Try our new research platform with insights from 80,000+ expert users

BigFix vs Qualys Patch Management comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

BigFix
Ranking in Patch Management
2nd
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
96
Ranking in other categories
Configuration Management (5th), Endpoint Protection Platform (EPP) (14th), Unified Endpoint Management (UEM) (4th)
Qualys Patch Management
Ranking in Patch Management
4th
Average Rating
8.8
Reviews Sentiment
7.5
Number of Reviews
28
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of February 2025, in the Patch Management category, the mindshare of BigFix is 10.9%, down from 12.4% compared to the previous year. The mindshare of Qualys Patch Management is 3.4%. It is calculated based on PeerSpot user engagement data.
Patch Management
 

Featured Reviews

Bella Yakoby - PeerSpot reviewer
Offers third-party patching feature, good scalability, and enhance endpoint management capabilities
From the perspective of the team that's handling the environment, it's not so user-friendly compared to other solutions, the competitors. We hire new teams from time to time, and they are complaining, look, although BigFix is very robust and cross-platform, it's not so fun to work with. The user interface for the technical teams is not so advanced. It's not so intuitive compared to SCCM, compared to ManageEngine. And this is the fact that they have, with the teams, because they have the rejection. The look and feel of the system are old-fashioned. For new employees, it's less easy to find someone I don't need to educate on how to work with BigFix. Although it's easy, it's not as intuitive as the other solutions, and the functionality of the other solutions is less advanced. Let's summarize: The user interface has to be changed from the perspective of the teams that are managing the product. It's old school.
Revathi VeeraRaghavan - PeerSpot reviewer
Provides a centralized platform for managing assets and vulnerabilities, enabling assessment, prioritization, and remediation
Qualys Patch Management system requires several improvements. Firstly, the inability to download asset patches and the lack of third-party application integration limit patch accessibility. Additionally, rollback options are unreliable, and pre-deployment patch testing is crucial. Reporting needs enhancement, particularly with group-based compliance percentages and clearer, VMDR-like reporting in the Patch Management module. Furthermore, detection speed should be improved, as patches are released 24 hours after QIDs are published. The user interface could be more functional, with dashboards for patch compliance visualization and simplified error code language. Finally, the Mac patch catalogue needs expansion, and automated workflows, policy enforcement, and testing procedures should be streamlined for seamless, user-independent operation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I like the inventory and life cycle management feature."
"The most valuable features of the solution are Windows patching and the hardware and software inventory."
"It is for multiple use cases. A lot of people are looking at it just for security, and that's really endpoint security. The endpoint management part of it in terms of being able to constantly do patching for Windows, Unix, macOS, Cloud, Raspberry, VMware, and all Linux flavors is important, and they are very good at that. They have support for virtually every OS on the market."
"I would advise someone considering this product to go for it. It's easy to use, cheaper than the value, and there is tons and tons of support from the BigFix community. With almost every challenge we have someone who has encountered it, and you will have a solution right away."
"Pre-packaged support for many third-party applications such as Adobe, Google, Mozilla, Sun (Java), WinZip, and others."
"Being able to intelligently create reports, gather data, export CSVs and give that to the leadership of some of the client groups that my team supports has helped my organization."
"It has improved my organization because we can automate a lot of tasks. We went from manually patching machines or doing our best and having very little visibility into it to us being able to set it and forget it and getting really good results on first-pass patching."
"The most valuable features are patch management, software installation, and asset management."
"Patch Management, if configured correctly, works effectively without requiring further action."
"Qualys Patch Management offers numerous valuable features, including automatic patching for Google browsers, which allows for scheduled updates immediately upon vendor release."
"Qualys Patch Management allows us to structure all the patches together and schedule patch management sessions."
"Qualys Patch Management has saved significant resources."
"Qualys Patch Management is beneficial for addressing critical vulnerability alerts quickly, providing significant improvements in mitigating risk within our organization."
"Qualys Patch Management offers a valuable feature that allows for deferred reboots, giving users control while still ensuring eventual patching."
"Automated features streamline patch deployment and ensure compliance, effectively mitigating risks and bolstering organizational security."
"Qualys Patch Management's most valuable feature is its responsiveness."
 

Cons

"In order to derive maximum benefit from BigFix, it is essential that we configure all of its features and implement them effectively. If the automation could be improved we would be able to mitigate the risks associated with zero-day threats."
"BigFix is actually a little bit on the expensive side in Turkey because of the dollar's exchange rate in our currency."
"Around the scalability concern, I would like to see the ability to run teamed, clustered, or hierarchical root servers, in order to provide a more robust, high availability system. The single monolithic root server model does somewhat bother me."
"The solution should have some kind of a local caching methodology, where the patches can be taken locally into a localized relay server, and from there, the patch can be applied, so that there is not much usage of the network required."
"The deployment has room for improvement and can be more streamlined."
"The look and feel of the system are old-fashioned."
"BigFix could improve its asset management capabilities to discover assets, including hardware."
"BigFix can improve the way machines report back to the console. In the external relay management environment, it has become more of a hybrid environment with most of the machines not being on-site. The need of having public-facing reporting items interconnected is becoming more and more crucial. In general, the reporting could use some enhancement."
"One area for improvement in Qualys Patch Management is knowing whether patches have been completely downloaded in a particular QGS appliance."
"I struggled to see patch availability for some applications in the Qualys console, requiring me to use third-party repositories."
"It would be beneficial to have more efficiently scheduled task deployments that are tailored to specific asset types or deployment needs."
"Qualys's current response time for releasing solutions to zero-day vulnerabilities, which takes approximately 12 to 16 hours, needs improvement."
"Qualys could improve its randomized download feature and provide more detailed information about patch failures, including the reason for failure."
"Downloading extensive vulnerability reports, especially those with millions of entries, is time-consuming. To improve efficiency, Qualys should implement faster download speeds and offer reports in Excel format in addition to the current CSV option."
"Not all patches are supported, so there are some restrictions. Some remediations require script-level changes which Qualys does not support."
"In our environment, the application sometimes crashes, requiring improvement."
 

Pricing and Cost Advice

"When purchasing, buying with other IBM tools provided us with a very good discount in pricing."
"The price of BigFix is better than the solutions. You are able to pay monthly or annually. There are not any hidden costs with BigFix. There is an additional cost for the SQL database."
"We have a subscription-based contract with BigFix."
"On a scale from one to ten, where one is expensive and ten is cheap, I rate the solution's pricing one out of ten."
"It is too costly. It is one of the best tools, but because of pricing, not all clients support it. Its licensing is on a yearly basis."
"The license is subscription-based."
"The tool's price continues to go up. The cost per endpoint can vary, ranging from approximately 30 to 80 dollars per year. Compared to other products, pricing is in the middle. You need to buy an additional database license, but most users already have it."
"It might be about $23 a client."
"While the cost of Qualys Patch Management is slightly high compared to alternative tools, it is not excessively expensive."
"Compared to other tools, the price of Qualys Patch Management is reasonable."
"Qualys Patch Management's pricing could be more competitive, as it presents a significant obstacle for many companies who find it unaffordable."
"The pricing is reasonable and less expensive than the previous tool."
"It is affordable, but they should provide features as per the rate they are charging. We have a big infrastructure with about 80,000 licenses. We expect better support from the Qualys team. So, it is affordable, but more features should be there, and the support should be better."
"Qualys Patch Management is a cost-effective solution for managing our 43,000-plus assets."
"Qualys Patch Management's pricing is competitive."
"The pricing is reasonable and competitive. We get many more features at the same price compared to other solutions such as Microsoft SCCM. It is worth the money considering the services and features it has. Their support team is also awesome."
report
Use our free recommendation engine to learn which Patch Management solutions are best for your needs.
832,138 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
51%
Financial Services Firm
7%
Government
6%
Computer Software Company
6%
Computer Software Company
21%
Government
11%
Manufacturing Company
10%
Financial Services Firm
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about BigFix?
The most valuable features of the solution are Windows patching and the hardware and software inventory.
What is your experience regarding pricing and costs for BigFix?
The pricing is competitive, but not the most competitive.
What needs improvement with BigFix?
BigFix could improve its asset management capabilities to discover assets, including hardware. More improvements could be made in asset management.
What is your experience regarding pricing and costs for Qualys Patch Management?
Qualys Patch Management comes as part of a bundled package with several modules, making it a cost-effective deal for us. I cannot speak to the separate cost, as we have always used it as part of th...
What needs improvement with Qualys Patch Management?
Some patches require OEM consent or must be released by OEM. For example, if an outdated version of a tool like Falcon is detected, Qualys flags it as a vulnerability, but cannot automate the patch...
What is your primary use case for Qualys Patch Management?
Our primary use case for Qualys Patch Management is vulnerability remediation and running scripts. It helps us detect vulnerabilities in our environment and identify specific patches that are requi...
 

Also Known As

Tivoli Endpoint Manager
No data available
 

Overview

 

Sample Customers

US Foods, Penn State, St Vincent's Health US Foods, Sabadell Bank, SunTrust, Australia Sydney, Stemac, Capgemini, WNS Global Services, Jebsen & Jessen, CenterBeam, Strauss, Christian Hospital Centre, Brit Insurance, Career Education Corporation
Information Not Available
Find out what your peers are saying about BigFix vs. Qualys Patch Management and other solutions. Updated: January 2025.
832,138 professionals have used our research since 2012.