We use it for vulnerability management and report generation mostly. I am trying to solve the issue wherein the stakeholders can get automated vulnerability reports to their mailbox.
Security Engineer at a consultancy with 10,001+ employees
Automated reporting enhances vulnerability management capabilities
Pros and Cons
- "I like the automated report generation and vulnerability report generation."
- "Using this product, we now have a vulnerability management cycle wherein VMDR plays a major role."
- "The response time of technical support takes a while."
- "The response time of technical support takes a while."
What is our primary use case?
How has it helped my organization?
Using this product, we now have a vulnerability management cycle wherein VMDR plays a major role. It has greatly increased the capability on the detection aspect of the vulnerability and improved our scope and visibility on all other endpoints.
What is most valuable?
I like the automated report generation and vulnerability report generation.
What needs improvement?
I don't have any improvement requests on top of my mind right now. The response time of technical support takes a while.
Buyer's Guide
Qualys VMDR
August 2025

Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
867,497 professionals have used our research since 2012.
For how long have I used the solution?
It's been more than two years now.
What do I think about the stability of the solution?
I would rate the stability as nine out of ten. It's quite stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
My rating for the technical support for Qualys is six out of ten. The response time takes a while.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I personally didn't use a different solution before Qualys.
How was the initial setup?
Although I was not present during the initial deployment process, it's pretty straightforward. It's just an agent installation, which automatically connects it to the cloud platform, so the implementation won't take as long.
What other advice do I have?
I would recommend Qualys VMDR to the other stakeholders because it already has its place in the market, and it's very reliable.
I'd rate the solution eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Server Services Operation Head at a logistics company with 10,001+ employees
Has robust vulnerability detection capabilities and good technical support services
Pros and Cons
- "The platform's most valuable features include its robust vulnerability detection capabilities and automated remediation workflows."
- "While Qualys VMDR is comprehensive, improvements in asset management functionality would be beneficial."
What is our primary use case?
Our primary use case of the product is comprehensive vulnerability management and asset inventory across a hybrid environment consisting of both cloud and on-premises deployments. We manage approximately 45,000 endpoints spread across multiple geographical locations.
What is most valuable?
The platform's most valuable features include its robust vulnerability detection capabilities and automated remediation workflows. These features not only help us identify vulnerabilities promptly but also enable us to prioritize and remediate them efficiently.
What needs improvement?
While Qualys VMDR is comprehensive, improvements in asset management functionality would be beneficial. Additionally, reducing dependency on multiple agents for data collection across different endpoints could simplify management and resource utilization.
In the next release, enhancements in reporting and analytics would be appreciated. Advanced analytics capabilities for trend analysis and predictive insights could further empower proactive decision-making in cybersecurity management.
For how long have I used the solution?
I have been using Qualys VMDR for approximately two years now.
What do I think about the stability of the solution?
The product is stable. I rate the stability a seven.
What do I think about the scalability of the solution?
I rate the product scalability an eight.
How are customer service and support?
The technical support services are good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was relatively straightforward. They provided comprehensive documentation and support during deployment, which helped streamline the process.
I would rate the process a seven or eight.
What about the implementation team?
We implemented the product with the help of in-house resources and support from Qualys.
Which other solutions did I evaluate?
We evaluated other options such as Tenable and Rapid7.
What other advice do I have?
I rate Qualys VMDR a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Qualys VMDR
August 2025

Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
867,497 professionals have used our research since 2012.
Information Communication Technology Specialist at UNIVERSITY OF JOHANNESBURG
Simplifies asset discovery and management, ensuring comprehensive scanning and reporting
Pros and Cons
- "The product's patch management is excellent for keeping our critical servers and third-party applications updated efficiently."
- "One area of the product that could be improved is the management of vulnerabilities detected on disabled applications."
What is our primary use case?
I primarily use Qualys VMDR for daily scans, onboarding assets, scanning, reporting, and managing the entire vulnerability management process, including test management.
How has it helped my organization?
VMDR has significantly improved our organization by simplifying asset discovery and management. We can easily identify and categorize assets, ensuring comprehensive scanning and reporting.
What is most valuable?
Qualys Patch Management is excellent for keeping our critical servers and third-party applications updated efficiently.
What needs improvement?
One area of the product that could be improved is the management of vulnerabilities detected on disabled applications. We currently face challenges with unnecessary alerts for Microsoft Defender, which we do not use. Additionally, enhancing the alerts for agent communication failures would be beneficial.
For how long have I used the solution?
I have been using Qualys VMDR for approximately three years.
What do I think about the stability of the solution?
The product has been very reliable in our day-to-day operations.
What do I think about the scalability of the solution?
I would rate the product scalability a ten. It easily scales with our organization's growth, allowing us to add new assets and expand our coverage seamlessly. We are considering expanding our deployment to include 500 assets next year.
How was the initial setup?
The initial setup was straightforward, taking less than a week to configure and generate reports. The deployment process was smooth, and we were able to integrate it effectively into our hybrid environment.
What was our ROI?
Within three months of deployment, we began seeing improvements in vulnerability management. This helped us significantly reduce vulnerabilities and streamline our patch management processes, providing a notable return on investment.
What's my experience with pricing, setup cost, and licensing?
The solution is reasonably priced for the value it provides. Our contract renewal was approximately 2.5 million ZAR for three years, including managed services.
Which other solutions did I evaluate?
Before selecting Qualys VMDR, we evaluated other options but ultimately chose Qualys due to its comprehensive features and effective proof of concept.
What other advice do I have?
We integrate Qualys VMDR with our infrastructure, conducting weekly scans and generating reports based on the findings. This provides daily views of vulnerabilities, and we use Qualys' patch management to deploy patches promptly, starting with the most severe vulnerabilities, thus reducing our threat exposure. Conducting a thorough proof of concept is essential to evaluate its effectiveness in your environment and to see how it integrates with your existing systems and handles your specific security needs.
I rate it a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Expert at a insurance company with 10,001+ employees
The solution is efficient, with easy implementation, and simple to use
Pros and Cons
- "The most valuable feature of the solution is the external channel."
- "I would like to have CSPM, a continuous scan-like cloud added to the solution."
What is our primary use case?
Qualys VM is used for vulnerability scans for the internet and applications using application exchange. There are many applications. We also use the solution for asset management per team, and the network scan to discover the devices on our network.
How has it helped my organization?
We have an excellent relationship with the vendor, so we use the solution in our company and in two other companies. We have a communication program. Japanese people can't speak English, but most of the tools have only English support, Qualys VM offers support in other languages which are essential for our company.
What is most valuable?
The most valuable feature of the solution is the external channel. The cloud-based channel within the AWS, which we implement accordingly.
The vulnerability cycle feature of the solution is valuable.
What needs improvement?
I would like to have CSPM, a continuous scan-like cloud added to the solution.
For how long have I used the solution?
I have been using the solution for one year.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
We have 25,000 storage devices that are currently using the solution.
Which solution did I use previously and why did I switch?
We previously used an AWS scanner but switched to Qualys VM because of the Japanese support and the cost.
How was the initial setup?
The initial setup is straightforward.
Qualys environment is implemented very easily, within one or two months. However, setting up the standard devices, such as opening a firewall, and preparing the network can take up to four or five months. The entire deployment takes about six months.
What about the implementation team?
The implementation was completed in-house.
What other advice do I have?
I give the solution an eight out of ten.
The maintenance is not difficult and we don't have any problems or concerns.
Implementation of the solution is very easy, using the solution is very easy, and it is very efficient.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Technology Security Analyst at Culina Group Limited
With an interesting dashboard, the solution offers stability and scalability
Pros and Cons
- "I find the solution's dashboard interesting...The response time is fine. You can pull up reports without dragging or consuming bandwidth."
- "It is a struggle to be able to pull our report and to be able to do onboarding using automated tools."
What is our primary use case?
Using the solution, I go through the reports and advise my organization on what needs to be done and how to go about it.
What is most valuable?
I find the solution's dashboard interesting since we get a proper view to streamline our findings and assist in prioritizing the schedule for patching or any other related incidents we believe have already been worked on.
What needs improvement?
Presently, I am more of the technical part. I am allowed to just go through the details of the report, which has been very interesting. It is a struggle to be able to pull our report and to be able to do onboarding using automated tools. So basically, the aforementioned aspect of the report needs improvement.
Presently, whatever I'm working on has been quite fantastic to the best of my knowledge.
For how long have I used the solution?
I have been using Qualys VMDR. I have been using it on my own site as a client. I am just a consultant. I work with Qualys VMDR due to my understanding of the product so that I can help my clients check one or two things that can help improve the digital infrastructure part.
What do I think about the stability of the solution?
The stability of the tool is okay. Most of the time, you need to do the updates online to be able to get off from any vulnerability. As long as you are online since it's on the cloud, it's just as software of which the update has been handled on the cloud as well.
The response time is fine. You can pull up reports without dragging or consuming bandwidth.
What do I think about the scalability of the solution?
The scalability of the tool is okay. Scalability-wise, I rate the solution an eight out of ten. I have not been able to have the solution function at a large scale. Hence, I will be able to categorically say that everything is fantastic.
How are customer service and support?
Presently on my own part, I've not been able to experience the support, but I can search the technical algorithm of which I've not yet got any reports.
How was the initial setup?
The initial setup phase has been quite interesting because of our experience when we had to use the agents on most of the endpoints, which means it was okay for us.
The solution is deployed on the cloud.
What other advice do I have?
I would tell those planning to use it that it is definitely not about the technology. However, at the same time, if you have the technology, make sure you have the right person with the ability to assist you in addressing the advantages of the product.
I rate the overall product an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Has tagging system and scanners, that doesn't overload
Pros and Cons
- "I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagging system is good for tagging. We can still use QualysAgent task ID tools even if tags aren't made."
- "There's a need to upgrade or fix the potential vulnerability rate. Around 20,000 potential vulnerabilities were showing in Qualys VMDR, but none of the other tools showed them. When we checked, it wasn't the case. Support explained that even small issues were being counted as vulnerabilities, causing issues in our audit. So, the security features could be improved to identify vulnerabilities accurately."
What is our primary use case?
In our DLP operations, we use the tool to address stability issues and implement fixes suggested by it. This helps manage risk levels and decide whether to fix issues or implement workarounds.
What is most valuable?
I like that we have many scanners and channels that don't overload. It helps us scan and track easily. Also, the tagging system is good for tagging. We can still use QualysAgent task ID tools even if tags aren't made.
The asset inventory management feature has improved our security posture, which is good. It was introduced recently, and we've just started using it. In terms of management, I believe it's better than what we were using before.
Qualys VMDR is good at handling vulnerability management trends, especially with its policy module. Qualys VMDR offers customizable labels that fit the organization's needs, unlike other tools. This is important for enhancing security and meeting compliance requirements.
What needs improvement?
There's a need to upgrade or fix the potential vulnerability rate. Around 20,000 potential vulnerabilities were showing in Qualys VMDR, but none of the other tools showed them. When we checked, it wasn't the case. Support explained that even small issues were being counted as vulnerabilities, causing issues in our audit. So, the security features could be improved to identify vulnerabilities accurately.
For how long have I used the solution?
I have been working with the product for two years.
What do I think about the stability of the solution?
The stability is generally good, but we did face issues during the pandemic due to connectivity problems with Qualys VMDR servers. There were syncing issues, and agents weren't getting updated. However, we later realized it was our issue because our software needed updating. We had to manually update the proxy settings, which Qualys VMDR should have done. We managed to tackle the challenge with the help of another team.
How are customer service and support?
Support should be faster and more customer-friendly. We often have to review a lot of documentation for issues we're already aware of and follow basic steps repeatedly. Additionally, we must wait for Qualys VMDR personnel to move scans into debug mode, which can be time-consuming. Getting notifications or updates on these processes more quickly would be helpful.
How was the initial setup?
Setting up the tool doesn't take long and doesn't require many people.
What's my experience with pricing, setup cost, and licensing?
We have an annual contract for Qualys VMDR. I believe it's for either two years or five years.
What other advice do I have?
I haven't personally done any integration, so I can't comment on it. However, I believe some integration was happening between Qualys VMDR and ServiceNow. Our asset management tool was also trying to integrate with Qualys VMDR, but I'm unsure about the details or how it works. I rate the overall product an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head: Cloud Platform Security at BCX Namibia
Helped us quickly remediate vulnerabilities thanks to its automation and ease of use
Pros and Cons
- "The biggest benefit is from a security operations perspective, where we are able to drive our security posture upwards by remediating any discovered vulnerabilities."
- "If anything, I would like to see the user interface modernized a bit more."
What is our primary use case?
Our use cases are primarily on-premises vulnerability management and remediation, external attack surface management and vulnerability scanning.
How has it helped my organization?
The benefits I've seen are twofold. The biggest benefit is from a security operations perspective, where we are able to drive our security posture upwards by remediating any discovered vulnerabilities. We can also automate the remediation process. The other big benefit is executive reporting because it's very easy to produce trends over time to report on risk.
What is most valuable?
The most valuable features are vulnerability detection, patching capabilities, and remediation. Cloud security posture management is also very valuable. I find these features valuable because getting a unified view of your cloud security posture across different environments is not always easy. For example, you might have most of your resources sitting in Azure, but you might have a couple of workloads in AWS. Naturally, there are different tools that report on that, so it's invaluable to have those pulled into a single dashboard so you can drive your remediation from a single platform.
What needs improvement?
If anything, I would like to see the user interface modernized a bit more. Also, there are a lot of various modules, and if they could be consolidated into fewer options, it would make the buying experience easier.
For how long have I used the solution?
I've been working with Qualys VMDR for the last three years or so.
What do I think about the stability of the solution?
We haven’t faced any issues, the solution is very stable.
What do I think about the scalability of the solution?
Because the management sits in the cloud, you don't have to worry about management appliances or anything like that on-premise, so the solution is very scalable. You can split your assets into asset groups and delegate management to different teams. Around 1,000 users are using Qualys in my organization across 60 locations.
How are customer service and support?
We've had very few technical issues, and the customer support team has quickly resolved issues we've had.
How would you rate customer service and support?
Positive
How was the initial setup?
In the first step, Qualys provisions your cloud-based management instance. From there, you get a small, lightweight agent deployed by deployment technology like Microsoft Intune, in our case, SCCM, or any deployment technology.
We worked with BCX Namibia and the Qualys team in South Africa while deploying the solution. It took two weeks to deploy the solution. The solution is not difficult to maintain because the management component is cloud-based and is taken care of by Qualys. Any agent upgrades that might be necessary are very seamless.
What was our ROI?
We have seen an ROI using Qualys. Most breaches nowadays are because of a vulnerability that is exploited. By virtue of being able to identify and remediate these vulnerabilities, I believe we are significantly driving our cybersecurity risk downwards.
What's my experience with pricing, setup cost, and licensing?
The pricing is very competitive, especially because Qualys is integrated and does vulnerability management and remediation patching in one solution, so there's no need for a separate patching solution. You can also get very granular with the amount of IP addresses you can cover. You can go from as few as 16 IP addresses to many more. And the Qualys team is also willing to work with organizations to make the solution make commercial sense. The prices are fixed. We have a yearly subscription model based on the number of IP addresses we’re scanning.
Which other solutions did I evaluate?
We evaluated vulnerability management in Microsoft Defender, but we found the reporting and functionality lacking compared to Qualys. And then the Microsoft licensing costs were also a bit of a dealbreaker.
What other advice do I have?
If you're considering implementing Qualys in your organization, work with a strong pre-sales partner. Evaluate the product, make sure it does what you need, make sure you buy the features that you need, and make sure to use the training and onboarding material that Qualys has made available on its website so you can leverage the solution's full capability from the start. I rate Qualys VMDR a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Risk & Security Admin at Goodyear Tire & Rubber Company
It is scalable and has efficient features for scanning and detecting vulnerabilities
Pros and Cons
- "It is a stable solution."
- "We face issues while scanning multiple assets."
What is our primary use case?
We use the solution for vulnerability management.
What is most valuable?
The solution's best features are scanning and vulnerability management. By using them, we can obtain all critical reports.
What needs improvement?
They should improve the solution's pricing. Also, they should enhance the authentication feature. Presently, we face issues while scanning multiple assets. In cases of heavy workloads, it must scan assets properly.
For how long have I used the solution?
We have been using the solution for more than six years.
What do I think about the stability of the solution?
It is a stable solution.
What do I think about the scalability of the solution?
It is a scalable solution. We have more than 50,000 solution users in our organization globally.
How are customer service and support?
The solution's technical support is excellent and responsive.
How was the initial setup?
The solution's initial setup is straightforward.
What about the implementation team?
We have over 30 administrators managing the solution in our organization. In addition to installing the solution internally, we receive assistance from other vendors.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive.
What other advice do I have?
I recommend the solution to others. It is excellent. We can detect and mitigate all the vulnerabilities using it.
I rate the solution as an eight.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2025
Product Categories
Vulnerability Management IT Asset Management Configuration Management Databases Container Security Risk-Based Vulnerability ManagementPopular Comparisons
ServiceNow
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
SentinelOne Singularity Cloud Security
Tenable Nessus
Tanium
CrowdStrike Falcon Cloud Security
Tenable Security Center
Tenable Vulnerability Management
Orca Security
JFrog Xray
Rapid7 InsightVM
Claroty Platform
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Qualys VM vs Tenable Nessus: Comparison
- How does Tenable Nessus compare with Qualys VM?
- How does Pentera compare with Qualys VMDR?
- What are the main differences between Qualys VMDR and Tenable Nessus?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?