ComplyGuideComplyGuide
HomeSoftwareLearn
Submit a Tool
ComplyGuideComplyGuide

Find and compare compliance automation tools.

Directory

  • All Vendors

Frameworks

  • SOC 2
  • HIPAA
  • GDPR
  • ISO 27001
  • PCI DSS
  • FedRAMP
  • NIST CSF

Resources

  • Learn

For Vendors

  • Submit a Tool
  • Pricing & Premium
  • Claim Your Listing

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 ComplyGuide. All rights reserved.

Made for compliance professionals

Get a RecommendationBrowse Tools
Home/Vendors/Qualys
Qualys logo

Qualys

Cloud-based IT security and compliance solutions

4.2
Editorial
based on 5 data points
HIPAA
PCI DSS
ISO 27001
Visit QualysSee pricing
Customer quotes
5
Customers
5
Case studies
0
Years active
27

founded 1999

Companies referencing Qualys

AvayaAvayaIBM SecurityIBM SecurityMicrosoftMicrosoftUniversity of MiamiUniversity of MiamiVismaVisma
“We moved to Qualys and our reporting has gotten 100% better. Qualys solutions make our job easier because of the accuracy.”
University of Miami
Jonathan Reyeros
Security Engineer · University of Miami
AboutReferences5Case studiesPricingFAQSimilar tools

About Qualys

Qualys provides cloud-based IT security and compliance solutions. Offers vulnerability management, policy compliance, and web application scanning for PCI DSS, HIPAA, and more.

Editorial summary

ComplyGuide

Qualys is a long-established name in vulnerability management that users trust for its comprehensive scanning capabilities and policy compliance modules. The cloud-based platform is valued for its scalability across large enterprise environments, though some users find the interface dated and the compliance features less modern than purpose-built GRC platforms.

Strengths
  • Battle-tested vulnerability management with decades of refinement
  • Highly scalable across large enterprise environments with thousands of assets
  • Comprehensive policy compliance scanning and CIS benchmark support
  • Strong API ecosystem for integration into existing security workflows
Considerations
  • User interface feels dated compared to modern compliance platforms
  • Compliance modules are secondary to vulnerability management focus
  • Licensing and module pricing can be confusing

What customers say

Showing 1 of 5. The rest are locked.

Avaya
Avaya

1 reference · Communications

Qualys has enabled us to integrate into build, test, operational and automation efforts, whether on premise or in the cloud.
Abie John·CISO
IBM Security

IBM Security

1 reference · Cybersecurity · Locked

Qualys' cloud-based platform uniquely provides real-time visibility of IT security and compliance posture.

John Wheeler · Vice President, Services Strategy and Offering Management

Microsoft

Microsoft

1 reference · Software · Locked

Qualys' continuous security platform enables customers to easily detect and identify vulnerable systems and apps.

Nicole Herskowitz · Senior Director of Product Marketing, Cloud Platform

University of Miami

University of Miami

1 reference · Higher Education · Locked

We moved to Qualys and our reporting has gotten 100% better. Qualys solutions make our job easier because of the accuracy.

Jonathan Reyeros · Security Engineer

Visma

Visma

1 reference · Business Software · Locked

With the Enterprise TruRisk Platform, we're succeeding in making the business aware of what they need to do.

Hans Petter Holen · CISO

4 more quotes from 4 companies locked

Claim this listing and upgrade to unlock the rest.

Claim listingTalk to us

Case studies

No case studies yet

We haven't harvested any public case studies for Qualys yet. Are you the vendor? Claim this listing to add documented customer outcomes.

Claim listingTalk to us

Pricing

2 plans available.

Express Lite

$542/mo

$5,424/yr with annual billing

  • Vulnerability scanning
  • Basic compliance
  • Asset discovery
  • Standard reports
Learn More
Most Popular

Enterprise

Contact for pricing
  • Full platform
  • Policy compliance
  • Web app scanning
  • Custom reporting
Learn More

User reviews

Be the first to write a community review of Qualys.

Write a review

Share your experience with Qualys and help others make informed decisions.

Company details

qualys.com
Founded 1999
1000+ employees
Foster City, CA

Frameworks

HIPAA
PCI DSS
ISO 27001
Visit website

Get Pricing Info

Are you the vendor? Claim this listing.

Claim this listing

Similar tools

Sprinto logo

Sprinto

4.8
Featured

Compliance automation for cloud-first companies

SOC 2
HIPAA
GDPR
+1

79 customer references

1Password logo

1Password

4.7

Enterprise password and secrets management with compliance

SOC 2
GDPR
ISO 27001
+1

26 customer references

Drata logo

Drata

4.7
Featured

Continuous compliance automation with 85+ integrations

SOC 2
HIPAA
GDPR
+2

119 customer references

Wiz logo

Wiz

4.7

Cloud security platform with compliance capabilities

SOC 2
HIPAA
GDPR
+2

1 customer reference

Anecdotes logo

Anecdotes

4.6

Compliance operating system for modern enterprises

SOC 2
HIPAA
GDPR
+1

21 customer references

Vanta logo

Vanta

4.6
Featured

Automated compliance for SOC 2, HIPAA, ISO 27001 & more

SOC 2
HIPAA
GDPR
+2

70 customer references

Compliance guides

What Is HIPAA? A Complete Guide to HIPAA Compliance

HIPAA (Health Insurance Portability and Accountability Act) is a US federal law that sets national standards for protecting sensitive patient health information (PHI) from being disclosed without the patient's consent or knowledge.

HIPAA
12 min read

HIPAA Compliance Checklist for 2025

A comprehensive HIPAA compliance checklist covers risk assessments, administrative/physical/technical safeguards, Business Associate Agreements, workforce training, breach notification procedures, and ongoing documentation requirements.

HIPAA
10 min read

What Is PCI DSS? A Complete Guide to Payment Card Security

PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards created by major card brands (Visa, Mastercard, Amex, Discover, JCB) to protect cardholder data. Any organization that accepts, processes, stores, or transmits credit card information must comply.

PCI-DSS
14 min read

PCI DSS 4.0 Requirements: All 12 Explained in Detail

PCI DSS 4.0 has 12 core requirements organized under 6 goals: build secure networks, protect account data, manage vulnerabilities, control access, monitor and test networks, and maintain security policies. Together they contain approximately 400 individual test procedures.

PCI-DSS
22 min read
Browse all compliance guides →