Try our new research platform with insights from 80,000+ expert users
SandeepKumar1 - PeerSpot reviewer
Design Engineer at Uop Ipl, Honeywell
Real User
Good security options but slow response time and needs more integration
Pros and Cons
  • "Qualys WAS' most valuable features are the navigation flow of the UI and the option for a different layer of security (identification and operation through email and mobile)."
  • "Sometimes the response time is low because the handshake fails, and then you have to re-login and start again."

What is our primary use case?

My main use of Qualys WAS is for multifactor authentication for web and mobile applications.

What is most valuable?

Qualys WAS' most valuable features are the navigation flow of the UI and the option for a different layer of security (identification and operation through email and mobile).

What needs improvement?

Sometimes the response time is low because the handshake fails, and then you have to re-login and start again. In the next release, Qualys should include more integration with different applications and single-sign-on protocol.

For how long have I used the solution?

I've been using Qualys Web Application Scanning for a year and a half.

Buyer's Guide
Qualys Web Application Scanning
March 2025
Learn what your peers think about Qualys Web Application Scanning. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
845,406 professionals have used our research since 2012.

What do I think about the stability of the solution?

Qualys WAS is stable unless we have a breach.

What do I think about the scalability of the solution?

Qualys WAS is scalable.

How are customer service and support?

Qualys' technical support is good but could improve its resolution speed.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, I used CA Identity Solutions by Broadcom, which had easier integration, more options for MFA, and biometric options.

How was the initial setup?

The initial setup was complex and took about three months to deploy. I would rate the setup experience as four out of five.

What about the implementation team?

We used a vendor team.

What's my experience with pricing, setup cost, and licensing?

Qualys WAS' pricing is competitive.

What other advice do I have?

I would recommend getting the POC done before implementing WAS, especially if there will be a lot of APIs involved in developing the product. Look at how the endpoint security works when the APIs run with a different channel, like web and mobile applications. I would give Qualys WAS a rating of six out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
YongjinLee - PeerSpot reviewer
Commercial Pre-Sales at Megazone
Consultant
Top 5
Highly stable and scalable solution which is suitable for enterprise businesses
Pros and Cons
  • "The Qualys Web Application Scanning solution offers a single comprehensive console and consolidated reporting, covering all aspects from on-prem to cloud and compliance, etcetera."
  • "There should be better visibility into the application."

What is our primary use case?

The primary use case includes scanning the web applications that are public facing.

What is most valuable?

The Qualys Web Application Scanning solution offers a single comprehensive console and consolidated reporting, covering all aspects from on-prem to cloud and compliance, etcetera.

What needs improvement?

There should be better visibility into the application. 

For how long have I used the solution?

Our customers have been using this solution for more than three years now.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

It is a cloud-based solution, so it is easy to scale. 

We work with enterprise-level clients with over 2500 endpoints. 

How are customer service and support?

The customer service and support are good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I would say Qualys is on the better side. It's more about the performance and the quality of the product because it's been around for a long time.

How was the initial setup?

The initial setup is easy. 

What about the implementation team?

The time taken for implementation depends on the customer's environment. It could take around a month, depending on the module. 

We have a team of two to three people to implement at the enterprise level. Moreover, it is easy to maintain. 

What's my experience with pricing, setup cost, and licensing?

We normally purchase an annual license. There are additional costs. From Qualys, it's for the license and maintenance, which includes patches and stuff like that. Additionally, we have our own service delivery costs.

Which other solutions did I evaluate?

I'm familiar with all of the Qualys-based products because we partner with Qualys, so I have a local contact in New Zealand who helps me with all the technical information.

Moreover, I'm a pre-sales specialist, so I recommend the solution to our potential customers and then we implement through another team for customers.

What other advice do I have?

Qualys is a stable and reliable solution. It has been around for a long time.

Overall, I would rate the solution an eight out of ten. There is scope for improvement. It is still an early technology. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Buyer's Guide
Qualys Web Application Scanning
March 2025
Learn what your peers think about Qualys Web Application Scanning. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
845,406 professionals have used our research since 2012.
S S RAMA KRISHNA MURTHY  SURI - PeerSpot reviewer
Senior Manager at valuelabs LLP
MSP
Helpful support, many great integrations, and lots of reference material
Pros and Cons
  • "It works with many different products."
  • "There could be better management and faster scanning."

What is our primary use case?

We use the solution alongside others for static scanning. It's used for endpoint scanning. 

What is most valuable?

The monitor's ability to read the reports, or to do very detailed reports is great. It's good at looking at the different vulnerabilities. Rarely are there security loopholes. It can also suggest ways to mitigate risks and vulnerabilities. 

There's a lot of great reference material. 

The integration is great. It works with many different products. 

What needs improvement?

There could be better management and faster scanning. An application may have a lot of URLs and complexity. If there are a couple of applications, that complexity multiplies. It can take three or four days to scan. That's too long. It should be maybe three or four hours. 

For how long have I used the solution?

We've been using the solution for two years. 

What do I think about the stability of the solution?

It's a stable product. There are no bugs or glitches and it doesn't crash or freeze. The solution is reliable. 

What do I think about the scalability of the solution?

It leverages the cloud. One of the upsides of that is the scalability that is possible. 

We have about 500 to 600 people on the solution currently.

How are customer service and support?

Technical support is very good whenever we send them a message. They will schedule a call and then they will check in with us until the issue's resolved or until we understand the entire problem and they clarify issues. They're very quick as well.

How was the initial setup?

The initial setup, due to the fact that it is the cloud, is very easy. It's a SaaS solution. We don't have to install anything in order to get going. You are on it right away. There is no deployment time to get through. 

Since it's so quick and immediate, you don't need a big team to get it of the ground. 

What about the implementation team?

We were able to handle the implementation ourselves. It's not hard. You don't need consultants or integrators.

What was our ROI?

We have seen an ROI and my understanding is that it is pretty good. 

What's my experience with pricing, setup cost, and licensing?

I don't directly deal with the licensing aspect of the product. 

What other advice do I have?

I'd recommend the solution to others. We haven't had any issues after two years of working with it. 

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
SubhajitAich - PeerSpot reviewer
Security Consultant at Cognizant
Real User
Top 10
User-friendly, good scanning analysis and reporting, and offers real-time vulnerability monitoring
Pros and Cons
  • "The interface is user-friendly and easy to understand."
  • "The scanner reports a lot of false positives, which is something that needs to be improved."

What is our primary use case?

We primarily use this solution for VM scanning. We scan more than a thousand applications.

What is most valuable?

The most valuable features are scanning analysis and reporting.

This solution also provides real-time monitoring.

The interface is user-friendly and easy to understand.

What needs improvement?

The reporting needs to be improved because there are a lot of search parameters, and at the end of the day, the reports are so large that it is very difficult for us to go through each and every point to analyze the vulnerabilities.

The scanner reports a lot of false positives, which is something that needs to be improved.

For how long have I used the solution?

We have been using Qualys for almost a year.

What do I think about the stability of the solution?

The stability is good.

What do I think about the scalability of the solution?

In terms of scalability, Qualys is good.

How are customer service and technical support?

I have not dealt with technical support yet because there are other people dealing with issues that arise. My understanding is that technical support is good.

Which solution did I use previously and why did I switch?

I have also used the Nexus Vulnerability Scanner and it reports fewer false positives.

How was the initial setup?

This solution was implemented before I joined the department.

What's my experience with pricing, setup cost, and licensing?

There are different options available with respect to licensing.

What other advice do I have?

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
IT Security Analyst at Banco de Fomento Angola
Real User
Top 5
A stable and easy-to-deploy solution that helps organizations to manage the vulnerabilities in their network
Pros and Cons
  • "The product prevents possible vulnerabilities in our network."
  • "The support could be faster."

What is our primary use case?

We use the solution for scanning and vulnerability management.

What is most valuable?

The product prevents possible vulnerabilities in our network.

What needs improvement?

It will be good if Qualys is integrated with QRadar.

For how long have I used the solution?

I have been using the solution for three years.

What do I think about the stability of the solution?

The tool is stable.

What do I think about the scalability of the solution?

The tool is scalable since it is on the cloud. We have 60 users.

How are customer service and support?

The support is moderately good. Sometimes, the team responds on time. Sometimes, it takes time. The support could be faster.

Which solution did I use previously and why did I switch?

I have used many other tools. In some cases, I prefer other tools because they give better visibility into the vulnerabilities. In general, Qualys is good.

How was the initial setup?

The initial setup was super easy because it is cloud-based. We use it internally. The installation took two days. We had to improve the tools and create the tags and assets. Two or three engineers can deploy the product. The product is easy to maintain.

What other advice do I have?

I integrate Qualys and QRadar. QRadar is for SCM. It helps centralize the management of the network. It provides good visibility of Qualys. Qualys is a good product. There are better tools in the market. However, I recommend Qualys to others. Overall, I rate the product an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
reviewer1138395 - PeerSpot reviewer
Sr Cybersecurity Leader at a non-tech company with 1,001-5,000 employees
Real User
We like its process of updating signatures, and it's way ahead of its industry peers.
Pros and Cons
  • "Qualys' process of updating signatures is something we really appreciate, and it's way ahead of its industry peers."
  • "We procured around 110 licenses for Web Application Scanning, but we have issues running concurrent scans. I don't currently have the option to trigger scans for all 100-plus websites. The default limit is around 10 conference scans. It's not very scalable, to be honest, because of the limitation that they put on concurrent scans."

What is our primary use case?

There are two parts. We use Web Application Scanning licenses to constantly assess our websites. When there are any changes on our websites, Qualys checks to see if there is a vulnerability. We use a SecOps/DevOps methodology, so Qualys is integrated into the development cycle. Qualys runs every time we update the site.

What is most valuable?

Qualys' process of updating signatures is something we really appreciate, and it's way ahead of its industry peers. 

For how long have I used the solution?

We have been using Web Application Scanning since 2018. 

What do I think about the stability of the solution?

Web Application Scanning is a stable solution.

What do I think about the scalability of the solution?

We procured around 110 licenses for Web Application Scanning, but we have issues running concurrent scans. I don't currently have the option to trigger scans for all 100-plus websites. The default limit is around 10 conference scans. It's not very scalable, to be honest, because of the limitation that they put on concurrent scans.

How are customer service and support?

I've had some issues with Qualys support. It's transactional. There is no face to the support model. I don't see anyone from Qualys engaging with us on a quarterly business or annual business review to help us understand if we are fully utilizing Qualys' capabilities. 

This isn't a technical problem. It's more of an issue with customer relations. I think they can improve by touching base with us more often to let us know if our rollout is following industry best practices or not. 

How was the initial setup?

We used Verizon to help us with the rollout, and there were no trouble tickets or any technical issues with the rollout, so I would say the implementation was pretty smooth. The design-build phase took a couple of weeks.

What's my experience with pricing, setup cost, and licensing?

We pay for a yearly license, but we also pay a separate cost for an engineer from Verizon.

Which other solutions did I evaluate?

When evaluating Qualys, we looked at industry best practices and state of-art-tools. Qualys was the default leader in its segment, so we went ahead with Qualys. I've used other solutions in the past, but Qualys the segment. That's why we went with them.

What other advice do I have?

I rate Qualys Web Application Scanning nine out of 10. I think Web Application Scanning should integrate VMDR, a more enhanced capability that Qualys offers for enterprise vulnerability assessments. However, Qualys is way ahead of the competition on the web application front. 

If you're an industrial company, you should evaluate the OT scanning capability that Qualys is about to launch. It will cover all your enterprise web applications and secure your factories as well. Qualys should be a one-stop shop meeting all your end-to-end vulnerability assessment requirements, so you don't need to buy solutions from different vendors,

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer2254848 - PeerSpot reviewer
Technical Lead at a computer software company with 501-1,000 employees
Real User
Top 20
Easy-to-deploy product with good stability
Pros and Cons
  • "It is a good product for website penetration testing to detect vulnerabilities."
  • "The product's pricing could be better."

What is our primary use case?

We primarily use Qualys Web Application Scanning for website penetration testing.

What is most valuable?

It is a good product for website penetration testing to detect vulnerabilities.

What needs improvement?

The product's pricing could be better.

For how long have I used the solution?

We have been using Qualys Web Application Scanning for less than a year.

What do I think about the stability of the solution?

The platform has good stability.

What do I think about the scalability of the solution?

It is a scalable product.

How are customer service and support?

The technical support services are good.

How was the initial setup?

Qualys Web Application Scanning is easy to deploy.

What's my experience with pricing, setup cost, and licensing?

It is an expensive platform.

What other advice do I have?

Qualys Web Application Scanning is easy to use and deploy. I rate it a nine out of ten. However, it could be less expensive compared to other open-source tools.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Sr. Director, Cloud Platform Engineering at a tech vendor with 5,001-10,000 employees
Real User
We’re a Linux shop and Qualys gave us good Linux vulnerability scanning; no experience with it on MSFT products.

What is most valuable?

We’re a Linux shop and Qualys gave us good Linux vulnerability scanning; no experience with it on MSFT products. It reports only a few glaring false-positive errors (directory ownership was a common one), and our post-processing dealt with the known exceptions we’d agreed on. The long baseline of iterative results was valuable to track changes and our rate of improvement. Access to the API let us automate its use in our CI/CD pipeline for machine images.

How has it helped my organization?

The biggest benefit was integrating Qualys scanning into our CI/CD pipeline to vulnerability-scan new custom machine images (for OpenStack or AWS) before deployment. We’d build the image, instantiate it, run Qualys against it, get the report, post-process it, look for new errors or changes (if any), review just those and either block deployment or update our exceptions list for next time.

What needs improvement?

The licensing and user permissions are a little wonky for a DevOps team to use, probably because it’s traditionally an InfoSec tool.

For how long have I used the solution?

Symantec has run Qualys Enterprise against our private OpenStack cloud for at least three years; we started using the Qualys VA on AWS in 06/17.

What do I think about the stability of the solution?

Only those which Qualys scanning revealed in our OpenStack implementation.

What do I think about the scalability of the solution?

Not really, we spun up multiple Qualys servers to walk through our data center cloud infrastructure on a regular basis.

How are customer service and technical support?

Pretty poor, as usual for almost all software products now. Getting past the Tier 1 and 2 call center people is always a challenge, so throwing the company name around isn’t a bad idea.

Which solution did I use previously and why did I switch?

Don’t know what, if anything, preceded Qualys at Symantec.

How was the initial setup?

It took about a month to get the Qualys scan completely integrated and automated in our CI/CD pipeline, but much of that was due to licensing issues and poor API documentation, not the product installation itself.

What's my experience with pricing, setup cost, and licensing?

The “bring your own licenses” model for the virtual appliance isn’t what you might think, so get a clear explanation up front before assuming you can go use virtual appliances on AWS.

Which other solutions did I evaluate?

Yes, the Symantec Global Security Office (GSO) did this, and I don’t know who else they looked at when the selection was made.

What other advice do I have?

My team was responsible for operating the Symantec development hybrid cloud (about 6K servers in four DCs and multiple AWS regions). We use Qualys Enterprise to scan our private cloud infrastructure and machine images, and the Qualys Virtual Appliance to do custom AMI validation before deployment in AWS. I don’t recall which versions we used but we kept them up to date.

I give them a seven out of 10. The product is pretty good, but not great. It simply isn’t feasible for a tool like this to be accurate (no false negatives, few false positives), so you wind up doing a fair amount of post-processing of scan results. The profile update cycles are not what I’d like to see, so the vendor isn’t reacting to new threats anywhere near fast enough.

Also, look at other vendors, of course. Tenable was getting a lot of good buzz at Symantec last year. Be clear in advance on how much “overhead” you’re willing to pay in order to run “regular” scans on your DC machines and networks. In the cloud space, it’s somewhat better to verify the base image once, and focus on application vulnerabilities, where possible.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Qualys Web Application Scanning Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2025
Buyer's Guide
Download our free Qualys Web Application Scanning Report and get advice and tips from experienced pros sharing their opinions.