We're using the entire suite except for Patch Management. I use Qualys VM for my production environment on Amazon AWS. I also use it for my endpoints and some BDI solutions that require on-premise solutions, and I use it for both.
Information Security Analyst at a tech services company with 11-50 employees
A robust and user-friendly cloud-based service that gives you immediate, global visibility into potential vulnerabilities and threats
Pros and Cons
- "I find Qualys VM very robust, and it's very useful for vulnerability management and patch management. The value that it brings to my environment is economies of scale. There is no limitation on adding any endpoints. You go by the rule, and it's added once another endpoint is added to our environment. It's automatically installed, and it's less work from our end. It frees up my license automatically if I don't need an endpoint or if my machine is decommissioned. I like the dashboard displays because I don't see any duplication. The most important part is vulnerability management and prioritization. Unlike Symantec, it shows the kind of vulnerability I would want to patch first. It provides a holistic view of the kind of vulnerabilities and the ones I should remediate first. I don't have to do a scan; it just brings up those critical kinds of vulnerabilities like zero-day vulnerabilities and tells me to prioritize them. You have to prioritize these vulnerabilities first and go on with the rest. The dashboard shows me the ones that have been fixed, so I don't have to complete an aging report. The user experience and the graphical interface are good. As it's user-friendly and understandable on an executive level, it brings real value. We also use this solution because it's robust and flexibile."
- "I find Qualys VM very robust, and it's very useful for vulnerability management and patch management."
- "The price could be better. Asset view is still a legacy feature. I'm not able to extract the information about the asset with complete details. It would be better if they fixed that in the next release. I know Qualys is already working on it, so I'm hopeful it will be available in the next five or six months. That would be something that's changed where I seek improvement."
- "Support could be a little bit faster."
What is our primary use case?
What is most valuable?
I find Qualys VM very robust, and it's very useful for vulnerability management and patch management. The value that it brings to my environment is economies of scale. There is no limitation on adding any endpoints. You go by the rule, and it's added once another endpoint is added to our environment. It's automatically installed, and it's less work from our end. It frees up my license automatically if I don't need an endpoint or if my machine is decommissioned.
I like the dashboard displays because I don't see any duplication. The most important part is vulnerability management and prioritization. Unlike Symantec, it shows the kind of vulnerability I would want to patch first. It provides a holistic view of the kind of vulnerabilities and the ones I should remediate first.
I don't have to do a scan; it just brings up those critical kinds of vulnerabilities like zero-day vulnerabilities and tells me to prioritize them. You have to prioritize these vulnerabilities first and go on with the rest. The dashboard shows me the ones that have been fixed, so I don't have to complete an aging report.
The user experience and the graphical interface are good. As it's user-friendly and understandable on an executive level, it brings real value. We also use this solution because it's robust and flexibile.
What needs improvement?
The price could be better. Asset view is still a legacy feature. I'm not able to extract the information about the asset with complete details. It would be better if they fixed that in the next release.
I know Qualys is already working on it, so I'm hopeful it will be available in the next five or six months. That would be something that's changed where I seek improvement.
For how long have I used the solution?
I have been working with Qualys VM for the past six months.
Buyer's Guide
Qualys VMDR
May 2026
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,942 professionals have used our research since 2012.
What do I think about the stability of the solution?
Qualys VM is a stable solution.
What do I think about the scalability of the solution?
Qualys VM is a scalable solution. We currently have about 4500 users in our organization.
How are customer service and support?
Support could be a little bit faster. I haven't been granted access to their support portal, but I have a technical support engineer who's always available, and there is only one person I can talk to. But the problem is if he's absent, I'm left waiting for access to his portal.
Which solution did I use previously and why did I switch?
I used Symantec before but switched to Qualys VM as there's no limitation to adding endpoints. The other reason everyone moved to Qualys VM was its robustness and flexibility. I think that's something that's there, and there was no hassle in deploying the agent. All I had to do was get these machines that were enrolled in our MDM solutions.
How was the initial setup?
As it's a cloud agent, there wasn't any specific setup. It's also managed centrally by Qualys, and when they always release a new update, all we have to do is push it. So, the maintenance requirement is minimum at best.
What about the implementation team?
We deployed this solution by ourselves.
What's my experience with pricing, setup cost, and licensing?
Qualys VM is quite expensive. It's a subscription-based license, and it's yearly. Right now, it's open for me, and I don't have any limitations or caps on the licenses. They are seeing if the product is viable for 4500 users. I can add as much as I want, and at the end of the subscription, they'll let me know how many licenses were actually used and bill me accordingly.
On a scale from one to five, I would give their pricing a three. It's still expensive.
What other advice do I have?
If you're going for an on-premises solution, you should dive into the POC. Because I wasn't procuring an on-premises solution, it was pretty easy for me, and the support was quite helpful. But if you're going to deploy it on-premises, you should go through a proper procedure of going through the POC and getting to know the product. I would rate it at the top because it's better than Nexpose, it's better than Tenable, and it's better than Symantec.
On a scale from one to ten, I would give Qualys VM an eight.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Principal at Cranny Group
Good return on investment, ease of deployment, and metrics
Pros and Cons
- "The Vulnerability Management and Patch Management features are the most valuable features of this solution."
- "Qualys VM has improved the way the organization functions."
- "Endpoint stability and fault resolution could be improved."
- "The technical support is mediocre at best. I would rate them a two out of five."
What is our primary use case?
It is a SaaS solution with agents distributed at endpoints.
How has it helped my organization?
Qualys VM has improved the way the organization functions.
What is most valuable?
The Vulnerability Management and Patch Management features are the most valuable features of this solution.
The most valuable qualities of Qualys VM are its ease of deployment and metrics.
What needs improvement?
Endpoint stability and fault resolution could be improved.
I would like to see the solution's footprint expanded to include iOS and iPads in the next release.
One example of how it could be better would be better handling of end-of-life systems and better feedback on job failures.
For how long have I used the solution?
We have been working with Qualys VM for just over two years.
It is a cloud platform. I'm not sure if a version is associated with that.
What do I think about the stability of the solution?
The stability of Qualys VM is quite good, but not fantastic. I would rate it an eight out of ten.
What do I think about the scalability of the solution?
The scalability of Qualys VM is very good.
This solution is used by five security or system administrators in our organization.
We have no plans to expand our usage; it is already widely deployed.
How are customer service and support?
The technical support is mediocre at best.
I would rate them a two out of five.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We were previously using Lansweeper, which was not scalable.
How was the initial setup?
I would rate the initial setup a three out of five.
It took several weeks to deploy.
What about the implementation team?
We completed the deployment in-house.
What was our ROI?
We have seen a return on investment.
What's my experience with pricing, setup cost, and licensing?
There are no additional fees in addition to the standard licensing fees.
What other advice do I have?
I would recommend identifying the right metrics to drive the program.
I would rate Qualys VM an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Qualys VMDR
May 2026
Learn what your peers think about Qualys VMDR. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,942 professionals have used our research since 2012.
Manager, Info Security Planning & Architecture at a comms service provider with 10,001+ employees
A great help to improve and maintain security
Pros and Cons
- "The most valuable features are vulnerability scanning, policy compliance scanning, and tablet for web application scanning."
- "Qualys VM has greatly helped us to improve and maintain our posture of security."
- "Sometimes the scanning can get overwhelmed and start to drag when a lot of users are trying to scan at once."
What is our primary use case?
I mainly use Qualys VM for vulnerability management to carry out vulnerability scans on IT assets to find out which are vulnerable and what is needed to patch them. We also use it for policy compliance scans and in tablet for web application scans.
How has it helped my organization?
Qualys VM has greatly helped us to improve and maintain our posture of security.
What is most valuable?
The most valuable features are vulnerability scanning, policy compliance scanning, and tablet for web application scanning.
What needs improvement?
Sometimes the scanning can get overwhelmed and start to drag when a lot of users are trying to scan at once. I think cloud-based solutions like Qualys VM should be prepared to throw more resources in to ensure they don't get overwhelmed like this.
For how long have I used the solution?
I've been using Qualys VM for about six years.
What do I think about the stability of the solution?
The stability and performance have been fine.
What do I think about the scalability of the solution?
Qualys VM is very easy to scale - that's one of the benefits of cloud-based solutions.
How are customer service and support?
Qualys' technical support is very responsive.
How was the initial setup?
Qualys VM is straightforward to set up.
What about the implementation team?
The deployment was done in-house.
What other advice do I have?
I would advise anybody looking into using Qualys to go online to also check on Gartner and Forrester. From a planning perspective, you need to look at your estate to determine what kind of tool you need. I would rate Qualys VM eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Professional services team lead at a tech services company with 1,001-5,000 employees
The reporting and GUI need improvement but it's reliable
Pros and Cons
- "Qualys VM is very stable."
- "The reporting and the GUI need improvements."
- "The reporting and the GUI need improvements. Tenable dominated in these two areas: reporting and graphical user interface."
What is our primary use case?
It was responsible for vulnerability scanning. It enforces vulnerability management websites.
What needs improvement?
The reporting and the GUI need improvements. Tenable dominated in these two areas: reporting and graphical user interface.
For how long have I used the solution?
Qualys VM was used once for one of our customers.
We were using the latest version.
What do I think about the stability of the solution?
Qualys VM is very stable.
What do I think about the scalability of the solution?
I didn't have all of the necessary information regarding the scalability or how to scale this solution, but all vulnerability management solutions have the same idea.
I believe that it is easy to scale.
How are customer service and support?
I did not contact technical support.
Which solution did I use previously and why did I switch?
I have also used Rapid7, which is very similar to Qualys VM.
Scaling is more difficult with Rapid7. When it comes to scaling, Rapid7 is not my first choice.
How was the initial setup?
I did not implement this solution, I performed one scan for our client.
What other advice do I have?
We have regulations in place in Saudi Arabia and Egypt that require all vulnerability management solutions to be implemented on-premise.
I would recommend this solution to others but Tenable is my preferred option.
I would rate Qualys VM a five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Director at a manufacturing company with 5,001-10,000 employees
Reliable with good technical support and good stability
Pros and Cons
- "The initial setup is straightforward."
- "The prioritization mechanism is the most valuable aspect of the solution."
- "The solution is a bit expensive if you do not have access to discounts."
What is our primary use case?
We primarily use the solution for full enterprise visibility from both an asset detection perspective and vulnerability detection perspective. Basically, we are tracking all the devices over agents, including PCs and servers, et cetera.
We are able to understand what our current situation is on the devices. At the second stage, we are able to catch the devices which do not have agents or which are not in the inventory, with on-premise scanners.
We are running security configuration hardening assessments or compliance with CIA security benchmarks.
In addition to that, we are also utilizing the cloud assessment solution of the Qualys, to ensure compliance with CIA security standards. For example, the Amazon cloud platform is configured compliantly with the CIA security benchmark. These are the four pillars utilized.
What is most valuable?
The prioritization mechanism is the most valuable aspect of the solution.
The initial setup is straightforward.
Technical support is great.
The stability and reliability are good.
What needs improvement?
The user experience, the UI, needs to be improved. The technology is there and it is obvious it is able to do many things, however, from a user experience perspective, the UI design is a bit complicated. If the platform could have a bit more of a user-friendly environment, it could be easier for the admins and analysts to use it.
The solution is a bit expensive if you do not have access to discounts.
From a general perspective, SLA tracking capabilities could be improved with a building method. There was a tracking method to be able to see if this vulnerability for a while or maybe it was patched. However, an internal SLA mechanism could help with batch prioritization and issue detection.
I'd rate the solution at a nine out of ten.
For how long have I used the solution?
I've been using the solution for six months. I've used it for less than a year now.
What do I think about the stability of the solution?
The solution is stable. The passive scanning capabilities are advanced. I'm able to see all the missing paths and many vulnerabilities or many configuration mistakes at the same time. Due to its passive scanning, we don't see any stress or research consumption from agents.
Network scans are a bit more intense and they of course require research and can create some noise, however, for the most part, it is okay. There is no reliability issue from our perspective.
What do I think about the scalability of the solution?
I haven't really tried to scale the solution and therefore cannot really speak to it. We do have some activities happening on there, however, I'm not ready to provide feedback for the results. It's my understanding, however, that the API extensibility is great. I've just not seen anything yet that I can really comment on.
How are customer service and technical support?
Technical support is pretty good. It is very easy to get support from the global team, at least for us. We don't depend on local partners, which is great due to the fact that, whenever you are acting in 10 or 11 countries, local partners can be an issue. The language barriers, et cetera, can be an issue. That's why it is great to have responsible global support.
How was the initial setup?
The initial setup was very straightforward. We just deployed the agents and everything went very smoothly. There were no big issues.
What's my experience with pricing, setup cost, and licensing?
We pay a yearly fee for a license.
They have very good discounts. That's why the price is okay for us. Generally, if we talk about the price without discounts, I do see a big peak in vulnerability management solutions licenses. It is not only Qualys. All the vendors peaked at some point.
We do see over $100,000 in terms of price, for mid-size programs. You likely will pay more than $100,000 without any discount. It is a bit pricey. There's room to improve, however, I believe they're managing things with discount offerings. I'm saying this not only for Qualys. All the vulnerability management solutions do the same thing price-wise.
Which other solutions did I evaluate?
We did evaluate other solutions. We looked at most other vulnerability management solutions.
What other advice do I have?
We are just a customer and end-user.
We are using the latest version of the solution. I cannot speak to the exact version we are using, however.
We are using both the on-premises and cloud deployment models. We have on-premise sensors and we have a scan-over cloud service from Qualys. Qualys cloud has a scanning capability for pairing sensors, for scanning an external perimeter. Therefore, we are utilizing that and agents as well.
I'd recommend the solution.
If anybody looks forward to first perimeter security, if any conceptual work is done around perimeter security, they have to solve that agent issue first for their program. Companies need to select a solution that can work wherever the PC is.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Lead Cyber Security engineer at a manufacturing company with 10,001+ employees
Provides an overview of the inventory assessment process and can be accessed across the company
Pros and Cons
- "It gives a very good overview of the inventory assessment process, and it can be accessed across our company because it's a global tool."
- "If you are familiar with or have hands on experience with Qualys Asset Inventory, this is a better tool, as it will give you in-depth details of all the assets and the managing inventory will be better, and it will also give you advanced features compared to those of other inventory tools."
- "It's not very user-friendly at times and requires in-depth understanding. So, a layman or someone new to Qualys won't be able to easily understand it. You need education to use the solution."
What is our primary use case?
We use Qualys Asset Inventory for doing infrastructure level scans or server inventory, or saving the server database or asset database.
How has it helped my organization?
Good Posture of Servers database. Gives easy access of all hardware details.
What is most valuable?
I think it's a good tracking mechanism, and it gives a good infrastructure level scan, which helps us to maintain the assets and the asset inventory or gives us a good understanding of both.
It gives a very good overview of the inventory assessment process.
IT Manages assets in your account that you want to scan for security and
compliance, define asset tags and AWS connectors.
Modules supported
VM, PC, SCA, CERTVIEW, CLOUDVIEW
It can be accessed across our company because it's a global tool.
What needs improvement?
One thing that can be improved is the flexibility and the fact that Qualys Asset Inventory provides too much detail, which makes it not very easy to understand. It's not very user-friendly at times and requires in-depth understanding. So, a layman or someone new to Qualys won't be able to easily understand it. You need education to use the solution.
As for additional features, the first thing would be providing call support whenever we require any kind of help with issues that have been identified. The second would be a simple reporting structure.
For how long have I used the solution?
I've been using Qualys Asset Inventory within the last 12 months.
What do I think about the stability of the solution?
Stability-wise, Qualys Asset Inventory is always stable, and for this particular asset inventory, it is a good tool. We have not had any kind of issues, and as of now, it's a stable environment.
What do I think about the scalability of the solution?
We currently have 50 plus users and have no plans to increase usage at present.
How are customer service and technical support?
Most of the time technical support has been through emails; calling is a back feature. It's not as easy compared to that of Veracode.
How was the initial setup?
The initial setup was quite complex and took two to three months, including customization and testing.
What's my experience with pricing, setup cost, and licensing?
The license is on a yearly basis.
What other advice do I have?
If you are familiar with or have hands on experience with Qualys Asset Inventory, this is a better tool. It will give you in-depth details of all the assets, and the managing inventory will be better. It will also give you advanced features compared to those of other inventory tools.
I would rate Qualys Asset Inventory at eight on a scale from one to ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. Manager, Vulnerability Management at a transportation company with 10,001+ employees
User-friendly, supports multiple platforms, and the VM DR capabilities are helpful
Pros and Cons
- "The features that are most valuable are the identification, scan features, and the identification of vulnerabilities."
- "I would like to see more accuracy in detections, better reporting capabilities, and better dashboard download capabilities."
What is our primary use case?
We are using Qualys VM, as our scanner tool. We also use it for Application Security and Policy Compliance.
We use it for the identification of vulnerabilities for all of our devices on the network. This includes Windows workstations, servers, and Linux machines. We also use it for cloud, and external use as well.
What is most valuable?
The features that are most valuable are the identification, scan features, and the identification of vulnerabilities. Recently, the VMDR additions and the threat protection has been useful.
It's pretty user-friendly.
What needs improvement?
The Patch Identifications, which are supersedence identifications, need improvement.
I would like to see more accuracy in detections, better reporting capabilities, and better dashboard download capabilities. These are things that are definitely needed.
For how long have I used the solution?
I have been using Qualys VM for more than 15 years.
We are using the latest version.
VMDR was added in July with newer enhancements.
What do I think about the stability of the solution?
It's a stable solution.
What do I think about the scalability of the solution?
It's very scalable for large networks. We have also used the agents and they work very well.
I have a team of five in our organization and external to it, there are approximately twenty-five.
How are customer service and technical support?
We engage with technical support often. There could be some improvements made.
How was the initial setup?
The initial setup is straightforward.
What's my experience with pricing, setup cost, and licensing?
It is different for every company, but for us, it's every three years. I will know more about the pricing in September because we are going to be looking at our pricing again.
We get a large volume discount, which is good.
What other advice do I have?
I would recommend this product to others who are interested in using it.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Global Infrastructure Architect at a energy/utilities company with 5,001-10,000 employees
Good technical support that is always there when you need them, but the prioritization of vulnerabilities needs to be improved
Pros and Cons
- "Technical support is great and we've never really had a problem."
- "What I like best about this product is that it does what it is supposed to do, which is vulnerability scanning."
- "We are moving away from Qualys to Defender ATP because I find that Defender ATP is much better at prioritizing the vulnerabilities that I should be looking at."
What is our primary use case?
We are currently using Qualys for vulnerability detection, as part of our security solution. We're moving towards Defender ATP because I am looking more at the Operational Technology (OT) side of things than I am at the Information Technology (IT) side.
What is most valuable?
What I like best about this product is that it does what it is supposed to do, which is vulnerability scanning.
What needs improvement?
We are moving away from Qualys to Defender ATP because I find that Defender ATP is much better at prioritizing the vulnerabilities that I should be looking at.
In general, I would like to see some better analytics and prioritization of vulnerabilities.
For how long have I used the solution?
We have been working with Qualys VM for three years.
What do I think about the stability of the solution?
Qualys VM is a stable solution.
What do I think about the scalability of the solution?
This is a stable product.
How are customer service and technical support?
Technical support is great and we've never really had a problem. They're always there if we need them.
Which solution did I use previously and why did I switch?
We did not work with another similar solution prior to Qualys.
How was the initial setup?
The initial setup is straightforward.
Our setup involved some on-premises deployments but ultimately, it uses the cloud.
What's my experience with pricing, setup cost, and licensing?
They have recently changed the pricing model, which is now better than it was before.
Which other solutions did I evaluate?
Right now, we don't have anything in our OT environment, and this is what I am particularly interested in. I am currently having discussions about new solutions with Qualys, Tenable, and Forescout.
What other advice do I have?
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Vulnerability Management IT Asset Management Configuration Management Databases Container Security Risk-Based Vulnerability ManagementPopular Comparisons
SentinelOne Singularity Cloud Security
ServiceNow
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
Checkmarx One
Tanium
NinjaOne
Orca Security
CrowdStrike Falcon Cloud Security
Tenable Nessus
TrendAI Vision One – Cloud Security
Zafran Security
JFrog Xray
Buyer's Guide
Download our free Qualys VMDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Qualys VM vs Tenable Nessus: Comparison
- How does Tenable Nessus compare with Qualys VM?
- How does Pentera compare with Qualys VMDR?
- What are the main differences between Qualys VMDR and Tenable Nessus?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?


















