Qualys VMDR vs Tenable Vulnerability Management comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 20, 2023
 

Categories and Ranking

Qualys VMDR
Ranking in Risk-Based Vulnerability Management
3rd
Average Rating
8.2
Number of Reviews
77
Ranking in other categories
IT Asset Management (7th), Configuration Management Databases (3rd), Container Security (11th)
Tenable Vulnerability Manag...
Ranking in Risk-Based Vulnerability Management
2nd
Average Rating
8.2
Number of Reviews
39
Ranking in other categories
Vulnerability Management (2nd)
 

Mindshare comparison

As of June 2024, in the Risk-Based Vulnerability Management category, the mindshare of Qualys VMDR is 18.4%, up from 17.8% compared to the previous year. The mindshare of Tenable Vulnerability Management is 21.4%, down from 26.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Risk-Based Vulnerability Management
Unique Categories:
IT Asset Management
4.0%
Configuration Management Databases
1.9%
Vulnerability Management
11.5%
 

Featured Reviews

AL
Sep 20, 2022
Reliable solution with good vulnerability management
I use Qualys VM for vulnerability scanning, enterprise management, web application scanning, and patch deployment Qualys VM's best features are vulnerability management and customizable scoring. Qualys VM's vulnerability scan could be improved, especially the number of CVE numbers it can manage…
VA
Jul 5, 2020
Supports container scanning, and the technical support is good
My advice for anybody who is implementing this product is to have all of the requirements documented and ready in advance. You match the solution to your requirements. Out of the box, we found that Tenable.io matched almost all of our requirements. The only clarification that we needed had to do with the Tenable.io Web App license. We have a good understanding of how Tenable.io works with containers and infrastructure, but when it comes to deep driving into applications, databases, APIs, and toolkits that you have in your environment, you need a separate license for that. This is what the Web Application license is. In order to enjoy the maximum value, you need to have the appropriate licensing. Overall, I am quite happy with Tenable.io. I would rate this solution a nine out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Qualys VM's best feature is vulnerability management."
"The most valuable feature is the certificate management."
"The biggest benefit is from a security operations perspective, where we are able to drive our security posture upwards by remediating any discovered vulnerabilities."
"Qualys has a continuous endpoint monitoring feature for agent-based scanning. Once you deploy the solution, it monitors everything that is happening every 30 minutes. Then, if there are any vulnerabilities, they are reported."
"The Vulnerability Management and Patch Management features are the most valuable features of this solution."
"The most valuable feature of Qualys Container Security is the detailed information in the reports and the remediation. This is done to make sure there are no vulnerabilities."
"Great web application security for scanning."
"This solution gives us insight into our environment and improves our security. It helps us to maintain a good patching system whereby we know that XYZ is vulnerable within the system."
"There is no burden of updating or upgrading this solution."
"Tenable.io, in particular, is quite a powerful product. It looks at your traditional environment, which is pretty much anything that is on-premises, and it also goes a step ahead and covers your modern assets, which is anything that is currently sitting in the cloud. You get complete visibility of your entire environment and tech operation. The ability to give you visibility across the entire tech surface is one of the biggest advantages that Tenable.io has."
"It is easy to manage. Most of the information the tool provided helped to further investigate the vulnerability and its impact."
"It helps us create remediation projects and assign the console’s responsibility to specific engineers."
"The interface is fine."
"I would rate Tenable's dashboards and reporting capabilities for illustrating security posture a nine out of ten, with ten being the best."
"It is a very, very user-friendly tool...The setup is easy"
"The solution creates vulnerability tickets within the VM profile but should also include them under the Remediation tab so the fixes can be viewed in the ticketing queue."
 

Cons

"I do not like that all of the data is stored on the cloud."
"Improve the user interface."
"Qualys VM could improve by having more skilled support personnel."
"Finding things in management can be quite difficult."
"The IoT scan is not great."
"I would like to have CSPM, a continuous scan-like cloud added to the solution."
"They should make it accessible for more operating systems."
"Make some minimal dashboard improvements."
"I don't recommend Tenable.io Vulnerability Management for web scanning"
"The UI has room for improvement."
"The solution must provide penetration testing."
"The stability has room for improvement."
"Tenable.io Vulnerability Management could be improved with an increased number of dashboards and MSSP integration."
"There needs to be better dashboard navigation."
"The interface could be improved; right now it's running on two interfaces simultaneously."
"They should include better customization of the dashboard, and integration tools."
 

Pricing and Cost Advice

"The product is more expensive than that of any other vendor."
"Qualys Virtual Scanner Appliance isn't expensive right now. But the price for their product bundles could be better."
"It is a high cost product. Compared to the other solutions, it is around 15 to 20% higher in cost."
"There is a license for the use of this solution. We pay annually instead of monthly to receive a better discount on the price."
"The pricing and licensing for Qualys could be improved."
"There are no additional fees in addition to the standard licensing fees."
"In Nigerian Naira, we spend about roughly four to five million to use this solution and this is expensive compared to solutions like Nessus."
"We do see over $100,000 in terms of price, for mid-size programs. You likely will pay more than $100,000 without any discount. It is a bit pricey."
"There are additional features that can be licensed for an additional cost."
"Compared to other VM solutions, Tenable.io Vulnerability Management is expensive."
"The product costs us around $137,000 annually for 4000 to 5000 assets."
"I would rate the pricing a five out of ten. It is in the middle."
"On a scale of one to ten, where one is low, and ten is high price, I rate the pricing an eight. So, it is a pretty expensive solution."
"The cost is determined by the number of endpoints, which is approximately one dollar per endpoint."
"The solution is not too expensive."
"The tool is reasonably priced."
report
Use our free recommendation engine to learn which Risk-Based Vulnerability Management solutions are best for your needs.
787,817 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
33%
Computer Software Company
11%
Financial Services Firm
11%
Manufacturing Company
6%
Educational Organization
25%
Computer Software Company
12%
Government
8%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your primary use case for Qualys VM?
Qualys VM is used for vulnerability scans for the internet and applications using application exchange. There are many applications. We also use the solution for asset management per team, and the ...
What do you like most about Qualys VMDR?
I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagging system is good for tagging. We can still use QualysAgent task ID tools even ...
What is your experience regarding pricing and costs for Qualys VMDR?
We have an annual contract for Qualys VMDR. I believe it's for either two years or five years.
What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
Tenable Nessus is a vulnerability assessment solution that is both easy to deploy and easy to manage. The design of the program is such that if a company should desire to handle the installation t...
 

Also Known As

Qualys VM, QualysGuard VM, Qualys Asset Inventory, Qualys Container Security, Qualys Virtual Scanner Appliance
Tenable.io
 

Learn More

 

Overview

 

Sample Customers

Agrokor Group, American Specialty Health, American State Bank, Arval, Life:), Axway, Bank of the West, Blueport Commerce, BSkyB, Brinks, CaixaBank, Cartagena, Catholic Health System, CEC Bank, Cegedim, CIGNA, Clickability, Colby-Sawyer College, Commercial Bank of Dubai, University of Utah, eBay Inc., ING Singapore, National Theatre, OTP Bank, Sodexo, WebEx
Global Payments AU/NZ
Find out what your peers are saying about Qualys VMDR vs. Tenable Vulnerability Management and other solutions. Updated: May 2024.
787,817 professionals have used our research since 2012.