Try our new research platform with insights from 80,000+ expert users
Qualys Patch Management Logo

Qualys Patch Management pros and cons

Vendor: Qualys
4.5 out of 5
Badge Leader

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Qualys Patch Management significantly reduces organizational risks and enhances patch rates, achieving compliance rates over 95%.
Qualys Patch Management offers robust automation capabilities, including automatic patch scheduling, retrieval, and Google browsers' patching upon vendor release.
Qualys Patch Management provides a single pane of glass for vulnerability management, streamlining vulnerability assessment, prioritization, and remediation.
Qualys Patch Management enables efficient policy enforcement to ensure users apply necessary updates, maintaining a secure environment.
Qualys Patch Management integrates Qualys Gateway Scanner to download and deploy patches efficiently, minimizing bandwidth consumption.

CONS

Qualys Patch Management lacks built-in driver updates.
There are limitations in patching capabilities, unlike SCCM, which is more flexible.
There are challenges in supporting legacy operating systems and integrating with various vendors for patch availability.
The reporting feature and detection logic require significant enhancements for accuracy and user-friendliness.
Pricing is considered high, making it unaffordable for some companies, requiring more competitive pricing.
 

Qualys Patch Management Pros review quotes

Brad Mathis - PeerSpot reviewer
Employee-Owner, Senior Consultant, Information Security at Keller Schroeder
Jun 10, 2024
The most valuable feature in Patch Management is the Qualys query language for set-it-and-forget-it patching for our preapproved patches, and our preapproved schedules, That is extremely helpful compared to the old days of patching.
Yuvaraaj Adhithya - PeerSpot reviewer
Cyber Security Analyst at WPP
Aug 20, 2024
For a few applications, you do not need to go and download the patches from the network or somewhere else. They have the patches or the latest updates in the directory. You can just select a patch and deploy it to a server. You can create a patch job and select the patch. Everything is within the interface. You do not need to go out of it.
reviewer2560884 - PeerSpot reviewer
SOC - Cyber Security Engineer at a computer software company with 201-500 employees
Sep 25, 2024
Qualys' best feature is its reporting. At first, it may seem a little complicated to a beginning user, but it's helpful once you get used to it. Most of these scans run automatically. We set the scans up for the client to run at daily, weekly, or monthly intervals, depending on how critical the server or other hardware is.
Learn what your peers think about Qualys Patch Management. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
Rafael Araujo - PeerSpot reviewer
Infrastructure and Information Security Supervisor at YKK MALAYSIA SDN BHD
Oct 4, 2024
Policy enforcement requires less time for my team because users cannot avoid applying updates. The user can skip two or three times or for a maximum of eight hours. After that, there is no way to avoid it. It helps us keep the environment safe.
AZ
System Admin at a insurance company with 501-1,000 employees
Oct 28, 2024
Patch Management's most valuable feature is the ability to search for vulnerabilities using their QID.
reviewer2584884 - PeerSpot reviewer
Foundation Services Director at a leisure / travel company with 10,001+ employees
Oct 14, 2024
The most valuable features are the ease of managing both first-party and third-party patching, the generation of dashboards, and the provision of real-time information.
Darrell Elmore - PeerSpot reviewer
System Architect at a leisure / travel company with 10,001+ employees
Oct 17, 2024
Patch Management gave my side and the security side a single pane of glass and the ability to better coordinate the delivery of patches.
RO
Cybersecurity Engineer at a manufacturing company with 51-200 employees
Oct 18, 2024
Patch Management, if configured correctly, works effectively without requiring further action.
reviewer2588394 - PeerSpot reviewer
Works at a comms service provider with 1-10 employees
Oct 24, 2024
The integration of Qualys Gateway Scanner is my favorite feature. The patches our downloaded to QGS in our environment and deployed, saving bandwidth. The patch logging and policies have been helpful. The dashboard shows you when the patch has been applied to your assets.
reviewer2589096 - PeerSpot reviewer
Senior Information Security Engineer at a consultancy with 10,001+ employees
Oct 30, 2024
Qualys Patch Management has significantly reduced our organizational risks.
 

Qualys Patch Management Cons review quotes

Brad Mathis - PeerSpot reviewer
Employee-Owner, Senior Consultant, Information Security at Keller Schroeder
Jun 10, 2024
A common area for improvement in Patch Management, both within our environment and others I've encountered, is the lack of built-in driver updates.
Yuvaraaj Adhithya - PeerSpot reviewer
Cyber Security Analyst at WPP
Aug 20, 2024
One of the challenges that we have faced with the Patch Management tool is that you cannot patch all the things. There are some limitations, whereas, in SCCM, we can create a package and just deploy that through it. Anything is deployable through SCCM, whereas Patch Management is very selective.
reviewer2560884 - PeerSpot reviewer
SOC - Cyber Security Engineer at a computer software company with 201-500 employees
Sep 25, 2024
Qualys could improve its capacity to fix vulnerabilities on VMware and other virtualized environments. The reporting could also be enhanced to make it more user-friendly. It's difficult for beginners to learn.
Learn what your peers think about Qualys Patch Management. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
Rafael Araujo - PeerSpot reviewer
Infrastructure and Information Security Supervisor at YKK MALAYSIA SDN BHD
Oct 4, 2024
Its implementation is too recent to make any judgments about areas needing improvement. In terms of pricing, of course, it is not free. Cheaper is always better.
AZ
System Admin at a insurance company with 501-1,000 employees
Oct 28, 2024
The Qualys agent sometimes encounters authorization issues, leading to inaccurate vulnerability reports.
reviewer2584884 - PeerSpot reviewer
Foundation Services Director at a leisure / travel company with 10,001+ employees
Oct 14, 2024
There is room for improvement in the detection logic. It sometimes detects open vulnerabilities that are not truly there, such as orphan files that are not really exploitable. It would be helpful if they were classified as information-only rather than Sev 4 or Sev 5.
Darrell Elmore - PeerSpot reviewer
System Architect at a leisure / travel company with 10,001+ employees
Oct 17, 2024
A patch contract is a bundle of patches that we are going to roll out. I would like to reference those patches from separate jobs. They explained at a conference that it cannot be done, but that is my main complaint. I wish that the whole schema was a little bit clearer because there is a little bit of cloudiness around it.
RO
Cybersecurity Engineer at a manufacturing company with 51-200 employees
Oct 18, 2024
Qualys can do regular check-ins to go over not only all the vulnerabilities but also the overall process to see if there is anything where we might need improvement.
reviewer2588394 - PeerSpot reviewer
Works at a comms service provider with 1-10 employees
Oct 24, 2024
There is room for improvement in terms of adding more patches. Not all patches are available for deployment on Qualys Patch Management, so collaborating with various vendors to provide new patches would be beneficial.
reviewer2589096 - PeerSpot reviewer
Senior Information Security Engineer at a consultancy with 10,001+ employees
Oct 30, 2024
Qualys could improve its randomized download feature and provide more detailed information about patch failures, including the reason for failure.