No more typing reviews! Try our Samantha, our new voice AI agent.

SmartGRC vs Vanta comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
39
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (6th)
SmartGRC
Average Rating
0.0
Number of Reviews
0
Ranking in other categories
Compliance Management (34th)
Vanta
Average Rating
8.6
Reviews Sentiment
5.5
Number of Reviews
10
Ranking in other categories
Compliance Consulting (1st), Data Governance (14th), Compliance Management (3rd)
 

Featured Reviews

RO
IT Security Expert at Alior Bank S.A.
Unified risk scoring has improved our cloud visibility and simplifies remediation priorities
Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS. This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score. The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified. Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.
Use SmartGRC?
Leave a review
reviewer2585640 - PeerSpot reviewer
Consultant at a consultancy with 11-50 employees
Compliance workflows have become organized and automation supports ongoing healthcare audits
There are always tons of rooms for improvement for Vanta. I kind of exaggerated a little bit about the policy control. I don't really love the way they handle the revision management of that feature. If I'm on V1 of the policy document and I make some changes to it, then I get rid of V1 and then I re-upload V2. It's not that it keeps a running history of each of the different revisions. A little bit of an issue with that, but workable. I don't really have any negative complaint right now that would be worthwhile expressing. It's just that there's a lot of features. The UI is not super intuitive, but now that I've worked with it for a couple of years, I know how to navigate and get around. Initially, it was a little bit of a struggle understanding how these things would all work.
report
Use our free recommendation engine to learn which Compliance Management solutions are best for your needs.
896,942 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
9%
Manufacturing Company
9%
Comms Service Provider
7%
No data available
Computer Software Company
16%
Financial Services Firm
9%
University
8%
Outsourcing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise3
Large Enterprise28
No data available
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise3
Large Enterprise1
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
Areas that need improvement in every solution include the remediation part. The remediation steps should be simple en...
What is your primary use case for Qualys TotalCloud?
Our use case involves the assets that we have under cloud, the assets exposed to the internet, and the internal appli...
Ask a question
Earn 20 points
What needs improvement with Vanta?
To improve Vanta, I suggest continuing to improve the areas of integration with the HITRUST CSF for R2 assessments. I...
What is your primary use case for Vanta?
My main use case is certification. I used Vanta to establish a HITRUST certification for a telecommunications organiz...
What advice do you have for others considering Vanta?
I would tell others looking into using Vanta to use it for HITRUST E1 and I1 assessments, as the R2 assessments are s...
 

Comparisons

 

Also Known As

Qualys TotalCloud with FlexScan
No data available
No data available
 

Overview

 

Sample Customers

Information Not Available
Information Not Available
Care Directives, Shortcut , Nayya, Heizenrader, Treasury Prime
Find out what your peers are saying about SentinelOne, Wiz, Vanta and others in Compliance Management. Updated: May 2026.
896,942 professionals have used our research since 2012.