Try our new research platform with insights from 80,000+ expert users

Qualys VMDR vs Rapid7 InsightVM comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 22, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Zafran Security
Sponsored
Average Rating
9.6
Reviews Sentiment
7.8
Number of Reviews
6
Ranking in other categories
Vulnerability Management (18th), Continuous Threat Exposure Management (CTEM) (2nd)
Qualys VMDR
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
94
Ranking in other categories
IT Asset Management (6th), Vulnerability Management (1st), Configuration Management Databases (2nd), Container Security (10th), Risk-Based Vulnerability Management (1st)
Rapid7 InsightVM
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
64
Ranking in other categories
Risk-Based Vulnerability Management (4th)
 

Featured Reviews

Israel Cavazos Landini - PeerSpot reviewer
Weekly insights and risk analysis facilitate informed security decisions
I appreciate the weekly insights Zafran provides, which include critical topics for networks and IT security, allowing us to evaluate which insights apply to our environment. The organization score feature is valuable to keep the leadership team updated on how our infrastructure fares security-wise. The applicable risk level versus base risk level feature is beneficial because prior to Zafran, we only used the base risk level, but now understand that risk depends on the asset itself. Zafran is an excellent tool.
Ankesh Raj - PeerSpot reviewer
Real-time responses and reporting streamline vulnerability management
Qualys VMDR provides a real-time response and reporting feature, which is excellent. It allows us to see real-time graphs and reports for every asset, server, and more, which is very user-friendly. Our clients have given good feedback, and they are satisfied with the tool. We use it daily to fix vulnerabilities by connecting with infrastructure to remediate. The feedback from the client side is very good.
Anusha Sadasivani - PeerSpot reviewer
Rapid deployment and user-friendly architecture streamline vulnerability management but customer support response needs improvement
We are still using Rapid7 InsightVM I personally still use Rapid7 InsightVM. We use Rapid7 InsightVM for vulnerability scanning. It supports both agent-based and agentless scanning, which is part of our vulnerability management strategy. The agentless scan in Rapid7 InsightVM is effective and…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We are able to see the real risk of a vulnerability on our environment with our security tools."
"We saw benefits from Zafran Security almost immediately after deploying it."
"Zafran is an excellent tool."
"Zafran has become an indispensable tool in our cybersecurity arsenal."
"Overall, we have seen about eighty-seven percent reduction of the number of vulnerabilities that require urgency to remediate, specifically the number of criticals."
"I like the automated report generation and vulnerability report generation."
"I am impressed with the VMDR feature."
"The process of defining and discovering scans is organized efficiently."
"It's really beneficial for scanning and interacting with the agent."
"The solution shows us classic categories, including high, medium, and low risks. It also shows critical items, and that gives us the advantage of prioritizing things."
"Using this product, we now have a vulnerability management cycle wherein VMDR plays a major role."
"Qualys VM is very stable."
"Qualys VMDR is easy to understand and provides detailed reports."
"The main functionality of identifying item endpoints that weren't properly patched or had vulnerabilities is the solution's most valuable feature."
"The discovery and prioritization of vulnerabilities."
"I have been in contact with technical support and they are not bad."
"The performance is good."
"The product is scalable."
"The most valuable feature for me is the risk calculation based on monthly effects."
"The most important aspect of the solution is that it rarely gives false positives, especially compared to other products. It provides very clear reports for our IT teams to look at."
"We feel the interface is very good. It is very easy to use, even a nontechnical person can use it."
 

Cons

"I think the ability to have some enhanced reporting capabilities is something they can improve on, as they have good reports but we have asked for some specific reporting enhancements."
"The dashboarding and reporting functionality of Zafran Security is an area that definitely could use some improvements."
"Initially, we were somewhat concerned about the scalability of Zafran due to our large asset count and the substantial amount of information we needed to process."
"Support could be improved since the response can be slow."
"Qualys could be improved in its overall performance compared to other vulnerability management or scanning tools."
"Qualys could improve the inbuilt dashboards."
"I would like to have CSPM, a continuous scan-like cloud added to the solution."
"When you want to cover yourself for scalability, you will be charged for the number you place on the scan itself."
"I would like to see this solution more developed and competitive in the Cloud space."
"We are moving away from Qualys to Defender ATP because I find that Defender ATP is much better at prioritizing the vulnerabilities that I should be looking at."
"Qualys VMDR is basically susceptible to false positives, and false negatives."
"InsightVM could be improved by providing passive scanning as an option."
"I’d like to see Rapid7 InsightVM improve by adding a knowledge base similar to what Qualys offers. This would help us easily check and search for vulnerabilities using Rapid7 IDs associated with CVs or CVSS. From a features perspective, everything was fine at the time, and the security features of Rapid7 InsightVM were effective."
"The drawback is that it is still not a fully SaaS solution, so you must deploy a console."
"I would say that it improved our visibility, but it left things open."
"It would be nice to have an additional feature that would provide reports on who has logged onto the console or who did what on the console."
"We have some issues with how it scans patches."
"The solution should include a tighter integration with third-party threat modeling and threat intelligence tools."
"In order to be able to properly test the solution and make a decision, I would like to receive the test license code instantly and eliminate the wait time."
 

Pricing and Cost Advice

Information not available
"When you want to cover yourself for scalability, you will be charged for the number you place on the scan itself."
"Qualys is cheaper and more affordable than other solutions."
"They have recently changed the pricing model, which is now better than it was before."
"Qualys Virtual Scanner Appliance isn't expensive right now. But the price for their product bundles could be better."
"Qualys is a pay-as-you-go model, so there's flexibility to the pricing."
"The tool's pricing is expensive and I would rate the pricing a seven out of ten."
"It is a high cost product. Compared to the other solutions, it is around 15 to 20% higher in cost."
"The solution is reasonably priced for the value it provides."
"A full license for the solution is expensive because it is at the organizational level and not by individual users."
"The product is cheaper than the other similar tools available in the market."
"Its price is too high. My only concern or issue with Rapid7 is its pricing."
"It is pretty expensive. It depends on what you consider pricey, however, if you only look at vulnerability management solutions, such as within VM or VMDR, there are, I suppose the prices are almost the same. But I believe you will discover that for yourself."
"Our licensing costs are somewhere around $40,000 annually. There are no additional fees."
"The solution is a bit more reasonably priced than other products."
"Its licensing is yearly. Everything is included in the price for one year."
"Pricing is reasonable because we pay according to asset usage. We can define our assets and sites according to our preference."
report
Use our free recommendation engine to learn which Risk-Based Vulnerability Management solutions are best for your needs.
863,564 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Financial Services Firm
11%
Manufacturing Company
7%
Healthcare Company
6%
Financial Services Firm
16%
Computer Software Company
13%
Manufacturing Company
8%
Government
7%
Computer Software Company
13%
Financial Services Firm
12%
Manufacturing Company
9%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Zafran Security?
The current pricing of Zafran Security is fair overall. They were good to work with to accommodate our organization w...
What needs improvement with Zafran Security?
The dashboarding and reporting functionality of Zafran Security is an area that definitely could use some improvement...
What is your primary use case for Zafran Security?
Zafran Security is helping reduce the amount of critical vulnerabilities in our environments that require prompt reme...
What do you like most about Qualys VMDR?
I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagg...
What is your experience regarding pricing and costs for Qualys VMDR?
Qualys offers better pricing and is feature-packed compared to other tools.
What needs improvement with Qualys VMDR?
There were some issues later with Qualys VMDR regarding security, specifically with numerous false positive reports.
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. Yo...
What do you like most about Rapid7 InsightVM?
The product's initial setup phase was very easy.
What is your experience regarding pricing and costs for Rapid7 InsightVM?
The customers are mostly SMBs, though some enterprise organizations have also deployed the solution. This is neither ...
 

Also Known As

No data available
Qualys VM, QualysGuard VM, Qualys Asset Inventory, Qualys Container Security
InsightVM, NeXpose
 

Overview

 

Sample Customers

Information Not Available
Agrokor Group, American Specialty Health, American State Bank, Arval, Life:), Axway, Bank of the West, Blueport Commerce, BSkyB, Brinks, CaixaBank, Cartagena, Catholic Health System, CEC Bank, Cegedim, CIGNA, Clickability, Colby-Sawyer College, Commercial Bank of Dubai, University of Utah, eBay Inc., ING Singapore, National Theatre, OTP Bank, Sodexo, WebEx
ACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBM
Find out what your peers are saying about Qualys VMDR vs. Rapid7 InsightVM and other solutions. Updated: June 2025.
863,564 professionals have used our research since 2012.