Qualys review: Features, pricing, and what to know before you commit

Updated on 09 Sep 2026
18 min read
AppSec

Qualys is a cloud based security and compliance company built around its Enterprise TruRisk Platform, a SaaS foundation that runs a set of separately licensed applications: vulnerability management (VM), vulnerability management, detection, and response (VMDR), web application and API testing (WAS, increasingly superseded by TotalAppSec), and cloud security posture management (TotalCloud). There’s no single “Qualys” purchase. Which of these apps you’re actually using determines what the platform can do for your team.

This review covers those four areas as they stand in September 2026, including what’s changed since Qualys began pushing harder into AI assisted scanning, unified API security, and cloud native workload protection over the past year. It’s written for security teams, AppSec practitioners, and technology decision makers evaluating whether Qualys fits their environment, not for existing Qualys customers looking for a features list they already know.

How we put this blog together
This article is based entirely on publicly available sources. We aggregated user reviews from G2, Capterra, and similar trusted sources, drew on discussions from Reddit communities, and reviewed vendor documentation and feature pages. Rather than proprietary testing, our evaluation reflects the collective experience of security practitioners who have shared their insights publicly.

TL;DR: Qualys review

Qualys is a broad, enterprise grade security platform built for organizations that need vulnerability management, web and API security testing, and cloud posture visibility from a single vendor. Its TruRisk approach layers threat intelligence and exploitability context on top of raw CVSS scores, which genuinely helps teams work through large vulnerability backlogs.

The trade offs show up in cost predictability and interface complexity. Qualys doesn’t publish pricing, so budgeting requires a sales conversation, and multiple review platforms consistently flag a real learning curve for new users, particularly during initial setup.

G2 ratingsWAS 4.5/5 (20 reviews), VM 4.0/5 (23 reviews), VMDR 4.4/5 (166 reviews), Cloud Security Assessment 4.4/5 (19 reviews)
Best suited forEnterprises needing unified vulnerability management, cloud posture, and compliance reporting across hybrid environments
CoverageVulnerability management, web application and API scanning, cloud security posture (CNAPP), patch management, compliance
Pricing modelQuote based, depending on which Cloud Platform Apps you select plus network address count, web application count, and user licenses
Key strengthsTruRisk based prioritization beyond CVSS, agentless multi cloud coverage, automated patch orchestration, strong compliance reporting
Key trade offsNo public pricing, meaningful setup and learning curve, WAS itself is now in maintenance mode with new capability moving to TotalAppSec

Reviewers consistently point to Qualys VMDR’s asset visibility and risk based prioritization as genuine strengths, and several specifically call out the value of seeing vulnerability, patch, and threat data in one workflow rather than three separate tools. The most common criticism across VM, VMDR, and WAS reviews is interface complexity during initial configuration, not a missing capability.

Key features of Qualys

Qualys WAS (web application scanning)

Qualys WAS is Qualys’s DAST module, scanning web applications and APIs for vulnerabilities including OWASP Top 10 issues like SQL injection and XSS. It supports authenticated scanning through recorded login sequences and other authentication methods, scheduled and on demand scans, and can import manual testing results from tools like Burp Suite and ZAP to combine automated and manual findings in one view.

What matters for a 2026 evaluation: Qualys has stopped adding new features to WAS. According to Qualys’s own documentation, WAS now receives critical bug fixes only, and all new development, unified API security, AI powered scan optimization, deep learning based web malware detection, ships in TotalAppSec instead. If you’re evaluating Qualys for web application testing today, TotalAppSec is the product actually being developed, not WAS.

G2 rating:

4.5 out of 5, based on 20 reviews. Recent reviews highlight ease of use and integration with the broader Qualys platform. Business logic coverage and report analysis complexity come up as recurring criticisms in independent review platforms, alongside pricing.

Qualys VM (vulnerability management)

Qualys VM is the foundational scanning module: continuous, automated vulnerability detection across networked assets, servers, workstations, network devices, and peripherals. It scans externally to assess internet facing perimeter devices and internally through Qualys Scanner Appliances or Cloud Agents, giving visibility across both attack surfaces from one console.

Calling VM “just a scanner” undersells it somewhat. Asset tagging, customizable dashboards, and reporting by host, severity, or vulnerability type are all part of the base module, and the same Scanner Appliance and Cloud Agent infrastructure feeds directly into VMDR if you later add that layer. It’s the detection foundation the rest of the platform builds risk management on top of.

G2 rating:

4.0 out of 5, based on 23 reviews. Recent reviews describe continuous scanning and risk prioritization as strengths, alongside criticism of scan and report speed, limited customization for filtering results, and a learning curve for new users.

Qualys VMDR (vulnerability management, detection, and response)

VMDR is where Qualys’s platform argument actually plays out. It combines asset discovery, continuous vulnerability scanning, TruRisk based prioritization, and remediation workflows into one product rather than three separately purchased tools you’d have to stitch together.

The remediation side is what distinguishes VMDR from basic scanning. It correlates detected vulnerabilities against available vendor patches, supports no code automated remediation workflows for pushing those patches, and integrates with ITSM platforms like ServiceNow and Jira so a finding can become a tracked ticket without manual handoff. Security configuration assessment runs alongside vulnerability scanning to catch misconfigurations, not just missing patches. For a team managing thousands of assets across hybrid infrastructure, that closed loop from detection to ticket to patch is the actual value proposition, not the scanning itself.

G2 rating:

4.4 out of 5, based on 166 reviews, one of the larger and more reliable samples among Qualys’s product lines. Recent reviews consistently cite risk based prioritization, asset visibility, and ITSM integration as strengths, with interface complexity during setup as the main recurring criticism.

Qualys cloud security (TotalCloud)

What the platform originally sold as “Cloud Security Assessment” has grown into TotalCloud , a full cloud native application protection platform (CNAPP) covering cloud security posture management, cloud workload protection, SaaS security posture management, infrastructure as code security, cloud detection and response, container and Kubernetes security, cloud infrastructure entitlement management, and data security posture management, correlated through the same TruRisk scoring used elsewhere on the platform.

TotalCloud now scans AWS, Azure, GCP, and Oracle Cloud Infrastructure agentlessly, meaning it doesn’t require installing an agent on every workload to get visibility, and it recently extended posture management to AI and ML workloads specifically, checking generative AI infrastructure against the same security baselines as traditional cloud resources. Qualys TotalCloud achieved FedRAMP High authorization in May 2026, which matters specifically for government agencies and contractors with strict compliance requirements.

G2 rating:

4.4 out of 5, based on 19 reviews, listed under Qualys’s legacy “Cloud Security Assessment” product name even though TotalCloud is the actively developed product today. Recent reviews describe solid vulnerability coverage and detailed reporting for AWS and Azure environments, with user experience and navigation cited as weaker points compared with newer, cloud native competitors.

Qualys in 2026: What’s changed?

Two structural shifts matter most for anyone evaluating Qualys this year. First, WAS has effectively been retired for new development in favor of TotalAppSec, which unifies web application scanning with API security (including OWASP API Top 10 coverage) and adds AI powered scan optimization and deep learning based malware detection for client side threats like malicious JavaScript injections. If your last look at Qualys was WAS as a standalone product, the current offering is meaningfully broader.

Second, TotalCloud has moved well past posture scanning into a full CNAPP, adding agentless coverage across a fourth major cloud provider, AI and ML workload security controls, and FedRAMP High authorization for regulated environments.

Qualys has also taken a clear public position on AI coding assistants like Claude Code Security and OpenAI’s Codex Security: it argues that reasoning based code analysis, however capable, only covers the source code layer, and that real application risk lives just as much in exposed APIs, runtime misconfigurations, and forgotten internet facing assets. That’s less a product feature than a stated rationale for why Qualys continues investing in attack surface discovery and runtime testing rather than treating AI code review as sufficient on its own.

Pros of Qualys

  • TruRisk goes beyond CVSS without overpromising on business context

TruRisk layers real world exploitability, threat intelligence, and asset criticality on top of raw CVSS scores to help prioritize a large vulnerability backlog. It’s a genuine improvement over sorting purely by CVSS severity, though it’s a prioritization aid, not a system that fully understands your organization’s specific business risk. Teams still need to validate that the highest TruRisk scores actually align with what matters to their environment.

  • Detection, patching, and ticketing in one closed loop

VMDR’s integration between vulnerability detection, automated patch remediation, and ITSM platforms like ServiceNow means a finding can move from discovery to an assigned, tracked ticket without someone manually bridging three separate tools. That operational integration is a specific, measurable time saver for teams managing vulnerability response at scale.

  • Agentless multi cloud coverage that keeps pace with provider changes

TotalCloud’s agentless scanning across AWS, Azure, GCP, and now OCI means new cloud accounts and workloads get visibility without a separate agent deployment project, and Qualys has kept pace with adding coverage for AI and ML workloads as that becomes a real part of typical cloud estates.

  • Compliance reporting built for audits, not just dashboards

Built-in monitoring against frameworks like PCI DSS and HIPAA, combined with FedRAMP High authorization for TotalCloud, gives regulated organizations audit ready documentation without a separate compliance tool.

Cons of Qualys

  • No public pricing, and no way to estimate cost without a sales call

Qualys’s own pricing page confirms cost depends on which Cloud Platform Apps you select plus your network address count, web application count, and user licenses, but provides no actual figures. Budgeting requires engaging sales, which is a real friction point compared with vendors that publish at least indicative pricing.

  • A genuine learning curve, especially during initial setup

This isn’t a single disgruntled reviewer’s opinion. It shows up consistently across VM, VMDR, and WAS reviews on multiple platforms: new users find the interface complex to navigate during onboarding and initial scan configuration. Teams without prior Qualys experience should budget real ramp up time, not expect a same day setup.

  • WAS itself is past its development lifecycle

If your evaluation is specifically about WAS as a standalone product, know that it’s in maintenance mode. Business logic coverage gaps mentioned in reviews are unlikely to be addressed in WAS directly, since Qualys’s own roadmap has moved that investment to TotalAppSec.

  • TruRisk reduces noise but doesn’t eliminate the need for tuning

TruRisk genuinely does more than raw CVSS scoring, but a large hybrid environment will still generate a meaningful volume of findings that need scope, policy, and asset criticality tuning to keep the highest priority list actually manageable. Teams expecting a fully automatic, zero configuration prioritization experience will still hit a real tuning phase.

  • Platform depth can exceed what a smaller team actually needs

Because Qualys’s value comes from correlating detection, patching, and cloud posture across a large environment, a small team managing a handful of applications may find the platform’s breadth, and its associated cost and complexity, more than the job requires compared with a narrower, purpose built tool.

Qualys pricing

Qualys doesn’t publish list pricing. Its official subscriptions page states that cost depends on which Cloud Platform Apps you select, plus the number of network addresses (IPs), web applications, and user licenses in your environment. Getting an actual number requires a quote from Qualys sales.

Third party pricing guides, cited with that caveat rather than as confirmed Qualys figures, commonly describe:

  • Qualys VMDR: in the range of $199 to $250 per asset per year

  • Qualys WAS: around $1,995 per year for 25 web applications

  • TotalCloud and Patch Management: custom pricing with no consistent third party benchmark available

A free trial is available directly through Qualys for teams that want to evaluate the platform before a sales conversation. Because pricing scales with asset count, application count, and which modules you license, organizations evaluating more than one Cloud Platform App should ask for a combined quote up front rather than pricing modules independently, since the combined total is what actually determines total cost of ownership.

Summing up: Qualys review

Qualys earns its reputation as a mature, enterprise capable security platform. VMDR’s closed loop from detection through prioritization to remediation, TotalCloud’s agentless multi cloud coverage, and the platform’s compliance reporting are real strengths for organizations managing a large, hybrid environment under real regulatory pressure. The shift from WAS to TotalAppSec and TotalCloud’s continued expansion show Qualys investing seriously in the parts of the platform that were genuinely behind a few years ago.

The honest trade off is that none of this is quick or free to adopt. Pricing requires a sales conversation to understand at all, the interface has a real learning curve that shows up consistently across independent reviews, and a team that only needs one layer, say, web and API testing, may find the full platform more than the job calls for.

Qualys makes the most sense for organizations that need vulnerability management, cloud posture, and compliance reporting unified under one vendor, with the internal capacity to work through the setup. For a team whose primary need is fast, developer friendly web and API security testing without adopting a broader infrastructure platform, a more focused tool may fit day to day workflows better. Beagle Security, for instance, is built around agentic AI driven testing for web applications and APIs with native GraphQL support and reporting that surfaces directly in developer workflows, aimed at teams that want that specific layer covered without standing up an enterprise vulnerability management platform. Start your 14 day free trial or explore the to see whether that fits better than Qualys for your team’s specific need.

FAQ

What is Qualys used for?

Qualys is used for vulnerability management, web application and API security testing, cloud security posture management, and compliance monitoring across on premise, cloud, and hybrid environments, unified through its Enterprise TruRisk Platform.

Is Qualys a DAST tool?

Partly. Qualys WAS provides DAST capabilities for web application and API scanning, though it’s now in maintenance mode. Qualys TotalAppSec is the actively developed product for web and API security testing today, adding unified API security and AI assisted scanning on top of what WAS offered.

What is Qualys TruRisk?

TruRisk is Qualys’s risk based prioritization approach. It combines vulnerability severity with real world threat intelligence, exploitability, and asset criticality to help teams focus remediation on what poses genuine risk, rather than relying on CVSS scores alone. It’s a prioritization framework, not a system that fully models an organization’s unique business context.

How much does Qualys cost?

Qualys doesn’t publish pricing. Cost depends on which Cloud Platform Apps you license plus your network address count, web application count, and user licenses, and requires a quote from Qualys sales. Third party estimates place VMDR around $199 to $250 per asset per year and WAS around $1,995 per year for 25 applications, though these aren’t official figures.

What is the difference between Qualys VM and VMDR?

Qualys VM handles continuous vulnerability detection and scanning, the foundational layer. VMDR builds on that same detection with TruRisk based prioritization, automated patch remediation, and ITSM integration, turning detection into a full response workflow rather than a scan report you act on manually.

Sufiyan Said Sha
Written by
Cyber Security Engineer

Sufiyan once spent an entire lunch break trying to prove he was right about something nobody else cared about. Guess what, he was right. Unfortunately, everyone else had already moved on. That stubborn attention to getting things right now comes in handy in cybersecurity, where he spends his days uncovering vulnerabilities and making applications harder to break.

Pooja B
Reviewed by
Product Marketing Specialist

Pooja believes a good outfit can fix a bad day, and a good story can fix a boring topic. Between chasing creative ideas, styling things just right, and convincing herself one more edit won't hurt, she spends her days creating content at Beagle, turning creative energy into blogs, social posts, and stories that bring cybersecurity closer to people.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo