Try our new research platform with insights from 80,000+ expert users

Qualys Policy Compliance vs RSA Archer comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on May 21, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.9
Qualys Policy Compliance improves data visibility and reliability, with many users noting efficiency despite challenges in ROI calculation.
Sentiment score
7.1
RSA Archer streamlines operations by automating processes, centralizing data, and enhancing risk management for high ROI and cost savings.
It relates to the effectiveness of employees and the time taken to complete tasks manually versus using the RSA system.
 

Customer Service

Sentiment score
8.1
Users commend Qualys Policy Compliance's responsive support, rating it highly, despite occasional challenges in providing necessary evidence.
Sentiment score
6.3
Users experience varied satisfaction with RSA Archer support, appreciating prompt assistance but sometimes requiring escalation for complex issues.
Qualys Policy Compliance customer support is very good.
The response time from RSA Archer's support team is not an issue; usually, there's no problem getting a timely response, but there could be more knowledgeable agents available.
They are responsive and perform well in technical support.
 

Scalability Issues

Sentiment score
7.7
Qualys Policy Compliance offers scalable solutions for complex environments, managing large IP volumes, despite minor web interface speed issues.
Sentiment score
7.1
RSA Archer offers scalable solutions for multiple organizations, though effectiveness varies with strategy, deployment, and resource management.
Scalability depends on the number of servers, including web and service servers.
The level of scalability depends on customization and how skillful our customization team is.
 

Stability Issues

Sentiment score
8.8
Qualys Policy Compliance is highly reliable, offering stability, excellent performance, and rare performance issues, earning a 9/10 rating.
Sentiment score
6.1
RSA Archer is stable and improved, though performance varies with resources and user load, rating around seven to eight.
It is very rare to encounter performance issues, about 0.1 to 0.01%.
The tool has stability, and it allows me to automate whatever process I have.
Performance issues arise mainly since it is not a core service for most organizations, so the resources provided are fewer.
 

Room For Improvement

Users seek improved reporting, support, customization, and educational resources in Qualys Policy Compliance for better industry alignment.
RSA Archer struggles with outdated interface, complex workflows, costly updates, and lacks intuitive design and efficient integrations.
They need to improve the reporting part of the CI/CD pipelines and the ability to download scans from pods.
While the AI features are emerging and the cost is comparatively low, it's not yet up to the market standard.
A remaining area for improvement is integration. There should be built-in integration mechanisms, for example, for organizations switching from platforms like ServiceNow to Archer, instead of custom integrations for each client.
Dashboards are usually effective, but while visibility from the dashboard level is good, drill-down details may be difficult to access, as they don't seem to have direct support for this drill-down.
 

Setup Cost

Qualys Policy Compliance pricing is device-based, viewed as mid-range, with value in security features and potential cost-effectiveness.
RSA Archer is costly but valued for flexibility and functionality, appealing more to large enterprises than smaller ones.
after comparing it with other products in the market, I would rate it around six or seven out of ten, as the price is relative.
 

Valuable Features

Qualys Policy Compliance provides automated threat detection, customizable policies, robust reporting, and integrates well with tools like Confluence and Jira.
RSA Archer enhances governance, risk, and compliance with configurable modules, automation, robust security, and strong reporting, appealing to users.
From the Qualys Policy Compliance, the best feature is that they have predefined templates for compliances, allowing easy application of compliance requirements against our products and providing clear reports on whether assets are compliant or not.
In the banking sector, Archer has been used to automate processes such as business continuity management, transitioning from manual processes to automated systems.
The helpful features of RSA Archer include providing an integrated overview of the landscape in the company, which leads the user to use the same inventory and other components, sharing the same set of references and objects we are working on.
This allows us to show end users and management where the issues lie and effectively demonstrate accountability and visibility in compliance.
 

Categories and Ranking

Qualys Policy Compliance
Ranking in IT Governance
3rd
Average Rating
8.6
Reviews Sentiment
7.9
Number of Reviews
7
Ranking in other categories
No ranking in other categories
RSA Archer
Ranking in IT Governance
1st
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
42
Ranking in other categories
GRC (1st), IT Vendor Risk Management (4th)
 

Mindshare comparison

As of August 2025, in the IT Governance category, the mindshare of Qualys Policy Compliance is 2.8%, up from 1.8% compared to the previous year. The mindshare of RSA Archer is 33.2%, up from 32.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Governance
 

Featured Reviews

Bhupendra Nayak - PeerSpot reviewer
A VMDR solution that can be used to detect, block, and mitigate vulnerabilities
We use QualysGuard Policy Compliance for VMDR (Vulnerability Management, Detection and Response). We can use the solution to detect, block, and mitigate vulnerabilities The most valuable feature of QualysGuard Policy Compliance is the automation that can detect real-time threats and decrease…
IMRAN ALMARZOOQI - PeerSpot reviewer
Automates compliance management effectively but needs improved interface and dashboards
The tool basically automates whatever processes you already have, so I cannot specify improvements in that regard. However, my main issue with Archer is the graphics. The graphics have always been lacking. I always need to depend on another tool to read information from Archer to have better dashboards. It is like using Linux, and it has a Linux mindset and interface. I want to use Archer for top management and CEOs, but it looks too technical, and the dashboards are not really friendly. They are bulky, like opening an old Nintendo system from nineteen-ninety. The management agrees that Archer lacks in terms of presentation and dashboarding. It is complex, not user-friendly, and bulky. The interface just looks old.
report
Use our free recommendation engine to learn which IT Governance solutions are best for your needs.
865,384 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Healthcare Company
18%
Financial Services Firm
18%
Government
10%
Insurance Company
8%
Financial Services Firm
23%
Insurance Company
12%
Manufacturing Company
9%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about QualysGuard Policy Compliance?
The most valuable feature of QualysGuard Policy Compliance is the automation that can detect real-time threats and decrease risks.
What is your experience regarding pricing and costs for QualysGuard Policy Compliance?
I was involved in the purchasing of Qualys Policy Compliance in my previous company, where the costs are based on the number of devices and features, with enterprise level pricing which I cannot sp...
What needs improvement with QualysGuard Policy Compliance?
I would appreciate improvements in our wrapper certificates and the policy compliance aligning better with automation scripting languages such as Python or Ansible. They need to improve the reporti...
What do you like most about RSA Archer?
It has various valuable features. For example, showing us if a control aligns with specific standards or frameworks helps us understand it better and verify its compliance.
What needs improvement with RSA Archer?
While it provides benefits in terms of security, the pricing is a bit higher than customers typically expect. It would be helpful if RSA Archer had the capability for two-way integration because, i...
What is your primary use case for RSA Archer?
Regarding the compliance, risk, and governance tools, I am comfortable discussing the tools in the GRC category. The specific module from ServiceNow is the ServiceNow Compliance, Risk, and Governan...
 

Comparisons

No data available
 

Also Known As

No data available
Archer
 

Overview

 

Sample Customers

PDX, Cigna
T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Find out what your peers are saying about Qualys Policy Compliance vs. RSA Archer and other solutions. Updated: July 2025.
865,384 professionals have used our research since 2012.