Try our new research platform with insights from 80,000+ expert users

Qualys CyberSecurity Asset Management vs SBOM Studio comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 20, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys CyberSecurity Asset ...
Ranking in Software Supply Chain Security
4th
Average Rating
9.2
Reviews Sentiment
7.7
Number of Reviews
22
Ranking in other categories
Vulnerability Management (8th), Patch Management (6th), Cyber Asset Attack Surface Management (CAASM) (3rd), Attack Surface Management (ASM) (3rd)
SBOM Studio
Ranking in Software Supply Chain Security
23rd
Average Rating
0.0
Number of Reviews
0
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2025, in the Software Supply Chain Security category, the mindshare of Qualys CyberSecurity Asset Management is 1.8%, up from 0.2% compared to the previous year. The mindshare of SBOM Studio is 0.8%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Software Supply Chain Security
 

Featured Reviews

Scott Frederick - PeerSpot reviewer
Well-integrated with our vulnerability scanning utilities and efficient in asset tagging and identification
Our favorite features are the tagging and the ability to quickly find assets in the portal. Additionally, I do like the fact that Qualys CSAM is integrated with the rest of our vulnerability scanning utilities. We use the full suite from Qualys. The fact that it is integrated makes it very easy to understand. It shares tagging information with VMDR. That is very nice. Qualys CSAM has discovered assets not previously covered by our vulnerability management program. Primarily, if we have assets without vulnerabilities, they become less visible, but Qualys CSAM alerts us to them because they have IP addresses and are attached to our network. It could discover everything from printers to servers to endpoints. It could discover UPSs, network devices, and across all operating systems. It discovers our security badge readers and digital signage. We have to feed that the IP address ranges, but beyond that, it finds everything in our internal network. We were able to realize its benefits within the first quarter of installing it. We did have to take some time to learn it and understand how to operationally leverage what it was telling us, but it was very quick. In addition to vulnerabilities, Qualys CSAM helps identify other risk factors to a degree. For instance, we can see if servers or assets have incorrect naming standards. We have our network segmented into development model, test, and production, and we have server naming standards that identify which management they should be in. If a production server has the naming standard of a development model server, we can find that. That is one area we have used it for. We are not fully using TruRisk, but we are using the Qualys detection score that is central to our corporate risk prioritization approach. It has completely replaced our homegrown one.
Use SBOM Studio?
Share your opinion
report
Use our free recommendation engine to learn which Software Supply Chain Security solutions are best for your needs.
858,945 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
14%
Government
9%
Comms Service Provider
6%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Qualys CyberSecurity Asset Management?
The pricing is reasonable relative to the features provided, as it collects all module data and operates as a main, centralized inventory, making it a cost-effective solution.
What needs improvement with Qualys CyberSecurity Asset Management?
Qualys CyberSecurity Asset Management helps us prioritize assets according to operating system, kernel version, installed software, and current version information. The ASM assists with attack surf...
What is your primary use case for Qualys CyberSecurity Asset Management?
We are using Qualys CyberSecurity Asset Management for daily activities such as identifying new assets through network scanning and agent-based scanning for newly provisioned assets. When any new a...
Ask a question
Earn 20 points
 

Overview

 

Sample Customers

Information Not Available
1. Atlassian 2. Cisco 3. Google 4. IBM 5. Intel 6. Microsoft 7. Oracle 8. SAP 9. VMware 10. Accenture 11. Capgemini 12. Deloitte 13. EY 14. KPMG 15. PwC 16. AWS 17. Azure 18. Google Cloud 19. IBM Cloud 20. Oracle Cloud 21. SAP Cloud 22. VMware Cloud 23. Arista Networks 24. Juniper Networks 25. NetApp 26. Cloudflare 27. Fastly 28. Incapsula 29. Imperva 30. Zscaler
Find out what your peers are saying about Mend.io, JFrog, Sonatype and others in Software Supply Chain Security. Updated: June 2025.
858,945 professionals have used our research since 2012.