Listing Thumbnail

    Qualys TotalCloud

     Info
    Sold by: Qualys 
    Deployed on AWS
    Free Trial
    AWS Free Tier
    Qualys TotalCloud: Making your cloud secure by providing the only solution that assesses, communicates and eliminates an organization's security risk.
    4.3

    Overview

    TotalCloud is a Cloud Native Application Protection Platform (CNAPP) built to detect, prioritize, and mitigate risks within multi-cloud and hybrid-cloud environments. As the most thorough cloud security solution, TotalCloud identifies, ranks, and facilitates the remediation of risks from key vulnerabilities, misconfigurations, and threats that other tools might miss, including potential attack paths and lateral movements targeting critical cloud resources. By integrating a wide range of solutions, including CSPM, KSPM, CWPP, CIEM, CDR, Workflow Automation and Remediation, TotalCloud provides a seamless cloud security management experience, without the complexity of managing multiple tools. For more details: https://www.qualys.com/apps/totalcloud/ 

    *Qualys provides custom pricing for customers via Private Offer. Please contact https://www.qualys.com/forms/request-a-call/  for a better understanding of our pricing model and products.

    Highlights

    • 6 Sigma Accurate Vulnerability Prioritization:Combines threat feeds from over 25 sources to create a unified vulnerability score. This score dynamically adjusts risk priorities based on patch availability, vulnerability criticality, and organizational context.
    • Integrated no-code/low-code remediation: Enable custom remediation workflows out of the box with Qualys QFlow Cloud Workflow Automation, allowing drag and drop of no-code/low-code workflows.
    • FlexScan : Allows security teams to combine agent and agentless scanning for workload protection across ephemeral and long-lived environments, including hosts, VMs, Containers, Kubernetes, and Serverless setups.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    Qualys TotalCloud

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    Total Cloud package 16
    Package of 16 Hosts for Total Cloud
    $5,400.00

    Vendor refund policy

    Licensed Qualys customers should refer to their Service User Agreement (SUA) or contact their Qualys Technical Account Manager if they have questions about refund or cancellation policies which would apply to them

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Qualys' policy is to respond to all Qualys customer cases promptly as per SLA. An incident ticket is assigned a priority number based on the nature of the issue. || Service Level Agreement (SLA): https://www.qualys.com/support/sla/  https://www.qualys.com/support/  || support@qualys.com  || US/Canada: +1 (866) 801-6161 (toll free) or +1 (650) 801-6161 || UK/Europe/International: +44 (0)1753 872102 || France: +33 1 41 97 35 81

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.3
    36 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    53%
    44%
    3%
    0%
    0%
    12 AWS reviews
    |
    24 external reviews
    External reviews are from PeerSpot .
    Timothy K

    Contextual risk insights have reduced my workload and provided clearer remediation paths

    Reviewed on Feb 03, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Qualys TotalCloud  provides container security, vulnerability management, posture management, and more.

    What is most valuable?

    Qualys TotalCloud  saves about a third of resources. Qualys TotalCloud provides written explanations to guide remediation paths and eliminate cyber risk, and I appreciate the written explanation and the visualization of attack paths.

    Qualys TotalCloud provides unified vulnerability and threat assessment for IaaS  and SaaS. Qualys TotalCloud provides a single prioritized view of risk, which helps reduce my workload by not having to combine multiple sources.

    What needs improvement?

    In my opinion, what can be improved in Qualys TotalCloud includes pricing and container scanning.

    For how long have I used the solution?

    I started working with Qualys TotalCloud approximately one year ago.

    What do I think about the stability of the solution?

    I assess Qualys TotalCloud as stable, and I would rate it an 8, with 10 being the best.

    What do I think about the scalability of the solution?

    I would rate Qualys TotalCloud a 7 for scalability on a scale from 1 to 10.

    How are customer service and support?

    I would rate the technical support for Qualys TotalCloud about a 7 on a scale from 1 to 10.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    It is easy to deploy Qualys TotalCloud.

    What's my experience with pricing, setup cost, and licensing?

    Qualys TotalCloud is on the pricier side, and I would rate the pricing around an 8 on a scale from 1 to 10.

    Which other solutions did I evaluate?

    I compare Qualys TotalCloud with other solutions and other vendors as a good contender, though I acknowledge there are differences. In comparison with other vendors, including Microsoft, Qualys TotalCloud holds its own but presents distinct features.

    What other advice do I have?

    I do use the TruRisk Insight feature with Qualys TotalCloud. I assess the comprehensiveness and the range of risks found with TruRisk Insights as adequate.

    The TruRisk Insights feature has found a small number of assets with high vulnerability scores. The effect of TruRisk Insights on security posture is significant, as it provides better awareness and focus on critical risks.

    I would recommend this product to other users, and my advice would include doing a proof of concept to see if it fits their needs. I would rate this product an 8 overall.

    reviewer2584311

    Cloud security posture has improved and compliance decisions are now driven by risk insights

    Reviewed on Jan 14, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I use Qualys TotalCloud  for cloud security posture management across AWS  and Google Cloud . I use this tool for compliance and other purposes. I scan AWS  and Azure  for S3  buckets, security groups, unencrypted databases, and generally for IAM  roles. It helps in terms of securing the data. I also use CIS benchmarks as a standard for hardening cloud posture management. Qualys TotalCloud  helps to ensure I am enforcing the CIS benchmarks automatically.

    For the TrueRisk insights, it provides context-aware prioritization of findings, asset criticality, risk trends, and real-time exposures of risk parameters. It ensures I can make informed decisions with higher management.

    FlexScan helps me run targeted, on-demand cloud security checks instead of waiting for full scheduled scans. It allows for immediate results on risky configurations or vulnerabilities after major configuration changes. I use it to validate checks post-scan.

    TrueRisk Eliminates helps in lowering risks from the organization's context by comparing with global standards. Though not used extensively, it aids in reducing exposure ratings or ensuring compliance.

    What is most valuable?

    One of the valuable features of Qualys TotalCloud is its recurring scanning patterns, which detect misconfigurations, risky configurations, and weak IAM  policies. The tool automates the maintenance of CIS benchmarks at scale, which is very useful. Qualys TotalCloud serves as a single-point tool integrating various modules such as VM and policy compliance and security, providing a holistic view of my security posture.

    Qualys TotalCloud provides threat intelligence feeds or threat integration, enabling me to mix data with other modules to identify recurring vulnerabilities or threats I face in my organization.

    What needs improvement?

    From a downside perspective, the UI is not user-friendly and feels dated compared to other tools like Prisma Cloud. The navigation is difficult in terms of understanding risk relationships. Attack path analysis is another area needing improvement. It struggles to predict how attackers may move through phases. Automating remediation could also be improved, as many tasks remain manual. The lack of data load speed sometimes leads to system lags. Customizing reports based on business standards is cumbersome. Pricing is high compared to competitors.

    Installation could be simplified with fewer integration issues. Documentation focused on detailed user cases with if and else scenarios would be beneficial.

    For how long have I used the solution?

    I have been using Qualys TotalCloud for the past four years with different organizations. I have been with two organizations in the past four years and have been using it at both.

    What do I think about the stability of the solution?

    It happens not very often, but sometimes it does occur. In terms of stability, I could say Qualys TotalCloud operates at 95% of the time, and the rest 5% depends on how I manage it.

    What do I think about the scalability of the solution?

    From a scalability standpoint, I could say it is 90% scalable. The remaining 10% presents a challenge that Qualys could address.

    How are customer service and support?

    From a technical support perspective, those individuals are competent enough to provide information regarding the product. They offer level one support initially, escalating as needed. I rate them four out of five because they respond quickly if issues are marked as high priority. I would give them 8.5.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I used Prisma Cloud previously. Prisma Cloud has better navigation and UI compared to Qualys TotalCloud. However, I have taken a whole package of Qualys and tend to use it.

    How was the initial setup?

    In terms of installation, it could be simplified compared to other tools due to its packaging and tooling. A lack of specific help articles and integration issues are present. From a security standpoint, it is good but requires time.

    What about the implementation team?

    For one of the organizations, I partnered with Qualys as a team since I have large projects. They assisted with a global rollout.

    What's my experience with pricing, setup cost, and licensing?

    Pricing compared to competitor tools is high. My costs depend on asset subscriptions. Pricing remains constant regardless of asset utilization, whereas other tools employ a credit system.

    Which other solutions did I evaluate?

    Prisma Cloud and similar tools have slight variations in flow but follow the same frameworks. Prisma Cloud offers user-friendly navigation that is better than Qualys TotalCloud.

    What other advice do I have?

    From a technical support perspective, those individuals are competent enough to provide information regarding the product feel. They provide level one support first to understand better. If they cannot resolve the issue, they can escalate it to the next level and come on a call. However, it does not make sense for them to escalate if it is a medium or low priority issue; they address those according to their SLAs. From another perspective, there could be some downsides. In my opinion, this is the best tool. My overall review rating for Qualys TotalCloud is 8.

    Nadeem-Inamdar

    Cloud security posture has improved and CI/CD pipeline now prevents misconfigurations early

    Reviewed on Jan 07, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My use case is for cloud security posture management and for getting alerts as we have onboarded most of our accounts in Qualys. Qualys provides the cloud and identifies misconfigurations in our cloud security module, providing us alerts, and we have integrated many tools into that solution. This helps us maintain our cloud security.

    Qualys TotalCloud  helps with my cloud security posture management by identifying vulnerabilities at a better early stage because we have deployed it into a CI/CD pipeline. This helps us detect vulnerabilities at the development level only. Before moving into production, it helps us detect the vulnerabilities, close them, remediate them, and then move the code into production. We have integrated that into our CI/CD pipeline.

    What is most valuable?

    The best features of Qualys TotalCloud  include good threat intelligence and segregation of cloud accounts. Since we have multiple cloud accounts, it provides a segregation overview of all of our cloud accounts. It also has workload protection which identifies vulnerabilities in the Kubernetes  environment and in our Docker  images.

    Qualys TotalCloud provides written explanations to help guide remediation paths and eliminate cyber risks with recommendations. Whenever any alerts or vulnerabilities have been detected by the solution, it provides the resource name, the asset name, and the solution on how to remediate that with all the steps included.

    Qualys TotalCloud provides unified vulnerability and threat assessment for both IaaS  and SaaS software.

    Qualys TotalCloud provides a single prioritized view of risk through the dashboard, which displays all the risks that are identified in our images, Docker  images, Kubernetes  environment, and cloud security.

    I use the TruRisk Insights feature, which is built into that solution. I assess the comprehensiveness of the risks found by the insights to be good due to its threat intelligence, as it identifies most risks whenever they are detected in the wild. It almost detects all the risks that are well-known in the industry. It has also some capabilities of artificial intelligence but not enough to detect any zero-day vulnerabilities.

    What needs improvement?

    The areas in the solution that have room for improvement include the UI/UX design, which should be improved, and they should integrate more artificial intelligence into the product.

    For how long have I used the solution?

    I have been using Qualys TotalCloud for around three years.

    What do I think about the stability of the solution?

    I would rate stability around eight out of ten.

    What do I think about the scalability of the solution?

    For scalability, I would rate it nine out of ten.

    How are customer service and support?

    Qualys TotalCloud requires maintenance, but it is managed by the Qualys team.

    I would rate the technical support around eight out of ten.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The deployment was not easy, but with the help of the support team, we completed it.

    It took about a week because we had many accounts we needed to migrate, and we needed to check the policies and define our policies. It took time because everything cannot go in one go, so we did it in a phase-wise manner.

    What was our ROI?

    It helps us because we have monthly meetings with our leadership team. These graphs help us give the return on investment of the product to the leadership team and also give us an overview of how this product is working, what the thresholds are, and how the configurations are working or not. This helps us determine that.

    What other advice do I have?

    I would recommend Qualys TotalCloud to other users because it is cost-efficient and has a good return on investment. We can recommend it over other tools available in the market that are more costly.

    I find the pricing of Qualys TotalCloud to be cost-efficient as of now. We evaluated three other tools that were more costly than this.

    My comparison of Qualys with other vendors is based on the different features we tested. Based on the reports, we implemented the tools into our environment. We conducted proof of concept testing and checked that every tool provides the CSPM feature, the CWP feature, and the IaC  feature. Qualys also provides those features. We tested those features with the default policies by running scans. We created some misconfigurations and checked whether they were detected by the tool. We conducted thorough POCs for each solution.

    Qualys TotalCloud can be mentioned as a total cloud platform because it has the CWP model and CSPM model.

    It has affected my security posture by integrating tools like Jira  into that solution, which helps to generate tickets on the development team dashboard and the DevOps team's dashboard. This helps them remediate the findings. We also create weekly reports from the tool, and with the help of the DevOps team, we try to mitigate the risks which helps us manage our security posture.

    Currently, there are around fifteen users who are using the solution. I would rate this solution an overall eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Sourav Dadhwal

    Unified cloud security has delivered strong compliance reporting and streamlined audit workflows

    Reviewed on Dec 16, 2025
    Review from a verified AWS customer

    What is our primary use case?

    I have approximately three to four years of experience working with Qualys TotalCloud .

    I have been using Qualys TotalCloud  while working with EY, Ernst & Young, where I utilize cloud tools for Qualys, employing two types of tools: one for policy and compliance, for security and compliance audits, and another for security audits such as vulnerability assessments and risk assessments. Based on that tool, it is very easy to go through the inventory and easily deploy the compliance policies as needed while also receiving comprehensive assessment scores.

    I use Qualys TotalCloud primarily for compliance and cloud security, and I am also getting certified from Qualys in both compliance auditing and vulnerability management, making me a certified specialist for Qualys.

    In Qualys TotalCloud, everything is in a single platform and as a unified CNAP application, it combines CSPM, CWPM, CIEMs, and workload securities with a lightweight agent that covers everything, including cloud resources, configuration, misconfigurations, and shadow assets, allowing us to work around AWS , Azure , and GCP platforms while generating compliance reports and providing end-users with easy access to dashboard audit reports and executive views.

    What is most valuable?

    To eliminate cyber risk, I think the best method in Qualys TotalCloud is correlating vulnerability exposure and configuration with identity instead of just CVs, making it the perfect option for use within Qualys TotalCloud. If someone were to ask me to review Qualys TotalCloud, I would summarize it as an end-to-end solution for cloud security with visibility and governance-grade controls without needing to manage multiple disconnected tools. In comparison to other tools such as Prisma, Wiz , and Defender, Qualys TotalCloud helps unify vulnerability and threat assessment in IaaS  and SaaS environments because it has an intuitive web interface that is simple enough for anyone to learn with just a few hours of preliminary training, allowing users to easily deploy initial assets and policy configurations as needed while generating customized reports.

    I have compared Qualys TotalCloud with other vendors such as Prisma, Wiz , and Defender, noting that despite some limitations in those other tools, Qualys TotalCloud performs exceptionally well across various compliance requirements, offering a simple interface for customizing reports while meeting auditors' needs with regulatory benchmarks, including CIS, NIST, ISO, and PCI.

    Qualys TotalCloud provides a single unified dashboard for all types of reports, executive views, and dashboards, allowing you to easily access key summaries and recommendations.

    What needs improvement?

    I think Qualys TotalCloud needs to improve its handling of zero-day vulnerabilities and supply chain management because modern ransomware attacks not only target prime critical infrastructures but also the supply chain system. If Qualys TotalCloud can solely assess risks based on initially added assets, there may be vulnerabilities within supporting firms that go undetected.

    What do I think about the stability of the solution?

    For stability, I would rate Qualys TotalCloud a nine out of ten. While there may be occasional disruptions due to internet connectivity issues, the application supports both offline and online functionality, maintaining operability even under hybrid working conditions.

    What do I think about the scalability of the solution?

    Qualys TotalCloud is highly scalable, rated at ten out of ten, facilitating easy scale-up or scale-down based on audit and compliance needs.

    How are customer service and support?

    I rate the technical support from Qualys TotalCloud a perfect ten out of ten because whenever we log incidents, all service level agreements are met within half an hour, with prompt provision of root cause analyses by the support teams.

    How would you rate customer service and support?

    Positive

    What other advice do I have?

    I have limited feedback on how Qualys TotalCloud helps my cloud security posture management, but it works well with misconfiguration detections and provides deep mapping with CIS, NIST, ISO frameworks, PCI compliance, and regulatory benchmarks.

    In terms of pricing, compared with the top market leaders in Gartner's reports, I find Qualys TotalCloud to have a reasonable standard rate, which is not too hard to access. They have also introduced use case basis rates that allow auditors to purchase specific instances of the cloud service, leading to a flexible pay-per-usage model.

    Overall, deploying Qualys TotalCloud across all cloud platforms is very easy.

    We handle clients of all sizes, including direct work with government entities, and are currently deployed in various states within government and public sectors.

    Vendor maintenance, such as patches for Qualys TotalCloud, is conducted promptly. I observe that if a zero-day vulnerability emerges, the vendor deploys patches as per market recommendations without significant delays.

    While we do not work directly with Qualys in our organization, I utilize it during audit activities at client premises alongside various other tools such as Metasploit , Rapid7, and others that I prefer not to disclose. We can deploy Qualys TotalCloud where needed, particularly for presentation layers, while other tools handle deeper network layer security requirements.

    I recommend Qualys TotalCloud, having written various articles on it. I suggest potential users align their use cases with its capabilities before deciding, as a proof of concept could be beneficial.

    I have given this review an overall rating of eight out of ten.

    reviewer2788209

    Automated vulnerability detection has improved risk visibility but container security still needs work

    Reviewed on Dec 15, 2025
    Review from a verified AWS customer

    What is our primary use case?

    We have experience with Veracode  and other SCA  solutions, but I'm not interested in participating in any campaign. Other than Snyk , we use Qualys for Vulnerability Management , specifically the VMDR solution. TrueRisk Management is not what we use; it's an extension to VMDR, but what we actually use is the main module of Qualys, which is Vulnerability Management , Detection, and Response.

    We are not using TrueRisk at all because we have our own framework and we use Qualys Detection Score for everything. We do use Qualys TotalCloud  for continuous monitoring. The main use case with Qualys TotalCloud  is that VMDR provides a direct solution for on-prem systems and it offers a similar solution for cloud infrastructure including AWS , Azure , and GCP, along with an option to scan containers and other related resources.

    The features I value about using Qualys include container scanning; they did give us some requested features, but maturity-wise, they are not there yet with respect to container scanning. The solution is maybe slightly expensive, but it's not as expensive as other tools such as Wiz . Generally, Qualys is very good at detections, whether on cloud or on-prem. The agent allows deployment on both infrastructures, providing continuous monitoring of your assets, which is a key selling point for us.

    What is most valuable?

    The features I value about using Qualys include container scanning; they provided us with some requested features, but maturity-wise, they are not there yet with respect to container scanning.

    The solution is slightly expensive, but it's not as expensive as other tools such as Wiz . Generally, Qualys is very good at detections, whether on cloud or on-prem. The agent allows deployment on both infrastructures, providing continuous monitoring of your assets, which is a key selling point for us.

    Detections get updated in Qualys with a unique identifier called QID. Whenever there's new information, such as a new CVE, Qualys processes that and generates a QID. Since our agents are installed across our infrastructure, they identify vulnerabilities based on the agent information, and any new detections also get updated to a manifest that runs every four hours, checking for new vulnerabilities.

    The single prioritized view of risk helps reduce the work significantly; Qualys Detection Score not only considers the basic CVSS score but also factors in threat information and the exploitability factor, which helps us prioritize effectively. We also have another separate framework we developed that we use on top of this.

    What needs improvement?

    The downside is only in container security, but it has not been a long time since they introduced these models. Our use cases were edge use cases, so they had to develop some features for us, but they are indeed doing a good job.

    How are customer service and support?

    I would rate their support a seven on a scale of one to ten. For working with the people from Qualys, I would say seven is an accurate rating.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Before switching to Qualys, we were doing everything completely manual, and we wanted a more automated solution, which prompted us to switch.

    How was the initial setup?

    Our experience with the setup and deployment was quite good; Qualys was supportive, and we met with them twice a week while setting up the scanners and operations.

    What about the implementation team?

    The setup was done by us while Qualys guided us, as they do not have access to our infrastructure for deployments.

    What's my experience with pricing, setup cost, and licensing?

    Regarding pricing and setup cost, it was not the most expensive. While checking tools for container scanning, we considered Wiz and a startup, but we believe having one tool for as much as possible makes tracking and monitoring easier. We had Qualys agents installed everywhere, which facilitated the shift to container scanning.

    What other advice do I have?

    Qualys TotalCloud does help guide remediation paths and eliminate cyber risks. I would rate this solution a seven overall.

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    View all reviews