Qualys VMDR FixIT (US Only) logo

    Qualys VMDR FixIT (US Only)

    Sold by
    Risk-Based Vulnerability Management & Patch Management

    Ratings and reviews

    4.2
    32 ratings
    3 star
    1 star
    47%
    50%
    0%
    3%
    0%
    9 AWS reviews
    |
    23 external reviews
    External reviews are from PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (32)
    Ajay Paul

    Vulnerability management has prioritized high‑risk patching and simplified bulk system reporting

    Reviewed on Aug 07, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I use Qualys Enterprise TruRisk Management for vulnerability management. We receive reports daily from Qualys Enterprise TruRisk Management that show which systems have vulnerabilities and prioritize them based on risk factors. This allows us to identify which systems have more vulnerabilities or higher risk levels and take appropriate action. We primarily use this tool for patch management and vulnerability patch management.

    What is most valuable?

    The most valuable feature is the ability to get vulnerability lists for bulk systems. My company has more than 300,000 employees, so we can generate a report of all systems and filter the results by location. This is the most interesting aspect of the tool. Additionally, Qualys Enterprise TruRisk Management provides many scoring metrics for critical and non-critical vulnerabilities, as well as high-risk ratings. This allows us to prioritize which vulnerabilities are more critical and focus on those first. Qualys Enterprise TruRisk Management also provides resolutions for vulnerabilities. For example, if a Windows update is missing, we can patch those systems directly from Qualys Enterprise TruRisk Management. It will connect directly to the Microsoft site and download the patch, so there is no need to search for patches separately. The patch will install directly from Qualys Enterprise TruRisk Management itself. For vulnerability management, Qualys Enterprise TruRisk Management is very good for our organization.

    What needs improvement?

    The primary issue is with the reporting functionality. Even though we fix vulnerabilities, the reports do not reflect the changes immediately. Sometimes we need to manually run a script to scan the systems before Qualys Enterprise TruRisk Management will update the scan results. The main issue is the reporting delay, and sometimes the Qualys Enterprise TruRisk Management agent will not scan the system, which means we do not receive accurate reports in a timely manner. Additionally, there are many metrics for calculating vulnerabilities, such as the Qualys ID, severity scores, CVSS scores, and other metrics. The abundance of information can be confusing. These two aspects are the most significant negatives I have experienced with this tool.

    For how long have I used the solution?

    I have been using this tool for the last one year.

    What do I think about the stability of the solution?

    I experienced a stability issue last week. For approximately 12 hours, we did not have access to Qualys Enterprise TruRisk Management. Even when we regained access, instead of displaying all 300 plus systems, it only showed fewer than 50 systems. This issue persisted for 12 hours and was only resolved after one day. I am uncertain whether the issue was caused by Qualys Enterprise TruRisk Management or our internal team. In one year of use, I have experienced this issue only once, when we lost access for one day.

    What do I think about the scalability of the solution?

    Qualys Enterprise TruRisk Management is highly scalable. As my company has many employees, the tool performs very well for handling this large number of users. I believe the tool is very scalable for enterprise environments.

    How are customer service and support?

    I cannot contact Qualys Enterprise TruRisk Management directly. Only our Qualys team can contact them. I do not have the ability to contact them directly.

    Which solution did I use previously and why did I switch?

    I have not used other solutions in this company. However, in my previous company, I used a tool called ManageEngine. Compared with ManageEngine, Qualys Enterprise TruRisk Management is by far better.

    What about the implementation team?

    In my company, we have nearly 300,000 employees and approximately five or six team members dedicated to Qualys Enterprise TruRisk Management. They handle the deployment, access management, and patching for the entire organization. The size of the implementation team depends on the company size. If the company has very few users, such as 10 to 100 users, one fully dedicated team member is sufficient for managing the deployment.

    What's my experience with pricing, setup cost, and licensing?

    I am not familiar with the pricing structure. I know that Qualys Enterprise TruRisk Management charges per user, but I do not have detailed knowledge of the pricing. The pricing decisions are handled by the marketing team and senior management, so I do not have information about those details.

    What other advice do I have?

    Qualys Enterprise TruRisk Management is very easy to use. If we have access to the system, there is no need for high technical knowledge, and an average person can navigate and use this tool easily. The tool is also available as a web application, making it very easy to access. If we have internet connectivity and a password, we can access it from any laptop or location. The entire process depends on the type of vulnerability being addressed. For example, for Windows patch updates, the process takes between half an hour and one hour to fully complete, depending on internet speed. I consider this a normal timeframe and it does not take excessively long. I would rate this review an 8.5 out of 10.

    SharmaAbhijeet

    Centralized risk-based visibility has improved vulnerability remediation and automates patching

    Reviewed on Jul 13, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We are using Qualys Enterprise TruRisk Management for vulnerability management. It identifies, prioritizes, and remediates vulnerabilities while focusing on the business risk itself. The latest TruRisk platform provides this functionality, and we are not just getting vulnerability counts, but we are actually working on the business risk of the vulnerabilities.

    We automate the vulnerability patching with Qualys Enterprise TruRisk Management and use patch management as well. In this overall scenario, we are automating the risk factor using Qualys for risk.

    What is most valuable?

    Qualys Enterprise TruRisk Management is a centralized vulnerability platform that provides us with wide centralized visibility. It has risk-based prioritization, useful reporting capabilities, and integration with different assets is quite easy. It is scalable in our environment.

    With Qualys Enterprise TruRisk Management, we are able to perform risk-based prioritization. It is scalable for our environment, which gives us a good advantage. Reporting is very useful, so we get valuable reports.

    Risk-based prioritization is a new feature with Qualys Enterprise TruRisk Management, and overall, the vulnerability posture of our organization has improved significantly. Qualys has quite improved the overall vulnerability management.

    With Qualys Enterprise TruRisk Management, we are able to automate processes and prioritize risks. The resources who were previously working on the administrative part of vulnerability management are now free to work on different areas and are able to automate the administrative part. They are working on the automation and are able to address different vulnerabilities and patch them in time. This helps us considerably, and resources are easily managed.

    With Qualys Enterprise TruRisk Management, all three metrics have improved. Resource allocation has decreased, time has improved, and we are getting positive results.

    What needs improvement?

    Qualys Enterprise TruRisk Management is a big platform, and the initial deployment is tedious.

    Licensing and features are somewhat complex for new customers, and that area could be improved.

    For how long have I used the solution?

    I have been working on Qualys Enterprise TruRisk Management for around three years.

    What do I think about the stability of the solution?

    Qualys Enterprise TruRisk Management has been stable, and no downtime has been experienced.

    What do I think about the scalability of the solution?

    Qualys Enterprise TruRisk Management is scalable, and that is why we opted for it. It is one of the best products available for scalability.

    How are customer service and support?

    We reach out to customer support for Qualys Enterprise TruRisk Management occasionally, and it is quite easy to reach them. False positives are the main issue that we encounter and need to be handled by the support team.

    Which solution did I use previously and why did I switch?

    We were using a ManageEngine solution previously with Qualys Enterprise TruRisk Management, and we were conducting a proof of concept. As our environment was quite large, we migrated to Qualys, which proved to be more useful and more powerful for this environment.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing for Qualys Enterprise TruRisk Management was somewhat tedious, and it consumed a lot of time.

    Which other solutions did I evaluate?

    Before choosing Qualys Enterprise TruRisk Management, we conducted a requirement analysis and selected a few vendors. We performed our own proofs of concept and finalized Qualys.

    What other advice do I have?

    We reach out to customer support for Qualys Enterprise TruRisk Management occasionally, and it is quite easy to reach them. False positives are the main issue that we encounter and need to be handled by the support team.

    If you are looking for a good vulnerability management platform with Qualys Enterprise TruRisk Management and are open to a cloud-based or hybrid-based environment with good scalability for a large environment, you should choose Qualys. I would rate this solution a 9 out of 10.

    Pramod Borana

    Clear risk scoring has guided my patch priorities and supports fully auditable vulnerability management

    Reviewed on Feb 23, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Primarily, I use Qualys Enterprise TruRisk Management for assessing the current posture of my infrastructure as I am responsible for vulnerability management for my organization. Qualys Enterprise TruRisk Management gives me a clear picture of the current status of vulnerabilities relative to different criteria across my various integrated servers.

    I work in a regulated banking entity, so we are highly regulated. Most of our data comes from Qualys itself, making all data auditable from the standpoint of Indian regulators. Every data point that comes out of Qualys is auditable.

    I work with Qualys Enterprise TruRisk Management, though we are not using Patch Management. Beyond that, we are using Vulnerability Management and Secure Configuration, which is the new name for Policy Audit in Qualys.

    What is most valuable?

    The most valuable function of Qualys Enterprise TruRisk Management is that it provides a clear picture of how my vulnerabilities across different servers can be categorized. I must provide input about servers and their criticality, but based on that information, it gives me a clear understanding of whether a particular vulnerability on my server needs to be fixed based on the proof of concept and attack vectors available in the market. Based on this, it provides me a scoring mechanism that tells me which vulnerabilities I need to patch immediately or which ones I can defer for a later time.

    Qualys Enterprise TruRisk Management provides me with a QDS scoring mechanism, which has helped me identify which vulnerabilities I need to patch immediately. It also provides me with the criticality rating of each vulnerability. Understanding whether a vulnerability needs immediate action or whether I can take some time based on my current posture and available bandwidth has been instrumental.

    What needs improvement?

    The live threat intelligence updates in Qualys are good, with updates provided on the last Friday of each month. However, I am not satisfied with Qualys support. The response time is slower than needed.

    I have raised only technical cases with Qualys. I am comfortable with the GUI and how they have defined it. However, I do require a certain level of technical input, and they take considerable time to provide responses. This typically misses the timeline or the criticality of the particular matter. After three years of working with Qualys, I am familiar with most aspects of the system. When the system misbehaves and I need to raise a case with Qualys, they take an extended amount of time to provide input. Even after that, the response time for scheduling calls to discuss and understand the issue is slow.

    Overall, they are good. A few bugs once or twice per month is acceptable because no tool is perfect. My primary recommendation is to increase their technical support team to ensure that clients are not impeded or running back and forth. We only raise support when we need urgent assistance or when action needs to be taken immediately. Receiving a response three to seven days later does not align with our needs.

    For how long have I used the solution?

    I have been working with Qualys Enterprise TruRisk Management for approximately three years.

    What do I think about the stability of the solution?

    I rate the stability of Qualys Enterprise TruRisk Management at eight point five out of ten because I occasionally find bugs that are frustrating, and I have already commented on the support issues. Overall, eight point five is a good rating.

    What do I think about the scalability of the solution?

    I rate the scalability of Qualys Enterprise TruRisk Management at nine out of ten. Scalability is not a challenge. Since it is primarily an on-premises solution, I can simply scale it up as needed.

    How are customer service and support?

    Regarding pricing, Qualys Enterprise TruRisk Management is a more costly product compared to what is available in the market. However, it does provide good features that justify the investment. My competitors, including Tenable, Rapid7, and other products, do not provide a good GUI function where I can actively track my vulnerabilities in real time. I always need to pull down a report in Excel and then work with the Excel file. With Qualys Enterprise TruRisk Management, I can work directly on the dashboard itself and ensure that all my servers are scanned within twenty-four hours or four hours according to my feasibility. Regarding its competitors in the market, I believe Qualys Enterprise TruRisk Management has a strong offering.

    The GUI in Qualys Enterprise TruRisk Management is excellent. Although it is quite elaborate and may require some navigation, it is very familiar and easy to use. Compared to other solutions, the GUI is superior.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have experience with competitors including Tenable, Nessus, and Rapid7. To be honest, they ask a high price, but they also provide certain functionality that other competitors do not. In the market, if you are pricing higher, that is what you can expect.

    How was the initial setup?

    Overall, the initial setup for Qualys Enterprise TruRisk Management is good and straightforward. I have taken the SaaS model and am not discussing the on-premises model. I am working with the SaaS model. Scanners and QGS need to be deployed on-premises, which is straightforward. I only need to build a server and deploy the ISO. Qualys provides the SaaS model itself. Overall, if I go with the SaaS model, I would not find much difficulty or hindrance.

    What about the implementation team?

    I set up Qualys Enterprise TruRisk Management on my own. It was not difficult. If I followed the official documentation, I could learn everything I needed. The process was straightforward.

    What's my experience with pricing, setup cost, and licensing?

    I rate the pricing of Qualys Enterprise TruRisk Management as high, giving it a six out of ten.

    What other advice do I have?

    Agentic AI is one of the models running in the background for Qualys. It is responsible for all vulnerability closures and vulnerability testing. All data collected by agents in the field is gathered and pushed into the Agentic AI model, which then processes that information and provides output based on proof of concept mechanisms or the MITRE ATT&CK pattern.

    Based on my understanding, I have not found any false positives in Qualys Enterprise TruRisk Management. There are some vulnerabilities that might not be applicable to my environment or that I do not want to address, but there have been no false positives in my environment. In the last three years, I have only seen one vulnerability for which the patch was not released, but that was also a true positive. The only issue was that the OEM did not release the patch for that particular vulnerability.

    My final score for Qualys Enterprise TruRisk Management is eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Roshan Ugale

    Comprehensive risk scanning has protected servers and improves monthly vulnerability remediation

    Reviewed on Jan 13, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I mostly work on Qualys Enterprise TruRisk Management. I work in an organization where I use cybersecurity to address cyber threats and system vulnerabilities. We focus on keeping the systems away from attackers, ensuring the system stays up to date and healthy, and increasing the performance of the system. For that purpose, we use Qualys Enterprise TruRisk Management.

    Qualys has multiple products, and the particular product we use is Qualys Enterprise TruRisk Management. As per your need, if you want to use Qualys Enterprise TruRisk Management for the assessment of vulnerabilities and only scanning, we use Qualys software for scanning the systems, taking out the report, taking out the remedies, and taking out the severity and compliances for these things. If someone wants to understand what purpose exactly they want to use Qualys Enterprise TruRisk Management for, it would be better to evaluate their needs. There are seven to eight other similar tools to Qualys Enterprise TruRisk Management, such as cybersecurity asset management, TruRisk management, vulnerability management, detection, and response. If they want to only take out the report for vulnerability management, detection, and response, that tool will be better. If they want compliance reports, remedies reports, severity reports, and everything that will impact their infrastructure, then Qualys Enterprise TruRisk Management will be better. Additionally, we can push the patch from Qualys Enterprise TruRisk Management to a particular system or server. If someone wants all things handled only by Qualys Enterprise TruRisk Management, they can go with the advanced version.

    What is most valuable?

    Qualys Enterprise TruRisk Management is quite good for analyzing and scanning the systems individually. It not only scans the system but also shows the hardware vulnerability as well. If there is any low hardware, for example, if there is one application running on DDR3 RAM, and the same application running on DDR4 RAM, it will show that this application will perform better on DDR4. It will be good or best to change your hardware. These kinds of things Qualys Enterprise TruRisk Management shows to us. For our infrastructure, it helps us understand how we can run our infrastructure smoothly without preventing any downtime. It also shows the remedies, such as how we can close those vulnerabilities, bugs, and loopholes if we find in our systems and infrastructure on our servers. It scans each and everything deeply. For example, if you just created a text file and you keep that file for one year, it will show you that file name, file path, and it will reflect as a vulnerability. It shows why this file was just left in your system for the last one year. Qualys Enterprise TruRisk Management is a very good software application to scan each and every vulnerability. Through that, it prevents the attackers from exploiting the systems, servers, or our data. It prevents data leaks in short.

    What needs improvement?

    Qualys Enterprise TruRisk Management has a few things that need to be enhanced. First, there is the issue of superseded patches. Superseded means if we miss the current month patch, for example, if we miss the January patch to deploy on a particular server, Microsoft includes January changes in the second month security patch, and then the second month security patch includes all things in March. For example, if we miss two month patches and we directly deploy the March month security patch on a system, the other two patches, such as January and February, will be closed. Superseded means these patches are not deployed on a system, but after the latest one, which we already deployed, the older one does not need to be installed or deployed on a system. Qualys Enterprise TruRisk Management takes a report of each and every vulnerability and shows that the January month patch was not deployed on a system and the February month patch was not deployed on a system. However, that is not a proper scanning method. If we have already deployed the latest patch that includes the older security things or older security parameters and the latest parameters, when we deploy that latest patch, why does Qualys Enterprise TruRisk Management show the older patches also in potential vulnerabilities? That is a main factor that should be improved from Qualys Enterprise TruRisk Management.

    Second, the remedies provided by Qualys Enterprise TruRisk Management are sometimes not useful most of the time. In that case, we need to troubleshoot or find out the remedies by ourselves. The remedies will also be something that needs to be improved in the system or in the application.

    What do I think about the stability of the solution?

    We did not analyze or monitor any issues in our stability, performance, or crashes.

    What do I think about the scalability of the solution?

    Qualys Enterprise TruRisk Management is scalable and flexible. It has multiple things for a particular need. For example, if we only want scanning, Qualys Enterprise TruRisk Management will provide that. Qualys Enterprise TruRisk Management has multiple products according to the infrastructure or the industrial demand. Whatever we choose as per our choice, we can choose, and in that application, such as Qualys Enterprise TruRisk Management that we use, we can add different plugins as well. It is flexible and scalable, and we can use it and modify it as per our needs.

    How are customer service and support?

    We have already done technical support for Qualys Enterprise TruRisk Management so many times. Since we use it daily, I know much more than the Qualys Enterprise TruRisk Management technical supporter sometimes in some things. I would give out of ten around seven out of ten.

    Which other solutions did I evaluate?

    As a product and solution, Qualys Enterprise TruRisk Management is one of the best I have ever seen. Another solution I would mention is BigFix. BigFix is quite popular, and I would place that one in the first position and Qualys Enterprise TruRisk Management in the second position. Regarding the rating, Qualys Enterprise TruRisk Management is also better, but most of the features and things are more in BigFix. According to me, I would give eight out of ten for Qualys Enterprise TruRisk Management for all its features.

    What other advice do I have?

    Qualys Enterprise TruRisk Management shows material impacts on security. For example, if we scan a UPI server from Qualys Enterprise TruRisk Management agent, it will show that if we are not going to update that UPI server, that UPI hardware, or that application, going forward, it will be risky to us. Anyone, even a small hacker, can exploit your server, lose your data, collect your data, and misuse it in a black market. Every parameter, small to small and high to high, each and every parameter Qualys Enterprise TruRisk Management identifies and shows in an alert way, functioning as a monitoring tool also. It shows the severity. If we are not going to close this vulnerability, then what will happen. Severity is there also. There are severity five, four, three, two, and one. If the severity is five, it is most critical, and that vulnerability needs to be closed as soon as possible.

    In the current place where I work, they have their own infrastructure with multiple servers. We usually get a monthly report of vulnerabilities. The vulnerability count around monthly is approximately twenty thousand, thirty thousand, or more every month. We get a report from the Qualys Enterprise TruRisk Management department showing what the vulnerabilities are. We need to find out the most potential vulnerability. Qualys Enterprise TruRisk Management shows that the most important things are operating system related criticality, application related, and third-party application related vulnerabilities. It aggregates the most potential criticality in a severity. Severity means how critical this vulnerability is. There are numbers from one to five, with five being the most critical vulnerability. When we get a report, there is a column as a criticality tier. We usually filter it out with tier five, so all the vulnerabilities that are the most potential come up. For example, if I filter out with the five-tier, it usually shows around the most potential vulnerability count of one thousand or two thousand. This is not only for one server. We manage around eight hundred to nine hundred servers. We get a report every month for all servers' vulnerabilities, and it is approximately thirty thousand plus. It shows each and every potential critical vulnerability. We found two or three for each server. If we want to patch or deploy that vulnerability on each server, we need to take downtime. We have limitations to patch the servers each day. For example, in one day, we can patch fifty servers. If we want to patch five hundred servers, within ten days, we close that potential vulnerability by taking downtime as per the scheduled time. Mostly we take downtime at night for the deployment and patching those vulnerabilities.

    Once we complete our side patching, as per the Patch Tuesday schedule when Microsoft releases their patches and security patches every second Tuesday, we do patches and close the vulnerability with the remedies Qualys Enterprise TruRisk Management shows you. After patching, we take a report and share with the security team that we have closed this vulnerability and kindly scan the servers for rescanning. After patching, we take a reboot, and then after reboot, we rescan the system. We ensure everything is as per the expectation or not, and we verify if the vulnerability is closed or not. We rescan all the systems, and after rescan, it shows the previous vulnerabilities are closed in our scanned system.

    Confidence comes when we do practical validation. If due to some vulnerabilities or some bugs or some loopholes, attackers attack the servers and successfully collect the data, we do the root cause analysis to understand why the server got compromised or data got compromised. In that case, we learn that the particular server has not been patched since the last one month, two months, or three months. Due to that, till now, this kind of attack has not happened in our infrastructure because we make sure that every month patches should be deployed on that particular server within one month, thirty days. It prevents the situation in which if Microsoft releases one security patch with some enhancement in security, we deploy that. It is not that a particular patch has total one hundred percent security enhancement. Every patch has a loophole and security enhancement both things. If we patch the system and after then, attackers will try to find out the loophole in that particular patch. But once they find the loophole, before that, the second patch will be released by Microsoft, and the second patch will be deployed on that particular server by the patching team. This is how all things work. The attacker will not get enough time. That is why monthly patching is most necessary. We call it patching or vulnerability management.

    Monitoring tools such as Zabbix provide real-time or active monitoring. Zabbix alerts provide alerts in different colors and criticality. For example, if there is one system that uses one hundred percent CPU utilization or memory usage, or disk space issue, these kinds of real environment monitoring will show. If you search some websites on Google, sometimes that website takes a long time to be visible on your device. That happens due to latency, and latency happens due to high memory utilization or RAM utilization. It is the time travel between the sender and receiver. When you send the request to the server, the server will give a response to you. The latency depends on read and write data. Zabbix is used for that. It enhances user experience, prevents downtime, and provides latest alerts. It monitors each and everything.

    My overall review rating for Qualys Enterprise TruRisk Management is eight out of ten.

    LuisPerez11

    Centralized monitoring has strengthened vulnerability control and automated preventive security

    Reviewed on Jan 11, 2026
    Review provided by PeerSpot

    What is our primary use case?

    When a company needs to review and focus on all the vulnerabilities for their endpoints from actualizations or patches and all the programs they have installed, they need actualizations or to have this function available regarding the main use cases for Qualys Enterprise TruRisk Management.

    What is most valuable?

    The best features of Qualys Enterprise TruRisk Management are the capability to search and mitigate vulnerabilities from attackers in endpoints and focus on the preventive view of organizational security through virtual patching, making this function automatic for cybersecurity teams.

    Qualys is a very good tool for companies, and the different tools this brand offers bring all the necessary tools for good development for these companies. Once it is set up, it works well.

    Qualys has a new tool called Total AI, which requires review of the use and correct use of AI in companies and review and protection of the information that collaborators use in AI.

    What needs improvement?

    When a customer does not have control over vulnerabilities or architecture and needs a solution that automates this function for the company, it can be difficult to identify the vulnerabilities.

    Because the case study is of the business model, I think identifying different vulnerabilities is not easy as companies need to be prepared to make decisions in time regarding what affects the business.

    I focus on areas that could be improved with Qualys Enterprise TruRisk Management.

    For how long have I used the solution?

    I have experience with Qualys for about one year.

    What do I think about the stability of the solution?

    This tool has good and excellent performance in the companies that we sell to in the last months for customers, so stability is evident.

    What do I think about the scalability of the solution?

    Qualys Enterprise TruRisk Management is a scalable solution.

    How are customer service and support?

    In the brand I work for, we have a very good team of many engineers who are prepared and certified with the levels of support for these tools from this brand, which helps me evaluate the customer service from Qualys or their technical support.

    The level of support is a nine out of ten.

    They provide very good support.

    Which solution did I use previously and why did I switch?

    We used Tenable before switching to Qualys for this type of threat management.

    Which other solutions did I evaluate?

    The main differences between Tenable and Qualys is the model that brands use to consume the product; the licensing or size is different between Tenable and Qualys.

    What other advice do I have?

    I speak a little English.

    I have experience with Check Point solutions and Microsoft solutions.

    I have a little experience with the product portfolio of Check Point, as I have worked with this brand in a product manager commercial profile.

    I sold a project two years ago about Check Point Harmony SASE or SASE product.

    In the last twelve months with Check Point, I have experience with the firewalls and Harmony Email, but not with SASE.

    With the Maestro lines, I have experience, but not with Quantum Force, as I have worked with Maestro and Harmony Email.

    With CrowdStrike, I have a little experience, something about five months.

    I have worked with Qualys Enterprise TruRisk Management and VMDR.

    In the cybersecurity view, I understand what is being said.

    I cannot understand the TrueConfirm capability or tool.

    I am not familiar with the term TrueConfirm for threat enrichment capability.

    Qualys is a reliable tool.

    It is beneficial so far because the market today needs to protect all these factors that use AI for taking confidential information from the company.

    My profile is more commercial, but I know about the deployment of these tools being easy for companies to be prepared for this; however, a good assessment is necessary to review the architecture of the customer for a good chronogram and good time for the development of these tools.

    For this tool, we do not need cloud deployment because it requires some server and deployment from the endpoints of the company, so I do not have this technical knowledge.

    Qualys has a good price for the benefits of the development of this tool.

    My overall rating for this review is nine out of ten.

    Vaibhav Ghule

    Continuous risk-based monitoring has strengthened incident response and vulnerability prioritization

    Reviewed on Jan 08, 2026
    Review from a verified AWS customer

    What is our primary use case?

    In my role, I work with Qualys VMDR as part of my responsibilities managing security operations and SecOps. I am currently a CrowdStrike administrator focused on EDR management, while my colleague serves as the Qualys administrator. Along with my responsibilities as a CrowdStrike administrator and EDR admin, I also serve as SOC Lead for the Security Operation Center. In this capacity, I need to navigate through all the tools in our security architecture to obtain details about any incidents or vulnerabilities that are detected. To accomplish this, I navigate through the CSAM and VMDR to check which devices have vulnerabilities present and how they are prioritized. I also check these details through True Risk in Qualys. These are the tools and features I navigate in the Qualys VMDR dashboard or portal when I log in.

    For my team, they have the use cases and necessary information readily available. Using Qualys VMDR is primarily to obtain vulnerabilities on the assets we have. Once they prioritize the vulnerabilities, I connect them with the MDM admins, which is InTune or JAMF. For Mac systems, we use JAMF, and for Windows systems, we use InTune. I function as a mediator between my Qualys team and the MDM team to get things done.

    We have been using the asset tagging and reporting features in Qualys VMDR. Qualys VMDR's continuous monitoring capabilities help us respond to emergent threats by enabling my team to reach out to the security engineers whenever there is any detection of a vulnerability, informing them about it, and creating an incident. We also work through the incident response phases. We identify the vulnerability and take necessary decisions on whether we need to patch or update software on which vulnerabilities are identified. If there are vulnerabilities regarding open ports or open services, we decide to block the exposed ports.

    The initial setup and onboarding process of Qualys VMDR was quite smooth. We were able to draft the SOPs from the documentation portal itself. Everything is available in the documentation, so it was not a hassle for us to get the integrations done on time.

    What is most valuable?

    From what I have seen and communicated with my team, True Risk is something that highlights separately. True Risk identifies which vulnerability needs patching, not solely based on the CVSS score. There could be vulnerabilities with higher CVSS scores, but it is not necessary to patch them on a priority basis. There could be others that need remediation despite having low CVSS scores. The prioritization from True Risk is what I appreciate the most.

    Qualys VMDR's continuous monitoring capabilities help us respond to emergent threats by enabling my team to reach out to the security engineers whenever there is any detection of a vulnerability, informing them about it, and creating an incident. We work through the incident response phases. We identify the vulnerability and take necessary decisions on whether we need to patch or update software on which vulnerabilities are identified. If there are vulnerabilities regarding open ports or open services, we decide to block the exposed ports.

    What needs improvement?

    I haven't explored Qualys VMDR's vulnerability lifecycle automation yet. One of my analysts mentioned that queries lack grouping operators in Qualys VMDR.

    From my experience, I would appreciate improvements in the query options in Qualys VMDR, specifically in the query-building process where I would need more features and operators. Additionally, we have been facing issues with Qualys on the cloud level. We cannot download the configuration profile from the cloud agent, and it is showing a pending action for download. During 2025, we noticed outages of Qualys a couple of times. I want to mention that there is an issue with receiving timely RCA deliveries. While this is not necessarily about the tool, it relates to support. The support has not been very responsive, and we are receiving RCAs a little delayed whenever we raise support cases or communicate with the TAMs.

    Additionally, the UI has a slight latency, which I and my team have experienced. They have also reported this latency issue when navigating through different pages.

    For how long have I used the solution?

    I have been working with Qualys VMDR for about one year.

    What do I think about the stability of the solution?

    During 2025, we noticed outages of Qualys a couple of times.

    How are customer service and support?

    The support has not been very responsive, and we are receiving RCAs a little delayed whenever we raise support cases or communicate with the TAMs. I would rate the tech support of Qualys a six because of the unsatisfactory experience we have experienced.

    Which solution did I use previously and why did I switch?

    Other than Qualys, I haven't worked on any other vulnerability management or asset management products. However, I will be getting the opportunity to work on CrowdStrike Spotlight and also on Rapid7 soon, which may help me identify certain things. I am not deployed in the role of SME right now, so I haven't explored the Qualys portal extensively. My main area is EDR, and I have explored CrowdStrike; I can provide comprehensive feedback about that product. Since we are discussing Qualys right now, I can ask my SME to join this discussion for a more detailed and proper review.

    How was the initial setup?

    The initial setup and onboarding process of Qualys VMDR was quite smooth. We were able to draft the SOPs from the documentation portal itself. Everything is available in the documentation, so it was not a hassle for us to get the integrations done on time.

    Which other solutions did I evaluate?

    I would recommend Qualys to other organizations, but I have heard from my seniors and leadership team that there is a cost factor which differentiates Qualys from other offerings. I haven't been involved in those calls where decisions are made about acquiring products, but I have heard it is more expensive than other tools in the market.

    What other advice do I have?

    I have some understanding about PeerSpot, and I have visited the website. PeerSpot is similar to TrustRadius. It takes reviews from customers or end users who are using the tools and technologies in the market, and then provides a total review of that tool.

    My team works with the Qualys TotalCloud and True Risk Management products, and they generate reports. As for hands-on experience with Qualys technologies, I navigate through the Qualys portal, and I only use CSAM and Qualys VMDR. Apart from that, I do not perform many other tasks in Qualys. I receive reports from my teammates who work in vulnerability management. They prioritize the vulnerabilities they have detected according to the workstation and servers, then they decide what to remediate and what to patch based on the priority.

    When I became SOC Lead, I also got the responsibility of administrator. Additionally, I have other responsibilities where I check on my teammates to ensure they are carrying out their tasks. I play a kind of team lead role. I receive reports from them about workstation vulnerabilities, server vulnerabilities, remediation and patching plans. I also check if the cloud agent is deployed in all the assets. My teammates deploy the scanner appliances and carry out the discovery scans and network scans. In my SIEM tool, I observe a log ingestion spike when the Qualys VMDR scanner appliance is running scans. This is also something I need to manage to tune it out when there are Qualys IPs and internal IPs assigned to the Qualys VMDR scanner appliance. These are some of the tasks I carry out day to day.

    Regarding the effectiveness of asset tagging in managing risk exposure, I haven't focused much in that area, but I see asset tagging as beneficial for us, similar to how we use tags in CrowdStrike. We have tags for all the different assets, which include site, cloud account, and department. It is easy for us to differentiate the assets based on those tags. Whenever we are creating groups and deploying policies or actions on those groups, we can use tags for separating them. That is the extent of my knowledge in this area for now.

    We haven't utilized Qualys VMDR's integration with threat intelligence feeds in our security architecture because we have our SIEM tool, which is centralized with integrated threat intelligence from CrowdStrike.

    I need to discuss the use of platform analytics in Qualys VMDR with my team to determine if they are using it. I can bring my Qualys SME into a discussion to provide feedback because he has been using Qualys for a very long time and has considerable expertise with the tool.

    What improvements would I suggest for this product? From what I have heard and seen, more clarity in group operations in query-building and resolving cloud agent download issues would be beneficial. For my experience, what were the initial challenges when using this product? The cloud level issues, especially during configuration profile downloads, stand out.

    I would rate this product an eight overall.

    reviewer2753559

    Reduces vulnerability exposure time and automates workflow for efficient security management

    Reviewed on Sep 03, 2025
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Qualys VMDR is to manage and remediate vulnerabilities and prioritize it based on the criticality score.

    I can give a quick, specific example of how I've managed and remediated vulnerabilities using Qualys VMDR: First of all, we use it to quickly detect critical vulnerabilities in the network environment, and apart from that, we are using it to apply patches directly through integrated patch management, which reduces exposure time and human efforts.

    I don't have anything else to add about my main use case or how I use Qualys VMDR at the moment.

    What is most valuable?

    The best features Qualys VMDR offers include built-in threat intelligence for prioritizing high-risk vulnerabilities and integrated patch management to remediate a vulnerability, providing coverage on the network level and on the OS level as well.

    Qualys VMDR has positively impacted my organization by reducing vulnerability exposure time through faster detection and patching, and it has improved compliance reporting with accurate and up-to-date data. It also lowered manual effort for the security team by automating workflow.

    One specific outcome I can share is that it has decreased by 30%.

    What needs improvement?

    One area where Qualys VMDR can be improved is the missing feature for deploying agents for over 1,000 assets, as we need to do it manually. Qualys doesn't have its own tool to deploy the agents all at once, so we need to use third-party tools such as BigFix or something else to deploy the agents, which is my main concern and should be fixed by the Qualys team.

    That is the main thing I would like to see changed, and apart from that, everything is good.

    For how long have I used the solution?

    I have been using Qualys VMDR for the past one year.

    What was my experience with deployment of the solution?

    We directly purchased Qualys VMDR from Qualys, not through the AWS Marketplace.

    What do I think about the stability of the solution?

    Sometimes we are facing downtime, but it is very rare, occurring once in a blue moon.

    Qualys VMDR is stable.

    What do I think about the scalability of the solution?

    Qualys VMDR's scalability is good, and the customer support is good, but sometimes the customer support occasionally delays in response more than expected.

    How are customer service and support?

    Qualys VMDR's scalability is good, and the customer support is good, but sometimes the customer support occasionally delays in response more than expected. I would rate the customer support an eight.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We didn't use any solution before Qualys.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing shows that we can consider both time and money saved.

    The detail I can share is that it is around 30 to 40%.

    What was our ROI?

    One specific outcome or metric I can share is that it has decreased by 30%.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing shows that we can consider both time and money saved.

    Which other solutions did I evaluate?

    Before choosing Qualys VMDR, we didn't evaluate any other options.

    What other advice do I have?

    I would advise others looking into using Qualys VMDR to make sure that Qualys is compatible with your network, and please ensure that all the configurations are in place before proceeding.

    I wasn't offered any gift card or incentive for this review.

    On a scale of 1-10, I rate Qualys VMDR a 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Nabanita Roy

    Strong report clarity and efficient deployment but customer support needs faster resolution

    Reviewed on May 22, 2025
    Review provided by PeerSpot

    What is our primary use case?

    My main use cases for Qualys VMDR are for server vulnerability and missing patches.

    What is most valuable?

    The most helpful and useful features of Qualys VMDR are its user-friendly design.

    Qualys VMDR is easy to understand and provides detailed reports.

    It impacts my workflow overall, with the patch management features as it has the missing patches listed in detail, making it easier to get a comprehensive report and providing some dashboards that offer visual representation.

    What needs improvement?

    There were some issues later with Qualys VMDR regarding security, specifically with numerous false positive reports.

    What was my experience with deployment of the solution?

    It doesn't take much time to deploy Qualys VMDR. There is a process mentioned already on the website about how to proceed with the installation, so we followed that process.

    How are customer service and support?

    I am satisfied with the support of Qualys VMDR as they are supportive. However, there are sometimes issues where we cannot talk to customer support directly, and we have to raise tickets, which sometimes takes a lot of time to resolve issues because it goes through their own phase. We cannot change the SLA or the priority of the tickets, so that is an issue.

    Which other solutions did I evaluate?

    Our organization changed to something else due to a higher management decision, and that might be the reason for the change regarding the pricing.

    What other advice do I have?

    We are not using any AI features with Qualys VMDR.

    Overall, I would rate Qualys VMDR as good, giving it an eight.

    reviewer2588394

    User-friendliness and effective prioritization improve remediation efforts

    Reviewed on Mar 05, 2025
    Review provided by PeerSpot

    What is our primary use case?

    We use Qualys VMDR for daily vulnerability management, scanning vulnerabilities, identifying vulnerabilities, reporting, creating dashboards, and the whole vulnerability management process. We also use it for patch management.

    What is most valuable?

    What I find valuable about Qualys VMDR is the capability of the tool and its user-friendliness. It is easy to use and provides accurate results, which is exactly what we are looking for. The prioritization of vulnerabilities has improved our remediation efforts by around thirty to thirty-five percent. The tool's integration between Patch Management and other Qualys products is also indispensable.

    What needs improvement?

    They can tweak their UI since the new version seems a bit jumbled up, and the old UI was more user-friendly.

    For how long have I used the solution?

    I have been using Qualys VMDR for three years.

    What do I think about the stability of the solution?

    We find Qualys VMDR quite stable and have not faced any performance issues with it.

    What do I think about the scalability of the solution?

    I believe the solution is scalable.

    How are customer service and support?

    We usually get on calls with tech support, and they are very helpful. I would rate the technical support a nine out of ten.

    Which solution did I use previously and why did I switch?

    We worked with Nessus and Rapid7 before switching to Qualys VMDR. Qualys offers better pricing and more features compared to other tools. We did not find anything particularly missing from previous tools.

    How was the initial setup?

    The setup is straightforward and easy. We deployed scanners and agents on all our devices, configured the network, whitelisted policy scanners, and public URLs. Testing was conducted before deploying, and it went smoothly.

    What about the implementation team?

    We had a team of five to six people involved in the deployment aspect due to the large number of assets.

    What was our ROI?

    Qualys VMDR helps us be compliant, and vulnerability management is a crucial part of maintaining our organization's security, significantly contributing to ROI.

    What's my experience with pricing, setup cost, and licensing?

    Qualys offers better pricing and is feature-packed compared to other tools.

    Which other solutions did I evaluate?

    We evaluated Nessus and Rapid7 before choosing Qualys VMDR.

    What other advice do I have?

    I would recommend getting both VMDR and the Cloud Agent to ensure comprehensive asset coverage. Understanding the network architecture is crucial to ensure no segments are missed under Qualys. Overall, I rate Qualys a nine out of ten.

    Ankesh Raj

    Real-time responses and reporting streamline vulnerability management

    Reviewed on Dec 04, 2024
    Review provided by PeerSpot

    What is our primary use case?

    We mostly use Qualys VMDR for vulnerability management and compliance practices. Every week, my team and I run automated scans that are scheduled, and we share whatever vulnerabilities are found with the infrastructure team to remediate them.

    What is most valuable?

    Qualys VMDR provides a real-time response and reporting feature, which is excellent. It allows us to see real-time graphs and reports for every asset, server, and more, which is very user-friendly.

    Our clients have given good feedback, and they are satisfied with the tool. We use it daily to fix vulnerabilities by connecting with infrastructure to remediate. The feedback from the client side is very good.

    What needs improvement?

    Regarding improvement, compliance features haven't been utilized much. I anticipate more benefits in this area in the future. Integrating other teams, such as GRV, with Qualys would be very beneficial.

    Additionally, if AI features were integrated, it could enhance the capabilities significantly.

    For how long have I used the solution?

    I have been using Qualys VMDR for about six months. I started working in vulnerability management with my company in the SOC.

    What do I think about the stability of the solution?

    I haven't experienced any downtime during my working hours. However, there might be times when it could go down. I would rate stability around 8.5 or nine out of ten.

    What do I think about the scalability of the solution?

    Qualys VMDR can handle scalability, although increasing the inventory can raise the licensing costs. However, it can escalate and adapt to many needs if required.

    How are customer service and support?

    Customer support is satisfactory. When reaching out via email, they reply quickly. I would rate their customer support eight out of ten.

    Which solution did I use previously and why did I switch?

    I have used another vendor for a different client, which is Rapid7. However, I found Rapid7 not as user-friendly as Qualys. The console is less user-friendly, and running sample templates or scans is more complex compared to Qualys.

    What's my experience with pricing, setup cost, and licensing?

    I am not aware of the exact pricing, as it comes as an MSP model from the client. However, I have a notion that Qualys might be more expensive than Rapid7.

    Which other solutions did I evaluate?

    I have evaluated Rapid7 along with Qualys. In a rating out of five, I would give Qualys four and Rapid7 two, as Rapid7 is more complex and not as user-friendly.

    What other advice do I have?

    I would recommend Qualys VMDR to others comparing it with other VM tools, due to its valuable features, including real-time responses and detailed reporting.

    Overall, I would rate Qualys eight out of ten. With potential improvements and AI integration, it could offer even more.