Try our new research platform with insights from 80,000+ expert users

BigFix vs Qualys Patch Management comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

BigFix
Ranking in Patch Management
2nd
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
97
Ranking in other categories
Configuration Management (6th), Endpoint Protection Platform (EPP) (23rd), Unified Endpoint Management (UEM) (4th)
Qualys Patch Management
Ranking in Patch Management
4th
Average Rating
9.0
Reviews Sentiment
7.5
Number of Reviews
33
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2025, in the Patch Management category, the mindshare of BigFix is 7.9%, down from 12.6% compared to the previous year. The mindshare of Qualys Patch Management is 4.3%, up from 0.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Patch Management
 

Featured Reviews

Bella Yakoby - PeerSpot reviewer
Offers third-party patching feature, good scalability, and enhance endpoint management capabilities
From the perspective of the team that's handling the environment, it's not so user-friendly compared to other solutions, the competitors. We hire new teams from time to time, and they are complaining, look, although BigFix is very robust and cross-platform, it's not so fun to work with. The user interface for the technical teams is not so advanced. It's not so intuitive compared to SCCM, compared to ManageEngine. And this is the fact that they have, with the teams, because they have the rejection. The look and feel of the system are old-fashioned. For new employees, it's less easy to find someone I don't need to educate on how to work with BigFix. Although it's easy, it's not as intuitive as the other solutions, and the functionality of the other solutions is less advanced. Let's summarize: The user interface has to be changed from the perspective of the teams that are managing the product. It's old school.
Revathi VeeraRaghavan - PeerSpot reviewer
Provides a centralized platform for managing assets and vulnerabilities, enabling assessment, prioritization, and remediation
Qualys Patch Management system requires several improvements. Firstly, the inability to download asset patches and the lack of third-party application integration limit patch accessibility. Additionally, rollback options are unreliable, and pre-deployment patch testing is crucial. Reporting needs enhancement, particularly with group-based compliance percentages and clearer, VMDR-like reporting in the Patch Management module. Furthermore, detection speed should be improved, as patches are released 24 hours after QIDs are published. The user interface could be more functional, with dashboards for patch compliance visualization and simplified error code language. Finally, the Mac patch catalogue needs expansion, and automated workflows, policy enforcement, and testing procedures should be streamlined for seamless, user-independent operation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The patch management and the BigFix Inventory have been the most valuable features."
"This has very much improved our organization by saving time to deploy thousands of endpoints to our customers."
"We are able to use BigFix through API connections to automate and reduce resources and time. The product's been great for us. It's increased the security posture ten-fold and it's increased our visibility across our endpoints enormously."
"All the vendor patches are synchronized automatically."
"The most valuable and essential features of BigFix are all of them, they are needed when serving the purpose of the desktop operation framework. We cannot run operations without patching or without having an appropriate mechanism for deploying software, et cetera. The features all serve their purpose for our use case."
"The solution is unbelievably scalable."
"DOWNLOADING-PATCHES; It has also helped to reduce network traffic when it comes to downloading patches. By only having to download the patch once to the central location and then utilizing the relay structure to then download the patch to a specific site and then everything gathering at local, it greatly reduces the bandwidth of multiple endpoints."
"The most valuable aspect of BigFix is its ability to patch desktops. While we have complete control over servers and can easily push patches to them, desktops pose a greater risk for leaks and vulnerabilities if patches are not installed in a timely manner. By using BigFix, we have significantly improved our ability to patch desktops, whether they are laptops, desktops, or other mobile devices used by end-users."
"The integrations with VMware include configurations to mitigate vulnerabilities. It helps us identify permissions and whatever is applicable for the vulnerability for faster patching."
"Qualys Patch Management offers a valuable feature that allows for deferred reboots, giving users control while still ensuring eventual patching."
"Overall, I would rate Qualys Patch Management a ten out of ten for everything."
"Patch management provides more clarity from the dashboard and console, which is very helpful for our team to prioritize and take prior action."
"Qualys Patch Management leverages vulnerability feeds from the VMDR module, allowing us to identify vulnerabilities missing Qualys patches."
"Qualys' best feature is its reporting. At first, it may seem a little complicated to a beginning user, but it's helpful once you get used to it. Most of these scans run automatically. We set the scans up for the client to run at daily, weekly, or monthly intervals, depending on how critical the server or other hardware is."
"Qualys allows us to automate and fix patches through the tool, achieving a compliance rate of over 95%."
"The first thing I would say is the ease of use."
 

Cons

"I self-taught for this online, so the initial setup was a little difficult to pick up at first. I had to create a couple of testing environments and destroy them in order to learn how to use it. There was a lot of trial and error, a lot of reading of the manuals."
"I would like to see API connectivity, built-in API connectors to the standard toolsets, whether it's for your ServiceNow or your Qualys. More API connectivity to make it easier to integrate to other tools."
"I would like to see improvements in the Web UI program and also a BigFix console for Mac OS."
"One aspect that could be improved is the speed of the console. Sometimes it can be slow, which is something that needs to be addressed."
"IBM has not focused on the Web Reports capabilities."
"The BigFix Inventory could have an increased scope regarding the tools that can be detected. It does not cover all the possible software installed in Asset."
"The scalability of the web UI product doesn't scale to the size that we need for our implementation so it needs to expand. I would also like to see the capability to develop on the back of the web UI capability. There are lots of web features and integrations that we could do with web UI that it would be nice to be able to put on top of what's already there, rather than waiting for IBM to develop what we need."
"While performing integration, we face many issues with IBM solution. We need detailed information about those issues that can help users to mitigate them."
"The Qualys agent sometimes encounters authorization issues, leading to inaccurate vulnerability reports."
"There is room for improvement in terms of adding more patches. Not all patches are available for deployment on Qualys Patch Management, so collaborating with various vendors to provide new patches would be beneficial."
"Downloading extensive vulnerability reports, especially those with millions of entries, is time-consuming."
"The patch status and patch completion information should be improved."
"Reporting needs enhancement, particularly with group-based compliance percentages and clearer, VMDR-like reporting in the Patch Management module."
"Qualys's current response time for releasing solutions to zero-day vulnerabilities, which takes approximately 12 to 16 hours, needs improvement."
"Downloading extensive vulnerability reports, especially those with millions of entries, is time-consuming. To improve efficiency, Qualys should implement faster download speeds and offer reports in Excel format in addition to the current CSV option."
"Qualys could improve its randomized download feature and provide more detailed information about patch failures, including the reason for failure."
 

Pricing and Cost Advice

"It is too costly. It is one of the best tools, but because of pricing, not all clients support it. Its licensing is on a yearly basis."
"When purchasing, buying with other IBM tools provided us with a very good discount in pricing."
"The price of BigFix is better than the solutions. You are able to pay monthly or annually. There are not any hidden costs with BigFix. There is an additional cost for the SQL database."
"The price of the solution is high. There are not any additional fees from the standard license."
"It might be about $23 a client."
"The license is subscription-based."
"I would stay with the Managed Virtual Server license model, which is a 1-to-1 license per OS whether it is virtual or physical."
"The cost is slightly high."
"Qualys Patch Management's pricing is competitive."
"Qualys Patch Management offers a moderate price point, neither cheap nor expensive, considering its comprehensive functionality."
"Qualys Patch Management comes as part of a bundled package with several modules, making it a cost-effective deal for us."
"Qualys is fairly priced."
"Pricing for Qualys Patch Management is moderate."
"The pricing is reasonable and less expensive than the previous tool."
"I'm unaware of Qualys' exact price, but it's more expensive than Nessus. With technological products, you need to pay to get the best."
"Compared to other tools, the price of Qualys Patch Management is reasonable."
report
Use our free recommendation engine to learn which Patch Management solutions are best for your needs.
864,053 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Government
10%
Manufacturing Company
9%
Computer Software Company
9%
Computer Software Company
13%
Government
13%
Manufacturing Company
11%
Financial Services Firm
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about BigFix?
The most valuable features of the solution are Windows patching and the hardware and software inventory.
What is your experience regarding pricing and costs for BigFix?
The pricing is competitive, but not the most competitive.
What needs improvement with BigFix?
While performing integration, we face many issues with IBM solution. We need detailed information about those issues that can help users to mitigate them. The problem was related to the hardware co...
What is your experience regarding pricing and costs for Qualys Patch Management?
From a pricing perspective, I find Qualys to be a bit higher, but it is worth it. Compared to other tools, it is on the costly side, but I believe it is worth the investment.
What needs improvement with Qualys Patch Management?
Regarding improvements in Qualys Patch Management, I did not quite understand the downsides they were expecting. Initially, I was confused about where to find and how to use the available features....
What is your primary use case for Qualys Patch Management?
I am using Qualys Patch Management for two years, and everything is satisfactory from my side. Before purchasing Qualys Patch Management, we were already using Qualys VMDR and the cloud agent model...
 

Also Known As

Tivoli Endpoint Manager
No data available
 

Overview

 

Sample Customers

US Foods, Penn State, St Vincent's Health US Foods, Sabadell Bank, SunTrust, Australia Sydney, Stemac, Capgemini, WNS Global Services, Jebsen & Jessen, CenterBeam, Strauss, Christian Hospital Centre, Brit Insurance, Career Education Corporation
Information Not Available
Find out what your peers are saying about BigFix vs. Qualys Patch Management and other solutions. Updated: July 2025.
864,053 professionals have used our research since 2012.