Sometimes I lack the details of misconfigured devices, such as cloud servers and cloud machines, which are hosted in our environment. We face issues while identifying these devices. We used to execute commands to check connectivity, which helped us identify misconfiguration issues or rely on vulnerability reports. Since TotalCloud was introduced, we can remediate these issues once we get the report from TotalCloud.
Senior Security Consultant at CyberNxt Solutions LLP
Misconfiguration detection and on-demand scans have transformed our cloud environment monitoring
Pros and Cons
- "The best part I like is the on-demand scans."
- "The main area needing improvement is integration. Although the team is strengthening TotalCloud, integration can be enhanced with SIEM, SOAR, ITSM, and other sources."
What is our primary use case?
What is most valuable?
There are many features that impress me. The first is the misconfiguration detection, as mentioned earlier, and the detection feature alerts us about security tools and reported users. TotalCloud allows us to monitor our cloud environment. Monitoring devices hosted in the cloud dashboard is easy. Additionally, some features prioritize the misconfiguration option. For instance, if a cloud server is critical, it should be prioritized for prompt alerts. These are key features I like about TotalCloud. The best part I like is the on-demand scans. For example, if some machines have open vulnerabilities and the remediation team resolves them, the on-demand feature allows us to verify vulnerability resolution promptly. This helps the remediation teams significantly in closing critical vulnerabilities efficiently.
What needs improvement?
While I am still learning TotalCloud, which has the latest features introduced, I attended a Qualys event this year. There are navigations that can be improved. Some customizable dashboards provided in the dashboard part also need attention. The main area needing improvement is integration. Although the team is strengthening TotalCloud, integration can be enhanced with SIEM, SOAR, ITSM, and other sources. An enhancement feature could improve TotalCloud further.
For how long have I used the solution?
I have been using TotalCloud for more than two and a half years.
Buyer's Guide
Qualys TotalCloud
March 2026
Learn what your peers think about Qualys TotalCloud. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
What do I think about the scalability of the solution?
It is obviously scalable. However, it is improving, so I rate it nine.
How are customer service and support?
Technical support can be rated 8.5 out of 10.
Which solution did I use previously and why did I switch?
I started my career in college. I was completely involved in college. I recently switched to CloudSight. As per the company's requirement, they have shifted me to the CloudSight product. I am still using Qualys and CloudSight. There is no difference as Callist is a centralized tool. It starts from the lifecycle, detection, remediation, and reporting. If vulnerabilities reopen, it detects them again. The lifecycle continues. It also patches and remediates endpoint servers in the tool itself. This is the part I like best about Callist compared to other vendors.
How was the initial setup?
It is quite easy. We deployed the Cloud TotalCloud Agent to servers and endpoints easily, without feeling any complexity.
What was our ROI?
It saves a lot of time and manual effort. We have many options to raise a case if it can be automated. CallStream helps us integrate and automate tasks. It helps us automate lots of things.
What's my experience with pricing, setup cost, and licensing?
It is not cheap. For smaller businesses, people running businesses with a small number of users cannot afford Qualys, as I understand. However, in MNCs and bigger organizations, the cost is not significant. There are different pricing models, like the patch management module, which requires a different price to access. It is not cheaper, but also not expensive.
What other advice do I have?
I definitely recommend other organizations to have this product in their environment. The price is a factor. Smaller organizations might find it unaffordable. However, there are different options depending on the budget, such as purchasing a smaller number of licenses. I highly recommend it. I work for LTI Mindtree, a large organization. Overall, I rate the product nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Senior Information Security Engineer at a consultancy with 10,001+ employees
Performs well and provides great visibility into our assets
Pros and Cons
- "The most valuable feature of Qualys TotalCloud is the visibility it provides."
- "The most valuable feature of Qualys TotalCloud is the visibility it provides."
- "I would appreciate additional integration options to connect Qualys TotalCloud with our other vulnerability management tools."
- "I would appreciate additional integration options to connect Qualys TotalCloud with our other vulnerability management tools."
What is our primary use case?
Our environment uses both on-premises containers and cloud-hosted applications. The majority of our applications reside in the cloud, and for those, we conduct vulnerability scans using Qualys TotalCloud.
How has it helped my organization?
Qualys TotalCloud offers clear explanations of identified vulnerabilities, aiding security and project teams in understanding and remediation. These user-friendly descriptions bridge the knowledge gap by providing essential context for those unfamiliar with security concepts. With a centralized dashboard, teams can readily access vulnerability details and take direct action to address them, streamlining the remediation process.
As a large organization, we've been using Qualys TotalCloud for a year. While it takes time to detect all containerized assets fully, we're gradually gaining comprehensive visibility within a single platform.
Qualys TotalCloud offers a unified platform for vulnerability and threat assessment across both Infrastructure as a Service and Software as a Service environment. Currently, our team utilizes IaaS, while a separate team manages SaaS. Qualys TotalCloud allows us to assess all software used within our infrastructure and categorize it based on the risk level of white, gray, or black. Whitelisted software poses no risk, while graylisted software may require remediation or controls, such as Data Loss Prevention or Anti-Virus, to mitigate potential risks. Blacklisted software is prohibited. This tool also helps identify unauthorized software, enabling us to remove it from our network and enhance overall security.
Qualys TotalCloud provides real-time risk assessment, including a TruRisk score that helps prioritize remediation efforts.
Qualys provides the TruRisk score, which we use to prioritize remediation efforts within our Service Level Agreement. We've collaborated with Qualys to develop a customized formula that considers whether a vulnerability is public-facing, resulting in adjusted risk scores. Any vulnerability that cannot be remediated within the SLA will be isolated from the network.
TruRisk helps identify a range of risks, but the public-facing application is a primary concern. Attackers often target this area by running scans and attempting to exploit vulnerabilities on the application or infrastructure side. To address this, we have a separate process based on the TruRisk score, which allows us to remediate all high-risk issues. While some vulnerabilities may appear to be a medium risk to us, they may pose a higher risk to the application or machine. TruRisk helps us identify and prioritize these discrepancies, enabling us to focus our efforts effectively.
Our infrastructure, encompassing over 300,000 machines, previously generated millions of vulnerabilities. However, by implementing the TruRisk score, we have successfully reduced these vulnerabilities to the thousands.
What is most valuable?
The most valuable feature of Qualys TotalCloud is the visibility it provides. We now have insight into previously unseen container vulnerabilities, allowing us to identify and address most emerging issues.
What needs improvement?
We are currently using a variety of tools and are working to consolidate them into a single platform. We are exploring options to integrate these tools with Qualys, our primary security and compliance tool, to centralize risk assessment and reporting. For example, while we use Qualys for vulnerability scanning and compliance assessments, we also utilize separate tools for web application scans and some SaaS application reviews. Our goal is to integrate all these functions into Qualys, creating a single dashboard for comprehensive security monitoring and management. I would appreciate additional integration options to connect Qualys TotalCloud with our other vulnerability management tools.
For how long have I used the solution?
I have been using Qualys TotalCloud for one year.
What do I think about the stability of the solution?
I would rate the stability of Qualys TotalCloud nine out of ten. We have not encountered any lagging or crashing from the tool.
What do I think about the scalability of the solution?
Qualys TotalCloud is scalable.
How are customer service and support?
I contacted Qualys technical support when we encountered scanning issues. They helped work to resolve our issues promptly.
How would you rate customer service and support?
Positive
What other advice do I have?
I rate Qualys TotalCloud nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Qualys TotalCloud
March 2026
Learn what your peers think about Qualys TotalCloud. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
Manager SOC at a tech services company with 51-200 employees
Streamlined onboarding elevates client cloud operations
Pros and Cons
- "I appreciate Qualys TotalCloud's ability to onboard any type of device with ease, including containers."
- "I highly recommend Qualys TotalCloud to other users."
- "Qualys's ticketing system can be confusing when assigning tasks to individuals, and support could be improved by offering instant call solutions with engineers in addition to ticket replies."
- "The support process is inefficient due to the excessive number of replies required when submitting tickets."
What is our primary use case?
We typically onboard all clients in both cloud using Qualys TotalCloud and on-premises environments.
How has it helped my organization?
We began to see the benefits of Qualys TotalCloud within the first month, despite initially having few clients with cloud-based environments. Most of our clients were on-premises, limiting our exposure to TotalCloud's capabilities. However, in recent months, we've gained more experience with the platform as we've acquired clients utilizing cloud assets. This increased usage has highlighted the tool's increasing user-friendliness, particularly noticeable in the improved query functionality, which was initially quite challenging.
Qualys TotalCloud provides a unified vulnerability and threat assessment across both IS and SaaS.
Qualys TotalCloud provides a single prioritized view of risk. We can prioritize the threats with TruRisk. A single prioritized view of risk reduces effort by allowing us to accept certain risks as exceptions, focusing only on the critical ones. This streamlined approach saves time and resources for both us and our clients. This saves us around 20 percent of our costs.
Qualys' TruRisk Insights provides comprehensive risk assessment using its own risk calculation system. This system automatically generates an asset risk score based on the criticality of assets and any provided context. By analyzing vulnerabilities and their potential impact on the environment, TruRisk effectively flags them, allowing for a comprehensive approach to risk prioritization. For instance, high-severity vulnerabilities with high CVSS scores affecting multiple assets would be prioritized for remediation. The system's ability to flag vulnerabilities based on the environment and asset criticality makes it a reliable tool for risk management.
TruRisk Insights sometimes identifies assets with high vulnerability scores. For clients onboarded in TotalCloud, patching is managed by the client, while for on-premise clients, patch management is handled using Qualys. Monthly and weekly reports are provided to all clients, highlighting high vulnerabilities and major risks based on asset criticality. Remediation steps, available through Qualys, are included in the reports to assist clients in addressing identified vulnerabilities.
TruRisk Insights has improved our security posture by providing a genuine number of critical vulnerabilities that need to be addressed immediately based on risk level.
What is most valuable?
I appreciate Qualys TotalCloud's ability to onboard any type of device with ease, including containers. This user-friendly platform provides a comprehensive inventory of all assets and allows for customized policy and control design, a feature I find unmatched by other tools.
What needs improvement?
Qualys's ticketing system can be confusing when assigning tasks to individuals, and support could be improved by offering instant call solutions with engineers in addition to ticket replies.
For how long have I used the solution?
I have been using Qualys TotalCloud for almost two years.
What do I think about the stability of the solution?
I would rate the stability of Qualys TotalCloud eight out of ten.
What do I think about the scalability of the solution?
I would rate the scalability of Qualys TotalCloud eight out of ten.
How are customer service and support?
The support process is inefficient due to the excessive number of replies required when submitting tickets. A more efficient solution would be to provide instant call options with engineers, comparable to features offered by other tools.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We switched from Rapid7 to Qualys because the latter offers a more comprehensive suite of modules, greater flexibility, and more advanced querying capabilities.
How was the initial setup?
The initial setup of Qualys TotalCloud is easy. If all the required information is available, it takes less than an hour to deploy.
What about the implementation team?
Deployment and other technical tasks are generally handled by two people, but the reporting team consists of many people.
What was our ROI?
Though I'm not deeply involved with the financial aspects, I estimate that at least twenty percent of costs are saved thanks to Qualys.
What other advice do I have?
I would rate Qualys TotalCloud nine out of ten.
Our clients consist of small and medium businesses.
I highly recommend Qualys TotalCloud to other users. Their strong technical team consistently delivers high-quality solutions and demonstrates a commitment to ongoing research and improvement, effectively addressing problems in a timely and long-lasting manner.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Developer at a consultancy with 10,001+ employees
Offers good web API security and IoT scanning features
Pros and Cons
- "I like the web API security and IoT scanning features the most. The user-friendly design of TotalCloud's interface enables customers to navigate it and use its full potential easily"
- "TruRisk Insights is the most important innovation they've released this year."
- "TotalCloud could improve its scanning of niche devices like Wi-Fi dongles and USB modems because they are often untested. It covers everything else, like laptops, mobile devices, and Bluetooth IoT devices. They can improve on the small IoT devices because hackers and testers use these."
- "TotalCloud could improve its scanning of niche devices like Wi-Fi dongles and USB modems because they are often untested."
What is our primary use case?
We use TotalCloud to identify and remedy cloud vulnerabilities.
What is most valuable?
I like the web API security and IoT scanning features the most. The user-friendly design of TotalCloud's interface enables customers to navigate it and use its full potential easily. TotalCloud provides written explanations of remediation paths, helping us to reduce risks. It has a single dashboard that shows all the vulnerability and application findings on one page.
TruRisk Insights is the most important innovation they've released this year. It's a true game-changer because no competing solution has implemented this. It will help cybersecurity professionals monitor the cloud and find vulnerabilities. We're scanning 21 million assets, and it has definitely helped.
What needs improvement?
TotalCloud could improve its scanning of niche devices like Wi-Fi dongles and USB modems because they are often untested. It covers everything else, like laptops, mobile devices, and Bluetooth IoT devices. They can improve on the small IoT devices because hackers and testers use these.
For how long have I used the solution?
I have been using Qualys products for approximately four to five months.
What do I think about the stability of the solution?
Stability is essential, especially on the cloud. Continuous monitoring is crucial to ensure system stability and avoid vulnerabilities or threats.
What do I think about the scalability of the solution?
Scalability is important as businesses and services evolve, ensuring all linked assets are secured. Our organization has a cloud environment deployed on EC2 instances, so we constantly run auto-scaling checks.
How are customer service and support?
I rate Qualys support 10 out of 10. They are helpful, respond to my queries, and can answer any question. I have to give them credit. Without their support, Qualys wouldn't be in the position they are in. Their support is better than any competing solution can provide.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used Zscaler, but I have not used another significant Qualys competitor. Since we're on the cloud, we also use other built-in tools like AWS Cloud Security and Amazon GuardDuty.
How was the initial setup?
The initial deployment was not difficult because we have a set of instructions and built-in queries we can run in Qualys. Maintenance after deployment is minimal because the solution automatically updates.
What other advice do I have?
I rate Qualys TotalCloud 10 out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
CIO at a venture capital & private equity firm with 11-50 employees
Daily reporting enables timely security actions
Pros and Cons
- "One of the features I appreciate is the ability to generate daily reports without relying on anyone else."
- "Qualys TotalCloud has improved our security posture."
- "It has been working very well, but it would be helpful if the dashboard could generate reports tailored to specific compliance needs. For example, in India, we have to comply with RBI and SEBI guidelines. It w"
What is our primary use case?
We use Qualys TotalCloud for patching and vulnerability management. We implemented it to improve patching and compliance for security purposes.
How has it helped my organization?
Qualys TotalCloud has been beneficial for our organization. We are getting a lot of functions in the portal for security assessment related to the third party. It tells us about vulnerabilities in the servers.
The vulnerability information available through the portal reduces my cyber risk. Qualys TotalCloud has improved our security posture. We receive daily security and vulnerability reports, which we act upon. We can remediate the issues on time.
I knew about the benefits of this product before buying it. We started seeing its benefits within two to three days of deployment.
What is most valuable?
One of the features I appreciate is the ability to generate daily reports without relying on anyone else. This feature has been very beneficial as it allows us to address security gaps and remediate them promptly.
What needs improvement?
I have been using Qualys TotalCloud for onyly two months. It has been working very well, but it would be helpful if the dashboard could generate reports tailored to specific compliance needs. For example, in India, we have to comply with RBI and SEBI guidelines. It would be great to have reports related to RBI and SEBI compliances.
For how long have I used the solution?
I have been using Qualys TotalCloud for not more than two months.
What do I think about the stability of the solution?
I would rate its stability as nine out of ten. It is a stable solution, which is why we chose it.
What do I think about the scalability of the solution?
I would rate its scalability a nine out of ten. The solution scales well.
We started our organization about nine months back. We started with about 30 users, and we now have more than 100 users. At first, we had one branch, but now, we have four branches. Some branches are based in India, and some are out of India.
How are customer service and support?
We have been working with it for only about two months. We have not used technical support. We have been in contact with presales and the deployment team. We have not had the need to engage with their customer support.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We did not use any other solution before implementing Qualys TotalCloud. We have started a new organization where I have taken full services from Qualys. We chose Qualys based on familiarity from past experiences in other organizations.
How was the initial setup?
The initial setup was straightforward.
It is an easy product. I was familiar with it from the previous organization. Other colleagues were not very familiar, but they were able to understand it. It is not command-based. It is GUI-based.
Its implementation took 10 to 15 days. We are a small organization. We do not have a large number of APIs and servers. There is no issue.
It does not require any maintenance from our side.
What was our ROI?
The solution is proving beneficial, allowing us to remediate vulnerabilities before any issues arise. Daily reports alleviate all the concerns that we had previously. We have seen more than 50% improvement.
What's my experience with pricing, setup cost, and licensing?
The cost is high, but it meets our organizational needs.
What other advice do I have?
It is a very good solution. I would rate it a nine out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Senior Consultant at a consultancy with 10,001+ employees
Helps manage compliance and gives a consolidated view of our security posture
Pros and Cons
- "CSPM is currently the most used feature, and we are enjoying the new feature, FlexScan, which is valuable for Internet-facing VMs."
- "Qualys TotalCloud has helped us view our risk structure, vulnerabilities, and security posture."
- "Overall, we are satisfied with it. However, the response part of the Cloud Detection and Response (CDR) module can be improved. It is not yet in place according to requirements; it is not completely available even though the module has been released."
- "The response part of the Cloud Detection and Response (CDR) module can be improved."
What is our primary use case?
We are using the Cloud Security Posture Management (CSPM) and the Cloud Detection and Response (CDR) module. CSPM helps manage configuration compliance, and we have configured FlexScan in our environment for Internet-facing VMs.
We are in the process of evaluating further advanced features like Cloud Detection and Response and IAC.
How has it helped my organization?
TotalCloud provides written explanations to help guide remediation paths and eliminate cyber risk. These explanations are very helpful because not everyone is well-versed in the technology. We have different layers of team. Everyone does not know the technology well. The explanations help across the board.
It provides a single, prioritized view of risk. That is absolutely what we want. We want everything organized in one place. It helps to focus on high risks.
Qualys TotalCloud has helped us view our risk structure, vulnerabilities, and security posture. It does require some fine-tuning, but we do see very good results.
Our risk team uses TruRisk insights, and we have heard very positive feedback about it.
What is most valuable?
CSPM is currently the most used feature, and we are enjoying the new feature, FlexScan, which is valuable for Internet-facing VMs. With everything moving to the cloud, it is something interesting.
What needs improvement?
We are still exploring it. Currently, we only have two modules. Overall, we are satisfied with it. However, the response part of the Cloud Detection and Response (CDR) module can be improved. It is not yet in place according to requirements; it is not completely available even though the module has been released.
For how long have I used the solution?
We have been using TotalCloud for approximately one and a half years, but we have been using Qualys products for the last 10 to 12 years.
What do I think about the stability of the solution?
I would rate it a seven out of ten in terms of stability.
What do I think about the scalability of the solution?
I would rate it a nine out of ten for scalability. It has been fairly scalable for our needs.
How are customer service and support?
The support from Qualys is excellent. They meet delivery timelines very well, and the response times are satisfactory.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have been a Qualys customer for a long time and have not yet used any alternatives to TotalCloud.
How was the initial setup?
FlexScan was a bit tricky, but CSPM was fine. Overall, it was easy. It took us approximately three months to fully align and deploy.
It took us some time to realize the benefits of TotalCloud. Being a new product, it took us some time to adapt and fine-tune TotalCloud to our infrastructure and security requirements. Once we went through that cycle, we started seeing its benefits.
What about the implementation team?
We received support from Qualys. Our TAM helped us in arranging resources.
What's my experience with pricing, setup cost, and licensing?
As a middle management member, I do not have direct pricing knowledge, but based on the knowledge from our meetings, its pricing is competitive.
What other advice do I have?
We are yet to explore it fully. I would rate TotalCloud an eight out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
retired at a consultancy with 10,001+ employees
Has immensely helped us reduce active vulnerabilities
Pros and Cons
- "It is a cloud-native app that integrates with both IaaS and SaaS. It seamlessly integrates with other platforms."
- "I would definitely recommend Qualys TotalCloud to other customers."
- "The patching process with Qualys Patch Management, which is part of TotalCloud, does not cover installing certain prerequisites on the servers or workstations. This shortcoming means we must rely on SCCM when any service stack updates or additional prerequisites are needed."
- "The patching process with Qualys Patch Management, which is part of TotalCloud, does not cover installing certain prerequisites on the servers or workstations."
What is our primary use case?
Our primary use case is to create an automated workflow that involves tagging assets, creating remediation policies, and automated patching. This process is intended to cover everything from asset discovery to remediation.
How has it helped my organization?
Qualys TotalCloud helps us with patching. There are certain limitations with SCCM when it comes to patching. A request needs to be created, and then it takes a lot of time, whereas Qualys TotalCloud, specifically in terms of remediation, is pretty much touchless, so zero-touch patching is what we have been trying to achieve. It helps us greatly in patching certain vulnerabilities that, for example, are Chrome-related. We do not have to depend on any other tool for patching.
Discovery is automated here. We have scheduled scans that discover. We have built an automation for that.
Qualys TotalCloud provides unified vulnerability and threat assessment across both IaaS and SaaS. We are using it more for SaaS environments. We are using it in Azure as well so that we can get a good security posture for it. We have a different team for IaaS.
Qualys TotalCloud has immensely helped us reduce active vulnerabilities. It has greatly affected our ability to build dashboards because we use it through the API. We have generated a lot of content and dashboards based on API integration, which provides us with up-to-date metrics. We have deployed cloud agents across Linux and Windows workstations. We get pretty much up-to-date data from Qualys scans. We also have vault integration. We have integrated it with CyberArk Vault. A lot of features have been helpful.
We are able to see the risks associated. It helps us prioritize based on the risk score. It helps us identify ground rules and remediate risks on them.
It has saved a lot of time and effort, but I do not have any metrics.
The TruRisk Insights feature gives us a good risk posture, but it is not yet embedded in our automation. We have built the GUI dashboards to view the risks and prioritize them.
The risk analysis is good. We are ingesting a lot of resources or products to see how we can improve the accuracy. The risk score helps us with accurate prioritization. There can be a scenario where something with a high vulnerability score might contribute to lower risk.
It has helped us in prioritizing the remediation and preparing better dashboards for our CISO's review.
What is most valuable?
It is a cloud-native app that integrates with both IaaS and SaaS. It seamlessly integrates with other platforms.
The features we use the most include zero-touch assessment for quick patch creation and deployment. Every time any vulnerabilities are identified, we can create quick patches and deploy them. Those are the ones that we basically use.
We are also trying to implement a risk-based program, although it is currently limited.
What needs improvement?
The patching process with Qualys Patch Management, which is part of TotalCloud, does not cover installing certain prerequisites on the servers or workstations. This shortcoming means we must rely on SCCM when any service stack updates or additional prerequisites are needed.
For how long have I used the solution?
I was a part of Qualys previously. I have used the whole Qualys VMDR suite for almost five years there and three years here. It has been a year or so with TotalCloud.
What do I think about the stability of the solution?
The stability of the solution is strong. I would rate it a nine out of ten for stability.
What do I think about the scalability of the solution?
It is absolutely scalable, and I would rate its scalability as nine out of ten.
We have multiple locations. The assets are spread across the globe, so we have deployments at multiple locations.
We have a team of five people working on this project, but we have many other projects and about 200 to 300 people working on TotalCloud.
How are customer service and support?
Support is good overall. While they do take some time to assess issues, we are generally satisfied with the support received.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have used Qualys for this project since its inception, and we did not use a different solution beforehand.
How was the initial setup?
The deployment was easy. On the infrastructure side, we have added agents to the base image itself. Automated scanning using discovery features helps ensure seamless operation.
We use Azure and OCI Cloud. The documentation provided was clear for our cloud setup. It was easy to install our scanners. The networking was set up by our cloud team, so it was easy to set it up.
We follow the whole change management request process here. The change request needs to be raised two weeks prior to installing the agents. There are a lot of processes involved where a sign-off is made for the agent to be deployed. It takes about two weeks for cloud agents to be deployed. For scanning through existing scanners, since the environment is already built up, we can scan within hours. That is not an issue. Scanner-based scanning is easy. We can scan seamlessly from the cloud and on-prem. Once an agent is a part of the base image, it is provisioned within hours. If we have to upgrade the agent, it goes through a whole change management process, which takes around two weeks.
It does require maintenance because we have to update our agents regularly. That is done as a part of our change management process. Its maintenance includes cleanups. There could be certain stale entries. We have to remove those stale entries in Qualys because there is no mechanism built in right now to clean them.
What other advice do I have?
I would definitely recommend Qualys TotalCloud to other customers. The accuracy of vulnerability detection signatures and the over-the-air updates for both scanners and agents ensure that everything is kept up-to-date.
I would rate Qualys TotalCloud a ten out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Senior Manager at a consultancy with 10,001+ employees
Focuses on identifying data leakage vulnerabilities and managing compliance risks
Pros and Cons
- "Qualys TotalCloud's most valuable features are its security capabilities that help identify and mitigate risk factors."
- "Qualys TotalCloud's most valuable features are its security capabilities that help identify and mitigate risk factors."
- "Enhancing clarity regarding its compliance capabilities would be beneficial, as the current scope is limited in geographic coverage."
- "Qualys TotalCloud has the potential to improve by integrating a hybrid platform for comprehensive management of both on-premises and cloud infrastructures."
What is our primary use case?
Our primary function for Qualys TotalCloud is managing SaaS applications within cloud environments. It focuses on identifying data leakage vulnerabilities and managing compliance risks.
How has it helped my organization?
Qualys TotalCloud offers written explanations to guide remediation and mitigate cyber risks. These explanations are crucial because they allow us to simulate the attack steps within a virtualized environment, fostering quicker comprehension and facilitating strategic responses as needed.
Qualys TotalCloud has provided frequent updates and support, drastically changing and enhancing the solution with additional features.
Qualys TotalCloud has offered unified vulnerability and threat assessment across both IaaS and SaaS environments, improving the organization's cloud security posture. This solution has instilled confidence in using the cloud infrastructure by overcoming challenges related to exposure and open internet access.
Qualys TotalCloud offers a unified, prioritized view of risk by combining the features of a compliance manager with other security management tools. This approach helps our organization effectively identify, assess, and prioritize risks, ultimately improving our overall security posture. The centralized platform provides a comprehensive view of risk while reducing the manual effort involved in identification. Previously, manual identification often failed to uncover risks that are now easily revealed by the platform.
The TruRisk Insights feature identifies assets with high vulnerability scores and the authorities to whom penalties may be owed.
TruRisk Insights has successfully identified all assets, including those with high vulnerability scores. We are able to use the information to quickly check for patches or fixes and address critical vulnerabilities.
The TruRisk Insights feature has improved our security posture by 80 percent.
What is most valuable?
Qualys TotalCloud's most valuable features are its security capabilities that help identify and mitigate risk factors. By providing a comprehensive view of the cloud environment's security, it detects malware, data leakages, and vulnerabilities. Additionally, the solution offers visualized attack paths to facilitate better understanding and implementation of security strategies.
What needs improvement?
Qualys TotalCloud has the potential to improve by integrating a hybrid platform for comprehensive management of both on-premises and cloud infrastructures. Additionally, enhancing clarity regarding its compliance capabilities would be beneficial, as the current scope is limited in geographic coverage. Expanding these features to provide a more comprehensive compliance solution would be advantageous.
For how long have I used the solution?
I have been using Qualys TotalCloud for over six months to a year.
What do I think about the stability of the solution?
I would rate the stability of Qualys TotalCloud nine out of ten.
What do I think about the scalability of the solution?
I would rate the scalability of Qualys TotalCloud nine out of ten.
How are customer service and support?
While customer service is satisfactory, providing necessary support, frequent updates, and beneficial training, more communication from the vendor would be appreciated.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup of Qualys TotalCloud took two months and involved four to five people. The setup process was straightforward.
What about the implementation team?
The implementation team consisted of four to five full-time employees who were involved in deploying the solution over a period of two months.
What other advice do I have?
I would rate Qualys TotalCloud eight out of ten.
We have Qualys TotalCloud deployed in multiple departments.
Qualys TotalCloud requires maintenance for servers, licensing, and additional features.
I would recommend Qualys TotalCloud to other users due to its scalability, insightful risk analysis, and overall effectiveness.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Download our free Qualys TotalCloud Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Cloud-Native Application Protection Platforms (CNAPP) Vulnerability Management Container Security Cloud Workload Protection Platforms (CWPP) Cloud Security Posture Management (CSPM) SaaS Security Posture Management (SSPM)Popular Comparisons
Datadog
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Darktrace
Prisma Cloud by Palo Alto Networks
Varonis Platform
Qualys VMDR
AWS GuardDuty
CrowdStrike Falcon Cloud Security
JFrog Xray
Orca Security
AWS Security Hub
Claroty Platform
Buyer's Guide
Download our free Qualys TotalCloud Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Cloud-Native Application Protection Platforms (CNAPP), what aspect do you think is the most important to look for?
- Why is a CNAPP (Cloud-Native Application Protection Platform) important?
- What CNAPP solution do you recommend for a hybrid cloud?
- Why are Cloud-Native Application Protection Platforms (CNAPP) tools important for companies?
- When evaluating Cloud-Native Application Protection Platforms (CNAPP) solutions, what aspect do you think is the most important to look for?
- Why is Cloud-Native Application Protection Platforms (CNAPP) important for companies?
- What Cloud-Native Application Protection Platform do you recommend?



















