Try our new research platform with insights from 80,000+ expert users

BigFix vs Qualys Patch Management comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

BigFix
Ranking in Patch Management
2nd
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
97
Ranking in other categories
Configuration Management (6th), Endpoint Protection Platform (EPP) (26th), Unified Endpoint Management (UEM) (4th)
Qualys Patch Management
Ranking in Patch Management
4th
Average Rating
9.0
Reviews Sentiment
7.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2025, in the Patch Management category, the mindshare of BigFix is 9.0%, down from 12.4% compared to the previous year. The mindshare of Qualys Patch Management is 4.5%, up from 0.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Patch Management
 

Featured Reviews

Bella Yakoby - PeerSpot reviewer
Offers third-party patching feature, good scalability, and enhance endpoint management capabilities
From the perspective of the team that's handling the environment, it's not so user-friendly compared to other solutions, the competitors. We hire new teams from time to time, and they are complaining, look, although BigFix is very robust and cross-platform, it's not so fun to work with. The user interface for the technical teams is not so advanced. It's not so intuitive compared to SCCM, compared to ManageEngine. And this is the fact that they have, with the teams, because they have the rejection. The look and feel of the system are old-fashioned. For new employees, it's less easy to find someone I don't need to educate on how to work with BigFix. Although it's easy, it's not as intuitive as the other solutions, and the functionality of the other solutions is less advanced. Let's summarize: The user interface has to be changed from the perspective of the teams that are managing the product. It's old school.
Revathi VeeraRaghavan - PeerSpot reviewer
Provides a centralized platform for managing assets and vulnerabilities, enabling assessment, prioritization, and remediation
Qualys Patch Management system requires several improvements. Firstly, the inability to download asset patches and the lack of third-party application integration limit patch accessibility. Additionally, rollback options are unreliable, and pre-deployment patch testing is crucial. Reporting needs enhancement, particularly with group-based compliance percentages and clearer, VMDR-like reporting in the Patch Management module. Furthermore, detection speed should be improved, as patches are released 24 hours after QIDs are published. The user interface could be more functional, with dashboards for patch compliance visualization and simplified error code language. Finally, the Mac patch catalogue needs expansion, and automated workflows, policy enforcement, and testing procedures should be streamlined for seamless, user-independent operation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's very straightforward."
"The most valuable feature is patch management, a must have, even for Linux and iOS."
"I would advise someone considering this product to go for it. It's easy to use, cheaper than the value, and there is tons and tons of support from the BigFix community. With almost every challenge we have someone who has encountered it, and you will have a solution right away."
"We rely on BigFix as part of our consulting engagements. It's more efficient from a visibility and discovery standpoint on the initial phase, the consulting engagement. It also increases our efficiencies on the remediation phase of our engagements."
"In terms of vulnerability management, it gives tough competition by providing a single management console with multiple benefits."
"The most valuable aspect of BigFix is its ability to patch desktops. While we have complete control over servers and can easily push patches to them, desktops pose a greater risk for leaks and vulnerabilities if patches are not installed in a timely manner. By using BigFix, we have significantly improved our ability to patch desktops, whether they are laptops, desktops, or other mobile devices used by end-users."
"BigFix can manage lost devices, so you can wipe them remotely to ensure the IP doesn't get out in public. Unified endpoint security is a new perspective. I know that HCL is also collaborating with IBM, but I'm not sure if there is any cooperation between them and MaaS360 or other endpoint components."
"Ability to run custom reports and custom relevance."
"Qualys allows us to automate and fix patches through the tool, achieving a compliance rate of over 95%."
"We've been able to reduce organizational risk by 50%."
"Qualys Patch Management has saved significant resources."
"We have all the information on one page. The dashboard provides comprehensive information on one page, making it easy to apply patches and monitor pending updates."
"The customer support team is quite responsive and always ready to assist."
"Compared to other tools, Qualys is better due to its automation capabilities, which allow us to achieve high compliance rates."
"Qualys' best feature is its reporting. At first, it may seem a little complicated to a beginning user, but it's helpful once you get used to it. Most of these scans run automatically. We set the scans up for the client to run at daily, weekly, or monthly intervals, depending on how critical the server or other hardware is."
"Patch Management offers pre-action and post-action features, which provide the ability to execute scripts during the installation or uninstallation of software. This helps me make changes from Qualys itself."
 

Cons

"The deployment has room for improvement and can be more streamlined."
"The main shortcoming of BigFix was integration with vulnerability management. If you had a vulnerability in your software and BigFix on the endpoint, you needed integration with Qualys, Tenable, or another vulnerability management solution to fix that. It was like, "Okay, we can identify issues, and get that information back from the endpoint, but what are we doing about it?""
"The product should become cloud-based. Also, the peer nesting ability of the product is a little backward."
"Needs to improve Network Access Protection (NAP) technologies to prevent computers with vulnerabilities from gaining access to networks."
"The BigFix Inventory could have an increased scope regarding the tools that can be detected. It does not cover all the possible software installed in Asset."
"In-place and OS upgrades can be improved."
"The product is quite buggy and complicated to use."
"I'd definitely like to see additional feature parody in the web UI versus the console. There are certain things that you can only do in the console and they're very cumbersome to do, like secure parameters, for example. That's definitely something that has a wide degree of utility but it needs to be easier to surface. At this particular juncture between the transition, between the legacy console and the web UI, it's hard to justify dealing with the cumbersome aspects of the legacy console when theoretically everything's been through the web UI."
"There is a limitation where Qualys may not always offer solutions for remediation, particularly for end-of-life or end-of-service applications."
"Qualys's current response time for releasing solutions to zero-day vulnerabilities, which takes approximately 12 to 16 hours, needs improvement."
"It would be beneficial to have more efficiently scheduled task deployments that are tailored to specific asset types or deployment needs."
"The GUI has areas that need improvement, particularly in the accuracy of results when adding dashboards and running queries."
"Qualys Patch Management's pricing could be more competitive, as it presents a significant obstacle for many companies who find it unaffordable."
"Not all patches are supported, so there are some restrictions. Some remediations require script-level changes which Qualys does not support."
"The Qualys agent sometimes encounters authorization issues, leading to inaccurate vulnerability reports."
"One of the challenges that we have faced with the Patch Management tool is that you cannot patch all the things. There are some limitations, whereas, in SCCM, we can create a package and just deploy that through it. Anything is deployable through SCCM, whereas Patch Management is very selective."
 

Pricing and Cost Advice

"The price of the solution is high. There are not any additional fees from the standard license."
"On a scale from one to ten, where one is expensive and ten is cheap, I rate the solution's pricing one out of ten."
"The tool's price continues to go up. The cost per endpoint can vary, ranging from approximately 30 to 80 dollars per year. Compared to other products, pricing is in the middle. You need to buy an additional database license, but most users already have it."
"Compliance, inventory, and licensing are really pricey. They should lower the price. It discourages users from getting onboard."
"You get what we call the Platform Edition, which you get for free. The patch service is maybe $0.50 per workstation per month. Then there's the basic server cost, which is about $1.50 per server per month. You also get into Lifecycle which does power management, OSD remote control, and those types of things, and that might be about 10 times the price - which works out to about $13 per server and, maybe $5 per workstation per month."
"I would stay with the Managed Virtual Server license model, which is a 1-to-1 license per OS whether it is virtual or physical."
"The cost is slightly high."
"It might be about $23 a client."
"The licensing cost is more than 2,000 for the whole Americas region"
"Compared to other tools, the price of Qualys Patch Management is reasonable."
"The pricing is reasonable and competitive. We get many more features at the same price compared to other solutions such as Microsoft SCCM. It is worth the money considering the services and features it has. Their support team is also awesome."
"Pricing for Qualys Patch Management is moderate."
"Qualys Patch Management's pricing could be more competitive, as it presents a significant obstacle for many companies who find it unaffordable."
"Its price is competitive in the market. Compared to other solutions like Rapid7, Qualys offers a favorable price point and robust features."
"Qualys Patch Management offers a moderate price point, neither cheap nor expensive, considering its comprehensive functionality."
"The pricing is fair and within our budget."
report
Use our free recommendation engine to learn which Patch Management solutions are best for your needs.
856,874 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
33%
Financial Services Firm
11%
Government
8%
Computer Software Company
7%
Computer Software Company
15%
Government
13%
Manufacturing Company
11%
Financial Services Firm
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about BigFix?
The most valuable features of the solution are Windows patching and the hardware and software inventory.
What is your experience regarding pricing and costs for BigFix?
The pricing is competitive, but not the most competitive.
What needs improvement with BigFix?
While performing integration, we face many issues with IBM solution. We need detailed information about those issues that can help users to mitigate them. The problem was related to the hardware co...
What is your experience regarding pricing and costs for Qualys Patch Management?
From a pricing perspective, I find Qualys to be a bit higher, but it is worth it. Compared to other tools, it is on the costly side, but I believe it is worth the investment.
What needs improvement with Qualys Patch Management?
Regarding improvements in Qualys Patch Management, I did not quite understand the downsides they were expecting. Initially, I was confused about where to find and how to use the available features....
What is your primary use case for Qualys Patch Management?
I am using Qualys Patch Management for two years, and everything is satisfactory from my side. Before purchasing Qualys Patch Management, we were already using Qualys VMDR and the cloud agent model...
 

Also Known As

Tivoli Endpoint Manager
No data available
 

Overview

 

Sample Customers

US Foods, Penn State, St Vincent's Health US Foods, Sabadell Bank, SunTrust, Australia Sydney, Stemac, Capgemini, WNS Global Services, Jebsen & Jessen, CenterBeam, Strauss, Christian Hospital Centre, Brit Insurance, Career Education Corporation
Information Not Available
Find out what your peers are saying about BigFix vs. Qualys Patch Management and other solutions. Updated: June 2025.
856,874 professionals have used our research since 2012.