Try our new research platform with insights from 80,000+ expert users

Diligent One Platform (formerly Highbond) vs Qualys Policy Compliance comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on May 21, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Diligent One Platform (form...
Ranking in IT Governance
9th
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
3
Ranking in other categories
GRC (23rd), IT Vendor Risk Management (21st)
Qualys Policy Compliance
Ranking in IT Governance
3rd
Average Rating
8.8
Reviews Sentiment
7.3
Number of Reviews
8
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2026, in the IT Governance category, the mindshare of Diligent One Platform (formerly Highbond) is 6.6%, up from 3.3% compared to the previous year. The mindshare of Qualys Policy Compliance is 3.6%, up from 2.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Governance Market Share Distribution
ProductMarket Share (%)
Qualys Policy Compliance3.6%
Diligent One Platform (formerly Highbond)6.6%
Other89.8%
IT Governance
 

Featured Reviews

WW
Data Analyst at Rhythex
Good automation and analytics, but is costly
The report model was our main concern. I believe currently the solution uses a third party for the reporting. As part of a consulting firm, one of the challenges we face is the difficulty in producing reports that meet the expectations of our clients and customers. It would be beneficial if the focus could be shifted toward improving the reporting aspect. The impact report is a crucial aspect, as we only have one opportunity to create it. Galvanize HighBond can improve by generating more impact reports post-project, and allowing access to the reports using a web version, which would greatly benefit us. The cost of the solution is expensive and needs improvement.
reviewer1906245 - PeerSpot reviewer
Information Security Analyst at a tech services company with 11-50 employees
Facilitates continuous compliance monitoring and simplifies vulnerability tracking for distributed cloud assets
Regarding improvements I would like to see in Qualys Policy Compliance, there are a couple of vulnerabilities where the metrics that are already there and the way Qualys measures those metrics and labels them as critical, high, or low does not align with my understanding from a user standpoint. Every time, I have to put in a false positive. Since I have been doing that for the past one year, the same vulnerability tends to pop up and they mark it as critical. Qualys needs to update and rediscover those weaknesses and re-label them. I understand what the company design and what the tool does, but it takes some time for us to manage those things. In terms of missing features that I would like to see included in Qualys Policy Compliance, I do not think there are any. The feature does what we require and does the job. If there were some sort of reporting that fulfills auditor's requirements, particularly if there is an external audit and they ask us for any historical data like how long we have been compliant to the PCI framework, that would be valuable. Having reporting that shows historical data that we have been compliant from the date of inception, for example, from 2023 to 2025 onwards, would bring value to what we are reporting.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is automation."
"The platform allows multiple features that are very useful. The first one is being able to define the enterprise policy. The second one is to be able to automatically check the compliance level based on that policy, and the third one is that it allows us to generate reports and dashboards to see the compliance level easily."
"The reporting and security checks are valuable."
"The most valuable feature of QualysGuard Policy Compliance is the automation that can detect real-time threats and decrease risks."
"The reason I decided to stick with Qualys is that for the past three years, we went through evaluating other tools, but Qualys was always our priority and always our first choice because of what it was offering as a platform."
"The solution's interface looks good, which enhances asset scanning and ensures automatic patching."
"It's a simple product."
"From the Qualys Policy Compliance, the best feature is that they have predefined templates for compliances, allowing easy application of compliance requirements against our products and providing clear reports on whether assets are compliant or not."
 

Cons

"The cost of the solution is expensive and needs improvement."
"Some sort of education or knowledge base about the product would be beneficial for beginners."
"The reporting needs improvement."
"It would be good if the solution’s technical support could be faster."
"They need to improve the reporting part of the CI/CD pipelines and the ability to download scans from pods."
"The policy creation aspect needs improvement."
"There are a couple of vulnerabilities where the metrics that are already there and the way Qualys measures those metrics and labels them as critical, high, or low does not align with my understanding from a user standpoint."
"There is no clear mapping for the CIS controls in terms of how they should be implemented into Qualys, so the implementation stage might be a little bit challenging for the customer. That means that the customer will end up opening support cases, which will overload their support team to explain those. If they are somehow published somewhere, it would save time and effort for both sides."
 

Pricing and Cost Advice

"I give the cost of the solution a six out of ten."
"The solution's pricing is in the mid-range, where it is neither expensive nor very cheap."
"The prices might be a little bit high. I cannot compare it with another product because we did not try any other product, but this is my impression when comparing different modules."
report
Use our free recommendation engine to learn which IT Governance solutions are best for your needs.
879,477 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Manufacturing Company
9%
Computer Software Company
9%
University
5%
Financial Services Firm
14%
Healthcare Company
14%
Government
10%
Performing Arts
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise2
Large Enterprise4
 

Questions from the Community

Ask a question
Earn 20 points
What is your experience regarding pricing and costs for QualysGuard Policy Compliance?
I was involved in the purchasing of Qualys Policy Compliance in my previous company, where the costs are based on the number of devices and features, with enterprise level pricing which I cannot sp...
What needs improvement with QualysGuard Policy Compliance?
Regarding improvements I would like to see in Qualys Policy Compliance, there are a couple of vulnerabilities where the metrics that are already there and the way Qualys measures those metrics and ...
What is your primary use case for QualysGuard Policy Compliance?
I have been working with Qualys Policy Compliance for the past four years. Our complete infrastructure is on cloud and we have assets distributed across Asia and North America. We have a couple of ...
 

Also Known As

Rsam GRC, HighBond, HighBond by Galvanize , Diligent GRC Platform
No data available
 

Overview

 

Sample Customers

CNA Insurance
PDX, Cigna
Find out what your peers are saying about Diligent One Platform (formerly Highbond) vs. Qualys Policy Compliance and other solutions. Updated: December 2025.
879,477 professionals have used our research since 2012.