shouldiuse.io

Categories

VERDICT

Qualys Review

Depends

Should I use Qualys?

Discover how Qualys helps your business measure & eliminate cyber threats through a host of cybersecurity detection & remediation tools. - qualys.com

· 17 hours ago

Buy if you're a large organization with dedicated security staff, compliance demands, and budget for enterprise tooling. Small teams and startups should skip it — simpler, cheaper scanners do the job.

Confidence

High. Based on 20+ public sources: G2, Gartner, Reddit, NVD, news coverage, and official Qualys pages. Some source snippets were truncated.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Not disclosed

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed

Best for

  • Large enterprises with dedicated SecOps
  • Compliance-heavy orgs (PCI, government)
  • MSPs scanning many client environments
  • Mixed on-prem plus cloud estates

Not for

  • Small teams needing only occasional scans
  • Startups without dedicated security staff
  • Anyone who can't stomach enterprise pricing
  • Teams expecting responsive, hands-on support

Gotchas - check before you buy

high

No public pricing; Reddit buyers struggle to pin down Nessus/Qualys costs

high

Support complaints are common enough to have their own dedicated Reddit thread

medium

False positives add triage overhead for lean teams

medium

Competitors pitch flat-priced self-hosted VMDR alternatives — a signal buyers chafe at Qualys licensing

Pros and cons

Pros

  • Gartner reviewers call it a powerful vulnerability assessment tool
  • Rated 4+ across 256 G2 reviews
  • Broad platform: vulnerability, web app, cloud, and patch coverage in one
  • Trusted by more than 10,000 subscriber organizations
  • Offers 24/7 support for subscribers

Cons

  • Poor support is a recurring user complaint
  • Described as very expensive versus rivals
  • False positives noted in head-to-head comparisons
  • Implementations commonly require paid consulting services

Sources & method

- 12 sources - No open platform CVEs surfaced here, but Qualys itself was breached twice — 2021 Accellion FTA, 2025 Salesloft Drift supply-chain attack — plus a CVE in its own cloud agent.

official x2review x7security x2news x1
  • Accellion FTA data breach (2021), Qualys confirmed a data breach related to Accellion file-transfer software.
  • Salesloft Drift supply-chain attack (Sept 2025), Qualys was hit in the Salesloft Drift hack and confirmed a data breach; Tenable was also targeted.
  • CVE-2022-29550 (Qualys Cloud Agent), NVD lists CVE-2022-29550, a vulnerability affecting Qualys Cloud Agent software. See NVD entry for full details.

Key stats

  • Value for money: 2/5

    Rating

  • Not disclosed

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 2/5. Users call it very expensive
  • Ease of use: 3/5. Implementations often need consulting services
  • Feature depth: 4/5. Powerful scanner, broad platform modules
  • Support quality: 2/5. Dedicated Reddit threads complain
  • Security posture: 2/5. Two vendor breaches; agent CVE
  • 4+/5 G2 rating 256 reviews on G2
  • 10,000+ Customers subscriber organizations, per Qualys
  • NASDAQ: QLYS Listed publicly traded
  • 2001 Selling since first network VA product release

Pricing

Not disclosed

Security

No open platform CVEs surfaced here, but Qualys itself was breached twice — 2021 Accellion FTA, 2025 Salesloft Drift supply-chain attack — plus a CVE in its own cloud agent.

  • Accellion FTA data breach (2021)Qualys confirmed a data breach related to Accellion file-transfer software.⁸
  • Salesloft Drift supply-chain attack (Sept 2025)Qualys was hit in the Salesloft Drift hack and confirmed a data breach; Tenable was also targeted.⁹
  • CVE-2022-29550 (Qualys Cloud Agent)NVD lists CVE-2022-29550, a vulnerability affecting Qualys Cloud Agent software. See NVD entry for full details.10

What users say

Reviewers credit Qualys with deep scanning and broad coverage but frequently cite high cost, false positives, and weak support.

“Qualys is very expensive”
Reddit, r/cybersecurity
“Is everyone's support experience with Qualys this bad?”
Reddit, r/qualys (thread title)

Alternatives

Compare Qualys with each alternative.

  • Tenable / Nessus

    The perennial rival; compare pricing hard before choosing.

  • OpenVAS

    Free, open-source scanning for tight budgets.

  • Wiz

    Cloud-native alternative rated 4.7/5 on G2.

    Qualys vs Wiz

Companies that use it

  • Cisco
  • UC San Diego
  • University of Illinois
Full analysis

Based on 20+ public sources: G2, Gartner, Reddit, NVD, news coverage, and official Qualys pages. Some source snippets were truncated.

Enterprise vulnerability management: powerful and broad, but pricey, complex, with recurring support complaints. Overkill for small teams.

Methodology

Based on 20+ public sources: G2, Gartner, Reddit, NVD, news coverage, and official Qualys pages. Some source snippets were truncated.

Read how a report is made.

Sources

  1. review
  2. review
  3. review
  4. review
  5. review
  6. review
  7. review
  8. security
  9. news
  10. security
  11. official
  12. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.