Try our new research platform with insights from 80,000+ expert users
reviewer2770635 - PeerSpot reviewer
Senior Infrastructure Architect at a tech vendor with 10,001+ employees
Real User
Top 20
Oct 22, 2025
Recurring jobs have simplified patching across hybrid environments and reduced manual effort
Pros and Cons
  • "It was complicated because there were so many different moving parts, that's where Qualys Patch Management comes in and is able to work across all platforms, it's easy because you don't have to manage all kinds of different things for every cloud."
  • "Unified QQL needs improvement because while they have QQL in Qualys Patch Management, it doesn't pull in the same tokens as VMDR or CCM, so I can't search by similar things."

What is our primary use case?

We do it for our OS patching across multiple clouds. If we don't put GE Vernova on there, then I can say we use it for AWS and Azure, plus on-prem. It's used across OS platforms too, so Windows and Linux-based. Our OS team uses it monthly to patch, and then we also supplement third-party software, such as Chrome, Edge, Notepad++, Wireshark, and all that software that people will install and forget to uninstall and forget that they have to patch it. We do that almost weekly as well.

What is most valuable?

My favorite feature is reoccurring jobs. We had some requirements where we needed some options added to do reoccurring jobs, and they were able to add that in. Now we mostly use reoccurring jobs, and we don't have to touch them. The hardest part now is just getting change controls through our change management team instead of actually creating the jobs.

It has simplified so much from a cost overhead and perspective.

What needs improvement?

For Qualys Patch Management, I actually talked with their product manager last week during their conference. Unified QQL needs improvement because while they have QQL in Qualys Patch Management, it doesn't pull in the same tokens as VMDR or CCM, so I can't search by similar things. Also, grouping or foldering for Qualys Patch Management jobs would be beneficial because if different groups own different jobs, it all gets dumped into what is essentially a flat file. You're just scrolling through it. You can search, but if we were able to do foldering, that would be great. The third piece would be having an approved catalog. For example, instead of my IT teams doing the patching, I wanted to enable our internal customers, our app teams, to run the jobs themselves but only on patches that we say are good - a curated catalog that the company patch admin approved.

Their frontline support could be improved. I'm really close with Qualys and spoke at the conference last week. They already know all this. They know that their support could be better. They just need to get more knowledgeable and not necessarily seem to have to pass the buck to engineering or VulnSig or the product teams.

For how long have I used the solution?

We've been using it since April of last year, so April of '24, which is approximately 18 months.
Buyer's Guide
Qualys Patch Management
March 2026
Learn what your peers think about Qualys Patch Management. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.

What do I think about the stability of the solution?

There are times where Qualys sometimes delays or doesn't have the catalog updated. For example, Red Hat comes out with an update and a week later, it wasn't in the Qualys catalog, which causes us to scramble.

What do I think about the scalability of the solution?

On our pod, we don't experience issues. One of my colleagues on a different pod has issues there. I'm on their biggest pod that brings in the most revenue, so they're very cautious with what they do on that.

How are customer service and support?

Their frontline support could be improved. I'm really close with Qualys and spoke at the conference last week. They already know all this. They know that their support could be better. They just need to get more knowledgeable and not necessarily seem to have to pass the buck to engineering or VulnSig or the product teams.

Which solution did I use previously and why did I switch?

We used WSUS and custom scripts for Linux before. On-prem, we used SSM for AWS and Patch Management for Azure. It was complicated because there were so many different moving parts. That's where Qualys Patch Management comes in and is able to work across all platforms. It's easy because you don't have to manage all kinds of different things for every cloud. Your agent's already on the box because we have a rule that every server has to have an agent on it.

How was the initial setup?

The setup was actually easy. We already had VMDR deployed and agents everywhere, so it was a couple clicks to enable it.

What about the implementation team?

The implementation took approximately a month, though some of that was due to our delay. We had one to two people involved, and part of the timeline was due to our internal processes, not Qualys Patch Management.

What was our ROI?

You can always drive pricing down, but I think it's reasonable. For what we get out of it, I think it's a reasonable investment.

What other advice do I have?

I think that's where we have to go as an industry because you can't address everything all the time. Adding the risk on top, if it's an external asset compared to something internal inside your vault, the risk is much greater for exfiltration of data. The risk-based approach absolutely is the right way to go about it.

I rate Qualys Patch Management a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Oct 22, 2025
Flag as inappropriate
PeerSpot user
Senior Information Security Analyst at a tech vendor with 1,001-5,000 employees
MSP
Top 20
Oct 23, 2025
Has enabled me to patch Windows workstations from detection to remediation in one place
Pros and Cons
  • "Qualys Patch Management gives me a single source of truth for assets and vulnerabilities that need to be assessed, prioritized, and remediated."
  • "I find the stability of Qualys Patch Management to be inconsistent; sometimes it works fine, while other times when I try to show a colleague something quickly, it takes considerable time to respond."

What is our primary use case?

My use cases for Qualys Patch Management are primarily for Windows workstations.

What is most valuable?

My favorite feature of Qualys Patch Management is being able to go from detection to patching in a single platform.

Qualys Patch Management helps me remediate vulnerabilities without needing to involve the security team because I am the security team. It helps me get context of what's going on.

What needs improvement?

One downside is that I've always wanted a dark mode in Qualys Patch Management. Because Qualys is so bright, if you're working in there for a while, you feel blind after extended time. Having a dark mode would be fantastic.

For how long have I used the solution?

I have been using Qualys Patch Management since the end of 2023.

What do I think about the stability of the solution?

I find the stability of Qualys Patch Management to be inconsistent; sometimes it works fine, while other times when I try to show a colleague something quickly, it takes considerable time to respond.

What do I think about the scalability of the solution?

The scalability of Qualys Patch Management seems good.

How are customer service and support?

I contact their technical support or customer support frequently.

The quality and speed of their support could be better.

I would rate their support a five out of ten.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial deployment of Qualys Patch Management is difficult.

I wasn't involved with the company during the initial deployment, which occurred approximately ten years ago. However, newer modules and connector configurations always seem more difficult than they should be.

What was our ROI?

Regarding pricing for Qualys Patch Management, if you can get a good deal, the value is there. It's on the pricier side, but it provides value if you can utilize it effectively.

Which other solutions did I evaluate?

I have used alternatives such as Tenable.

I prefer Qualys over Tenable.

The biggest difference between Qualys and Tenable is reporting, as the quality of reports from Qualys is much better received than those from Tenable.

What other advice do I have?

I use Qualys Patch Management with VMDR.

This integration with VMDR is important for me.

Qualys Patch Management gives me a single source of truth for assets and vulnerabilities that need to be assessed, prioritized, and remediated.

I use the Risk Reduction Recommendation report in Qualys Patch Management.

The Risk Reduction Recommendation report is helpful.

Qualys Patch Management helps me streamline remediation and gives me a good starting point.

If the risk-based approach to automation is set up correctly, it performs excellently.

For newer deployments of Qualys Patch Management, typically one person handles the implementation.

I maintain Qualys Patch Management consistently, so it requires minimal effort on my end.

My advice for new users of Qualys Patch Management is to spend time at the training center. A streamlined initial video guide would be beneficial.

I rate Qualys Patch Management an eight out of ten overall.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Oct 23, 2025
Flag as inappropriate
PeerSpot user
Buyer's Guide
Qualys Patch Management
March 2026
Learn what your peers think about Qualys Patch Management. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
Karan Bhateja - PeerSpot reviewer
System Engineer at a tech services company with 11-50 employees
Real User
Top 20
Dec 23, 2024
Quick vulnerability detection and patching with room for better support
Pros and Cons
  • "Qualys Patch Management's most valuable feature is its responsiveness."
  • "Qualys Patch Management has reduced our organization's risk by almost 90 percent."
  • "There is a limitation where Qualys may not always offer solutions for remediation, particularly for end-of-life or end-of-service applications."
  • "Customer support for Qualys Patch Management is lacking. The support cases we've raised often resulted in us finding the solution independently."

What is our primary use case?

We use Qualys Patch Management for patching Windows updates, deploying third-party and Microsoft patches, and other application updates to manage vulnerabilities and respond to threats.

If new vulnerabilities are found in the environment, we deploy patches or find solutions to remediate the problems. We implemented Qualys Patch Management for this purpose.

How has it helped my organization?

To enhance vulnerability management by upgrading or updating applications, we've implemented a recurring job in Qualys Patch Management. This job automatically scans for missing updates on a daily or weekly basis, ensuring all applications remain current. This automated process streamlines patch management and strengthens our overall security posture.

We use Patch Management with Qualys VMDR and find its integration capabilities helpful. This tool automatically identifies vulnerabilities and provides the necessary patches, configuration changes, or updates for remediation. Previously, we needed separate tools for vulnerability scanning, solution finding, and implementation. Qualys streamlines this process by not only identifying vulnerabilities but also recommending and implementing solutions, including patches, updates, and configuration changes, effectively helping us remediate vulnerabilities in our environment.

The machines connected to the environment and reporting to Qualys have a better patching system. It continuously monitors for missing updates daily through scheduled tasks. If any are found, they are automatically installed. This ongoing monitoring and automatic installation is an excellent benefit of Qualys Patch Management.

TruRisk automation allows us to address vulnerabilities without direct involvement from our security team. When we first implemented Qualys, we had a backlog of approximately 130,000 vulnerabilities, some dating back six months or more. By utilizing Qualys as a remediation tool to track, address, and resolve these vulnerabilities, we have successfully reduced the number to 15,000.

Qualys Patch Management provides a centralized platform to identify, prioritize, and address vulnerabilities across our assets. It uses a severity scoring system ranging from one to five, allowing us to assess and prioritize vulnerabilities accordingly.

Before using Qualys, we used SCCM, which gave us good results with over 95 percent compliance. Qualys achieves similar compliance rates if we maintain regular monthly patching. While the compliance numbers haven't changed significantly, Qualys offers greater automation, eliminating the need for manual checks on individual machines. This automation is a significant advantage over our previous system.

We are using Qualys Patch Management in parallel with our Vulnerability Management solution.

Qualys Patch Management has reduced our organization's risk by almost 90 percent.

What is most valuable?

Qualys Patch Management's most valuable feature is its responsiveness. Unlike other products that require waiting for a scheduled update cycle, Qualys allows for immediate deployment of patches and updates. This ensures vulnerabilities are addressed quickly, minimizing security risks.

What needs improvement?

Qualys Patch Management needs improvement in customer support and certain feature enhancements. Although we receive support from Qualys, we often find that we must identify solutions independently. Additionally, features could be refined or expanded, as we've already submitted several requests to improve functionality. 

There is a limitation where Qualys may not always offer solutions for remediation, particularly for end-of-life or end-of-service applications. In these cases, we must seek solutions from alternative sources like Microsoft or the product vendor.

For how long have I used the solution?

I have been using Qualys Patch Management for almost one and a half years.

What do I think about the stability of the solution?

Qualys Patch Management is relatively stable. There might be occasional implementation errors where tasks overlap, but overall, it is reliable, and I would rate the stability eight out of ten.

What do I think about the scalability of the solution?

The scalability of Qualys Patch Management is good, allowing it to handle a large number of devices and updates efficiently. I would rate the scalability eight out of ten.

How are customer service and support?

Customer support for Qualys Patch Management is lacking. The support cases we've raised often resulted in us finding the solution independently. Improvement in response time and solution accuracy is needed.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Before using Qualys, I used Rapid7 for vulnerability detection. However, Qualys Patch Management is superior because it provides both vulnerability detection and remediation within a single tool.

What other advice do I have?

I would rate Qualys Patch Management a six out of ten. Qualys Patch Management is a good tool, but we've encountered some issues during implementation. Occasionally, patches fail to deploy to target machines. Additionally, when multiple jobs run concurrently, subsequent jobs become blocked until the initial job is completed.

We are a global organization with locations in multiple regions. We have around 20,000 employees that use Qualys Patch Management in our organization with 5,000 in our area.

As of now, no maintenance has been required.

I would recommend Qualys Patch Management, but it is crucial to understand its features and limitations thoroughly. Expect some learning curve and utilize its automation capabilities to avoid manual interventions. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
ShantanuChoubal - PeerSpot reviewer
Project Lead at Persistent Systems
MSP
Top 5
Dec 17, 2024
Automated patch deployment and a single source of truth boost vulnerability remediation
Pros and Cons
  • "The most valuable features of Qualys Patch Management include its ability to automate patch deployment for hundreds or thousands of assets, reducing our reliance on the IT team to perform these tasks manually."
  • "It works with Windows and Linux, but Mac patch support is not yet available."
  • "Some patches require OEM consent or must be released by OEM. For example, if an outdated version of a tool like Falcon is detected, Qualys flags it as a vulnerability, but cannot automate the patch update."

What is our primary use case?

Our primary use case for Qualys Patch Management is vulnerability remediation and running scripts. It helps us detect vulnerabilities in our environment and identify specific patches that are required. If we want to mitigate any vulnerabilities, we can run scripts. It is utilized on a very large scale in our organization.

Before Qualys Patch Management, the challenge that we faced was that we were able to detect the vulnerabilities using Qualys VMDR, but mitigation was not easy. Qualys Patch Management helped us to identify which specific patch is required and which patch is missing from our environment. Most of the time, we considered the most suited patches to make sure that all the vulnerabilities get remediated but that was not always the case. We also wanted to see the old patches that were missing. Qualys Patch Management helped us there.

How has it helped my organization?

Qualys Patch Management helped us to automate processes. We did not have to do anything manually. All we had to do was write a particular query command, and based on that, we could time or schedule our patches. If a patch is not properly installed or is crashing on the system, there is the ability to roll back that particular patch. We can see what caused the problem and fix the issue.

We have an improved vulnerability detection rate, and the remediation timelines have been reduced significantly. Earlier, if 100 vulnerabilities were detected, only 50 might be closed after several months. Now, with Qualys Patch Management, the number of vulnerabilities can drop from 100 to 20 in less than a month.

We have information about the severity of the vulnerability. QDS also gives us a score of the vulnerability severity. Accordingly, we also have the categorization of our assets. Qualys VMDR creates the scoring of the assets for us. It tells us what is the asset criticality and the risk score of the asset. Based on that entire calculation, it helps determine which asset to prioritize and fix. It helps us identify what needs to be prioritized.

We use Qualys VMDR with Qualys Patch Management. It is a combined package. Qualys VMDR helps with detection. The data about the vulnerabilities detected by the agents and the scanners is being fed into the Patch Management model which helps to know how to mitigate them. This integration saves a lot of time and makes business operations easy. As soon as we perform a scan, the data gets populated in the Patch Management module. We can see all the data in the Patch Management module. By entering the asset name or the IP address of the host, we can see all the information already over there. We do not have to sync anything or have to pull anything separately using the APIs.

Qualys Patch Management has removed the requirement of approval from the security team for patches because the patches recommended by Qualys are required from the security standpoint itself. They are not showing any patches for functionality improvement or something like that. That is why the security team's intervention is not required anymore. The patching team can schedule and deploy patches.

We now have a single source of truth. Previously, everyone was relying on their own inventory or reports, so the chances of errors were pretty high because there could be data mismatch. Now that we have a single source of truth, there is less chance of errors. All the teams are seeing the same data.

Qualys Patch Management has not reduced a lot of costs. There is about a 15% reduction. It has improved our patch rate by about 60% over the last one to two years.

We have integration with ServiceNow for ticket management. As soon as the patches have been deployed, tickets are getting resolved. When the rescans happen, there is again a revalidation of whether the vulnerabilities have been closed or not. The process of resolving or closing the tickets is 40% to 50% faster than before.

Qualys Patch Management has reduced our organization's risk by 40% to 50%. 

What is most valuable?

Qualys Patch Management automates patch deployment for hundreds or thousands of our assets, reducing our reliance on the IT team to perform these tasks manually. It is able to fix most of our vulnerabilities. The count is reducing significantly. We do not have to rely on our IT team to manually log in to systems or deploy using the AD group. We can just put in a command and schedule the patches for our hundreds or thousands of assets. The vulnerability count has reduced significantly.

Secondly, it helps us not just deploy a patch, it also helps us to install a particular software if it is required from an IT standpoint. Tomorrow, if the organization has a requirement for certain software to be installed on a device, Qualys Patch Management has that capability as well. It can install that software on the machine irrespective of whether it is a security tool or some other tool. We can just put in the URL or source path of it, and it will install that software.

The last one is the registry remediation. It is not just limited to patch management or patch deployment. We can also create a script to fix a particular vulnerability that cannot be fixed through patch deployment. It might require logging into the system, opening the registry keys, and editing some values to it. We can create a script for that.

What needs improvement?

Some patches require OEM consent or must be released by OEM. For example, if an outdated version of a tool like Falcon is detected, Qualys flags it as a vulnerability, but cannot automate the patch update. We can not simply download and do an upgrade. Improved partnerships with OEMs could resolve this.

It works with Windows and Linux, but Mac patch support is not yet available.

For how long have I used the solution?

We have been using Qualys Patch Management for approximately five years. We were given a subscription to Patch Management along with the VMDR module.

What do I think about the stability of the solution?

I would rate the stability of the solution a ten out of ten. It is a stable solution.

What do I think about the scalability of the solution?

So far, Qualys Patch Management fits our company requirements. However, Mac patch support is not available, which could be improved. Overall, I would give it a nine out of ten.

Our organization has a global presence. We have offices in Asia, Europe, and America. The Patch Management solution is being used by 30 to 40 teams. We have the infra team, the security team, and the managers keeping track of what is going on and whether everything is on track.

How are customer service and support?

Whenever we raise a ticket, Qualys has a quick response time of 48 hours. They provide the necessary resolution once all information is shared. I would rate their support a nine out of ten.

How would you rate customer service and support?

Which solution did I use previously and why did I switch?

Before using Qualys Patch Management, my team used SCCM. However, there were challenges. It did not detect required security patches effectively and had limitations on asset detection. The number of vulnerabilities was still pretty high even after deploying the patches.

There were also limitations in terms of asset detection. Certain types of assets did not work with SCCM. Qualys provides better asset detection.

Qualys Patch Management works with Windows and Linux. We do not have to use different tools. 

How was the initial setup?

The setup was straightforward and quick. We just had to connect with a Qualys partner. They set up the cloud environment for us and gave us the URL and the credentials.

As soon as the contract application was done, it took about a week to get the cloud environment set up and ready.

It does not require any maintenance from our side. Qualys takes care of its maintenance. There is a periodic maintenance schedule every quarter. 

What about the implementation team?

The implementation was supported by a partner at Qualys who set up the cloud environment.

What's my experience with pricing, setup cost, and licensing?

Qualys Patch Management comes as part of a bundled package with several modules, making it a cost-effective deal for us. I cannot speak to the separate cost, as we have always used it as part of the package.

What other advice do I have?

I would recommend Qualys Patch Management to others because it is user-friendly and has a wide database of vulnerabilities and patches. I am fond of Qualys, having started my journey with them. Overall, I would rate the solution a ten out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
reviewer2593263 - PeerSpot reviewer
Manager Information Security at a consultancy with 10,001+ employees
MSP
Top 5
Dec 4, 2024
Remediated nearly 25 million vulnerabilities within our organization, significantly reducing our overall vulnerability count
Pros and Cons
  • "Qualys Patch Management offers excellent features, most notably the Qualys Gateway Service, which caches patches and distributes them to agents, minimizing bandwidth consumption."
  • "Qualys Patch Management has reduced our organizational risk by 99.9 percent."
  • "One area for improvement in Qualys Patch Management is knowing whether patches have been completely downloaded in a particular QGS appliance."
  • "One area for improvement in Qualys Patch Management is knowing whether patches have been completely downloaded in a particular QGS appliance."

What is our primary use case?

We primarily use Qualys Patch Management for deploying Microsoft's monthly security updates, released every second Tuesday. To mitigate vulnerabilities, we promptly create patch jobs for all endpoints and servers upon release and inform stakeholders of the urgent need for deployment. We adhere to strict SLAs, ensuring the entire patch cycle is completed within one to two weeks.

We implemented Qualys Patch Management to efficiently patch our endpoints, and servers.

How has it helped my organization?

Qualys' risk-based approach to automation is helpful for addressing vulnerabilities. We utilize TruRisk management for a comprehensive risk overview, employing a tag-based system to assign criticality scores. This allows us to prioritize patching through Qualys Vulnerability Management, Detection, and Response based on the severity of risks.

The integration of Qualys Patch Management and VMDR is critical for automating the deployment of relevant patches and configurations to remediate vulnerabilities. Within our organization's 343,000 assets, multiple entities and tags allow us to leverage VMDR to identify critical vulnerabilities and prioritize patching for high-value machines. This integration enables us to proactively push patches to all server and endpoint agents, effectively mitigating vulnerabilities.

The implementation of Qualys Patch Management has resulted in the remediation of nearly 25 million vulnerabilities within our organization, significantly reducing our overall vulnerability count.

TruRisk automation allows us to address vulnerabilities without involving our security team, as we can directly assess their criticality levels.

Qualys Patch Management provides a single source of truth for managing assets and vulnerabilities, enabling assessment, prioritization, and remediation. Its comprehensive view of each asset streamlines collaboration between security and IT teams, facilitating efficient vulnerability management.

The single source of truth helped reduce costs by 95 percent.

We have improved our patch rate to over 86 percent by implementing Qualys Patch Management. Previously, patches were managed through both Microsoft Intune and SCCM, which proved less effective.

The risk reduction report allows us to split the remediation based on criticality.

The risk reduction report provides recommendations on how to remediate vulnerabilities. Once a fix is available, the corresponding patch can be deployed to all assets based on the associated CVE identifier.

Qualys Patch Management has reduced our organizational risk by 99.9 percent.

What is most valuable?

Qualys Patch Management offers excellent features, most notably the Qualys Gateway Service, which caches patches and distributes them to agents, minimizing bandwidth consumption. The platform provides comprehensive visibility into patch status across endpoints and servers, supporting Linux and macOS in addition to Windows. Qualys has been instrumental in our vulnerability remediation efforts, enabling us to address nearly 25 million vulnerabilities.

What needs improvement?

One area for improvement in Qualys Patch Management is knowing whether patches have been completely downloaded in a particular QGS appliance. If a platform owner could verify that patches are downloaded on the appliance side, it would be possible to push them through to all agents confidently.

For how long have I used the solution?

I have been using the Patch Management solution for more than four years.

What do I think about the stability of the solution?

We did not encounter any significant stability issues. Control level issues can arise, but these can be addressed through support cases.

What do I think about the scalability of the solution?

I rate the scalability of Qualys Patch Management ten out of ten.

How are customer service and support?

I am completely satisfied with Qualys' customer service.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We are using SCCM and Intune, but they are not able to achieve the same Qualys patch percentages.

How was the initial setup?

The initial setup was straightforward. Since Patch Management is not a separate module, it is integrated with the overall Qualys deployment, allowing us to enable licenses for VMDR and PM automatically.

To deploy on one machine it takes ten minutes.

What about the implementation team?

To begin, we'll deploy the Qualys agent using an external tool on a separate system. Once the agent appears in the Qualys console, we can proceed by differentiating tags, assigning activation keys, verifying reported machines, and creating multiple vulnerability-based jobs.

What was our ROI?

We have achieved significant time savings of 90 percent, primarily due to comprehensive oversight and visibility of security issues. This streamlined approach reduces time spent addressing vulnerabilities and ensures efficient mitigation of any threats. Consequently, our robust security posture remains uncompromised, yielding substantial benefits.

What's my experience with pricing, setup cost, and licensing?

Qualys Patch Management is a cost-effective solution for managing our 43,000-plus assets. Its efficiency and effectiveness in vulnerability remediation justify the associated expenses.

What other advice do I have?

I would rate Qualys Patch Management ten out of ten.

To enhance visibility, we will utilize the TruRisk features more effectively in the future.

Our organization has 342,000 assets and over 150 people with access to Qualys, which is deployed across the entire organization.

No maintenance is required from our end.

I recommend Qualys Patch Management due to its comprehensive features. It saves time and provides significant tools for identifying vulnerabilities, pushing patches, and providing pre and post-action capabilities. Virtual patching is available to mitigate many vulnerabilities.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer2589096 - PeerSpot reviewer
Senior Information Security Engineer at a consultancy with 10,001+ employees
MSP
Top 10
Nov 7, 2024
Seamlessly integrated vulnerability detection with automated script-based patching
Pros and Cons
  • "Qualys Patch Management has significantly reduced our organizational risks."
  • "Qualys could improve its randomized download feature and provide more detailed information about patch failures, including the reason for failure."

What is our primary use case?

We use Qualys Patch Management to remediate vulnerabilities. Qualys synchronizes with both the Vulnerability Management, Detection, and Response module and the Patch Management module. This provides a unified view of which vulnerabilities can be patched through Qualys and allows patching to be initiated directly from the VMDR module.

Most Windows security patches are released on Patch Tuesdays and become available to us through Qualys the following day. Once available, we can initiate patching to reduce vulnerabilities within our infrastructure. This process primarily addresses critical security updates from Microsoft and other third-party applications, allowing us to mitigate vulnerabilities using Qualys proactively.

How has it helped my organization?

Qualys Patch Management effectively mitigates risks through its risk-based automation, enabling rapid vulnerability remediation.

The integration of Qualys Patch Management with Qualys VMDR allows us to use the same device identification ID for both patch management and vulnerability identification. This enables us to easily determine which vulnerability a patch addresses, access CVE information, and validate patches based on product or product family. For instance, if we have Google applications with vulnerabilities, we can efficiently identify and patch them without searching for specific versions or missions. By selecting assets in Patch Management, we can automatically patch QID-based or family-based vulnerabilities identified by VMDR. This integration streamlines the patching process and provides clear visibility into the vulnerability status of our assets.

Our previous patch management products had communication issues with their agents. Qualys Patch Management utilizes the same agent as their vulnerability management system, streamlining the process. Security agents are more reliable than standard IT solutions, and because our IT team prioritizes agent uptime, patching is more accessible, and risk is reduced within our infrastructure. Qualys Patch Management offers immediate benefits. If a patch requires a reboot, Qualys allows users to initiate one within a specified timeframe automatically. Upon rebooting, the machine reports to the Qualys console and is automatically scanned. If the patch is successfully installed, the console reflects the update within 20 to 30 minutes. This streamlined process ensures efficient patch management and reduces vulnerabilities.

Qualys Patch Management's TruRisk automation allows us to prioritize patching vulnerabilities with available patches. This prioritization helps us focus on critical vulnerabilities and quickly remediate them, improving our security posture. The TruRisk score provides a clear metric to demonstrate the effectiveness of our remediation efforts to leadership, showing how quickly we address critical vulnerabilities and enhance our security.

TruRisk automation enhances data accuracy across business units. Leveraging the Vulnerability Management Tool for Remediation within TruRisk, patching can be initiated based on a risk score mechanism query, which provides the TruRisk score for a specific business unit. A subsequent query determines patch dispatchability, triggering a patch job if applicable. This process can be streamlined using Patch Query Language to efficiently retrieve data and execute accurate patching, reducing risk based on TruRisk scores.

Initially, the IT team resisted using Qualys Patch Management for vulnerability remediation due to its critical importance. However, after we demonstrated how integrating Patch Management with Vulnerability Management provides a single report and effectively reduces vulnerabilities, we convinced them to adopt it. This consolidated approach enhances efficiency and streamlines patch management throughout our organization.

Qualys Patch Management significantly improved our patching rates. Qualys provides access to exclusive security patches and boasts a comprehensive knowledge base covering a wide range of applications, including third-party software like Google Chrome, Edge browsers, and SQL. As Qualys expands its knowledge base, our patch management rates continue to improve. Furthermore, the Qualys support team has been instrumental in helping us resolve patching issues, such as installation failures, by efficiently identifying the root cause, whether it stemmed from network problems or the Qualys platform itself. With their assistance and the robust Qualys product, we have successfully mitigated these challenges.

Qualys Patch Management has significantly reduced our organizational risks. Previously, when using other solutions, our patch percentage was low, resulting in high risk. Qualys Patch Management, integrated with VMDR, immediately improved our patch percentage. Features like patch initiation, recurring patches, scheduling, and randomized patch downloading have been crucial in mitigating risk, especially for employees working from home with network issues. The randomized download option ensures patches are successfully downloaded even with interruptions, resuming automatically when the network connection is restored. These capabilities ensure Qualys Patch Management effectively reduced our organizational risk by 88 percent.

What is most valuable?

My favorite feature of Qualys Patch Management is its flexibility in executing scripts before and after patching. This is particularly useful for third-party or enterprise applications that require registry modifications to address vulnerabilities. We leverage this functionality to deploy scripts that adjust registry values, effectively patching vulnerabilities and enhancing the security of our machines. The ability to automate these tasks through Qualys Patch Management streamlines our workflow and improves our overall security posture.

What needs improvement?

Qualys could improve its randomized download feature and provide more detailed information about patch failures, including the reason for failure. This could include specifying whether the failure is related to a file download error, network interruption, application crash, or installer error based on the operating system. These enhancements would offer more insights into the patch management process and improve overall functionality.

For how long have I used the solution?

I have been using Qualys Patch Management for the last two years.

What do I think about the stability of the solution?

The stability of Qualys Patch Management is a nine out of ten. While it's generally stable, there have been occasional issues, particularly when new patches for Linux have been introduced.

What do I think about the scalability of the solution?

Qualys Patch Management's scalability is a ten out of ten. It scales efficiently across different machines globally, ensuring patches are deployed smoothly.

How are customer service and support?

Qualys' technical support has been excellent. Their team has effectively resolved various issues, including some that originated within our network.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was straightforward, leveraging the existing vulnerability management tool, which facilitated easy integration of Patch Management.

Deploying software to a single machine takes approximately one minute. However, in an organization with 1,000 machines, a traditional push deployment method could take up to four days to complete.

What other advice do I have?

I would rate Qualys Patch Management ten out of ten. Qualys Patch Management has significantly benefited our security and remediation efforts.

Qualys Patch Management is deployed across multiple locations and time zones in various countries. While most of the IT team has access to view Qualys Patch Management, only a few individuals can initiate patching. Those with view access can assess the patching capabilities and compliance of specific machines, while a limited number of authorized personnel can deploy the patches.

Qualys Patch Management requires minimal maintenance, primarily involving updating the agent software on managed devices.

I would recommend Qualys Patch Management to those using a vulnerability management solution as it helps significantly in reducing risks. It provides various options such as using third-party repositories for patches, which are beneficial for comprehensive patch management.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Sr Info security analyst at Televox Software
Real User
Top 10
Oct 18, 2025
Significantly improves patch coverage and provides the ability to schedule jobs
Pros and Cons
  • "Qualys Patch Management has helped reduce our organization's risk by 20%, and we have seen an improvement in our patch rates."
  • "For those patches that I have to download for Patch Management, I would prefer if I could upload them to a repository instead of having to download them every time."

What is our primary use case?

Our use case for Qualys Patch Management is patching and updating. We use it for adding and removing local admin to the machines, along with various other tasks.

How has it helped my organization?

Qualys Patch Management helps the IT and security teams work together by enabling the IT team to handle Patch Tuesday and Microsoft patches. With Patch Management, I can monitor when patches have not been applied and help ensure 100% coverage on Patch Tuesday for the desktop team. 

Qualys Patch Management has helped reduce our organization's risk by 20%, and we have seen an improvement in our patch rates.

What is most valuable?

The best feature of Qualys Patch Management is the ability to schedule jobs. I have browser updates that run automatically every day to update the three browsers, and I don't have to worry about it.

What needs improvement?

For those patches that I have to download for Patch Management, I would prefer if I could upload them to a repository instead of having to download them every time.

For how long have I used the solution?

I have been using the solution for about eight months.

What do I think about the stability of the solution?

I haven't experienced any bugs, glitches, or downtime, so I would rate Qualys Patch Management a ten out of ten for stability.

What do I think about the scalability of the solution?

For scalability, I would rate it a ten out of ten. We have approximately 8 to 10 users using this solution.

How are customer service and support?

I would rate the vendor support a ten out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We had another patch management solution, but we were using Qualys for VMDR and moved everything into Qualys Patch Management for the simplicity of the user interface and because we had an existing relationship with Qualys. That way we can not only manage our vulnerabilities, but if the vulnerability requires a patch, it's very easy to fix it in Qualys. We were using BigFix for patch management.

How was the initial setup?

The deployment was easy.

The agents self-update, and by using Qualys Cloud, that's all handled by the vendor, so the maintenance aspect requires little to no interaction from our end.

What was our ROI?

It has improved our patch rate by 40%.

What's my experience with pricing, setup cost, and licensing?

Regarding the single source of truth, it really at this juncture has not reduced costs as of yet.

What other advice do I have?

I would recommend this product to other users because it's very user-friendly. I can't speak to the pricing aspect, but from a user standpoint, it's a very good product.

I would rate it a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Oct 18, 2025
Flag as inappropriate
PeerSpot user
Information Security Manager at BARC India
Real User
Top 20
Dec 4, 2024
Streamlined patching process enhances efficiency and risk management
Pros and Cons
  • "Qualys Patch Management excels with its user-friendly interface and comprehensive reporting features."
  • "The organization's risk score has significantly improved since integrating with Qualys Patch Management."
  • "Sometimes, legacy operating systems are not supported by Qualys Patch Management, which is an issue."
  • "There are certain integration parts that could be improved. Sometimes, legacy operating systems are not supported by Qualys Patch Management, which is an issue."

What is our primary use case?

We use Qualys Patch Management to patch our servers, which run on both Linux and Windows operating systems.

We implemented Qualys Patch Management to identify and address operating system vulnerabilities.

How has it helped my organization?

A risk-based approach to automation prioritizes addressing vulnerabilities according to their criticality, ensuring that the most significant risks are mitigated first.

The integration of Qualys Patch Management and VMDR is crucial because it automates the process of identifying and deploying necessary patches and configuration changes to address vulnerabilities. This automation minimizes manual intervention, streamlining both patching and vulnerability scanning. The integrated system automatically generates reports that include vulnerability details and their corresponding Software Development Lifecycle phase, along with patching status and the number of systems patched across production, DMZ, and VOD environments.

We used to do manual patching, which took more time to complete. With Qualys Patch Management, we have reduced the time it takes to patch. We can now perform patching with a single click and obtain a report of the patch application. We saw the benefits of Qualys Patch Management within seven months.

What is most valuable?

Qualys Patch Management excels with its user-friendly interface and comprehensive reporting features. Additionally, it offers robust vulnerability scanning for both network devices and operating systems, ensuring thorough and effective security assessments.

The TruRisk automation has significantly reduced the time it takes for risk management and reporting.

Qualys Patch Management gives us a single source of truth for assets and vulnerabilities that need to be assessed, prioritized, and remediated.

Qualys Patch Management enabled us to increase our patching frequency. Previously, limited staffing necessitated quarterly patching, but with Qualys, we can now patch monthly as releases become available. This proactive approach minimizes risk to our infrastructure.

We have integrated Qualys Patch Management with our SIEM solution, enabling us to build a single dashboard that displays vulnerability reports from both systems. This allows both the infrastructure and security teams to simultaneously access and utilize the Qualys Patch Management reports within the SIEM dashboard.

The organization's risk score has significantly improved since integrating with Qualys Patch Management. Previously at 60 percent, the score is now down to 39 percent, with the potential for even further reduction.

What needs improvement?

There are certain integration parts that could be improved. Sometimes, legacy operating systems are not supported by Qualys Patch Management, which is an issue. There should be a document readily available with Qualys that lists unsupported operating systems and provides solutions on how to achieve patching in other ways.

For how long have I used the solution?

I have been using Qualys Patch Management for the last three years.

What do I think about the stability of the solution?

We have used Qualys Patch Management for the past three years without issue and would rate its stability a ten out of ten.

What do I think about the scalability of the solution?

Qualys Patch Management is a globally scalable product, easily handling increasing workloads and users. Its scalability gets a ten out of ten rating.

How are customer service and support?

We have not faced any challenges with customer service. Whenever we raised a case with Qualys for troubleshooting or any assistance, we received support as required.

How would you rate customer service and support?

Which solution did I use previously and why did I switch?

Earlier, we were using Nessus. There were some challenges with Nessus, such as the reporting part not being customizable as per our requirements, and some management pricing issues. We conducted a POC and switched to Qualys Patch Management.

How was the initial setup?

The initial setup was straightforward, with servers deployed in two days using a broadcasting tool for installation. This allowed for the successful deployment of Qualys Patch Management within one week.

What was our ROI?

With Qualys, we've experienced reductions of 70 percent in work hours and 30 percent in overall security costs.

What's my experience with pricing, setup cost, and licensing?

The pricing is fair and within our budget. With the capabilities Qualys offers, we believe we are getting good value for the price.

What other advice do I have?

I would rate Qualys Patch Management nine out of ten.

We use a ticket submission tool to assign IT service tickets. Once the IT team completes a ticket, they close it.

We have around 1,500 users that are located evenly between the office and home environments.

Qualys Patch Management typically requires maintenance only for agents that encounter operating system issues preventing automatic updates.

I recommend using Qualys due to its ease of deployment, automation capabilities that reduce human intervention, and cost-saving benefits. As a highly effective product, Qualys Patch Management may eliminate the need to consider alternative solutions.

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Download our free Qualys Patch Management Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Product Categories
Patch Management
Buyer's Guide
Download our free Qualys Patch Management Report and get advice and tips from experienced pros sharing their opinions.