No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Vulnerability Management (formerly Kenna.VM) vs Qualys VMDR vs Tenable Nessus comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Risk-Based Vulnerability Management Mindshare Distribution
ProductMindshare (%)
Cisco Vulnerability Management (formerly Kenna.VM)2.6%
Qualys VMDR12.1%
Rapid7 InsightVM10.5%
Other74.8%
Risk-Based Vulnerability Management
Vulnerability Management Mindshare Distribution
ProductMindshare (%)
Qualys VMDR4.9%
Wiz6.4%
Tenable Nessus4.9%
Other83.8%
Vulnerability Management
Vulnerability Management Mindshare Distribution
ProductMindshare (%)
Tenable Nessus4.9%
Wiz6.4%
Qualys VMDR4.9%
Other83.8%
Vulnerability Management
 

Featured Reviews

AshishPaliwal - PeerSpot reviewer
Self-employed at Self-employed
Offers contextual prioritization and risk-based remediation of vulnerability
An improvement would be some sort of an integration with any GRC suite. There are a lot of GRC suites available, like Archer, MetricStream, Rsam, Protiviti, for example. So how would a solution like this work if my company has already invested thousands or maybe millions in a GRC solution? Do I still need it and how does it fit into an existing SAP environment? There could be interoperability, having more data sources, integrating Splunk, Qualys, FireEye, Rapid7, Carbon Black. I'm sure all that can be done to an extent, with a little more insight and a little more accuracy on the industry numbers and trends. I'd like the solution to offer any sort of assistance in any way with the remediation part, not just identification of vulnerability risk, and that is second.
Vaibhav Ghule - PeerSpot reviewer
Soc Lead & Edr Administration at Persistent Systems
Continuous risk-based monitoring has strengthened incident response and vulnerability prioritization
I haven't explored Qualys VMDR's vulnerability lifecycle automation yet. One of my analysts mentioned that queries lack grouping operators in Qualys VMDR. From my experience, I would appreciate improvements in the query options in Qualys VMDR, specifically in the query-building process where I would need more features and operators. Additionally, we have been facing issues with Qualys on the cloud level. We cannot download the configuration profile from the cloud agent, and it is showing a pending action for download. During 2025, we noticed outages of Qualys a couple of times. I want to mention that there is an issue with receiving timely RCA deliveries. While this is not necessarily about the tool, it relates to support. The support has not been very responsive, and we are receiving RCAs a little delayed whenever we raise support cases or communicate with the TAMs. Additionally, the UI has a slight latency, which I and my team have experienced. They have also reported this latency issue when navigating through different pages.
MohammedJaffir - PeerSpot reviewer
Founder at Cipheroot
Has enabled me to reduce false positives and perform deep credential auditing with seamless integrations
I mostly use the configuration audit feature for the audit configuration as a scan policy, and I will use it for credential audit, which helps me scan credentials access such as local administrator or root access, performing a deeper and more accurate check of local configuration settings and file systems, making it a highly recommended feature. Regarding integration capabilities, we can integrate Tenable Nessus with SIM tools such as Splunk, IBM QRadar, and Azure Sentinel, as well as with ticketing systems such as ServiceNow, Jira, and Slack. There is no complexity as it is very easy to integrate everything. In terms of the reporting feature, while vulnerability scanning can throw some false positives, Tenable Nessus has very few, achieving a reduction of 75% to 80% false positives with manual analysis needed. We can generate standard Nessus reports that typically include host summaries and vulnerabilities by host and plugin, alongside solutions and remediation recommendations. The main benefits I get from Tenable Nessus are complete asset inventory and comprehensive attack surface management, allowing us to prioritize vulnerabilities based on risk, focusing on true risk and threat path analysis.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The risk context of any vulnerability is a valuable feature; that is what it is used for and then data from different sources can be fed into it, and they have good dashboards, risk meters, and virtualization."
"The risk context of any vulnerability is a valuable feature."
"Qualys help identifies the weakness in our critical infrastructure and provides guidelines how to address them."
"I strongly recommend that you use this solution."
"The advantage with Qualys is that you get a lot of features because it has been a market leader for quite a long time."
"This solution gives us insight into our environment and improves our security. It helps us to maintain a good patching system whereby we know that XYZ is vulnerable within the system."
"Vulnerability management is the most valuable one and it’s a must in every organization."
"The prioritization feature is great. I think it has all of the advanced features that we need."
"What I like best about this product is that it does what it is supposed to do, which is vulnerability scanning."
"It gives you a lot of options, and it integrates with our ServiceNow for ticketing and all."
"Vulnerability assessment is the most valuable feature in Tenable Nessus, as it provides brief details regarding the vulnerability issues we have in our network."
"Once you get past the initial implementation, the solution is very stable."
"The solution can conduct a full vulnerability assessment and also suggest mitigation of vulnerabilities and has a lot of other features."
"Tenable Nessus is an absolutely stable and fantastic product."
"So far, I am quite pleased with this product and don't have any complaints."
"The interface is excellent; it makes it very user friendly and easy to navigate for the most part, and the product is pretty problem-free so we don't have any real issues with it."
"Nessus is effortless to integrate."
"The value that Tenable Nessus brings to my company is significant because we can see risks; it is also good to see the pages risk and system risks, and it saves money."
 

Cons

"An improvement would be some sort of an integration with any GRC suite."
"An improvement would be some sort of an integration with any GRC suite."
"The reporting capabilities are good but I would like to be able to make more customized reports."
"The technical support is mediocre at best. I would rate them a two out of five."
"The user interface (UI) is quite complicated."
"The IT infrastructure, especially server administration, needs to be improved."
"The price could be better. Asset view is still a legacy feature. I'm not able to extract the information about the asset with complete details. It would be better if they fixed that in the next release. I know Qualys is already working on it, so I'm hopeful it will be available in the next five or six months. That would be something that's changed where I seek improvement."
"The reporting in this solution can be improved."
"I can't say as I have worked mostly on its vulnerability management module."
"Reports were lacking somewhat on the customization side."
"It would be nice for the professional module to include some of the reports available in the expert module."
"There could be an integration between Tenable Nessus and other Tenable products. It will help us manage all the solutions using one dashboard."
"There is very little to improve but cloud security tests would be something helpful to have."
"Vulnerability recommendations are outdated and not in line with industry standards."
"I have found it is sometimes difficult to control the Zoom meeting sessions. For example, it is difficult to know who is talking and when trying to mute everyone but the speaker you end up muting everyone."
"Sometimes, the categorization for clients was tricky at first, however, they eventually got used to it."
"From my point of view, the solution basically is not for large enterprises."
"Tenable Nessus could improve the reporting."
 

Pricing and Cost Advice

"I think the pricing is based on the number of endpoints, so it's more subscription-based."
"There are no additional fees in addition to the standard licensing fees."
"Qualys VM is better suited for medium to large companies because the price can be too much for smaller customers."
"Qualys is cheaper and more affordable than other solutions."
"Qualys is a pay-as-you-go model, so there's flexibility to the pricing."
"There is a license for the use of this solution. We pay annually instead of monthly to receive a better discount on the price."
"The solution is reasonably priced for the value it provides."
"The price is very reasonable."
"It is a high cost product. Compared to the other solutions, it is around 15 to 20% higher in cost."
"The price of the solution is reasonable."
"The product is free."
"Its price is high for Libya. The companies here in Libya don't have the awareness of and a good budget for cybersecurity services. If you want them to go for a product, you need to provide something different. This differentiation is related to the price. They should give about 40% to 45% discount per person on the current cost."
"It has a fair cost and very good cost-benefit ratio."
"I rate the product's price seven or eight on a scale of one to ten, where one is low price and ten is high price."
"There is an annual license required to use this solution."
"The solution has free options."
"Cost-wise, it's an affordable tool."
report
Use our free recommendation engine to learn which Risk-Based Vulnerability Management solutions are best for your needs.
885,789 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Retailer
16%
Computer Software Company
13%
Financial Services Firm
10%
Construction Company
9%
Financial Services Firm
16%
Computer Software Company
8%
Manufacturing Company
7%
Government
6%
Manufacturing Company
10%
Financial Services Firm
10%
Government
9%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business20
Midsize Enterprise12
Large Enterprise70
By reviewers
Company SizeCount
Small Business40
Midsize Enterprise19
Large Enterprise35
 

Questions from the Community

Ask a question
Earn 20 points
What do you like most about Qualys VMDR?
I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagg...
What is your experience regarding pricing and costs for Qualys VMDR?
My experience with pricing, setup cost, and licensing shows that we can consider both time and money saved.
What needs improvement with Qualys VMDR?
I haven't explored Qualys VMDR's vulnerability lifecycle automation yet. One of my analysts mentioned that queries la...
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. Yo...
What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
Tenable Nessus is a vulnerability assessment solution that is both easy to deploy and easy to manage. The design of ...
What is your experience regarding pricing and costs for Tenable Nessus?
Based on my experience, the pricing for Tenable Nessus is somewhat higher, but customers still want to pay for it, so...
 

Also Known As

Kenna.VM, Kenna Security, Kenna, Kenna Security Platform
Qualys VM, QualysGuard VM, Qualys Asset Inventory, Qualys Container Security
No data available
 

Overview

 

Sample Customers

TransUnion
Agrokor Group, American Specialty Health, American State Bank, Arval, Life:), Axway, Bank of the West, Blueport Commerce, BSkyB, Brinks, CaixaBank, Cartagena, Catholic Health System, CEC Bank, Cegedim, CIGNA, Clickability, Colby-Sawyer College, Commercial Bank of Dubai, University of Utah, eBay Inc., ING Singapore, National Theatre, OTP Bank, Sodexo, WebEx
Bitbrains, Tesla, Just Eat, Crosskey Banking Solutions, Covenant Health, Youngstown State University
Find out what your peers are saying about Qualys, Tenable, Rapid7 and others in Risk-Based Vulnerability Management. Updated: March 2026.
885,789 professionals have used our research since 2012.