need them.

Which solution did I use previously and why did I switch?

We did not work with another similar solution prior to Qualys.

How was the initial setup?

The initial setup is straightforward.

Our setup involved some on-premises deployments but ultimately, it uses the cloud.

What's my experience with pricing, setup cost, and licensing?

They have recently changed the pricing model, which is now better than it was before.

Which other solutions did I evaluate?

Right now, we don't have anything in our OT environment, and this is what I am particularly interested in. I am currently having discussions about new solutions with Qualys, Tenable, and Forescout.

What other advice do I have?

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Qualys VMDR
June 2026
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,838 professionals have used our research since 2012.
reviewer1342815 - PeerSpot reviewer
Consultant at a media company with 51-200 employees
Real User
Nov 25, 2020
Enables us to check the validity of legacy applications, infrastructure, and simple data operating systems
Pros and Cons
  • "The initial setup was good. We didn't have any problems with it."
  • "The ability to manage user accounts and give rights to the operator to know about abnormalities of applications is something that needs improvement."

What is our primary use case?

I use Qualys to review the validity of legacy applications, infrastructure, and simple data operating systems.

What needs improvement?

The ability to manage user accounts and give rights to the operator to know about abnormalities of applications is something that needs improvement. 

The pricing is also expensive.

For how long have I used the solution?

I have been using Qualys for four years. 

What do I think about the stability of the solution?

It's stable.

How are customer service and technical support?

I haven't needed to use technical support. 

How was the initial setup?

The initial setup was good. We didn't have any problems with it. 

What other advice do I have?

I would rate Qualys VM a ten out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1307133 - PeerSpot reviewer
IT Consultant Supervisor at a financial services firm with 5,001-10,000 employees
Consultant
Apr 16, 2020
Scans our security posture and has very good scalability
Pros and Cons
  • "It's a good product. After the scan our internet works well. It scans our security posture."
  • "Qualys help identifies the weakness in our critical infrastructure and provides guidelines how to address them."
  • "The reporting needs improvement. It should generate much more stuff like field reports."

What is our primary use case?

We use Qualys to check the status of our security posture.

How has it helped my organization?

Qualys help identifies the weakness in our critical infrastructure and provides guidelines how to address them.

What is most valuable?

maybe compliance monitoring.

What needs improvement?

Reporting can be improved more. It should generate much more stuff like field reports. Though the reports generally meet our need we hope we can customize it better.

For how long have I used the solution?

2 years

What do I think about the stability of the solution?

very satisfactory

What do I think about the scalability of the solution?

Its scalability is a four or five out of five. 

How are customer service and technical support?

We haven't had problems up until this point that required technical support. The solution can run by itself and generate reports. We didn't have any issues that would need us to call technical support.

Which solution did I use previously and why did I switch?

None

How was the initial setup?

Simple and straightforward

What about the implementation team?

in-house.

What was our ROI?

acceptable.

What's my experience with pricing, setup cost, and licensing?

I would give the pricing three out of five.

Which other solutions did I evaluate?

No.

What other advice do I have?

I would like for Qualys to have the ability to scan OT operation technology assets as well. 

If it can I would rate it 8 out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Anusha Sadasivani - PeerSpot reviewer
Enterprise Security Architect at a energy/utilities company with 10,001+ employees
Real User
Top 20
Mar 11, 2020
Vulnerability scanner with good dashboard presentation and clear reporting
Pros and Cons
  • "What I like about Qualys VM is the dashboard presentation. It's very good."
  • "If you are comparing Nexpose and Qualys, I would prefer Qualys."
  • "The customer support is very bad."
  • "The customer support is very bad; when we submit a ticket, we do not get a response immediately."

What is our primary use case?

The primary use cases of this solution are as a scanner. We use it with Azure and AWS. For on-premises, we use physical scanners all over the globe. We have deployed our external scanners in approximately 70 regions.

What is most valuable?

What I like about Qualys VM is the dashboard presentation. It's very good.

The reporting capability and executive reporting are very good.

What needs improvement?

Customer support needs to be improved because it was not to our SLA standards.

Suddenly, the scan engine will go down. We don't know what the reason is, or how it goes down. Because of that, the business is impacted.

I had a look at the PCI reports  (policy compliance reports) and I have heard that most memberships have been taken by Azure, although I was not aware of that. I would like to see more documentation or awareness.

For how long have I used the solution?

I have worked with Qualys VM for the last two years.

What do I think about the stability of the solution?

This solution is stable.

What do I think about the scalability of the solution?

The scalability is good.

How are customer service and technical support?

The customer support is very bad. When we submit a ticket, we do not get a response immediately.

Which solution did I use previously and why did I switch?

Previously, I have used Rapid 7 Nexpose. They are similar solutions although what Qualys is providing, it provides well but requires less. Qualys reporting is better.

Nexpose has upgraded too, and now their reporting is also very good.

How was the initial setup?

The initial setup was straightforward and we didn't have any issues with it.

What other advice do I have?

If you are comparing Nexpose and Qualys, I would prefer Qualys. The UI is good and whatever reports you are getting, are very clear. If you present it to management, the reports are good. They require an executive report that highlights the vulnerability and how many servers are affected. You can customize it also.

Nexpose is coming out with new features, but Qualys has already implemented them.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1228836 - PeerSpot reviewer
Solutions Architect at a tech services company with 10,001+ employees
Real User
Jan 30, 2020
A lightweight solution with good reporting, but multi-cloud support should be improved
Pros and Cons
  • "The most valuable feature is that this solution is very lightweight."
  • "I would like to see this solution simplified to work more easily in a multi-cloud environment."

What is our primary use case?

We are a solution provider and this is one of the products that we implement for our clients. We do a lot of work with containers. With respect to containerization, security is important for us and we regularly check the market to see what solutions are available in these areas.

This solution is primarily used for container security and compliance. Moving into any environment, in particular, one that is cloud-based, our clients want to make sure that things are okay from a compliance perspective. We generate reports and they can see whether there are any violations. If they see violations or security breaches during the audit then they have to be addressed.

What is most valuable?

The most valuable feature is that this solution is very lightweight.

What needs improvement?

I would like to see this solution simplified to work more easily in a multi-cloud environment. One of our customers has more than 3,000 servers across multiple regions, and they were asking about security and vulnerability checking in an automated fashion. This could be done with a cloud-based service that monitors all of the deployments, pulls the data from the containers, and checks for compliance.

For how long have I used the solution?

We have been dealing with Qualys for at least three years, which is when our container journey began. At that point, our proposals did not deal with security for containers because our customers did not ask for it, but now it is something that we recommend.

How are customer service and technical support?

The technical support for this solution is good. We are required to solve any kind of security issue whin two hours, so these are critical tickets. The entire instance usually has to come down until the fix is delivered.

Which other solutions did I evaluate?

We often demonstrate these types of tools to the enterprise architecture team, who will ultimately decide which solutions they are going to implement based on their environment and requirements.

We are completely agnostic with respect to which tools our customers decide to implement. As an engineering team, we implement what the customer wants. In the case of Qualys and other solutions, we download the information and pass it along to our customers. We also facilitate or set up communication between vendors and customers to best help our clients.

We do try to learn about who the providers are and what differentiates their solutions from others. Sometimes our customers do not know very much about the products, so we try to provide as much insight as possible to facilitate their decision making. 

What other advice do I have?

A lot of our customers have a workload that is scattered across a multi-cloud environment. This means that some of the RFPs we answer are based on very large landscapes with distributed workloads.

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1248798 - PeerSpot reviewer
Sr. Manager, Vulnerability Management at a transportation company with 10,001+ employees
Real User
Dec 14, 2019
Assists us with vulnerability management and policy compliance across our network
Pros and Cons
  • "The most valuable features are vulnerability detection and the scanning capability to enable identification of vulnerabilities across our network."
  • "It's been the chosen solution year after year for vulnerability management and our vulnerability management program is centered around this tool."
  • "I would like to see this solution more developed and competitive in the Cloud space."

What is our primary use case?

Our primary uses for this solution are security vulnerability detection and policy compliance.

How has it helped my organization?

It's been the chosen solution year after year for vulnerability management and our vulnerability management program is centered around this tool.

What is most valuable?

The most valuable features are vulnerability detection and the scanning capability to enable identification of vulnerabilities across our network.

What needs improvement?

I would like to see this solution more developed and competitive in the Cloud space.

For how long have I used the solution?

We have been using Qualys VM for fifteen years.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Technology Security Expert at T-Mobile Polska (Deutsche Telekom)
Real User
Oct 18, 2019
Identifies and helps to remedy vulnerabilities, has good certificate management
Pros and Cons
  • "The most valuable feature is the certificate management."
  • "This solution has provided information about existing vulnerabilities, and helped with quick remediation in case of global malware attacks."
  • "The reporting in this solution can be improved."

What is our primary use case?

Our primary use case is vulnerability assessment.

How has it helped my organization?

This solution has provided information about existing vulnerabilities, and helped with quick remediation in case of global malware attacks.

What is most valuable?

The most valuable feature is the certificate management. The reason is the limited license provided by the mother company.

What needs improvement?

The reporting in this solution can be improved.

For how long have I used the solution?

I have been using this solution for five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Dr. SureshHungenahally - PeerSpot reviewer
Chief Executive Officer at a consultancy with 1-10 employees
Real User
Top 5
Sep 8, 2019
An excellent solution for vulnerability management that's highly scalable and very stable
Pros and Cons
  • "Technical support is fantastic."
  • "The way we can maintain a current actual registry of all the IP assets within it is very good."
  • "It's quite complex on the way it is set up, so it takes a fair bit of time in order to get your head around it in order to deploy it. Once you've deployed it, then you're never confident on the versions of the browsers and the SSL certificates, etc. You have to always go back into Qualys and check."

What is our primary use case?

The primary use for the solution is vulnerability management.

What is most valuable?

The way we can maintain a current actual registry of all the IP assets within it is very good. The scanning of software assets on the endpoint machine is also useful. I've tried the scanning of similar asset vulnerabilities throughout different servers, including Unix and Windows. Qualys maintains a good intervention database. We have a service line that updates to the newest software, or whenever you set it up. The second service line has denominated my nodes across the globe. It's easy to deploy the solution.

What needs improvement?

The server application scanning has room for improvement.

It's quite complex on the way it is set up, so it takes a fair bit of time in order to get your head around it in order to deploy it. Once you've deployed it, then you're never confident on the versions of the browsers and the SSL certificates, etc. You have to always go back into Qualys and check.

They do talk about an agent-based scanning for non-IP machines. It sort of sits between server scanning and endpoint scanning. That's not very clear. If they can improve that and deploy, then it'll be such a nice package.

The solution should help its vendors more with renewals. For example, we had deployed the solution as a reseller to a client and then somebody else came along and we didn't end up getting the renewal licenses for the servers. I wasn't very happy about that. We put all the hard work to get it in, but the following years we didn't get the benefit of our low pricing in the first year. 

They should integrate with the dashboard and provide a plugins link for data that's coming into API on the dashboard. When the users buy the license, they can turn it items on. So, that way you know you've got the full solution. What you don't pay for is not switched on, and what you pay for can get switched on immediately.

For how long have I used the solution?

I've been using the solution for since 2005.

What do I think about the stability of the solution?

The solution is very stable. 

What do I think about the scalability of the solution?

The solution is highly scalable.

How are customer service and technical support?

Technical support is fantastic.

What other advice do I have?

I would advise others to always have a proof of concept version of the solution put into play. Then spend a good two months on it. Stabilize the solution and check out the features and then deploy it into production. Otherwise, you will spend money during the real project for what could have been done as a POC. Deploy the core solution, get the scanning done and all the critical components put it in a proof of concept and then move it into production.

I would rate the solution eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
PeerSpot user
it_user924705 - PeerSpot reviewer
Information Security Officer at Zamil
Real User
Aug 29, 2019
Threat detection tells us which machines are infected with a vulnerability
Pros and Cons
  • "They also have threat detection which maps threats. There is a feed that comes from Qualys when a new vulnerability is found. It tells us which machines are infected with that vulnerability."
  • "I would recommend Qualys because it's very easy to use."
  • "What we have found is that the solution is not closely tied with the patch management. It is okay with newer ones, like Windows 10 machines; it gives the correct patch. But for Windows 7 or Windows Server 2008, it does not give us the correct patch so we have to manually identify the patches. This is a major problem."

What is most valuable?

The first thing we like is the scanner, the device which checks vulnerability management.

They also have threat detection which maps threats. There is a feed that comes from Qualys when a new vulnerability is found. It tells us which machines are infected with that vulnerability. If there is a new attack, we definitely know that it is happening, what is happening in our environment.

What needs improvement?

What we have found is that the solution is not closely tied with the patch management. It is okay with newer ones, like Windows 10 machines; it gives the correct patch. But for Windows 7 or Windows Server 2008, it does not give us the correct patch so we have to manually identify the patches. This is a major problem.

For how long have I used the solution?

This is the third year we are using Qualys. This year we included one more module, the patching module.

What do I think about the stability of the solution?

It's stable. Every month we scan more than 5,000 IP addresses and we are able to detect vulnerabilities.

How are customer service and technical support?

Our experience is that the problems we send them take too much time to resolve. For example, we opened a case for the problem I mentioned earlier, the vulnerabilities with Windows 7 and Server 2008 where it's trying the wrong patch. It took them a long time to even give us the correct explanation. So this is a problem.

How was the initial setup?

The initial setup was very easy. We just needed to download the virtual machine. There is a key and we just needed to provide a proxy setting. That's it.

We did all the configuration as a one-time job where we defined our subnet and mapped. We needed to schedule the scan and the map and we needed to schedule a group of, say, Windows. It was just a one-time job where needed to configure the query and run it. It created a report and sent it to the administrators. After that one-time job, everything happens automatically.

What about the implementation team?

We did it on our own.

What other advice do I have?

I would recommend Qualys because it's very easy to use. It does not require many specific skills. We are always on the latest version because Qualys provides automatic updates.

We have a virtual appliance in each site and that sends the logs to the cloud. We have the consoles on the cloud which enable us to query and scan. All this happens through the cloud.

We only have one administrator for the solution who monitors and checks if there is anything to be aware of. It sends the reports to all the different administrators, such as network, Linux, and Windows administrators and they take it from there.

We also have Qualys configuration management module. If there are any particular issues in any servers or in any network, it gives us a report to suggest and rectify the issues. It tells us what changes are needed to on that device.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2026
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros sharing their opinions.