Softwr
Qualys VMDR logo

Qualys VMDR

Cloud-delivered vulnerability management licensed per asset, using scanner appliances and a lightweight agent.

As of 30 August 2026, Qualys VMDR starts at $3/month. One of the oldest SaaS vulnerability management platforms, combining scheduled network scanning with a persistent agent so laptops that are never online during a scan window still get assessed. Softwr lists it under Cybersecurity. Qualys VMDR is made by Qualys, Inc., launched in 1999, available on Web, API.

Overview

What Qualys VMDR does

Qualys VMDR is a vulnerability management platform delivered as a service. It builds an asset inventory, detects vulnerabilities and misconfigurations, scores them with the vendor's own risk model, and can deploy patches. Data reaches the platform through several collectors: internet-facing scanners run by Qualys, virtual or hardware scanner appliances inside the network, a Cloud Agent for Windows, Linux and macOS, passive network sensors, container sensors, and API connectors for AWS, Azure and Google Cloud. Qualys is a public company founded in 1999 and was one of the first vendors to deliver security scanning as SaaS rather than as an on-premises appliance, and it runs regional platform instances so data can stay in a chosen jurisdiction. The distinguishing piece is the Cloud Agent, and its significance is commercial rather than technical. A scheduled network scan only sees devices that are on the network at the time, which in a hybrid workforce is a shrinking fraction of the fleet, and credentialed scanning of laptops that roam is close to impossible. The agent decouples detection from the scan window and reports continuously, which is what makes the vulnerability data plausible as an operational input rather than a monthly snapshot. It is also where the switching cost lives: once an agent is deployed across tens of thousands of hosts and wired into build images, replacing the vendor means a fleet-wide agent migration, not a contract change. Buyers are enterprises with compliance-driven scanning obligations, PCI merchants needing approved scanning vendor reports, and hybrid estates mixing datacentre, cloud and endpoints. The trade-off is that the platform is priced per asset and sold as separate subscriptions per capability, so the single product name covers a stack of line items, and the output volume outruns the organisation's ability to act. Qualys will reliably tell you about tens of thousands of vulnerabilities; deciding which ones matter and getting someone in IT operations to fix them is the part the licence does not buy.

What people use it for

  • A hybrid workforce where scheduled network scans miss most laptops and continuous agent-based assessment is the only way to get real coverage
  • PCI DSS external scanning where an approved scanning vendor report is a contractual requirement
  • An estate spanning datacentre, multiple public clouds and endpoints that needs one vulnerability view rather than three tools
  • Organisations replacing a manual patch-verification process with agent-reported evidence that a fix actually landed

The honest half

Where it falls short

Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Qualys VMDR.

  • Licensing is per asset and each capability is its own subscription, so patch management, endpoint detection, web application scanning, container security and policy compliance are separate line items, and the platform demonstrated in a proof of concept is rarely the platform in the quote.
  • Ephemeral cloud instances consume asset entitlement until they age out of inventory, so an autoscaling group that creates and destroys hosts hourly can burn licence capacity on machines that existed for minutes, and controlling that means tuning purge policies rather than tuning the cloud.
  • Authenticated scanning produces materially better results than unauthenticated, but it requires storing and rotating privileged credentials for every target platform, which is a security project in its own right, and teams that skip it receive reports full of unconfirmed potential findings that nobody trusts.
  • The console is a set of modules with separate interfaces, search syntaxes and report engines, so an analyst moving between vulnerability management, policy compliance and web application scanning learns each one, and cross-module reporting usually ends in a spreadsheet or a script against the API.
  • The tool surfaces findings far faster than any organisation can remediate them, and it does not solve the ownership problem: without an agreed prioritisation policy and a named owner in IT operations, a first scan producing tens of thousands of findings becomes a dashboard that everyone learns to ignore.

Cross-shopped

What people choose instead of Qualys VMDR

Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.

Pricing

What Qualys VMDR costs

Taken from the vendor's own pricing page. Prices move, so check before you buy.

VMDR

$3 /mo

  • Per asset
  • Vulnerability scanning
  • Detection
  • Basic remediation

VMDR+

$5 /mo

  • All VMDR features
  • Advanced analytics
  • Cloud integration
  • Reporting

VMDR Complete

$7 /mo

  • All VMDR+ features
  • Threat intel
  • Response automation
  • 24/7 support

Capabilities

Features

  • Cloud Agent

    Lightweight persistent agent that reports continuously so roaming devices are assessed without a scan window

  • Scanner appliances

    Virtual or hardware scanners for internal network segments, plus Qualys-hosted scanners for external perimeter testing

  • Authenticated scanning

    Credentialed checks that read installed package versions and configuration rather than inferring from network responses

  • TruRisk scoring

    Risk scoring that weights known exploitation and threat intelligence rather than CVSS base score alone

  • Asset inventory

    Normalised hardware, software and lifecycle inventory built from the same sensors as the vulnerability data

  • Patch Management

    Deploys patches from the same agent, sold as a separate subscription

  • Cloud connectors

    Pulls asset metadata from AWS, Azure and Google Cloud so cloud instances appear in inventory automatically

  • Container sensor

    Assesses container images in registries and running containers on supported hosts

  • Policy Compliance

    CIS and custom configuration benchmarks assessed against the same agent data, licensed separately

  • Regional platforms and API

    Choice of platform region for data residency, with a documented API for exports and automation

Answered, with sources

Questions people ask

Each answer names the page it came from, so you can check it rather than take our word for it.

Agent or scanner: which do I need?

Usually both. The agent covers endpoints and servers you control and gives continuous data; scanners cover devices you cannot install an agent on, such as network gear, printers and appliances, and provide the external perimeter view.

Does it patch as well as detect?

Yes, through the Patch Management module, which is a separate subscription using the same agent. Core VMDR detects and prioritises but does not deploy fixes.

How are assets counted for licensing?

By the number of assets in inventory, which includes cloud instances and containers depending on the modules in use. Short-lived cloud assets count until they are purged, so purge settings directly affect what you consume.

Can I keep the data in a specific region?

Yes. Qualys operates several regional platform instances and you choose which one your subscription lives on. Moving between them later is not trivial, so decide before onboarding.

Does it scan web applications?

Web Application Scanning is a separate module licensed per application, not part of core VMDR, and it is a dynamic scanner with the usual limits around authenticated flows in single-page applications.

Behind it

Who makes Qualys VMDR

Company
Qualys, Inc.
Based in
Santa Clara, California, USA
Share

Keep looking

Where to go from Qualys VMDR

Best Cybersecurity software for

Compare Qualys VMDR with

Other Cybersecurity software

  • Simplify online life with LastPass password manager

    Free plan12 researched notes
  • The world's most-loved password manager

    From $2.99/mo10 researched notes
  • Powerful protection against evolving threats

    From $36/yr14 researched notes
  • AI-powered exposure management platform for unified security visibility

    From $3,500/yr11 researched notes
  • XDR platform correlating Trend Micro's endpoint, email, server, cloud and network sensors, licensed through a shared credit pool.

    From $75/yr14 researched notes
  • Unified security platform automating vulnerability detection and fixing across development

    Free plan12 researched notes
  • Email security and data protection suite from a private company owned by Thoma Bravo, licensed per user with modules sold separately.

    From $6/mo14 researched notes
  • Vulnerability management at scale

    From $1.62/mo13 researched notes
  • Intelligence-driven cybersecurity

    From $25,000/yr11 researched notes
  • CNCF-graduated runtime threat detection for Linux and Kubernetes using eBPF

    Open source12 researched notes
  • Client lifecycle management and KYC onboarding for regulated financial institutions

    Pricing on request10 researched notes
  • Free TOTP two-factor authentication app that gained optional cloud sync in 2023

    Free plan8 researched notes
  • Vulnerability scanner for container images and filesystems

    Open source8 researched notes
  • Korean camera maker whose Wisenet WAVE VMS licences are perpetual per channel with no annual renewal

    12 researched notes
  • Built on CyberArk's legacy and powered by Palo Alto Networks

    Pricing on request7 researched notes
  • The most trusted vulnerability assessment solution

    From $4,790/yr11 researched notes

Softwr does not host reviews and shows no star rating for Qualys VMDR, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.

More on Qualys VMDR

Best Cybersecurity software alternatives

Privileged access management from the merged Thycotic and Centrify

quote

Large Chinese video platform that US federal buyers and federal contractors cannot lawfully use

quote

Managed video loss prevention with human auditors for restaurants, convenience stores and retail

quote

Privileged access management, endpoint privilege management and secure remote access

quote

Cloud video surveillance billed per camera per month, where retention length drives the bill more than anything else

Per camera per month

AI video search that runs on cameras you already own, starting near five dollars per camera per month

Per camera per month

Phishing-resistant passwordless authentication with device trust enforced at every login

quote

Compare Qualys VMDR with alternatives