Qualys VMDR (Vulnerability Management, Detection, and Response) allows you to discover, assess, prioritize in real time across your global hybrid IT environment.
Qualys VMDR seamlessly brings together discovery, assessment, detection and response into a single cloud-based app - significantly reducing risk, and effectively prevent breaches.
Highlights:
Comprehensive coverage and visibility
Pre-approved scanner for AWS EC2 Cloud
AWS EC2 Cloud Connector
Highlights
Comprehensive coverage and visibility. Cloud context aware scanning, providing end to end visibility from inventory and remediation.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy Qualys VMDR under a contract based on host packages. Each dimension covers a fixed number of hosts you plan to protect. Options range from 64 hosts up to 5,120 hosts, with steps at 64, 128, 256, 512, 1024, 1536, 2048, 2560, 3072, 4096, and 5120. You pick the package that matches your host count. Larger packages cover more hosts under one commitment. Pricing scales with the host quantity you choose, so you select the tier that fits the size of your environment.
Top-of-mind questions for buyers
What counts as one host for VMDR billing?
A host is a single asset you scan or monitor, such as a server, virtual machine, or workstation. Each package covers a set number of these assets. Every virtual machine counts as one host, even when several share the same physical server.
What happens if my host count grows past the package I bought?
Each package covers a fixed host count under one contract. If your environment grows beyond that count, you move to a package that covers more hosts. The change is not automatic. You pick the tier matching your host count when you commit.
What does VMDR do for each host I pay to cover?
VMDR discovers, assesses, prioritizes, and helps patch vulnerabilities across the hosts in your package. It covers vulnerability detection and response for each protected asset. Coverage is the same per host across every package size; only the host count differs.
www.qualys.com
Helpful?
Vendor refund policy
Licensed Qualys customers should refer to their Service User Agreement (SUA) or contact their Qualys Technical Account Manager if they have questions about refund or cancellation policies which would apply to them.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Qualys' policy is to respond to all Qualys customer cases promptly as per SLA. An incident ticket is assigned a priority number based on the nature of the issue. || Service Level Agreement (SLA): https://www.qualys.com/support/sla/https://www.qualys.com/support/ || support@qualys.com || US/Canada: +1 (866) 801-6161 (toll free) or +1 (650) 801-6161 || UK/Europe/International: +44 (0)1753 872102 || France: +33 1 41 97 35 81
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Great Vulnerability Insights, But API, Support, and Deployment Need Work
Reviewed on Aug 10, 2026
Review provided by G2
What do you like best about the product?
it tells me vulnerabilities that exist in my various systems
What do you dislike about the product?
their API, their customer service, their ease of deployment
What problems is the product solving and how is that benefiting you?
it tells me about vulnerabilities within my environemnt
Ajay Paul
Vulnerability management has prioritized high‑risk patching and simplified bulk system reporting
Reviewed on Aug 07, 2026
Review provided by PeerSpot
What is our primary use case?
I use Qualys Enterprise TruRisk Management for vulnerability management. We receive reports daily from Qualys Enterprise TruRisk Management that show which systems have vulnerabilities and prioritize them based on risk factors. This allows us to identify which systems have more vulnerabilities or higher risk levels and take appropriate action. We primarily use this tool for patch management and vulnerability patch management.
What is most valuable?
The most valuable feature is the ability to get vulnerability lists for bulk systems. My company has more than 300,000 employees, so we can generate a report of all systems and filter the results by location. This is the most interesting aspect of the tool. Additionally, Qualys Enterprise TruRisk Management provides many scoring metrics for critical and non-critical vulnerabilities, as well as high-risk ratings. This allows us to prioritize which vulnerabilities are more critical and focus on those first. Qualys Enterprise TruRisk Management also provides resolutions for vulnerabilities. For example, if a Windows update is missing, we can patch those systems directly from Qualys Enterprise TruRisk Management. It will connect directly to the Microsoft site and download the patch, so there is no need to search for patches separately. The patch will install directly from Qualys Enterprise TruRisk Management itself. For vulnerability management, Qualys Enterprise TruRisk Management is very good for our organization.
What needs improvement?
The primary issue is with the reporting functionality. Even though we fix vulnerabilities, the reports do not reflect the changes immediately. Sometimes we need to manually run a script to scan the systems before Qualys Enterprise TruRisk Management will update the scan results. The main issue is the reporting delay, and sometimes the Qualys Enterprise TruRisk Management agent will not scan the system, which means we do not receive accurate reports in a timely manner. Additionally, there are many metrics for calculating vulnerabilities, such as the Qualys ID, severity scores, CVSS scores, and other metrics. The abundance of information can be confusing. These two aspects are the most significant negatives I have experienced with this tool.
For how long have I used the solution?
I have been using this tool for the last one year.
What do I think about the stability of the solution?
I experienced a stability issue last week. For approximately 12 hours, we did not have access to Qualys Enterprise TruRisk Management. Even when we regained access, instead of displaying all 300 plus systems, it only showed fewer than 50 systems. This issue persisted for 12 hours and was only resolved after one day. I am uncertain whether the issue was caused by Qualys Enterprise TruRisk Management or our internal team. In one year of use, I have experienced this issue only once, when we lost access for one day.
What do I think about the scalability of the solution?
Qualys Enterprise TruRisk Management is highly scalable. As my company has many employees, the tool performs very well for handling this large number of users. I believe the tool is very scalable for enterprise environments.
How are customer service and support?
I cannot contact Qualys Enterprise TruRisk Management directly. Only our Qualys team can contact them. I do not have the ability to contact them directly.
Which solution did I use previously and why did I switch?
I have not used other solutions in this company. However, in my previous company, I used a tool called ManageEngine. Compared with ManageEngine, Qualys Enterprise TruRisk Management is by far better.
What about the implementation team?
In my company, we have nearly 300,000 employees and approximately five or six team members dedicated to Qualys Enterprise TruRisk Management. They handle the deployment, access management, and patching for the entire organization. The size of the implementation team depends on the company size. If the company has very few users, such as 10 to 100 users, one fully dedicated team member is sufficient for managing the deployment.
What's my experience with pricing, setup cost, and licensing?
I am not familiar with the pricing structure. I know that Qualys Enterprise TruRisk Management charges per user, but I do not have detailed knowledge of the pricing. The pricing decisions are handled by the marketing team and senior management, so I do not have information about those details.
What other advice do I have?
Qualys Enterprise TruRisk Management is very easy to use. If we have access to the system, there is no need for high technical knowledge, and an average person can navigate and use this tool easily. The tool is also available as a web application, making it very easy to access. If we have internet connectivity and a password, we can access it from any laptop or location. The entire process depends on the type of vulnerability being addressed. For example, for Windows patch updates, the process takes between half an hour and one hour to fully complete, depending on internet speed. I consider this a normal timeframe and it does not take excessively long. I would rate this review an 8.5 out of 10.
SharmaAbhijeet
Centralized risk-based visibility has improved vulnerability remediation and automates patching
Reviewed on Jul 13, 2026
Review provided by PeerSpot
What is our primary use case?
We are using Qualys Enterprise TruRisk Management for vulnerability management. It identifies, prioritizes, and remediates vulnerabilities while focusing on the business risk itself. The latest TruRisk platform provides this functionality, and we are not just getting vulnerability counts, but we are actually working on the business risk of the vulnerabilities.
We automate the vulnerability patching with Qualys Enterprise TruRisk Management and use patch management as well. In this overall scenario, we are automating the risk factor using Qualys for risk.
What is most valuable?
Qualys Enterprise TruRisk Management is a centralized vulnerability platform that provides us with wide centralized visibility. It has risk-based prioritization, useful reporting capabilities, and integration with different assets is quite easy. It is scalable in our environment.
With Qualys Enterprise TruRisk Management, we are able to perform risk-based prioritization. It is scalable for our environment, which gives us a good advantage. Reporting is very useful, so we get valuable reports.
Risk-based prioritization is a new feature with Qualys Enterprise TruRisk Management, and overall, the vulnerability posture of our organization has improved significantly. Qualys has quite improved the overall vulnerability management.
With Qualys Enterprise TruRisk Management, we are able to automate processes and prioritize risks. The resources who were previously working on the administrative part of vulnerability management are now free to work on different areas and are able to automate the administrative part. They are working on the automation and are able to address different vulnerabilities and patch them in time. This helps us considerably, and resources are easily managed.
With Qualys Enterprise TruRisk Management, all three metrics have improved. Resource allocation has decreased, time has improved, and we are getting positive results.
What needs improvement?
Qualys Enterprise TruRisk Management is a big platform, and the initial deployment is tedious.
Licensing and features are somewhat complex for new customers, and that area could be improved.
For how long have I used the solution?
I have been working on Qualys Enterprise TruRisk Management for around three years.
What do I think about the stability of the solution?
Qualys Enterprise TruRisk Management has been stable, and no downtime has been experienced.
What do I think about the scalability of the solution?
Qualys Enterprise TruRisk Management is scalable, and that is why we opted for it. It is one of the best products available for scalability.
How are customer service and support?
We reach out to customer support for Qualys Enterprise TruRisk Management occasionally, and it is quite easy to reach them. False positives are the main issue that we encounter and need to be handled by the support team.
Which solution did I use previously and why did I switch?
We were using a ManageEngine solution previously with Qualys Enterprise TruRisk Management, and we were conducting a proof of concept. As our environment was quite large, we migrated to Qualys, which proved to be more useful and more powerful for this environment.
How was the initial setup?
My experience with pricing, setup cost, and licensing for Qualys Enterprise TruRisk Management was somewhat tedious, and it consumed a lot of time.
Which other solutions did I evaluate?
Before choosing Qualys Enterprise TruRisk Management, we conducted a requirement analysis and selected a few vendors. We performed our own proofs of concept and finalized Qualys.
What other advice do I have?
We reach out to customer support for Qualys Enterprise TruRisk Management occasionally, and it is quite easy to reach them. False positives are the main issue that we encounter and need to be handled by the support team.
If you are looking for a good vulnerability management platform with Qualys Enterprise TruRisk Management and are open to a cloud-based or hybrid-based environment with good scalability for a large environment, you should choose Qualys. I would rate this solution a 9 out of 10.
Information Technology and Services
Real-Time Asset Visibility and TruRisk Prioritization at Scale
Reviewed on Mar 16, 2026
Review provided by G2
What do you like best about the product?
Real‑Time Asset Visibility Risk-Based Prioritization (TruRisk) Cloud‑Native & Highly Scalable Integrates with ServiceNow, Splunk, QRadar, Sentinel etc.
What do you dislike about the product?
Limited Third‑Party Application Patching
What problems is the product solving and how is that benefiting you?
Continuously tracks new assets as they appear so environments don’t become outdated or incomplete. Turns vulnerability volume into meaningful, risk‑based actions. Allows creating automated remediation workflows and packaging patches directly.
Pramod Borana
Clear risk scoring has guided my patch priorities and supports fully auditable vulnerability management
Reviewed on Feb 23, 2026
Review provided by PeerSpot
What is our primary use case?
Primarily, I use Qualys Enterprise TruRisk Management for assessing the current posture of my infrastructure as I am responsible for vulnerability management for my organization. Qualys Enterprise TruRisk Management gives me a clear picture of the current status of vulnerabilities relative to different criteria across my various integrated servers.
I work in a regulated banking entity, so we are highly regulated. Most of our data comes from Qualys itself, making all data auditable from the standpoint of Indian regulators. Every data point that comes out of Qualys is auditable.
I work with Qualys Enterprise TruRisk Management, though we are not using Patch Management. Beyond that, we are using Vulnerability Management and Secure Configuration, which is the new name for Policy Audit in Qualys.
What is most valuable?
The most valuable function of Qualys Enterprise TruRisk Management is that it provides a clear picture of how my vulnerabilities across different servers can be categorized. I must provide input about servers and their criticality, but based on that information, it gives me a clear understanding of whether a particular vulnerability on my server needs to be fixed based on the proof of concept and attack vectors available in the market. Based on this, it provides me a scoring mechanism that tells me which vulnerabilities I need to patch immediately or which ones I can defer for a later time.
Qualys Enterprise TruRisk Management provides me with a QDS scoring mechanism, which has helped me identify which vulnerabilities I need to patch immediately. It also provides me with the criticality rating of each vulnerability. Understanding whether a vulnerability needs immediate action or whether I can take some time based on my current posture and available bandwidth has been instrumental.
What needs improvement?
The live threat intelligence updates in Qualys are good, with updates provided on the last Friday of each month. However, I am not satisfied with Qualys support. The response time is slower than needed.
I have raised only technical cases with Qualys. I am comfortable with the GUI and how they have defined it. However, I do require a certain level of technical input, and they take considerable time to provide responses. This typically misses the timeline or the criticality of the particular matter. After three years of working with Qualys, I am familiar with most aspects of the system. When the system misbehaves and I need to raise a case with Qualys, they take an extended amount of time to provide input. Even after that, the response time for scheduling calls to discuss and understand the issue is slow.
Overall, they are good. A few bugs once or twice per month is acceptable because no tool is perfect. My primary recommendation is to increase their technical support team to ensure that clients are not impeded or running back and forth. We only raise support when we need urgent assistance or when action needs to be taken immediately. Receiving a response three to seven days later does not align with our needs.
For how long have I used the solution?
I have been working with Qualys Enterprise TruRisk Management for approximately three years.
What do I think about the stability of the solution?
I rate the stability of Qualys Enterprise TruRisk Management at eight point five out of ten because I occasionally find bugs that are frustrating, and I have already commented on the support issues. Overall, eight point five is a good rating.
What do I think about the scalability of the solution?
I rate the scalability of Qualys Enterprise TruRisk Management at nine out of ten. Scalability is not a challenge. Since it is primarily an on-premises solution, I can simply scale it up as needed.
How are customer service and support?
Regarding pricing, Qualys Enterprise TruRisk Management is a more costly product compared to what is available in the market. However, it does provide good features that justify the investment. My competitors, including Tenable, Rapid7, and other products, do not provide a good GUI function where I can actively track my vulnerabilities in real time. I always need to pull down a report in Excel and then work with the Excel file. With Qualys Enterprise TruRisk Management, I can work directly on the dashboard itself and ensure that all my servers are scanned within twenty-four hours or four hours according to my feasibility. Regarding its competitors in the market, I believe Qualys Enterprise TruRisk Management has a strong offering.
The GUI in Qualys Enterprise TruRisk Management is excellent. Although it is quite elaborate and may require some navigation, it is very familiar and easy to use. Compared to other solutions, the GUI is superior.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have experience with competitors including Tenable, Nessus, and Rapid7. To be honest, they ask a high price, but they also provide certain functionality that other competitors do not. In the market, if you are pricing higher, that is what you can expect.
How was the initial setup?
Overall, the initial setup for Qualys Enterprise TruRisk Management is good and straightforward. I have taken the SaaS model and am not discussing the on-premises model. I am working with the SaaS model. Scanners and QGS need to be deployed on-premises, which is straightforward. I only need to build a server and deploy the ISO. Qualys provides the SaaS model itself. Overall, if I go with the SaaS model, I would not find much difficulty or hindrance.
What about the implementation team?
I set up Qualys Enterprise TruRisk Management on my own. It was not difficult. If I followed the official documentation, I could learn everything I needed. The process was straightforward.
What's my experience with pricing, setup cost, and licensing?
I rate the pricing of Qualys Enterprise TruRisk Management as high, giving it a six out of ten.
What other advice do I have?
Agentic AI is one of the models running in the background for Qualys. It is responsible for all vulnerability closures and vulnerability testing. All data collected by agents in the field is gathered and pushed into the Agentic AI model, which then processes that information and provides output based on proof of concept mechanisms or the MITRE ATT&CK pattern.
Based on my understanding, I have not found any false positives in Qualys Enterprise TruRisk Management. There are some vulnerabilities that might not be applicable to my environment or that I do not want to address, but there have been no false positives in my environment. In the last three years, I have only seen one vulnerability for which the patch was not released, but that was also a true positive. The only issue was that the OEM did not release the patch for that particular vulnerability.
My final score for Qualys Enterprise TruRisk Management is eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?