We compared Qualys VMDR and Tenable Vulnerability Management based on our users reviews in six parameters. After reading the collected data, you can find our conclusion below:
Users generally find the setup process for Qualys VMDR to be easy and fast, taking only a few minutes. However, there are some integration issues with other systems. In contrast, setting up Tenable Vulnerability Management can be time-consuming, ranging from a couple of hours to a few weeks. Some users find it difficult to configure IP ranges and firewall settings.
Qualys VMDR offers a prioritization mechanism, continuous monitoring, a customizable dashboard, and a comprehensive overview of vulnerabilities. On the other hand, Tenable Vulnerability Management provides complete visibility, scalability, and a user-friendly dashboard for vulnerability analysis.
Both Qualys VMDR and Tenable Vulnerability Management have areas that require improvement. Qualys VMDR could benefit from enhancements in user experience, UI design, SLA tracking, batch prioritization, integration, reporting, and dashboards. On the other hand, Tenable Vulnerability Management needs improvements in visibility, support, dashboards, integration, reporting, pricing, user interface, and automation.
The cost of setting up Qualys VMDR can be high for smaller customers, as it varies depending on the specific features needed. Some reviewers mentioned that additional fees are required for features like patch management and EDR policy compliance. In contrast, Tenable Vulnerability Management has a pricing model that varies among users, which some users did not find ideal. While basic vulnerability scanning and management have no hidden costs, the overall cost can be relatively expensive compared to other solutions.
Qualys VMDR is praised for its ability to effectively reduce risks and mitigate cybersecurity threats, resulting in a good return on investment. On the other hand, Tenable Vulnerability Management is acknowledged for providing long-term value and identifying vulnerabilities, although not everyone experiences a significant return on investment.
The feedback for Qualys VMDR's customer service varies, with some customers appreciating the support provided, while others highlight the need for quicker response times and more knowledgeable staff. Similarly, Tenable Vulnerability Management's customer service has received mixed reviews, with certain users expressing dissatisfaction regarding issue resolution and turnaround time, while others commend the team's round-the-clock availability and promptness.
Comparison Results
In comparing Qualys VMDR to Tenable Vulnerability Management, both solutions have easy initial setups and offer comprehensive vulnerability management. Qualys VMDR provides a prioritization mechanism, continuous monitoring, and great technical support. It also has a customizable dashboard. However, it lacks user-friendliness, integration with other systems, and needs improvement in reporting and dashboards. On the other hand, Tenable Vulnerability Management offers complete visibility, is considered reliable and cost-effective, and has a user-friendly dashboard. It also provides efficient risk assessments. However, it lacks coverage of the entire vulnerability management process and needs improvements in support, pricing, and user interface customization.
"The most valuable features are vulnerability scanning, policy compliance scanning, and tablet for web application scanning."
"It's a good product. After the scan our internet works well. It scans our security posture."
"It is a stable solution."
"Qualys VM's best feature is vulnerability management."
"The solution shows us classic categories, including high, medium, and low risks. It also shows critical items, and that gives us the advantage of prioritizing things."
"Intuitive and easy to use."
"The Vulnerability Management and Patch Management features are the most valuable features of this solution."
"It gives a very good overview of the inventory assessment process, and it can be accessed across our company because it's a global tool."
"I would rate Tenable's dashboards and reporting capabilities for illustrating security posture a nine out of ten, with ten being the best."
"Technical support has been good. They respond quite quickly."
"The vulnerability management itself is the most valuable feature as well as references to the mitigation techniques."
"It is a very, very user-friendly tool...The setup is easy"
"Tenable.io Vulnerability Management is an easy-to-use product. I"
"The solution is very simple to use."
"The initial setup is mostly straightforward."
"The dashboard is pretty intuitive, and it lets you do a drill-down analysis of each vulnerability. That is something that brings a lot of value to the organization."
"There's a need to upgrade or fix the potential vulnerability rate. Around 20,000 potential vulnerabilities were showing in Qualys VMDR, but none of the other tools showed them. When we checked, it wasn't the case. Support explained that even small issues were being counted as vulnerabilities, causing issues in our audit. So, the security features could be improved to identify vulnerabilities accurately."
"They have integrated with other third parties, but it is still not viable."
"Improve the user interface."
"Qualys could improve the inbuilt dashboards."
"There needs to be better documentation."
"The ability to manage user accounts and give rights to the operator to know about abnormalities of applications is something that needs improvement."
"This solution could be improved by extending the agent capabilities to different operating systems including Mac and Linux. We would also like the capability to easily check for vulnerability in assets in the IOTs."
"The price could be better. Asset view is still a legacy feature. I'm not able to extract the information about the asset with complete details. It would be better if they fixed that in the next release. I know Qualys is already working on it, so I'm hopeful it will be available in the next five or six months. That would be something that's changed where I seek improvement."
"It can have more integration."
"The solution must provide penetration testing."
"The shortcoming of the solution that needs improvement is related to its capability to do vulnerability assessments on applications."
"I'm not satisfied with the reporting structure."
"The tool's reports are bad. They're not very customizable or flexible. During audits, we often have to exclude things that aren't relevant to our organization, but we can't do that easily with the reports. They come in HTML or PDF format, and we can't compare current results with previous ones in Excel because we never receive reports in Excel."
"The solution’s pricing could be improved."
"The stability has room for improvement."
"Tenable could improve visibility into assets, including automated asset tagging. You should be able to automatically tag assets based on location, function, ownership, etc. That would help us because we spend a lot of time identifying and tagging assets by hand."
More Tenable Vulnerability Management Pricing and Cost Advice →
Qualys VMDR is ranked 3rd in Risk-Based Vulnerability Management with 77 reviews while Tenable Vulnerability Management is ranked 2nd in Risk-Based Vulnerability Management with 38 reviews. Qualys VMDR is rated 8.2, while Tenable Vulnerability Management is rated 8.2. The top reviewer of Qualys VMDR writes "Good visibility but expensive and needs better support". On the other hand, the top reviewer of Tenable Vulnerability Management writes "Discovers vulnerabilities and integrates well with other solutions". Qualys VMDR is most compared with Tenable Nessus, Tenable Security Center, Rapid7 InsightVM, Microsoft Defender Vulnerability Management and Microsoft Defender for Cloud Apps, whereas Tenable Vulnerability Management is most compared with Tenable Security Center, Tenable Nessus, Amazon Inspector, Microsoft Defender Vulnerability Management and Rapid7 InsightVM. See our Qualys VMDR vs. Tenable Vulnerability Management report.
See our list of best Risk-Based Vulnerability Management vendors.
We monitor all Risk-Based Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.