Try our new research platform with insights from 80,000+ expert users
reviewer2246079 - PeerSpot reviewer
Cyber Security Sales Specialist at a tech services company with 1,001-5,000 employees
Reseller
Aug 1, 2023
Stable and reliable solution with good performance
Pros and Cons
  • "It is a cloud-based solution, so it is easy to scale."
  • "The Qualys Web Application Scanning solution offers a single comprehensive console and consolidated reporting, covering all aspects from on-prem to cloud and compliance, etcetera."
  • "There should be better visibility into the application."
  • "There should be better visibility into the application."

What is our primary use case?

The primary use case includes scanning the web applications that are public facing.

What is most valuable?

The Qualys Web Application Scanning solution offers a single comprehensive console and consolidated reporting, covering all aspects from on-prem to cloud and compliance, etcetera.

What needs improvement?

There should be better visibility into the application.

For how long have I used the solution?

Our customers have been using this solution for more than three years now.

Buyer's Guide
Qualys Web Application Scanning
March 2026
Learn what your peers think about Qualys Web Application Scanning. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

It is a cloud-based solution, so it is easy to scale.

We work with enterprise-level clients with over 2500 endpoints.

How are customer service and support?

The customer service and support are good.

Which solution did I use previously and why did I switch?

I would say Qualys is on the better side. It's more about the performance and the quality of the product because it's been around for a long time.

How was the initial setup?

The initial setup is relatively easy. The installation process is quite straightforward, making it user-friendly.

What about the implementation team?

The duration of deployment varies depending on the complexity of the customer's environment and their implementation status. We ensure to accommodate the customer's preferred implementation pace.

What's my experience with pricing, setup cost, and licensing?

We normally purchase an annual license. There are additional costs. From Qualys, it's for the license and maintenance, which includes patches and stuff like that. Additionally, we have our own service delivery costs.

What other advice do I have?

Qualys is a stable and reliable solution. It has been around for a long time.

Overall, I would rate the solution an eight out of ten. There is scope for improvement. It is still an early technology.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
YongjinLee - PeerSpot reviewer
Commercial Pre-Sales at Megazone
Reseller
Top 5
Aug 1, 2023
Highly stable and scalable solution which is suitable for enterprise businesses
Pros and Cons
  • "The Qualys Web Application Scanning solution offers a single comprehensive console and consolidated reporting, covering all aspects from on-prem to cloud and compliance, etcetera."
  • "There should be better visibility into the application."

What is our primary use case?

The primary use case includes scanning the web applications that are public facing.

What is most valuable?

The Qualys Web Application Scanning solution offers a single comprehensive console and consolidated reporting, covering all aspects from on-prem to cloud and compliance, etcetera.

What needs improvement?

There should be better visibility into the application. 

For how long have I used the solution?

Our customers have been using this solution for more than three years now.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

It is a cloud-based solution, so it is easy to scale. 

We work with enterprise-level clients with over 2500 endpoints. 

How are customer service and support?

The customer service and support are good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I would say Qualys is on the better side. It's more about the performance and the quality of the product because it's been around for a long time.

How was the initial setup?

The initial setup is easy. 

What about the implementation team?

The time taken for implementation depends on the customer's environment. It could take around a month, depending on the module. 

We have a team of two to three people to implement at the enterprise level. Moreover, it is easy to maintain. 

What's my experience with pricing, setup cost, and licensing?

We normally purchase an annual license. There are additional costs. From Qualys, it's for the license and maintenance, which includes patches and stuff like that. Additionally, we have our own service delivery costs.

Which other solutions did I evaluate?

I'm familiar with all of the Qualys-based products because we partner with Qualys, so I have a local contact in New Zealand who helps me with all the technical information.

Moreover, I'm a pre-sales specialist, so I recommend the solution to our potential customers and then we implement through another team for customers.

What other advice do I have?

Qualys is a stable and reliable solution. It has been around for a long time.

Overall, I would rate the solution an eight out of ten. There is scope for improvement. It is still an early technology. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Buyer's Guide
Qualys Web Application Scanning
March 2026
Learn what your peers think about Qualys Web Application Scanning. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
reviewer1138395 - PeerSpot reviewer
Sr Cybersecurity Leader at a non-tech company with 1,001-5,000 employees
Real User
Feb 23, 2022
We like its process of updating signatures, and it's way ahead of its industry peers.
Pros and Cons
  • "Qualys' process of updating signatures is something we really appreciate, and it's way ahead of its industry peers."
  • "Qualys' process of updating signatures is something we really appreciate, and it's way ahead of its industry peers."
  • "We procured around 110 licenses for Web Application Scanning, but we have issues running concurrent scans. I don't currently have the option to trigger scans for all 100-plus websites. The default limit is around 10 conference scans. It's not very scalable, to be honest, because of the limitation that they put on concurrent scans."
  • "We procured around 110 licenses for Web Application Scanning, but we have issues running concurrent scans."

What is our primary use case?

There are two parts. We use Web Application Scanning licenses to constantly assess our websites. When there are any changes on our websites, Qualys checks to see if there is a vulnerability. We use a SecOps/DevOps methodology, so Qualys is integrated into the development cycle. Qualys runs every time we update the site.

What is most valuable?

Qualys' process of updating signatures is something we really appreciate, and it's way ahead of its industry peers. 

For how long have I used the solution?

We have been using Web Application Scanning since 2018. 

What do I think about the stability of the solution?

Web Application Scanning is a stable solution.

What do I think about the scalability of the solution?

We procured around 110 licenses for Web Application Scanning, but we have issues running concurrent scans. I don't currently have the option to trigger scans for all 100-plus websites. The default limit is around 10 conference scans. It's not very scalable, to be honest, because of the limitation that they put on concurrent scans.

How are customer service and support?

I've had some issues with Qualys support. It's transactional. There is no face to the support model. I don't see anyone from Qualys engaging with us on a quarterly business or annual business review to help us understand if we are fully utilizing Qualys' capabilities. 

This isn't a technical problem. It's more of an issue with customer relations. I think they can improve by touching base with us more often to let us know if our rollout is following industry best practices or not. 

How was the initial setup?

We used Verizon to help us with the rollout, and there were no trouble tickets or any technical issues with the rollout, so I would say the implementation was pretty smooth. The design-build phase took a couple of weeks.

What's my experience with pricing, setup cost, and licensing?

We pay for a yearly license, but we also pay a separate cost for an engineer from Verizon.

Which other solutions did I evaluate?

When evaluating Qualys, we looked at industry best practices and state of-art-tools. Qualys was the default leader in its segment, so we went ahead with Qualys. I've used other solutions in the past, but Qualys the segment. That's why we went with them.

What other advice do I have?

I rate Qualys Web Application Scanning nine out of 10. I think Web Application Scanning should integrate VMDR, a more enhanced capability that Qualys offers for enterprise vulnerability assessments. However, Qualys is way ahead of the competition on the web application front. 

If you're an industrial company, you should evaluate the OT scanning capability that Qualys is about to launch. It will cover all your enterprise web applications and secure your factories as well. Qualys should be a one-stop shop meeting all your end-to-end vulnerability assessment requirements, so you don't need to buy solutions from different vendors,

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1580550 - PeerSpot reviewer
Lead Cyber Security engineer at a tech services company with 201-500 employees
Real User
May 20, 2021
Thorough detection, good visual interface, scalable
Pros and Cons
  • "I have found the detection of vulnerabilities tool thorough with good results and the graphical display output to be wonderful and full of colors. It allows many types of outputs, such as bar and chart previews."
  • "I have found the detection of vulnerabilities tool thorough with good results and the graphical display output to be wonderful and full of colors."
  • "When comparing this solution to Veracode, Veracode has good interactive features and gives a clear understanding of what the vulnerabilities are, which error line of the vulnerability is on and what can be done. It gives interactive features, whereas this solution does not give a clear understanding of where or how to fix the problem."
  • "When comparing this solution to Veracode, Veracode has good interactive features and gives a clear understanding of what the vulnerabilities are, which error line the vulnerability is on and what can be done."

What is our primary use case?

My company works for another company called Ecolab here in Bangalore. We are an Ecolab digital center, we develop mobile application. We use Vericode and this solution for testing these web applications before going live. This includes the full testing periods and the production phase. Once it has been tested, we then get them ready to go live.

What is most valuable?

I have found the detection of vulnerabilities tool thorough with good results and the graphical display output to be wonderful and full of colors. It allows many types of outputs, such as bar and chart previews.

What needs improvement?

When comparing this solution to Veracode, Veracode has good interactive features and gives a clear understanding of what the vulnerabilities are, which error line of the vulnerability is on and what can be done. It gives interactive features, whereas this solution does not give a clear understanding of where or how to fix the problem.

In the future, customer support could improve and the output report needs to be simplified for better understanding.

For how long have I used the solution?

I have been using the solution for the last 12 months.

What do I think about the scalability of the solution?

We have expanded the solution in a few areas and it was scalable. We have approximately 50 people using the solution in my organization.

How are customer service and technical support?

There is some improvement needed for the technical support.

Which solution did I use previously and why did I switch?

We have used Veracode previously and we are currently still using it.

How was the initial setup?

The installation is complex and it took approximately one month which included the customization.

What's my experience with pricing, setup cost, and licensing?

We are on an annual license for the solution and the pricing could be more affordable.

Which other solutions did I evaluate?

We are planning on moving to Veracode because we are getting better results and is easier to use than this solution.

What other advice do I have?

My advice to those wanting to implement this solution is if you have experience and knowledge with vulnerability management and reading through all the threats, this could be a good platform for you. If you are a new starter this solution is not a good place to start.

I rate Qualys Web Application Scanning an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Data Specialist at CHUN SHIN LIMITED
Real User
Sep 30, 2020
Easy to use for detection of WAS and VM vulnerabilities
Pros and Cons
  • "It is easy to use."
  • "It is a very stable solution."
  • "The best thing about this product is that it is really easy to use."
  • "The reporting contains too many false positives."
  • "The virus code updates are not frequent enough."
  • "Deployment can be complicated."
  • "We are researching open source software because Qualys needs to improve their reports and the documentation for the end-users in resolving scanned issues."

What is our primary use case?

We are using Qualys for vulnerability detection in our IDC (International Data Center) on our web pages and world-wide-web applications and services.  

What is most valuable?

The best thing about this product is that it is really easy to use.  

What needs improvement?

We are concerned with the frequency of their virus code updates and reporting that contains false positives. We do not think that the accuracy of the reporting is as good as it should be.  

It would be nice if Qualys would provide a solution after analyzing the data for us so we can understand what the cause of a vulnerability is and how to fix it. It would be good enough to provide something like just a download page that describes the problem and the steps to take to resolve the vulnerability.  

We are researching open source software because Qualys needs to improve their reports and the documentation for the end-users in resolving scanned issues.  

Sometimes the deployment is complicated. It is not so easy to deploy and that should be simplified. Something like Zap or other open-source software is often easier to deploy.  

For how long have I used the solution?

I am in the IT department in our company and we have been using Qualys for three years.  

What do I think about the stability of the solution?

Qualys is a very stable solution for us. We have not had trouble with downtime.   

What do I think about the scalability of the solution?

We get a license to use this application for up to a year and we file for a license every year to renew. We would need to renew this license in September of 2020, so we will need to make a decision whether we will be continuing to use Qualys as a solution.  

How was the initial setup?

Sometimes the deployment is complicated. The deployment should be easier and more consistent.  

What's my experience with pricing, setup cost, and licensing?

The cost of the solution should be lower. In our company now, we only have 200 employees. For us, the license fee is kind of expensive. The cost is $30,000 USD for one year to cover WAS (Web Application Security) and the VM (Virtual Machine) security. That price includes maintenance and any consulting with Qualys.  

What other advice do I have?

I would recommend Qualys if the budget is not a problem. There may be other open-source solutions that could be used to perform a similar analysis.   

On a scale from one to ten (where one is the worst and ten is the best), I would rate this solution as an eight-out-of-ten.  

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1387992 - PeerSpot reviewer
Senior Software Developer at a tech vendor with 1,001-5,000 employees
Real User
Aug 13, 2020
Has a good progressive scan feature but the data server needs improvement
Pros and Cons
  • "The feature that I have found most valuable is the progressive scan. It is good. It's done in 24 hours."
  • "Qualys Web Application Scanning is very stable and reliable."
  • "The UI is not user-friendly and you don't have a yearly reporting facility where you can slice and dice in different jobs."
  • "The UI is not user-friendly and you don't have a yearly reporting facility where you can slice and dice in different jobs."

What is our primary use case?

I think we have the fastest version, and they always upgrade it. I think it's the $2 or $3-a-month version. They have multiple engines inside it, but it's a site-based service. It is not on-demand, so Qualys will host it. It's the pay as you go service that is on the software-as-a-service. 

We use the DAST, dynamic application scan test.

What is most valuable?

The feature that I have found most valuable is the progressive scan. It is good. It's done in 24 hours.

What needs improvement?

One area that could be improved is the a data server. That's probably what I most noticed in comparison with the Rapid7. Also, the UI is not user-friendly and you don't have a yearly reporting facility where you can slice and dice in different jobs. This is not good. 

Additionally, you don't have a recording feature, where you can record your screen navigation. Like a macro, you want to create the full screen, and they don't provide a tool which can record your navigation and then do a replay.

In terms of what should be included in the next release, like I mentioned, just the UI, the user interface screen. Also, it would be good If they could improve and enrich the reports. These are the fundamental differences with Rapid7.

For how long have I used the solution?

I have been using Qualys Web Application Scanning for five years.

What do I think about the stability of the solution?

Qualys Web Application Scanning is very stable and reliable. But the reporting does not look that great.

What do I think about the scalability of the solution?

In terms of scalability, it is very easy to expand. It's very fast and visible.

We don't have many people working on the solution. But our applications are big applications. We are using six components in different applications.

How are customer service and technical support?

Support is very good.

How was the initial setup?

Because of tasking, the initial setup is very straightforward. We didn't have to purchase any hardware for the installation. It is task-based. The cloud provision is there. It is good. I think nowadays everyone is going with the cloud provisioning. That way you can subscribe for any number of years to use the software. 

I think the initial setup took a couple of hours because there were no plugins and nothing to be installed.

What about the implementation team?

We implemented it ourselves and there was no installation expert here.

Which other solutions did I evaluate?

Yes, we are still comparing it with Rapid7. We want to first make assessments of what advantages we can get with Rapid7.

What other advice do I have?

My advice for anyone considering this solution is, "Go for it." 

On a scale of one to ten, I would give Qualys Web Application Scanning a seven.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2254848 - PeerSpot reviewer
Technical Lead at a computer software company with 501-1,000 employees
Real User
Aug 11, 2023
Easy-to-deploy product with good stability
Pros and Cons
  • "It is a good product for website penetration testing to detect vulnerabilities."
  • "The product's pricing could be better."

What is our primary use case?

We primarily use Qualys Web Application Scanning for website penetration testing.

What is most valuable?

It is a good product for website penetration testing to detect vulnerabilities.

What needs improvement?

The product's pricing could be better.

For how long have I used the solution?

We have been using Qualys Web Application Scanning for less than a year.

What do I think about the stability of the solution?

The platform has good stability.

What do I think about the scalability of the solution?

It is a scalable product.

How are customer service and support?

The technical support services are good.

How was the initial setup?

Qualys Web Application Scanning is easy to deploy.

What's my experience with pricing, setup cost, and licensing?

It is an expensive platform.

What other advice do I have?

Qualys Web Application Scanning is easy to use and deploy. I rate it a nine out of ten. However, it could be less expensive compared to other open-source tools.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Vivek Sathaye - PeerSpot reviewer
Director at Benelec
Real User
Mar 11, 2023
Effective scanning, scalable, but scanning may result in false positives
Pros and Cons
  • "The most valuable feature of Qualys Web Application Scanning is the effective scanning that can be done."
  • "We receive false positives sometimes when using a solution that could be improved. However, the technical team provides us with the exact explanation why it was giving us that kind of error."

What is our primary use case?

We are using Qualys Web Application Scanning for our customers. We have the expertise in the solution to provide our customers with the results.

We use the tool for scanning web applications for our clients.

What is most valuable?

The most valuable feature of Qualys Web Application Scanning is the effective scanning that can be done.

What needs improvement?

We receive false positives sometimes when using a solution that could be improved. However, the technical team provides us with the exact explanation why it was giving us that kind of error.

For how long have I used the solution?

I have been using Qualys Web Application Scanning for approximately five years.

What do I think about the stability of the solution?

The stability of Qualys Web Application Scanning could be better.

I rate the stability of Qualys Web Application Scanning an eight out of ten.

What do I think about the scalability of the solution?

Qualys Web Application Scanning has been scalable we have not had any problems in our operations.

How was the initial setup?

The initial setup of Qualys Web Application Scanning is simple for us. However, we have trained engineers that are registered. The deployment did not take very long.

What about the implementation team?

We do the migration for our customers and provide them with testing results. One person can do the implementation of the solution.

What other advice do I have?

I would recommend this solution to others.

I rate Qualys Web Application Scanning a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Qualys Web Application Scanning Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free Qualys Web Application Scanning Report and get advice and tips from experienced pros sharing their opinions.