Try our new research platform with insights from 80,000+ expert users

Qualys Policy Compliance vs RSA Archer comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys Policy Compliance
Ranking in IT Governance
4th
Average Rating
8.2
Number of Reviews
5
Ranking in other categories
No ranking in other categories
RSA Archer
Ranking in IT Governance
1st
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
38
Ranking in other categories
GRC (1st), IT Vendor Risk Management (2nd)
 

Mindshare comparison

As of January 2025, in the IT Governance category, the mindshare of Qualys Policy Compliance is 2.6%, up from 1.7% compared to the previous year. The mindshare of RSA Archer is 32.8%, down from 33.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Governance
 

Featured Reviews

Bhupendra Nayak - PeerSpot reviewer
A VMDR solution that can be used to detect, block, and mitigate vulnerabilities
We use QualysGuard Policy Compliance for VMDR (Vulnerability Management, Detection and Response). We can use the solution to detect, block, and mitigate vulnerabilities The most valuable feature of QualysGuard Policy Compliance is the automation that can detect real-time threats and decrease…
Raviteja Nekkanti - PeerSpot reviewer
User-friendly, minimal learning curve and good for security assessment
My use case is for security assessment. It's my daily task. I use it for security assessment in Azure. We have tickets where users need to submit details about an application, computer, or server. For Archer, my direct task is to assess the security risk of an application, infrastructure, or…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's a simple product."
"The reporting and security checks are valuable."
"The most valuable feature of QualysGuard Policy Compliance is the automation that can detect real-time threats and decrease risks."
"The platform allows multiple features that are very useful. The first one is being able to define the enterprise policy. The second one is to be able to automatically check the compliance level based on that policy, and the third one is that it allows us to generate reports and dashboards to see the compliance level easily."
"RSA is a very rich application. I like its adaptive suggestion, where based on your users and the class of data, it can actually recommend you the proper control to choose. For example, we have been using PCI DSS as an NIST. So based on application feedback, it will provide you with a suggestion on which control objective needs to be set. Based on that, you can make a decision—you don't need to take the suggestion, but you can customize that particular provided suggestion. RSA Archer's workflow is also good, in terms of process automation."
"Its user interface is pretty neat, and there is flexibility in generating the data. You can customize reports at any level. You can directly get reports in Tableau format. If you want to generate statistical data, you can create reports with graphs. There is an adequate amount of flexibility for changing the format, the type of graphs, etc."
"RSA Archer's best features are advanced workflow, reports, dashboards, and notifications."
"This solution helped us with the centralization of our governance data, so we could house all of our controls in one place. We could use that central repository of all our controls to build our risk management strategy and our policy and governance. So we could use controls as a central library and build policy, and then build risk management around it."
"With RSA Archer, an admin can set permissions for a normal user to go directly to the tool they need to input some data. Admins can then go through that and approve some requests. Also, they can log in based on these kinds of permissions, including ticketing, service patches, or upgrades."
"It has various valuable features. For example, showing us if a control aligns with specific standards or frameworks helps us understand it better and verify its compliance."
"The part I liked about Archer was the risk assessment for deficiencies and being able to use it there."
"The product is very flexible."
 

Cons

"It would be good if the solution’s technical support could be faster."
"There is no clear mapping for the CIS controls in terms of how they should be implemented into Qualys, so the implementation stage might be a little bit challenging for the customer. That means that the customer will end up opening support cases, which will overload their support team to explain those. If they are somehow published somewhere, it would save time and effort for both sides."
"The reporting needs improvement."
"The policy creation aspect needs improvement."
"There should be a way to export and get data from the system in PDF or PowerPoint presentation format. This would be a great addition."
"RSA Archer might be a bit expensive for small companies because it's a vast tool."
"The first improvement I would suggest for RSA Archer is a better search feature. The search criteria needs to be improved. Sometimes I do a search and the search doesn't return the exact item I'm looking for. RSA Archer could also be improved by being more user-friendly. Maybe I have been using a limited version of RSA Archer, but I'm not sure whether it has ESG, environmental and social governance. In the next couple of years, ESG is the next feature that will be integrated into GRC tools. I would recommend RSA Archer adds ESG."
"Performance could be improved."
"There is no inbuilt alert in Archer to let us know that a data feed has failed or did not run for different reasons. So, we don't even get to know that a feed has not run until somebody reports it to us. This has been a problem all the time. Data feeds have always been a big headache for us because there is no feature to let us know if a feed has not run or has failed. If Archer had a feature to send us an email notification when a feed has failed, it would've been very helpful. This is the reason why our users are slowly moving away to another platform. Some of the modules that I have been managing are being moved to ServiceNow. Next year, a lot of our modules will be moved from RSA Archer to ServiceNow, and the data feed issue has been one of the main reasons."
"It would be useful for customers if COBIT 2019 could be translated into different languages."
"Archer could be improved by having more customization. I'm not sure if the backend processes have API calls and those kinds of seamless integrations, but from the front, some of the solutions are very out-of-the-box. It's not customizable, so that could be a little problematic since you have to use their features. In terms of the backend structure, I'm not too sure because I'm not a developer—I was an end user and product owner of Archer—and I don't quite know the backend and developmental features. But since it's an out-of-the-box solution, sometimes customization was challenging and support was a little problematic because we had to reach out to them all the time."
"There are certain restrictions on API integrations, and it is not simple or straightforward."
 

Pricing and Cost Advice

"The prices might be a little bit high. I cannot compare it with another product because we did not try any other product, but this is my impression when comparing different modules."
"The solution's pricing is in the mid-range, where it is neither expensive nor very cheap."
"RSA Archer's price is justifiable and not as expensive, compared to ServiceNow. I have heard that the licensing for ServiceNow is much more expensive. I'm unaware whether there are any additional costs after licensing fees."
"As I am a developer and responsible for providing production support, I do not have personal knowledge of the pricing. However, my colleagues claim that it is very expensive in comparison with other tools."
"The license is costly for the solution, but the remaining set up and maintenance is quite cheaper."
"The price of RSA Archer is good. The price isn't too high considering it is a leading tool in the market."
"The price of the solution is very affordable."
"Fairly highly-priced, especially for smaller companies."
"I am not 100% familiar with that, especially with their new model. I just know that the way they've licensed per user to scale is good."
"The solution's price should be reduced. You only have to pay the license and there are no additional fees."
report
Use our free recommendation engine to learn which IT Governance solutions are best for your needs.
830,596 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
25%
Healthcare Company
16%
Government
9%
Educational Organization
7%
Educational Organization
54%
Financial Services Firm
12%
Computer Software Company
5%
Manufacturing Company
3%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about QualysGuard Policy Compliance?
The most valuable feature of QualysGuard Policy Compliance is the automation that can detect real-time threats and decrease risks.
What is your experience regarding pricing and costs for QualysGuard Policy Compliance?
Qualys Policy Compliance is cost-efficient and provides great security features for the price. It is used by most companies because of its cost-effective and efficient nature.
What needs improvement with QualysGuard Policy Compliance?
The policy creation aspect needs improvement. Our team has limited knowledge about creating policies, and I need to focus on this area more. I should study more about creating and handling policies...
What do you like most about RSA Archer?
It has various valuable features. For example, showing us if a control aligns with specific standards or frameworks helps us understand it better and verify its compliance.
What needs improvement with RSA Archer?
The user interface needs work. There are many small text boxes, like credit card size's boxes, where we need to input a lot of text. You can't see what you're typing beyond the tiny window, so you ...
What is your primary use case for RSA Archer?
We primarily use the system control module and specific IT control models for ongoing risk assessment activities. We use it on a day-to-day basis.
 

Comparisons

No data available
 

Also Known As

No data available
Archer
 

Learn More

 

Overview

 

Sample Customers

PDX, Cigna
T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Find out what your peers are saying about Qualys Policy Compliance vs. RSA Archer and other solutions. Updated: January 2025.
830,596 professionals have used our research since 2012.