No more typing reviews! Try our Samantha, our new voice AI agent.

Calico Cloud vs Google Cloud Security Command Center comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
7th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (10th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (9th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd)
Calico Cloud
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
19th
Average Rating
7.8
Reviews Sentiment
6.5
Number of Reviews
5
Ranking in other categories
Container Security (28th), AI Observability (22nd)
Google Cloud Security Comma...
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
21st
Average Rating
7.6
Reviews Sentiment
5.0
Number of Reviews
4
Ranking in other categories
Cloud Security Posture Management (CSPM) (26th)
 

Mindshare comparison

As of October 2026, in the Cloud-Native Application Protection Platforms (CNAPP) category, the mindshare of Qualys TotalCloud is 2.4%, up from 1.6% compared to the previous year. The mindshare of Calico Cloud is 0.6%, up from 0.1% compared to the previous year. The mindshare of Google Cloud Security Command Center is 1.5%, down from 2.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud-Native Application Protection Platforms (CNAPP) Mindshare Distribution
ProductMindshare (%)
Qualys TotalCloud2.4%
Calico Cloud0.6%
Google Cloud Security Command Center1.5%
Other95.5%
Cloud-Native Application Protection Platforms (CNAPP)
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
Olakunle Obasoro - PeerSpot reviewer
DevOps Engineer at Exponential Craft
Security posture has become visible and container risks are managed proactively
Regarding improvements for Calico Cloud, there is a need to build agentic security systems. I believe Calico Cloud is progressing towards this, and I believe they can enhance their teaching methods to facilitate adoption. Documentation needs continuous improvement. It is good and easy to read, but it can get better. Having a searchable summary feature, such as a chatbot, could help users quickly resolve issues without having to read extensive documentation. At the moment, I do not believe there are more improvements needed, but as mentioned earlier, there should be a focus on better documentation, possibly by embedding chatbot features that could respond to user prompts effectively.
RaviUpadhyay - PeerSpot reviewer
Security Consultant at HCLSoftware
Security posture has improved with automated insights but reporting and integrations still need work
The best feature of Google Cloud Security Command Center is that it is flexible to integrate with several third-party tools or services, and it is more customized. For example, it is already giving a misconfiguration and the vulnerability, and if somebody wants to do some in-depth analysis for patterns such as metrics, they can export the continuous log on the spot with that tool. From an integration point of view, I would say it is more customized with different tools. The asset discovery feature of Google Cloud Security Command Center enhances my security strategy because, nowadays, data sensitivity and data privacy are very important, and using some DLP utility, I can classify and set up rules to generate reports based on the classification in their asset discovery. This can also include data classification on Google storage buckets, and overall, Google Cloud Security Command Center has that information, which can be used for various analyses or alerts. It is very important for compliance assessment because every business is global and connects with different geographical locations, meaning each country has its own regulatory systems and internal compliance policies. Google Cloud Security Command Center has the feature to set up security postures based on which resources or assets inside Google Cloud can be marked as compliant or non-compliant, giving a risk score for immediate reporting to higher management or CISO, making it very helpful in terms of security, risk, and compliance.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Qualys TotalCloud's most valuable features are its cloud security posture management, Kubernetes, and container security capabilities."
"Qualys TotalCloud's most valuable feature is its agent versatility."
"I highly recommend Qualys TotalCloud to other users."
"The agent and agentless scanning in TotalCloud, particularly the FlexScan method, is incredibly valuable. With traditional scanning approaches, we had to give IP ranges and whitelist IPs. All that is now simplified. FlexScan requires minimal intervention, and after configuration, it automatically collects data and performs necessary scans."
"In my opinion, this is the best tool."
"The biggest strengths of Qualys TotalCloud are that it is pretty good at cloud visibility, has easy integration, and also has multi-cloud compatibility."
"Its dashboards are brilliant. It provides in-depth insights."
"Qualys TotalCloud is overall the best tool available in the market for scanning purposes."
"Calico Cloud has had a positive impact on our organization by improving both our Kubernetes security posture and operational efficiency."
"The number one standout feature is the multi-cloud hybrid workload support, as the fact that Calico Cloud is not strictly bound to Kubernetes pods but can also utilize bare metal or virtual machines means it offers a unified control plane and allows for a single security policy to be applied and for traffic flow to be observed between VM-based databases and containerized applications running in Kubernetes, which is amazing for increasingly popular hybrid workloads."
"Calico Cloud has positively impacted my organization by improving the security of deployed applications while having greater control and visibility over communication between the different microservices."
"Calico Cloud has positively impacted my organization, especially on the security front, as it helped us anticipate security threats."
"The impact of Calico Cloud is that we were able to achieve a more secure understanding of our security posture, access our containers knowing full well that all policies set were followed through, and see visually how everything was interconnected, which has impacted our business positively."
"It simplifies compliance efforts."
"I would definitely recommend Google Cloud Security Command Center to others."
"The compliance reporting feature helped us maintain a baseline of compliance within the information security policies."
"Most people use the threat detection dashboard."
 

Cons

"There is room for improvement in the support."
"I chose a rating of nine out of ten because there is a complex interface that sometimes overwhelms new engineers."
"Enhancing clarity regarding its compliance capabilities would be beneficial, as the current scope is limited in geographic coverage."
"Their customer support needs improvement."
"TotalCloud could improve the classification of vulnerabilities. Specifically, it could enhance the categorization of what aspects fall under patches resolved by OS or software updates and what pertains to configuration adjustments."
"There is room for improvement in vulnerability scanning, particularly for PaaS environments. Currently, Qualys does not have full access to these instances, which limits its effectiveness."
"In my opinion, what can be improved in Qualys TotalCloud includes pricing and container scanning."
"Qualys's ticketing system can be confusing when assigning tasks to individuals, and support could be improved by offering instant call solutions with engineers in addition to ticket replies."
"Another issue is the resource footprint because Calico Cloud is an all-inclusive networking solution with many daemons running inside the cluster, putting a noticeable load on the Kubernetes API server in large clusters."
"They may not have all the features that their competitor Cilium has, and they are doing a portion of what Cilium does and a portion of what Istio does."
"I think Calico Cloud could be improved by being a bit cheaper."
"The integration process of Calico Cloud with existing systems has its challenges."
"Calico Cloud is a very good product with well-defined usage. I would appreciate seeing more improvement on real-time analysis capabilities."
"The AI capabilities have been heavily promoted, but I haven't seen a significant impact."
"Visibility can be improved along with automation."
"There is definitely room for improvement in Google Cloud Security Command Center. While the functionality is very native, compared to third-party tools that offer a variety of features for easy integrations and custom KPIs, Google Cloud Security Command Center lacks some of these functionalities, requiring complex workarounds for custom reporting, and given that customers often use hybrid environments, having a broader perspective is necessary for integration."
 

Pricing and Cost Advice

"TotalCloud's price is about right where I would expect it to be."
"I am not sure about the pricing. From what I understand, it is a bit on the higher side, but I do not have the exact numbers."
"Qualys TotalCloud is expensive, but it offers a premier solution with no headaches."
"Qualys TotalCloud is cost-efficient and was selected for its value compared to other products."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
"Qualys TotalCloud is expensive."
"As a middle management member, I do not have direct pricing knowledge, but based on the knowledge from our meetings, its pricing is competitive."
"Qualys TotalCloud offers cost-effective licensing flexibility."
Information not available
"Initially, it used to be relatively expensive, starting at around four or five hundred dollars."
report
Use our free recommendation engine to learn which Cloud-Native Application Protection Platforms (CNAPP) solutions are best for your needs.
915,287 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
No data available
Financial Services Firm
14%
Computer Software Company
13%
Comms Service Provider
7%
Marketing Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise35
No data available
No data available
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
What is your experience regarding pricing and costs for Calico Cloud?
My experience with pricing, setup cost, and licensing for Calico Cloud was determined by management who evaluated the...
What needs improvement with Calico Cloud?
I think there are a couple of issues with Calico Cloud, at least during the first time I used it more intensively. On...
What is your primary use case for Calico Cloud?
My main use case for Calico Cloud was primarily cloud network security. An unfortunate aspect of cloud architecture i...
What is your primary use case for Google Cloud Security Command Center?
I am primarily working with Google Cloud Security Command Center, which is their CSPM, and also with the next-generat...
What advice do you have for others considering Google Cloud Security Command Center?
I rate Google Cloud Security Command Center a seven and a half out of ten. While it is a ten from a security perspect...
What needs improvement with Google Cloud Security Command Center?
There is definitely room for improvement in Google Cloud Security Command Center. While the functionality is very nat...
 

Also Known As

Qualys TotalCloud with FlexScan
No data available
No data available
 

Overview

Find out what your peers are saying about Calico Cloud vs. Google Cloud Security Command Center and other solutions. Updated: September 2026.
915,287 professionals have used our research since 2012.