Listing Thumbnail

    Qualys VMDR (US Only)

     Info
    Sold by: Qualys 
    Deployed on AWS
    Qualys VMDR (Vulnerability Management, Detection, and Response) allows you to discover, assess, prioritize in real time across your global hybrid IT environment.
    4.3

    Overview

    Qualys VMDR seamlessly brings together discovery, assessment, detection and response into a single cloud-based app - significantly reducing risk, and effectively prevent breaches.

    Highlights: Comprehensive coverage and visibility Pre-approved scanner for AWS EC2 Cloud AWS EC2 Cloud Connector

    Highlights

    • Comprehensive coverage and visibility. Cloud context aware scanning, providing end to end visibility from inventory and remediation.

    Details

    Sold by

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Qualys VMDR (US Only)

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (11)

     Info
    Dimension
    Description
    Cost/month
    VMDR Package 128
    Package of 128 Hosts for VMDR
    $596.00
    VMDR Package 256
    Package of Hosts for VMDR
    $942.00
    VMDR Package 512
    Package of 512 Hosts for VMDR
    $1,489.00
    VMDR Package 1024
    Package of 1024 Hosts for VMDR
    $2,352.00
    VMDR Package 1536
    Package of 1536 Hosts for VMDR
    $3,075.00
    VMDR Package 2048
    Package of 2048 Hosts for VMDR
    $3,719.00
    VMDR Package 2560
    Package of 2560 Hosts for VMDR
    $4,309.00
    VMDR Package 3072
    Package of 3072 Hosts for VMDR
    $4,857.00
    VMDR Package 4096
    Package of 4096 Hosts for VMDR
    $5,878.00
    VMDR Package 5120
    Package of 5120 Hosts for VMDR
    $6,805.00

    AI Insights

     Info

    Dimensions summary

    You buy Qualys VMDR under a contract based on host packages. Each dimension covers a fixed number of hosts you plan to protect. Options range from 64 hosts up to 5,120 hosts, with steps at 64, 128, 256, 512, 1024, 1536, 2048, 2560, 3072, 4096, and 5120. You pick the package that matches your host count. Larger packages cover more hosts under one commitment. Pricing scales with the host quantity you choose, so you select the tier that fits the size of your environment.

    Top-of-mind questions for buyers

    A host is a single asset you scan or monitor, such as a server, virtual machine, or workstation. Each package covers a set number of these assets. Every virtual machine counts as one host, even when several share the same physical server.
    Each package covers a fixed host count under one contract. If your environment grows beyond that count, you move to a package that covers more hosts. The change is not automatic. You pick the tier matching your host count when you commit.
    VMDR discovers, assesses, prioritizes, and helps patch vulnerabilities across the hosts in your package. It covers vulnerability detection and response for each protected asset. Coverage is the same per host across every package size; only the host count differs.
    www.qualys.com
    Helpful?

    Vendor refund policy

    Licensed Qualys customers should refer to their Service User Agreement (SUA) or contact their Qualys Technical Account Manager if they have questions about refund or cancellation policies which would apply to them.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Qualys' policy is to respond to all Qualys customer cases promptly as per SLA. An incident ticket is assigned a priority number based on the nature of the issue. || Service Level Agreement (SLA): https://www.qualys.com/support/sla/  https://www.qualys.com/support/  || support@qualys.com  || US/Canada: +1 (866) 801-6161 (toll free) or +1 (650) 801-6161 || UK/Europe/International: +44 (0)1753 872102 || France: +33 1 41 97 35 81

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Monitoring
    Top
    50
    In Device Security

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    2 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Cloud-Based Vulnerability Management Platform
    Single cloud-based application that integrates discovery, assessment, detection, and response capabilities for vulnerability management
    Real-Time Prioritization
    Real-time prioritization of vulnerabilities across global hybrid IT environments
    AWS EC2 Integration
    Pre-approved scanner for AWS EC2 Cloud with AWS EC2 Cloud Connector for seamless integration
    Cloud Context-Aware Scanning
    Cloud context aware scanning providing end-to-end visibility from inventory to remediation
    Comprehensive Asset Discovery and Assessment
    Discovers and assesses assets across hybrid IT environments with comprehensive coverage and visibility
    Vulnerability Scanning
    Integrated vulnerability scanning with automatic updates to protect against the latest vulnerabilities
    Penetration Testing
    Penetration testing capabilities integrated within the platform
    Scan Policy Configuration
    20 built-in scan policies available with support for custom policy creation
    Compliance Reporting
    Compliance reporting templates for PCI, FISMA, HIPAA, NERC CIP, and SOX standards
    Multi-Scanner Architecture
    Support for both standalone and multi-scanner deployment architectures
    Cloud Asset Scanning
    Vulnerability management through extraction of dependent components in servers, containers, and applications by connecting AWS account to the service
    Software Bill of Materials and Software Composition Analysis
    Extraction of dependent components in application code with vulnerability management functions and SBOM generation capabilities
    Configuration Management
    Checks and manages AWS configuration deficiencies based on general rules such as CIS Benchmarks
    End-of-Life Management
    Detection and management of end-of-life software based on extracted SBOM information with notifications for software reaching EOL status
    Threat-Based Automatic Triage
    Automatic prioritization of vulnerabilities based on threat level to focus resources on high-risk vulnerabilities

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.3
    196 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    58%
    36%
    4%
    1%
    1%
    9 AWS reviews
    |
    187 external reviews
    External reviews are from G2  and PeerSpot .
    Higher Education

    Great Vulnerability Insights, But API, Support, and Deployment Need Work

    Reviewed on Aug 10, 2026
    Review provided by G2
    What do you like best about the product?
    it tells me vulnerabilities that exist in my various systems
    What do you dislike about the product?
    their API, their customer service, their ease of deployment
    What problems is the product solving and how is that benefiting you?
    it tells me about vulnerabilities within my environemnt
    Ajay Paul

    Vulnerability management has prioritized high‑risk patching and simplified bulk system reporting

    Reviewed on Aug 07, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I use Qualys Enterprise TruRisk Management for vulnerability management. We receive reports daily from Qualys Enterprise TruRisk Management that show which systems have vulnerabilities and prioritize them based on risk factors. This allows us to identify which systems have more vulnerabilities or higher risk levels and take appropriate action. We primarily use this tool for patch management and vulnerability patch management.

    What is most valuable?

    The most valuable feature is the ability to get vulnerability lists for bulk systems. My company has more than 300,000 employees, so we can generate a report of all systems and filter the results by location. This is the most interesting aspect of the tool. Additionally, Qualys Enterprise TruRisk Management provides many scoring metrics for critical and non-critical vulnerabilities, as well as high-risk ratings. This allows us to prioritize which vulnerabilities are more critical and focus on those first. Qualys Enterprise TruRisk Management also provides resolutions for vulnerabilities. For example, if a Windows update is missing, we can patch those systems directly from Qualys Enterprise TruRisk Management. It will connect directly to the Microsoft site and download the patch, so there is no need to search for patches separately. The patch will install directly from Qualys Enterprise TruRisk Management itself. For vulnerability management, Qualys Enterprise TruRisk Management is very good for our organization.

    What needs improvement?

    The primary issue is with the reporting functionality. Even though we fix vulnerabilities, the reports do not reflect the changes immediately. Sometimes we need to manually run a script to scan the systems before Qualys Enterprise TruRisk Management will update the scan results. The main issue is the reporting delay, and sometimes the Qualys Enterprise TruRisk Management agent will not scan the system, which means we do not receive accurate reports in a timely manner. Additionally, there are many metrics for calculating vulnerabilities, such as the Qualys ID, severity scores, CVSS scores, and other metrics. The abundance of information can be confusing. These two aspects are the most significant negatives I have experienced with this tool.

    For how long have I used the solution?

    I have been using this tool for the last one year.

    What do I think about the stability of the solution?

    I experienced a stability issue last week. For approximately 12 hours, we did not have access to Qualys Enterprise TruRisk Management. Even when we regained access, instead of displaying all 300 plus systems, it only showed fewer than 50 systems. This issue persisted for 12 hours and was only resolved after one day. I am uncertain whether the issue was caused by Qualys Enterprise TruRisk Management or our internal team. In one year of use, I have experienced this issue only once, when we lost access for one day.

    What do I think about the scalability of the solution?

    Qualys Enterprise TruRisk Management is highly scalable. As my company has many employees, the tool performs very well for handling this large number of users. I believe the tool is very scalable for enterprise environments.

    How are customer service and support?

    I cannot contact Qualys Enterprise TruRisk Management directly. Only our Qualys team can contact them. I do not have the ability to contact them directly.

    Which solution did I use previously and why did I switch?

    I have not used other solutions in this company. However, in my previous company, I used a tool called ManageEngine. Compared with ManageEngine, Qualys Enterprise TruRisk Management is by far better.

    What about the implementation team?

    In my company, we have nearly 300,000 employees and approximately five or six team members dedicated to Qualys Enterprise TruRisk Management. They handle the deployment, access management, and patching for the entire organization. The size of the implementation team depends on the company size. If the company has very few users, such as 10 to 100 users, one fully dedicated team member is sufficient for managing the deployment.

    What's my experience with pricing, setup cost, and licensing?

    I am not familiar with the pricing structure. I know that Qualys Enterprise TruRisk Management charges per user, but I do not have detailed knowledge of the pricing. The pricing decisions are handled by the marketing team and senior management, so I do not have information about those details.

    What other advice do I have?

    Qualys Enterprise TruRisk Management is very easy to use. If we have access to the system, there is no need for high technical knowledge, and an average person can navigate and use this tool easily. The tool is also available as a web application, making it very easy to access. If we have internet connectivity and a password, we can access it from any laptop or location. The entire process depends on the type of vulnerability being addressed. For example, for Windows patch updates, the process takes between half an hour and one hour to fully complete, depending on internet speed. I consider this a normal timeframe and it does not take excessively long. I would rate this review an 8.5 out of 10.

    SharmaAbhijeet

    Centralized risk-based visibility has improved vulnerability remediation and automates patching

    Reviewed on Jul 13, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We are using Qualys Enterprise TruRisk Management for vulnerability management. It identifies, prioritizes, and remediates vulnerabilities while focusing on the business risk itself. The latest TruRisk platform provides this functionality, and we are not just getting vulnerability counts, but we are actually working on the business risk of the vulnerabilities.

    We automate the vulnerability patching with Qualys Enterprise TruRisk Management and use patch management as well. In this overall scenario, we are automating the risk factor using Qualys for risk.

    What is most valuable?

    Qualys Enterprise TruRisk Management is a centralized vulnerability platform that provides us with wide centralized visibility. It has risk-based prioritization, useful reporting capabilities, and integration with different assets is quite easy. It is scalable in our environment.

    With Qualys Enterprise TruRisk Management, we are able to perform risk-based prioritization. It is scalable for our environment, which gives us a good advantage. Reporting is very useful, so we get valuable reports.

    Risk-based prioritization is a new feature with Qualys Enterprise TruRisk Management, and overall, the vulnerability posture of our organization has improved significantly. Qualys has quite improved the overall vulnerability management.

    With Qualys Enterprise TruRisk Management, we are able to automate processes and prioritize risks. The resources who were previously working on the administrative part of vulnerability management are now free to work on different areas and are able to automate the administrative part. They are working on the automation and are able to address different vulnerabilities and patch them in time. This helps us considerably, and resources are easily managed.

    With Qualys Enterprise TruRisk Management, all three metrics have improved. Resource allocation has decreased, time has improved, and we are getting positive results.

    What needs improvement?

    Qualys Enterprise TruRisk Management is a big platform, and the initial deployment is tedious.

    Licensing and features are somewhat complex for new customers, and that area could be improved.

    For how long have I used the solution?

    I have been working on Qualys Enterprise TruRisk Management for around three years.

    What do I think about the stability of the solution?

    Qualys Enterprise TruRisk Management has been stable, and no downtime has been experienced.

    What do I think about the scalability of the solution?

    Qualys Enterprise TruRisk Management is scalable, and that is why we opted for it. It is one of the best products available for scalability.

    How are customer service and support?

    We reach out to customer support for Qualys Enterprise TruRisk Management occasionally, and it is quite easy to reach them. False positives are the main issue that we encounter and need to be handled by the support team.

    Which solution did I use previously and why did I switch?

    We were using a ManageEngine solution previously with Qualys Enterprise TruRisk Management, and we were conducting a proof of concept. As our environment was quite large, we migrated to Qualys, which proved to be more useful and more powerful for this environment.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing for Qualys Enterprise TruRisk Management was somewhat tedious, and it consumed a lot of time.

    Which other solutions did I evaluate?

    Before choosing Qualys Enterprise TruRisk Management, we conducted a requirement analysis and selected a few vendors. We performed our own proofs of concept and finalized Qualys.

    What other advice do I have?

    We reach out to customer support for Qualys Enterprise TruRisk Management occasionally, and it is quite easy to reach them. False positives are the main issue that we encounter and need to be handled by the support team.

    If you are looking for a good vulnerability management platform with Qualys Enterprise TruRisk Management and are open to a cloud-based or hybrid-based environment with good scalability for a large environment, you should choose Qualys. I would rate this solution a 9 out of 10.

    Information Technology and Services

    Real-Time Asset Visibility and TruRisk Prioritization at Scale

    Reviewed on Mar 16, 2026
    Review provided by G2
    What do you like best about the product?
    Real‑Time Asset Visibility
    Risk-Based Prioritization (TruRisk)
    Cloud‑Native & Highly Scalable
    Integrates with ServiceNow, Splunk, QRadar, Sentinel etc.
    What do you dislike about the product?
    Limited Third‑Party Application Patching
    What problems is the product solving and how is that benefiting you?
    Continuously tracks new assets as they appear so environments don’t become outdated or incomplete.
    Turns vulnerability volume into meaningful, risk‑based actions.
    Allows creating automated remediation workflows and packaging patches directly.
    Pramod Borana

    Clear risk scoring has guided my patch priorities and supports fully auditable vulnerability management

    Reviewed on Feb 23, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Primarily, I use Qualys Enterprise TruRisk Management for assessing the current posture of my infrastructure as I am responsible for vulnerability management for my organization. Qualys Enterprise TruRisk Management gives me a clear picture of the current status of vulnerabilities relative to different criteria across my various integrated servers.

    I work in a regulated banking entity, so we are highly regulated. Most of our data comes from Qualys itself, making all data auditable from the standpoint of Indian regulators. Every data point that comes out of Qualys is auditable.

    I work with Qualys Enterprise TruRisk Management, though we are not using Patch Management. Beyond that, we are using Vulnerability Management and Secure Configuration, which is the new name for Policy Audit in Qualys.

    What is most valuable?

    The most valuable function of Qualys Enterprise TruRisk Management is that it provides a clear picture of how my vulnerabilities across different servers can be categorized. I must provide input about servers and their criticality, but based on that information, it gives me a clear understanding of whether a particular vulnerability on my server needs to be fixed based on the proof of concept and attack vectors available in the market. Based on this, it provides me a scoring mechanism that tells me which vulnerabilities I need to patch immediately or which ones I can defer for a later time.

    Qualys Enterprise TruRisk Management provides me with a QDS scoring mechanism, which has helped me identify which vulnerabilities I need to patch immediately. It also provides me with the criticality rating of each vulnerability. Understanding whether a vulnerability needs immediate action or whether I can take some time based on my current posture and available bandwidth has been instrumental.

    What needs improvement?

    The live threat intelligence updates in Qualys are good, with updates provided on the last Friday of each month. However, I am not satisfied with Qualys support. The response time is slower than needed.

    I have raised only technical cases with Qualys. I am comfortable with the GUI and how they have defined it. However, I do require a certain level of technical input, and they take considerable time to provide responses. This typically misses the timeline or the criticality of the particular matter. After three years of working with Qualys, I am familiar with most aspects of the system. When the system misbehaves and I need to raise a case with Qualys, they take an extended amount of time to provide input. Even after that, the response time for scheduling calls to discuss and understand the issue is slow.

    Overall, they are good. A few bugs once or twice per month is acceptable because no tool is perfect. My primary recommendation is to increase their technical support team to ensure that clients are not impeded or running back and forth. We only raise support when we need urgent assistance or when action needs to be taken immediately. Receiving a response three to seven days later does not align with our needs.

    For how long have I used the solution?

    I have been working with Qualys Enterprise TruRisk Management for approximately three years.

    What do I think about the stability of the solution?

    I rate the stability of Qualys Enterprise TruRisk Management at eight point five out of ten because I occasionally find bugs that are frustrating, and I have already commented on the support issues. Overall, eight point five is a good rating.

    What do I think about the scalability of the solution?

    I rate the scalability of Qualys Enterprise TruRisk Management at nine out of ten. Scalability is not a challenge. Since it is primarily an on-premises solution, I can simply scale it up as needed.

    How are customer service and support?

    Regarding pricing, Qualys Enterprise TruRisk Management is a more costly product compared to what is available in the market. However, it does provide good features that justify the investment. My competitors, including Tenable, Rapid7, and other products, do not provide a good GUI function where I can actively track my vulnerabilities in real time. I always need to pull down a report in Excel and then work with the Excel file. With Qualys Enterprise TruRisk Management, I can work directly on the dashboard itself and ensure that all my servers are scanned within twenty-four hours or four hours according to my feasibility. Regarding its competitors in the market, I believe Qualys Enterprise TruRisk Management has a strong offering.

    The GUI in Qualys Enterprise TruRisk Management is excellent. Although it is quite elaborate and may require some navigation, it is very familiar and easy to use. Compared to other solutions, the GUI is superior.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have experience with competitors including Tenable, Nessus, and Rapid7. To be honest, they ask a high price, but they also provide certain functionality that other competitors do not. In the market, if you are pricing higher, that is what you can expect.

    How was the initial setup?

    Overall, the initial setup for Qualys Enterprise TruRisk Management is good and straightforward. I have taken the SaaS model and am not discussing the on-premises model. I am working with the SaaS model. Scanners and QGS need to be deployed on-premises, which is straightforward. I only need to build a server and deploy the ISO. Qualys provides the SaaS model itself. Overall, if I go with the SaaS model, I would not find much difficulty or hindrance.

    What about the implementation team?

    I set up Qualys Enterprise TruRisk Management on my own. It was not difficult. If I followed the official documentation, I could learn everything I needed. The process was straightforward.

    What's my experience with pricing, setup cost, and licensing?

    I rate the pricing of Qualys Enterprise TruRisk Management as high, giving it a six out of ten.

    What other advice do I have?

    Agentic AI is one of the models running in the background for Qualys. It is responsible for all vulnerability closures and vulnerability testing. All data collected by agents in the field is gathered and pushed into the Agentic AI model, which then processes that information and provides output based on proof of concept mechanisms or the MITRE ATT&CK pattern.

    Based on my understanding, I have not found any false positives in Qualys Enterprise TruRisk Management. There are some vulnerabilities that might not be applicable to my environment or that I do not want to address, but there have been no false positives in my environment. In the last three years, I have only seen one vulnerability for which the patch was not released, but that was also a true positive. The only issue was that the OEM did not release the patch for that particular vulnerability.

    My final score for Qualys Enterprise TruRisk Management is eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    View all reviews