Overview
TotalCloud is a Cloud Native Application Protection Platform (CNAPP) built to detect, prioritize, and mitigate risks within multi-cloud and hybrid-cloud environments. As the most thorough cloud security solution, TotalCloud identifies, ranks, and facilitates the remediation of risks from key vulnerabilities, misconfigurations, and threats that other tools might miss, including potential attack paths and lateral movements targeting critical cloud resources. By integrating a wide range of solutions, including CSPM, KSPM, CWPP, CIEM, CDR, Workflow Automation and Remediation, TotalCloud provides a seamless cloud security management experience, without the complexity of managing multiple tools. For more details: https://www.qualys.com/apps/totalcloud/
*Qualys provides custom pricing for customers via Private Offer. Please contact https://www.qualys.com/forms/request-a-call/ for a better understanding of our pricing model and products.
Highlights
- 6 Sigma Accurate Vulnerability Prioritization:Combines threat feeds from over 25 sources to create a unified vulnerability score. This score dynamically adjusts risk priorities based on patch availability, vulnerability criticality, and organizational context.
- Integrated no-code/low-code remediation: Enable custom remediation workflows out of the box with Qualys QFlow Cloud Workflow Automation, allowing drag and drop of no-code/low-code workflows.
- FlexScan : Allows security teams to combine agent and agentless scanning for workload protection across ephemeral and long-lived environments, including hosts, VMs, Containers, Kubernetes, and Serverless setups.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
|---|---|---|
Total Cloud package 16 | Package of 16 Hosts for Total Cloud | $5,400.00 |
Vendor refund policy
Licensed Qualys customers should refer to their Service User Agreement (SUA) or contact their Qualys Technical Account Manager if they have questions about refund or cancellation policies which would apply to them
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Qualys' policy is to respond to all Qualys customer cases promptly as per SLA. An incident ticket is assigned a priority number based on the nature of the issue. || Service Level Agreement (SLA): https://www.qualys.com/support/sla/ https://www.qualys.com/support/ || support@qualys.com || US/Canada: +1 (866) 801-6161 (toll free) or +1 (650) 801-6161 || UK/Europe/International: +44 (0)1753 872102 || France: +33 1 41 97 35 81
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products


Customer reviews
Unified cloud security has delivered strong compliance reporting and streamlined audit workflows
What is our primary use case?
I have approximately three to four years of experience working with Qualys TotalCloud .
I have been using Qualys TotalCloud while working with EY, Ernst & Young, where I utilize cloud tools for Qualys, employing two types of tools: one for policy and compliance, for security and compliance audits, and another for security audits such as vulnerability assessments and risk assessments. Based on that tool, it is very easy to go through the inventory and easily deploy the compliance policies as needed while also receiving comprehensive assessment scores.
I use Qualys TotalCloud primarily for compliance and cloud security, and I am also getting certified from Qualys in both compliance auditing and vulnerability management, making me a certified specialist for Qualys.
In Qualys TotalCloud, everything is in a single platform and as a unified CNAP application, it combines CSPM, CWPM, CIEMs, and workload securities with a lightweight agent that covers everything, including cloud resources, configuration, misconfigurations, and shadow assets, allowing us to work around AWS , Azure , and GCP platforms while generating compliance reports and providing end-users with easy access to dashboard audit reports and executive views.
What is most valuable?
To eliminate cyber risk, I think the best method in Qualys TotalCloud is correlating vulnerability exposure and configuration with identity instead of just CVs, making it the perfect option for use within Qualys TotalCloud. If someone were to ask me to review Qualys TotalCloud, I would summarize it as an end-to-end solution for cloud security with visibility and governance-grade controls without needing to manage multiple disconnected tools. In comparison to other tools such as Prisma, Wiz , and Defender, Qualys TotalCloud helps unify vulnerability and threat assessment in IaaS and SaaS environments because it has an intuitive web interface that is simple enough for anyone to learn with just a few hours of preliminary training, allowing users to easily deploy initial assets and policy configurations as needed while generating customized reports.
I have compared Qualys TotalCloud with other vendors such as Prisma, Wiz , and Defender, noting that despite some limitations in those other tools, Qualys TotalCloud performs exceptionally well across various compliance requirements, offering a simple interface for customizing reports while meeting auditors' needs with regulatory benchmarks, including CIS, NIST, ISO, and PCI.
Qualys TotalCloud provides a single unified dashboard for all types of reports, executive views, and dashboards, allowing you to easily access key summaries and recommendations.
What needs improvement?
I think Qualys TotalCloud needs to improve its handling of zero-day vulnerabilities and supply chain management because modern ransomware attacks not only target prime critical infrastructures but also the supply chain system. If Qualys TotalCloud can solely assess risks based on initially added assets, there may be vulnerabilities within supporting firms that go undetected.
What do I think about the stability of the solution?
For stability, I would rate Qualys TotalCloud a nine out of ten. While there may be occasional disruptions due to internet connectivity issues, the application supports both offline and online functionality, maintaining operability even under hybrid working conditions.
What do I think about the scalability of the solution?
Qualys TotalCloud is highly scalable, rated at ten out of ten, facilitating easy scale-up or scale-down based on audit and compliance needs.
How are customer service and support?
I rate the technical support from Qualys TotalCloud a perfect ten out of ten because whenever we log incidents, all service level agreements are met within half an hour, with prompt provision of root cause analyses by the support teams.
How would you rate customer service and support?
Positive
What other advice do I have?
I have limited feedback on how Qualys TotalCloud helps my cloud security posture management, but it works well with misconfiguration detections and provides deep mapping with CIS, NIST, ISO frameworks, PCI compliance, and regulatory benchmarks.
In terms of pricing, compared with the top market leaders in Gartner's reports, I find Qualys TotalCloud to have a reasonable standard rate, which is not too hard to access. They have also introduced use case basis rates that allow auditors to purchase specific instances of the cloud service, leading to a flexible pay-per-usage model.
Overall, deploying Qualys TotalCloud across all cloud platforms is very easy.
We handle clients of all sizes, including direct work with government entities, and are currently deployed in various states within government and public sectors.
Vendor maintenance, such as patches for Qualys TotalCloud, is conducted promptly. I observe that if a zero-day vulnerability emerges, the vendor deploys patches as per market recommendations without significant delays.
While we do not work directly with Qualys in our organization, I utilize it during audit activities at client premises alongside various other tools such as Metasploit , Rapid7, and others that I prefer not to disclose. We can deploy Qualys TotalCloud where needed, particularly for presentation layers, while other tools handle deeper network layer security requirements.
I recommend Qualys TotalCloud, having written various articles on it. I suggest potential users align their use cases with its capabilities before deciding, as a proof of concept could be beneficial.
I have given this review an overall rating of eight out of ten.
Automated vulnerability detection has improved risk visibility but container security still needs work
What is our primary use case?
We have experience with Veracode and other SCA solutions, but I'm not interested in participating in any campaign. Other than Snyk , we use Qualys for Vulnerability Management , specifically the VMDR solution. TrueRisk Management is not what we use; it's an extension to VMDR, but what we actually use is the main module of Qualys, which is Vulnerability Management , Detection, and Response.
We are not using TrueRisk at all because we have our own framework and we use Qualys Detection Score for everything. We do use Qualys TotalCloud for continuous monitoring. The main use case with Qualys TotalCloud is that VMDR provides a direct solution for on-prem systems and it offers a similar solution for cloud infrastructure including AWS , Azure , and GCP, along with an option to scan containers and other related resources.
The features I value about using Qualys include container scanning; they did give us some requested features, but maturity-wise, they are not there yet with respect to container scanning. The solution is maybe slightly expensive, but it's not as expensive as other tools such as Wiz . Generally, Qualys is very good at detections, whether on cloud or on-prem. The agent allows deployment on both infrastructures, providing continuous monitoring of your assets, which is a key selling point for us.
What is most valuable?
The features I value about using Qualys include container scanning; they provided us with some requested features, but maturity-wise, they are not there yet with respect to container scanning.
The solution is slightly expensive, but it's not as expensive as other tools such as Wiz . Generally, Qualys is very good at detections, whether on cloud or on-prem. The agent allows deployment on both infrastructures, providing continuous monitoring of your assets, which is a key selling point for us.
Detections get updated in Qualys with a unique identifier called QID. Whenever there's new information, such as a new CVE, Qualys processes that and generates a QID. Since our agents are installed across our infrastructure, they identify vulnerabilities based on the agent information, and any new detections also get updated to a manifest that runs every four hours, checking for new vulnerabilities.
The single prioritized view of risk helps reduce the work significantly; Qualys Detection Score not only considers the basic CVSS score but also factors in threat information and the exploitability factor, which helps us prioritize effectively. We also have another separate framework we developed that we use on top of this.
What needs improvement?
The downside is only in container security, but it has not been a long time since they introduced these models. Our use cases were edge use cases, so they had to develop some features for us, but they are indeed doing a good job.
How are customer service and support?
I would rate their support a seven on a scale of one to ten. For working with the people from Qualys, I would say seven is an accurate rating.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before switching to Qualys, we were doing everything completely manual, and we wanted a more automated solution, which prompted us to switch.
How was the initial setup?
Our experience with the setup and deployment was quite good; Qualys was supportive, and we met with them twice a week while setting up the scanners and operations.
What about the implementation team?
The setup was done by us while Qualys guided us, as they do not have access to our infrastructure for deployments.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing and setup cost, it was not the most expensive. While checking tools for container scanning, we considered Wiz and a startup, but we believe having one tool for as much as possible makes tracking and monitoring easier. We had Qualys agents installed everywhere, which facilitated the shift to container scanning.
What other advice do I have?
Qualys TotalCloud does help guide remediation paths and eliminate cyber risks. I would rate this solution a seven overall.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Has supported vulnerability detection and device inventory but needs better automation and risk prioritization
What is our primary use case?
I use Qualys TotalCloud for vulnerability as a service, vulnerability management as a service. I use it to check my devices to see if they're free from vulnerabilities, to send updates, and also as a form of inventory for the devices.
What is most valuable?
I can use Qualys TotalCloud to uninstall unwanted devices, which is great. I can also use the feature of seeing what my vulnerabilities are, a form of inventory, and knowing the criticals and the less criticals. Once you have your vulnerabilities fixed and your patches pushed out using Qualys TotalCloud, then you are able to eliminate threats and cyber risk. Qualys TotalCloud is also used to provide unified vulnerability and threat assessment across both IaaS and SaaS.
What needs improvement?
I sometimes have difficulty detecting or uninstalling certain versions of applications, which I have to do manually. More advanced features or AI could improve this process. A single prioritized view of risk is also lacking, which could enhance decision-making. Additionally, it could use improvements to perform actions without requiring manual intervention.
For how long have I used the solution?
I have been using Qualys TotalCloud for one year now.
What do I think about the stability of the solution?
It is stable. I have not had any issues with it.
How are customer service and support?
I rate the documentation they provide or the knowledge base between five to seven.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
I have done POC with Okta and CrowdStrike. Qualys TotalCloud focuses on vulnerability management and security features. Okta focuses more on identities and IAMs. CrowdStrike is more of intrusion detection and assessment.
How was the initial setup?
The application was quite easy to deploy in over 3,000 applications using Qualys TotalCloud.
What about the implementation team?
It's just me using Qualys TotalCloud. The users don't really have anything to do with it. I do all the admin side from my end.
What was our ROI?
The return on investment I've seen in the past year with Qualys TotalCloud is quite significant, around 10% to 20%.
What's my experience with pricing, setup cost, and licensing?
Qualys TotalCloud's pricing is fair. It is not expensive and is affordable.
What other advice do I have?
Cloud security posture changes with time when using Qualys TotalCloud. It depends on how early you detect threats and fix them. Qualys TotalCloud doesn't provide a single prioritized view of risk. The product does what it says it's going to do, so I recommend it. I rate Qualys TotalCloud six out of ten.
A centralized tool for vulnerability and misconfiguration management in a multiple cloud environment
What is our primary use case?
We are managing AWS , Azure , as well as Google Cloud services in the cloud. We have different applications using those. We were previously checking the configurations manually. Qualys is helping us identify vulnerabilities related to the cloud. It identifies if something is misconfigured or if any AWS key or private key is exposed. We receive this information from Qualys TotalCloud.
How has it helped my organization?
Qualys TotalCloud provides written explanations to help guide the remediation paths and eliminate cyber risk. We are using TruRisk for the remediations. The TruRisk shows anything critical, and we can then focus on that. We also assess manually whether an asset is a critical target or not.
Qualys TotalCloud provides a single, prioritized view of risk. We are using CIS-CAT standards to harden our clouds, such as AWS, Google Cloud , and Azure. We are able to analyze the scans and identify which policies have failed and how we can remediate them. We can customize policies as per our organization's requirements. That is very helpful for us.
With the TruRisk Insights feature, security has significantly improved. In six months of using it, we see that everything is under control. We've solved many problems related to asset management, cloud configuration, and the new asset identification. If an application team has onboarded any cloud asset, we can see that. We have that information now.
What is most valuable?
The best features in Qualys TotalCloud include the total asset management of the cloud environment. It is very easy to export the report and see the vulnerabilities related to the cloud specifically. We can segregate that particular report and give it to the appropriate team for remediation. Before, we were doing it manually. From the whole sheet, we had to find out the cloud vulnerabilities and check manually if it was a cloud vulnerability.
It is very helpful for us to generate reports related to the cloud vulnerabilities.
What needs improvement?
The onboarding process is a bit difficult. In the initial phase, it is very difficult to understand the features, what the dashboard contains, and what criteria they are using. This information is very difficult to understand as a newcomer to Qualys TotalCloud. Once we learn it, it becomes easy. It is hard for a complete newcomer.
For how long have I used the solution?
I have been using Qualys TotalCloud for the last six months. There was one Qualys conference, and after that, we purchased it. Our management people were there, and they saw the usage of Qualys TotalCloud and how we could secure the cloud environment. They looked at how we can identify cloud vulnerabilities. That's why they decided to use this product.
What do I think about the stability of the solution?
Qualys TotalCloud is stable. We didn't experience any lag or slowness issues. They inform us beforehand that maintenance is scheduled, and there might be some slowness. Apart from that, there are no issues. I would rate it a ten out of ten for stability.
What do I think about the scalability of the solution?
For scalability, I would rate it a ten out of ten. It does not matter how many assets we have; it's very manageable. It's centralized.
Our environment consists of multiple clouds and multiple locations. We have only three members using Qualys TotalCloud. The team is narrow. After six months, more users will come since they're having different customizations available.
How are customer service and support?
The support from Qualys TotalCloud is a ten out of ten. The support team is very helpful in every aspect. If we get any issues, we can directly communicate with them. They have been helpful from day one. They have been solving issues efficiently.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before using Qualys TotalCloud, we were using the cloud-native tools. For example, for AWS, we used the AWS console. We were doing the misconfiguration identification manually, checking everything manually. If any new policies or vulnerabilities came, we needed to check those manually. They provided some advice, and we relied on them, but we don't need to depend on them anymore. Qualys TotalCloud is identifying everything, and we take action based on that.
How was the initial setup?
The deployment was handled by a third-party vendor. They completed it within one week because they had expertise in that. Afterward, they did a knowledge transfer with us about how we can deploy and the process involved.
Qualys TotalCloud does not require any maintenance as it is based on the cloud.
What's my experience with pricing, setup cost, and licensing?
It isn't cheap, but it's reasonable. It helps us to manage things with very few resources.
What other advice do I have?
Currently, AI access is restricted in our environment. We are testing the outcomes and possibilities. Within two months, we may start using GenAI.
I would definitely recommend Qualys TotalCloud to other users. If someone is looking for a centralized management tool while using different cloud platforms, Qualys TotalCloud is very helpful. It helps manage and identify vulnerabilities and misconfigurations. It helps with asset management. It helps understand how many AWS or Google Cloud instances are in the environments.
I would rate Qualys TotalCloud a ten out of ten.
Makes cloud and asset management easy
What is our primary use case?
Qualys TotalCloud is very helpful for me for auditing purposes.
How has it helped my organization?
Qualys TotalCloud has helped us with centralized cloud management. We have Azure and AWS machines on the cloud. Previously, we were facing a lot of issues with vulnerability remediation. With Qualys TotalCloud, we can see vulnerabilities and misconfigurations and provide them to the remediation team with a timeline for fixing. Previously, we were unable to do that. It has helped us identify and plan the timeframe for the updates.
Qualys TotalCloud helped us show the attack vectors and their criticality to the client. The client could take immediate action. Previously, the client could not understand how critical an issue was. This automation is beneficial for us compared to the manual process.
Qualys TotalCloud has made asset management easy. We have many cloud resources. Previously, the cloud team was not aware of all of the resources. It is pretty easy now because we have visibility into the assets hosted on the cloud.
Qualys TotalCloud provides a single, prioritized view of risk. It reduces the work needed to combine multiple sources to prioritize risk. We can see them categorized based on the criticality which saves time. Previously, it would take us a week to manage, investigate the issues, and configure three or four cloud resources. We can now do that in two days. Once we have the report, we need to analyze it and showcase it to the client. They can then start the remediation.
Over three months, we have seen 20% to 25% improvement in the security posture. It identified about 70% misconfigurations which have now been reduced to 20%.
What is most valuable?
With TotalCloud, we can scan through the API. If we are not able to deploy cloud agents on the machine, we can use the API. This feature is quite nice.
What needs improvement?
It is already perfect, but they can bring some newer dashboards and customization options for the dashboard. It would be great to be able to include on-prem assets on the dashboard. For example, when I am hosting my own server to the public, I should be able to segregate the dashboard to monitor that particular server.
For how long have I used the solution?
I have been using Qualys TotalCloud for about three months.
What do I think about the stability of the solution?
Initially, we faced some performance issues. After implementing it, I noticed it took a lot of time to load. However, it was not an issue from the Qualys side, so we waited on our end. After logging out and in again, the issue was resolved, and it became perfectly smooth. The initial gathering of data seems to have contributed to the delay.
What do I think about the scalability of the solution?
We have not scaled it yet.
How are customer service and support?
We did not need any support so far because TotalCloud has been working well. However, in the future, I might require support, and I expect good assistance from the company. It should not take much time.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
This is the first time I am working on a cloud security platform like this.
How was the initial setup?
We did not encounter complexity because TotalCloud supports AWS . We do not need much customization or configuration either. The options for configuration are user-friendly. It took around two weeks to complete, with some management approval delays contributing to the timeframe.
Its maintenance is easy. We do not need more utilization or resources. We currently have 7 applications, and we will be onboarding 17 applications soon.
What about the implementation team?
There are five members in our team. Three of us were deploying and configuring the cloud setup, while others managed tasks, analyzed errors, and showcased the progress to the client.
What's my experience with pricing, setup cost, and licensing?
Its price seems higher compared to other tools, but it is worth it. If they could adjust the pricing and make it comparable with other tools, that would be great.
Which other solutions did I evaluate?
We evaluated WIZ cloud security. It has a limited number of dashboards, and customization is not possible. We have to rely on the data showcased on the dashboards, whereas Qualys TotalCloud shows us a lot of parameters and data which makes it easier to show information to the management.
What other advice do I have?
I would definitely recommend it because it is easy to handle any cloud resources. Asset management is possible, and we can effectively do an audit of cloud resources.
I would rate Qualys TotalCloud a ten out of ten.