I mainly use Qualys VM for vulnerability management to carry out vulnerability scans on IT assets to find out which are vulnerable and what is needed to patch them. We also use it for policy compliance scans and in tablet for web application scans.
Manager, Info Security Planning & Architecture at a comms service provider with 10,001+ employees
A great help to improve and maintain security
Pros and Cons
- "The most valuable features are vulnerability scanning, policy compliance scanning, and tablet for web application scanning."
- "Qualys VM has greatly helped us to improve and maintain our posture of security."
- "Sometimes the scanning can get overwhelmed and start to drag when a lot of users are trying to scan at once."
- "Sometimes the scanning can get overwhelmed and start to drag when a lot of users are trying to scan at once."
What is our primary use case?
How has it helped my organization?
Qualys VM has greatly helped us to improve and maintain our posture of security.
What is most valuable?
The most valuable features are vulnerability scanning, policy compliance scanning, and tablet for web application scanning.
What needs improvement?
Sometimes the scanning can get overwhelmed and start to drag when a lot of users are trying to scan at once. I think cloud-based solutions like Qualys VM should be prepared to throw more resources in to ensure they don't get overwhelmed like this.
Buyer's Guide
Qualys VMDR
March 2026
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,286 professionals have used our research since 2012.
For how long have I used the solution?
I've been using Qualys VM for about six years.
What do I think about the stability of the solution?
The stability and performance have been fine.
What do I think about the scalability of the solution?
Qualys VM is very easy to scale - that's one of the benefits of cloud-based solutions.
How are customer service and support?
Qualys' technical support is very responsive.
How was the initial setup?
Qualys VM is straightforward to set up.
What about the implementation team?
The deployment was done in-house.
What other advice do I have?
I would advise anybody looking into using Qualys to go online to also check on Gartner and Forrester. From a planning perspective, you need to look at your estate to determine what kind of tool you need. I would rate Qualys VM eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Security Consultant at a tech services company with 10,001+ employees
Excellent continuous monitoring, helpful technical support, easy to scale, and simple to install
Pros and Cons
- "The most recent is VMDR, which provides a comprehensive overview of how to detect, patch, and remediate specific vulnerabilities."
- "For a typical IT system, it is very good to go with this solution."
- "Qualys currently does not have any features for scanning SCADA, IoT, and Industrial Control Systems."
- "Qualys currently does not have any features for scanning SCADA, IoT, and Industrial Control Systems."
What is our primary use case?
Qualys' main function is to scan IT systems. It does the scanning of computer systems.
What is most valuable?
Continuous Monitoring is excellent because it is entirely dependent on the agent, and the Agent Scan, is also quite good.
I also like the asset tagging, asset grouping features, and the dashboard, because we can customize and create our own dashboard. That's quite good.
The most recent is VMDR, which provides a comprehensive overview of how to detect, patch, and remediate specific vulnerabilities. That is also an excellent module.
What needs improvement?
The dashboard itself could be improved, while we can customize it, they can create different tabs where we can see the trending vulnerabilities, how many there are, or how many have been fixed, as in the most recent scan report, so that trend analysis is a little easier.
Aside from that, the solution itself is fairly generic in nature. What they can do is pretty much customize everything and provide a relevant solution for everything. For example, because Qualys has a Cloud Agent that scans a system's entire inventory. As a result, they can test their use cases to determine whether or not a vulnerability has been confirmed. If they can do so, they can also provide us with a straightforward solution to a specific problem rather than a generic one. That could be one area where they can improve.
Qualys does not currently have an IoT, SCADA vulnerability assessment, they can significantly improve their IoT, SCADA, and ICS (Industrial Control Systems) vulnerability assessment technique. When you compare with Tenable SC it has more features than Qualys VM.
If you see power grids, large oil stations, they fall under SCADA and Industrial Control Systems. These systems are very different from standard IT systems. Qualys currently does not have any features for scanning SCADA, IoT, and Industrial Control Systems.
I believe they can improve on the addition of devices. Assume I have two lakhs of devices that cannot all be added at the same time. For example, if I have two lakhs of devices, and two lakhs of those devices have a Cloud Agent, adding all of those devices at once is not easy. We have to add it 1,000 at a time, which takes a long time when there are two lakhs of assets to add. If we do 1,000 at a time, we'll have to do it for around two lakhs, which is quite difficult.
They can increase their frequency of working faster, similar to the time constraint they currently have. The second thing they can improve is the addition of assets. They can almost completely automate the process of adding assets, or they can increase the maximum number of assets that can be added in one go. They are only allowed to add 1,000 assets. If I want to add two lakh assets, it will be extremely difficult to do so by adding 1,000, at a time.
That is a fairly technical issue. Most of the false positives reported by Qualys or the inability to detect a cumulative patch update, if any, are the few things that they can improve and incorporate.
As I previously stated, it would be extremely beneficial if they could implement scanning, vulnerability scanning of IoT systems, Industrial Control Systems, and SCADA devices.
For how long have I used the solution?
I have been working with Qualys VM for approximately four years.
We have been using multiple Qualys modules, such as VMDR, Cloud Agent, AssetView, and Continuous Monitoring. The most recent version that we are using is 4.14.
What do I think about the stability of the solution?
It's reasonably steady. When we say stable version, there is also room for improvement in that Qualys will not be able to handle large amounts of data at once. When you do billions of scans, such as a scan for millions of devices, it becomes extremely slow, and gathering data and populating the report becomes extremely tedious.
What do I think about the scalability of the solution?
Scalability is quite good. We can pretty much rely on the tool. It is easy to scale.
If the organization grows, we can pretty much scale it to most of the areas. The only problem is that they must primarily work on Industrial Control Systems and lightweight devices such as CCTV cameras, and lightweight devices. As a result, they are required to work in that field, otherwise, it is pretty good.
Based on my previous experience, there were approximately 300 or more users using Qualys in organizations with a population of more than two lakh people. Currently, I see that approximately 400 users are using it, and the size of the organization is significantly larger than the previous one.
We use this solution daily.
How are customer service and support?
Technicals support is pretty good. Since I've been working in this, they've been friendly and straightforward, and we were able to get the most out of them.
We have suggested areas for improvement, and they have been working on them. They always make a good impression on us.
Which solution did I use previously and why did I switch?
As a consultant, I've worked on a variety of projects in a variety of organizations.
How was the initial setup?
The initial setup is simple and straightforward.
What about the implementation team?
We initially had assistance from the vendor, but once we had a good understanding of it, we scaled it in our organization.
Which other solutions did I evaluate?
Because I've been using Qualys for quite some time, I was looking for a comparison of several solutions such as Tenable SC, Rapid7, InsightVM, and Tenable Nessus. I was curious to know if there were any other tools that were better than Qualys.
I was looking for more information about Tenable SC and wanted to compare it to Qualys in more detail, with parameters such as, how the false positives are detected in Tenable SC and how good it is in comparison to Qualys. In a similar manner, in comparison to Qualys, we learn about its usability, interface, and how user-friendly it is. Those are the few things I was looking for, and I'm still looking for more information about Tenable right now.
What other advice do I have?
They have the ability to improve SCADA. SCADA stands for Supervisory Control and Data Acquisition, and IoT stands for Internet of Things scanning.
Recommending this solution would depend on the organization, the requirements, and the devices they have.
For a typical IT system, it is very good to go with this solution. Microsoft, Deloitte, and the majority of organizations still use it, it is pretty much good to go. But, once again, it is entirely dependent on how the organization is, what type of devices they have, and what kind of scans they would like to have, it is entirely dependent.
In a broad sense, it is a good solution to go with.
I would rate Qualys VM an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Qualys VMDR
March 2026
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,286 professionals have used our research since 2012.
Information Security Engineer at a university with 1,001-5,000 employees
Efficient automation feature and provides us with a comprehensive security solution
Pros and Cons
- "The most valuable feature is automation."
- "Qualys VMDR is basically susceptible to false positives, and false negatives."
What is our primary use case?
Qualys VMDR is a vulnerability management and detection response tool. It belongs to the first generation of vulnerability assessment tools. It enables us to manually identify vulnerable keys and fix them. It is built as a cutting-edge continuous platform where we can detect and protect. With this product, we can respond to specific vulnerabilities, going beyond just using artificial intelligence features. We have implemented VMDR across our cloud, physical interfaces, endpoints, and log servers. It's a good digital product for our organization.
How has it helped my organization?
It has improved our organization in many ways. We needed to have a security solution that focuses on different types of things. We discussed budgeting for the cloud and the need for an alternative to taking care of malware. Additionally, we have to consider various attacks. Therefore, Qualys VMDR is a great tool that helps us improve.
What is most valuable?
The most valuable feature is automation.
What needs improvement?
Qualys VMDR is basically susceptible to false positives, and false negatives. We receive a lot of false positives in there. VMDR can be considered a complex solution, especially for enterprises with limited resources or organizations. It requires extensive knowledge as an engineer. So, when using this tool, you need to utilize other tools to remediate the false security issues.
So maybe it should also have the ability to automatically identify and address false positives. In additional features, an automated process for remediating false positives. We might be looking for new types of signatures that can help us identify and address specific issues.
For how long have I used the solution?
I have been using Qualys VMDR for one last year.
What do I think about the stability of the solution?
I would rate the stability an eight out of ten.
What do I think about the scalability of the solution?
I would rate the scalability an eight out of ten.
How was the initial setup?
It took us one month to set up.
What was our ROI?
I have seen an ROI.
What's my experience with pricing, setup cost, and licensing?
The price is very reasonable, so you can definitely go with all the endpoints it offers.
What other advice do I have?
Just consider the licenses we have within VMware. They could replicate some of these features, which are used for premium customers. So, it might be useful to include those features in the subscription plans.
Overall, I would rate the solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Architect at a tech vendor with 5,001-10,000 employees
Good analysis, helpful reports, and a straightforward setup
Pros and Cons
- "The solution shows us classic categories, including high, medium, and low risks. It also shows critical items, and that gives us the advantage of prioritizing things."
- "It would be nice to have an all-in-one solution that was automated and could handle the scanning and reports as well as the patching and updating."
What is our primary use case?
This is a virtual scanner appliance. We have both physical and virtual options.
I'm still in training and getting the hang of the solution. I do not know what features the company uses the most. They generally use it to scan all the AWS workloads and Azure workloads.
What is most valuable?
We generally analyze everything at the OS level and application level, including the open ports, the OS, and older versions, including the packaged versions. We generate the scan, and then we generate the report, and then we will issue it to the application teams to clear off those.
We have Java remediation happening, and if Java has, for example, multiple versions and when I run the scan, it is going to identify all Java versions that are really vulnerable so you can fix them. Therefore, it helps keep things secure and up-to-date.
The reporting is good. We give reports to the application teams and we will ask them to either fix or remove applications. Once that is done, then we will read the scan, and if it comes back that we don't have any critical, we are assured of good safety.
The solution shows us classic categories, including high, medium, and low risks. It also shows critical items, and that gives us the advantage of prioritizing things.
It's very clear on what components need to be fixed.
The initial setup is straightforward.
It's stable.
Technical support is helpful.
What needs improvement?
I can't speak to disadvantages since I am in training and still learning and have yet to run a scan.
It would be nice to have an all-in-one solution that was automated and could handle the scanning and reports as well as the patching and updating.
For how long have I used the solution?
I am pretty new to this organization. However, the organization has been dealing with the solution for almost four or five years now.
What do I think about the stability of the solution?
The stability has been good. The company has been using it for a while and hasn't had issues. I use dit in a previous company as well and never hear of any problems.
What do I think about the scalability of the solution?
It's easy to scale.
How are customer service and support?
Technical support is good. We always get a quick response.
How was the initial setup?
The setup process is simple. It's not overly complex.
What's my experience with pricing, setup cost, and licensing?
I don't have any details about the licensing process.
What other advice do I have?
We're implementors.
When it comes to security, my only advice is based on my experience. They always say to use multiple products due to the fact that, even if the vulnerability is missed in one product, it'll be identified in the other product so that you are safe.
However, when it comes to implementation, if you have multiple products, pipelining is a big problem. For example, if I use the Qualys scanner, and then it gives me all the vulnerabilities: how do I fix it? Either I have to fix it manually, or I have to fix it automatically.
I'd like to use one product, and, for example, use a vulnerability scanner from Qualys and have patch management as well. While the solution is still maturing, I like the tight integration and I like that the scanner can identify items and patch management can fix them. It simplifies things, instead of having to deal with multiple products and then maybe having to manually fix items on top of that.
I'd rate the solution nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
Security Specialist at a financial services firm with 1,001-5,000 employees
Robust, good agent support, and simple to setup
Pros and Cons
- "It's really beneficial for scanning and interacting with the agent."
- "The disadvantage of working with Qualys is that the graphical interface is quite outdated."
What is our primary use case?
Qualys VM is used for vulnerability scanning.
What is most valuable?
It's really beneficial for scanning and interacting with the agent.
What needs improvement?
The disadvantage of working with Qualys is that the graphical interface is quite outdated.
If you want to choose a scan result, or maybe configure an IP range or something similar, it opens up a lot of processes, or steps, which is somewhat bothersome. Because it opens several phases, it is not a single-window program.
For how long have I used the solution?
We are testing it, as well as Rapid 7 InsightVM.
We have been testing Qualys VM for approximately five weeks.
What do I think about the stability of the solution?
Qualys VM is a stable solution.
What do I think about the scalability of the solution?
Qualys VM is a scalable product.
It works with ten assets. It works with 100 assets. It has worked with 3,000 assets. It's quite scalable.
In our organization, we have two dedicated people, and five others are only dedicated to gaining insights.
It actually depends on how you remediate all of the vulnerabilities in Qualys since you can also set up it such that product owners, that is, the owners of the apps that are deployed on all systems, can access reports and everything. But that's not how we do things.
The security and infrastructure departments are using this solution in our organization.
How are customer service and support?
We have a dedicated Qualys team of two persons assisting us with the implementation.
Which solution did I use previously and why did I switch?
We are currently doing a proof of concept with both Qualys VM and Rapid 7 InsightVM.
How was the initial setup?
Qualys is a fully SaaS solution.
It is dependent on the configuration. When you work with the agent, you are primarily concerned with deploying the agents to all assets. However, if you want to scan based on IP, you'll run into some problems.
If you wish to scan on an IP basis, for example, you should deploy a virtual appliance. You may set up several appliances for different domains. Otherwise, you must have your network rules properly configured so that the appliance can reach every asset.
It's relatively simple to set up the basics, but if you want to scan, it really depends on how many networks and domains you have.
In a couple of weeks, you can set it up.
What's my experience with pricing, setup cost, and licensing?
It's very expensive, especially if you want to use multiple modules of Qualys.
What other advice do I have?
I think mainly decide how you want to scan: based on IP or based on an agent.
Then work with the interface and then explore how it works.
I would rate Qualys VM an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Lead IT Security and Remediation at a financial services firm with 1,001-5,000 employees
Cloud-based vulnerability management solution that provides protection of our systems but could offer improved performance
Pros and Cons
- "This solution gives us insight into our environment and improves our security. It helps us to maintain a good patching system whereby we know that XYZ is vulnerable within the system."
- "This solution gives us insight into our environment and improves our security."
- "Qualys could be improved in its overall performance compared to other vulnerability management or scanning tools."
- "Qualys could be improved in its overall performance compared to other vulnerability management or scanning tools."
What is our primary use case?
We use this solution to scan the servers on the network. It is used predominantly by our information security team.
How has it helped my organization?
This solution gives us insight into our environment and improves our security. It helps us to maintain a good patching system whereby we know that XYZ is vulnerable within the system.
What is most valuable?
Qualys makes us proactive in terms of handling patching and effective when it comes to scanning out network.
What needs improvement?
Qualys could be improved in its overall performance compared to other vulnerability management or scanning tools.
For how long have I used the solution?
I have been using this solution for five years.
Which solution did I use previously and why did I switch?
I have previously used Nessus. Overall, Nessus is a better tool because it provides greater insight into all vulnerabilities, some of which are skipped by Qualys.
How was the initial setup?
This solution is very easy to set up.
What about the implementation team?
We worked with a third party to complete deployment.
What's my experience with pricing, setup cost, and licensing?
In Nigerian Naira, we spend about roughly four to five million to use this solution and this is expensive compared to solutions like Nessus.
What other advice do I have?
I would advise others to run a proof of concept and to exhaust all functionality if considering Qualys. This may take between 15 and 60 days to complete.
I would rate this solution a six out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Infrastructure Security Consultant at ANECT
Easy to use, well supported with continually improving functionality
Pros and Cons
- "Provides great functionality."
- "I like the Qualys Cloud Agent because it's very easy to use."
- "Finding things in management can be quite difficult."
- "If you're not overly experienced and you're looking for something in their management, it can sometimes be quite difficult because they can move buttons around without sending an update."
What is our primary use case?
Our customers use Qualys for vulnerability management, it's a way for them to discover the kinds of vulnerabilities they have on their systems. We are a partner with Qualys and I'm an infrastructure security consultant. We currently have 20 clients using Qualys.
How has it helped my organization?
The functionality continues to improve and knowing when there are security issues is very helpful.
What is most valuable?
I like the Qualys Cloud Agent because it's very easy to use. It has a low impact and is supported on Windows, Linux, and others. I deploy process scanners, which are usually connected to core switches so customers can replicate all the connections. Almost all our customers try to use the agents because they're already installed and integrated into the cloud and communicate with Qualys management. There are no problems and it's really better than using some virtual appliance to scan the various kinds of assets. Qualys has a lot of information and it's great to integrate with the Central Management Database.
What needs improvement?
If you're not overly experienced and you're looking for something in their management, it can sometimes be quite difficult because they can move buttons around without sending an update. Previously, if you deployed the Cloud Agent, you could define which tech would be under the agent and where it would be deployed. It now requires some text preparation and the Cloud Agent then downloads the specific profile defined without any indication that this might happen. If you are not using vulnerability management, you are not able to create the correct patch process for all applications stored on the system.
It would be helpful if Qualys would integrate with more systems like ServiceNow, Jira, and so on, to create some tickets and integrate them into the active directory, because each group works differently and if you need to prepare a ticket, it must be defined to a specific group of people. Qualys just created a kit on ServiceNow, but it doesn't have the correct group of people in the active directory.
For how long have I used the solution?
I've been using this solution for three years.
What do I think about the scalability of the solution?
The solution is scalable. If you need more resources they can be added to the backend, depending on the circumstances and requirements. If you are able to deploy in the VMDR licensing, you are able to deploy unlimited virtual active appliances to discounted appliances. It all depends on your resources.
How was the initial setup?
Each customer is different and if you need to deploy a more active virtual process that will affect the implementation. If a customer wants to use policy compliance on their machines that can add to deployment time too. I tend to deploy myself because I'm usually making the POCs of Qualys.
What's my experience with pricing, setup cost, and licensing?
I believe the annual cost is approximately $40 per asset in VMDR, although it also depends on the circumstances. It contains all the features one needs although if you need synchronization with ServiceNow and CMDB, there is an additional cost.
Which other solutions did I evaluate?
I constantly speak to other companies to find out what they're doing and what the differences are between the different products. My job is to find the best solution for my customers so it's important to know what's on the market.
What other advice do I have?
I rate this solution eight out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Reliable solution with good vulnerability management
Pros and Cons
- "Qualys VM's best features are vulnerability management and customizable scoring."
- "Qualys VM's best features are vulnerability management and customizable scoring."
- "Qualys VM's vulnerability scan could be improved, especially the number of CVE numbers it can manage at a time."
- "Qualys VM's vulnerability scan could be improved, especially the number of CVE numbers it can manage at a time."
What is our primary use case?
I use Qualys VM for vulnerability scanning, enterprise management, web application scanning, and patch deployment.
What is most valuable?
Qualys VM's best features are vulnerability management and customizable scoring.
What needs improvement?
Qualys VM's vulnerability scan could be improved, especially the number of CVE numbers it can manage at a time. It could also be more user-friendly. In the next release, Qualys VM should include threat intelligence and external test service management.
For how long have I used the solution?
I've been using Qualys VM for around six months.
What do I think about the stability of the solution?
Qualys VM is stable and reliable.
What do I think about the scalability of the solution?
Qualys VM is quite easy to scale.
How are customer service and support?
Qualys' customer service could be better.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup was not user-friendly.
Which other solutions did I evaluate?
I evaluated Tenable but chose Qualys VM because of its management features.
What other advice do I have?
I would rate Qualys VM eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Vulnerability Management IT Asset Management Configuration Management Databases Container Security Risk-Based Vulnerability ManagementPopular Comparisons
ServiceNow
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
Checkmarx One
Tanium
Zafran Security
Tenable Nessus
NinjaOne
CrowdStrike Falcon Cloud Security
JFrog Xray
Orca Security
Tenable Security Center
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Qualys VM vs Tenable Nessus: Comparison
- How does Tenable Nessus compare with Qualys VM?
- How does Pentera compare with Qualys VMDR?
- What are the main differences between Qualys VMDR and Tenable Nessus?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?


















