• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • No categories available

      Browse All Categories

      Select a category to view markets

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In

Overview

Product Information on Qualys VMDR

Updated 13th October 2025

What is Qualys VMDR?

Qualys VMDR is a software that integrates vulnerability management, detection, and response capabilities into a single platform. The software enables organizations to identify assets across their environment, detect vulnerabilities, prioritize threats based on risk, and automate remediation workflows. Qualys VMDR assists in maintaining visibility by continuously scanning systems for potential security risks and providing actionable insights to address them. The software supports compliance efforts by helping users document security controls and produce audit-ready reports. By streamlining the processes of vulnerability assessment, threat detection, and response, Qualys VMDR aims to help organizations reduce security risks and improve operational efficiency in managing their IT infrastructure.

Qualys VMDR Pricing

Qualys VMDR software uses a subscription-based pricing model, typically determined by the number of assets or endpoints managed. Pricing can vary depending on the chosen features, modules, and asset quantities, with additional charges for extended services or optional add-ons. The software is generally offered in tiered plans designed to scale with organizational requirements.

Overall experience with Qualys VMDR

Manager
250M - 500M USD, IT Services
FAVORABLE

“Qualys is powerful vulnerability tool for any application and network system.”

4.0
Apr 24, 2026
Qualys is a Powerful vulnerability tool to monitoring any kind of web application and it provides the detailed report bases on PCI severity. I like the explanation against each vulnerability and how to address it.
Senior Technical Lead
500M - 1B USD, IT Services
CRITICAL

“Qualys - A product that could have been great.”

2.0
Nov 10, 2025
Qualys VMDR is strong when it comes to detection and assessment, but my experience has highlighted several limitations that impact efficiency and customer experience. What works well - Comprehensive vulnerability scanning: It does a good job of exposing vulnerabilities across environments and provides a solid foundation for your security posture. - Cloud-based platform: no need for on-premise appliances which simplifies deployment and maintenance - Integration with patch management: the ability to link vulnerabilities with patching is useful and automated jobs can be configured to support assets Challenges and pain points - Limited 3rd party application patching coverage. It says it works, but it doesn't. MS patches, however, work fine. - Reporting burden: reports are not intuitive and require manual formatting. Preparing a report for a customer can take hours. The reports are very Windows 2000 style. - Accuracy concerns: vulnerability counts are inflated. A single outdated app can generate hundreds of entries even when superseded updates are ignored. - Performance issues: The platform is... SLOW!. After 5pm UK time it grinds to a halt and checks take between 4-8 hours. - Licensing complexity: Patching licenses are separate to VMDR which adds admin overhead and can lead to activation issues if not calculated correctly. Support is terrible. P1 first response can take weeks.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Peer Discussions

Recommended Gartner Insights

  • Market Guide for Vulnerability Assessment

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.

  1. Home
  2. /
  3. Qualys VMDR
Logo of Qualys VMDR

Qualys VMDR

byQualys
in Vulnerability Assessment
4.4

About Company

Company Description

Updated 25th July 2024

Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices.

Company Details

Updated 26th February 2025
Company type
Public
Year Founded
1999
Head office location
Foster City, United States
Number of employees
1001 - 5000
Website
https://www.qualys.com

Do You Manage Peer Insights at Qualys?

Access Vendor Portal to update and manage your profile.

Qualys VMDR Likes & Dislikes

Like

Qualys does a great job of detecting the network/Application vulnerabilities. To Become PCI compliant, Qualys does the job by checking and spot out the necessary changes needs to be done to prevent hijacking and to protect your data.

Like

Comprehensive vulnerability detection Provides deep visibility across systems and applications, helping identify potential risks quickly and thoroughly. Cloud Based Architecture No need for on-premise appliances Integration for Vulnerability detection and patch management - We can view the reasons and where a vulnerability is detected in order to take action

Like

We like the freedom Qualys provide like Run and pause the scans anytime, Agents cover 4hrs health checks. Reporting view is easy to understand

Dislike

Scanning takes a lot of time however its depending upon the bandwidth and resources available for the scan and it needs to improve the UI interface. Reports having too much information better if we can customize it.

Dislike

Support teams have slow response times. The product says it can do xyz (patch certain applications), but it can't. The reports are very Windows 2000.

Dislike

False positive report can be minimize. Sometime Loading of data can takes minutes to see.

Top Qualys VMDR Alternatives

Qualys VMDR Reviews and Ratings

User Sentiment About Qualys VMDR
Reviewer Insights for: Qualys VMDR
Performance of Qualys VMDR Across Market Features
Logo of InsightVM
1. InsightVM
4.3
(743 Ratings)
Logo of Tenable Nessus
2. Tenable Nessus
4.6
(658 Ratings)
Logo of Tenable Vulnerability Management
3. Tenable Vulnerability Management
4.6
(336 Ratings)
View All Alternatives
Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • Senior Technical Lead
    50M-1B USD
    IT Services
    Review Source

    Qualys - A product that could have been great.

    2.0
    Nov 10, 2025
    Qualys VMDR is strong when it comes to detection and assessment, but my experience has highlighted several limitations that impact efficiency and customer experience. What works well - Comprehensive vulnerability scanning: It does a good job of exposing vulnerabilities across environments and provides a solid foundation for your security posture. - Cloud-based platform: no need for on-premise appliances which simplifies deployment and maintenance - Integration with patch management: the ability to link vulnerabilities with patching is useful and automated jobs can be configured to support assets Challenges and pain points - Limited 3rd party application patching coverage. It says it works, but it doesn't. MS patches, however, work fine. - Reporting burden: reports are not intuitive and require manual formatting. Preparing a report for a customer can take hours. The reports are very Windows 2000 style. - Accuracy concerns: vulnerability counts are inflated. A single outdated app can generate hundreds of entries even when superseded updates are ignored. - Performance issues: The platform is... SLOW!. After 5pm UK time it grinds to a halt and checks take between 4-8 hours. - Licensing complexity: Patching licenses are separate to VMDR which adds admin overhead and can lead to activation issues if not calculated correctly. Support is terrible. P1 first response can take weeks.
  • Manager
    50M-1B USD
    IT Services
    Review Source

    Qualys is powerful vulnerability tool for any application and network system.

    4.0
    Apr 24, 2026
    Qualys is a Powerful vulnerability tool to monitoring any kind of web application and it provides the detailed report bases on PCI severity. I like the explanation against each vulnerability and how to address it.
  • IT SECURITY & RISK MANAGEMENT ASSOCIATE
    50M-1B USD
    Banking
    Review Source

    Dashboard Offers Clarity While False Positives in Reports Remain a Concern

    5.0
    Nov 20, 2025
    Dashboard view is one the best in market. Report generation is also easy and understandable
  • IT ASSOCIATE
    50M-1B USD
    Banking
    Review Source

    Vulnerability Management: Proactive Defense via Identification and Prioritization

    5.0
    Dec 3, 2025
    Vulnerability Management is a user friendly platform. it is a preventative control to identify vulnerabilities in critical servers
  • Chief Information Security Officer
    <50M USD
    IT Services
    Review Source

    Product Fully Meets Testing Needs With Responsive Sales And Technical Support

    4.0
    Apr 21, 2026
    Good response from the sales and technical team to help us trial, review and decide to purchase.
...
Showing Result 1-5 of 548

4.4

(525 Ratings)

Rating Distribution

5 Star
46%
4 Star
45%
3 Star
7%
2 Star
2%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.4

Integration & Deployment

4.4

Service & Support

4.2

Product Capabilities

4.5