Qualys VMDR vs. Tenable Nessus

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Qualys VMDR
Score 8.9 out of 10
N/A
Qualys VMDR 2.0 with TruRisk gives enterprises visibility and insight into cyber risk exposure with the goal of making it easy to prioritize vulnerabilities, assets, or groups of assets based on business risk. Security teams can take action to mitigate risk, helping the business measure its true risk, and track risk reduction over time.N/A
Tenable Nessus
Score 8.7 out of 10
N/A
Tenable headquartered in Columbia offers Nessus, a vulnerability scanning and security assessment solution used to analyze an entity's security posture, vulnerability testing, and provide configuration assessments.
$2,790
Pricing
Qualys VMDRTenable Nessus
Editions & Modules
No answers on this topic
1 Year
$2,790.00
1 Year + Advanced Support
$3,190.00
2 Years
$5,440.00
2 Years + Advanced Support
$6,240.00
3 Years
$7,951.00
3 Years + Advanced Support
$9,151.00
Offerings
Pricing Offerings
Qualys VMDRTenable Nessus
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Qualys VMDRTenable Nessus
Considered Both Products
Qualys VMDR
Chose Qualys VMDR
You can widgets galore from Qualys VMDR whereas with the others noted it's really vuln scanning.
Chose Qualys VMDR
Breadth of services, Overall cost and Strong services expertise
Chose Qualys VMDR
Qualys is quite user friendly and gives more easy information related to asset and risk an asset possess. Plus high quality of support as well as ease of use. Qualys is single suite for multiple task for your organization like VMDR rather than using multiple tools for different …
Tenable Nessus
Chose Tenable Nessus
Ease of deployment and use even for junior analysts, strong plugin support, and up-to-date CVE coverage, cost-effective licensing, especially for mid-size companies, and seamless integration with the SIEM tool. Overall, Nessus hit the right balance between functionality, …
Features
Qualys VMDRTenable Nessus
Threat Intelligence
Comparison of Threat Intelligence features of Product A and Product B
Qualys VMDR
8.4
7 Ratings
4% above category average
Tenable Nessus
6.2
4 Ratings
26% below category average
Network Analytics7.57 Ratings1.12 Ratings
Threat Recognition8.07 Ratings7.04 Ratings
Vulnerability Classification9.57 Ratings9.53 Ratings
Automated Alerts and Reporting9.07 Ratings10.03 Ratings
Threat Analysis8.57 Ratings5.53 Ratings
Threat Intelligence Reporting8.07 Ratings5.03 Ratings
Automated Threat Identification8.07 Ratings5.53 Ratings
Vulnerability Management Tools
Comparison of Vulnerability Management Tools features of Product A and Product B
Qualys VMDR
8.8
7 Ratings
6% above category average
Tenable Nessus
7.5
4 Ratings
10% below category average
IT Asset Realization9.07 Ratings7.03 Ratings
Authentication8.57 Ratings7.53 Ratings
Configuration Monitoring9.07 Ratings8.04 Ratings
Web Scanning8.56 Ratings5.53 Ratings
Vulnerability Intelligence9.07 Ratings9.34 Ratings
Best Alternatives
Qualys VMDRTenable Nessus
Small Businesses
Action1
Action1
Score 9.4 out of 10
Action1
Action1
Score 9.4 out of 10
Medium-sized Companies
Action1
Action1
Score 9.4 out of 10
Action1
Action1
Score 9.4 out of 10
Enterprises
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.0 out of 10
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Qualys VMDRTenable Nessus
Likelihood to Recommend
9.5
(7 ratings)
9.0
(9 ratings)
Likelihood to Renew
10.0
(1 ratings)
9.1
(1 ratings)
Usability
8.5
(2 ratings)
8.0
(5 ratings)
Availability
10.0
(1 ratings)
-
(0 ratings)
Performance
9.0
(1 ratings)
-
(0 ratings)
Support Rating
8.0
(2 ratings)
7.1
(4 ratings)
Implementation Rating
9.0
(1 ratings)
-
(0 ratings)
Configurability
9.0
(1 ratings)
-
(0 ratings)
Contract Terms and Pricing Model
9.0
(1 ratings)
-
(0 ratings)
Ease of integration
9.0
(1 ratings)
-
(0 ratings)
Product Scalability
9.0
(1 ratings)
-
(0 ratings)
Vendor post-sale
8.0
(1 ratings)
-
(0 ratings)
Vendor pre-sale
8.0
(1 ratings)
-
(0 ratings)
User Testimonials
Qualys VMDRTenable Nessus
Likelihood to Recommend
Qualys
Qualys VMDR is best suited for larger companies with a very large IT asset footprint. Qualys VMDR is not suited for businesses that are small and upcoming as the price for the tool is very expensive and could be a budget sink if not used properly. In our organization we use the Qualys VMDR dashboard and reporting in order to collect any vulnerabilities we miss during our routine audits to ensure that our environment is stable and protected for attacks.
Read full review
Tenable
It is an excellent tool for scanning servers, workstations, and network devices to identify missing patches and misconfiguration; we regularly use it to confirm patch effectiveness after the update; it also helps us for preparing audits such as iso 27001, and regulatory requirements, it also helps us to identify open ports and services that violate security.
Read full review
Pros
Qualys
  • Seamless reporting across the different widgets (i.e. TruRisk)
  • DEEP-DIVE into an asset's info/vulns
  • Baked-in PCI ASV scans that a Qualys QSA can approve
Read full review
Tenable
  • Nessus is best at performing vulnerability scans, in fact, it gives findings and moreover accurate findings of the assessments. It does not do penetration testing or exploit the vulnerabilities because it is concerned about scanning the systems/applications.
  • In fact, Nessus has multiple profiles/policies to perform different types of scans such as, scans oriented for PCI-DSS, malware scans, web application scans, bad shell shock detection scan to name a few.
  • Nessus has the ability to classify the vulnerabilities into risk-based categories from critical to even informational which I think is one of the things that separates Nessus from other vulnerability scanners.
Read full review
Cons
Qualys
  • Qualys VMDR can definitely improve on its reporting of assets as we have caught devices not captured in the Qualys VMDR scans.
  • We would like to see an improvement on the dashboard interface as it is faulty sometimes.
  • Qualys VMDR should focus on more competitive pricing as it is very expensive.
Read full review
Tenable
  • The tool has lots of options for setting up before scanning any device, this methodology could be simplified further with default configuration for various devices predefined, anyhow we can use this technique by making use of policies.
  • For advanced users we cannot disable the plugins inside the plugin groups, we can enable the whole set of plugins at a time, for few hundreds its ok, but thousands of plugins are of waste of resource and time.
Read full review
Likelihood to Renew
Qualys
Next to Veeam (which is a tremendous product for backup/DR) this is the best service/software I have used in the past three decades. Should be called the Swiss Army Knife of security.
Read full review
Tenable
Nessus is best and easy to use application for Vulnerabilities finding and reporting, it has multiple platforms and wide scope covering almost all devices for security improvement so far, thus we are very likely to continue its services.
Read full review
Usability
Qualys
infrastructure to identify vulnerabilities
Read full review
Tenable
Tenable Nessus is a great product and provides a lot of value, but it is difficult to set up and use and the amount of data it generates can be overwhelming. It does help us prioritize based on the severity of the detection, however there are sometimes mitigating factors that we have implemented that Nessus does not account for, which causes lots of noise in the reports.
Read full review
Reliability and Availability
Qualys
Always available with the exception on maint windows
Read full review
Tenable
No answers on this topic
Performance
Qualys
Once in a while it would be slow -
Read full review
Tenable
No answers on this topic
Support Rating
Qualys
This is iron but I am giving it 5 star and I can give more If I can do because they are best in support. So once you own this product they will assign a dedicated support for you and when you are under the weather with anything just connect them with anything call, ping or ticket they will come like Genie.
Read full review
Tenable
I haven't needed to contact support yet. But issues are easily solved with a quick internet search which means support and by extension, the larger community are involved and knowledgeable.
Read full review
Implementation Rating
Qualys
Not really - the integrations via connectors is not heavy lifting. Any complexity has to do with a service that requires more steps (i.e. AWS/GCP)
Read full review
Tenable
No answers on this topic
Alternatives Considered
Qualys
It is a very similar tool but Qualys VMDR is much better when it comes to reporting and solutions provided. Asset management is really good in Qualys VMDR. Qualys VMDR support is really quick , you can get a TPM if you run into any issues. Qualys VMDR has wide variety of scanning options which lacks in tenable.
Read full review
Tenable
Sometimes when we identify a vulnerability with Nessus that has an exploit, we made a proof of concept with Metasploit in order to show to the IT managers the importance of the software/hardware hardening.
Read full review
Contract Terms and Pricing Model
Qualys
MOSTLY good - but as noted having all features purchased on portal only - nothing that is not purchased.
Read full review
Tenable
No answers on this topic
Scalability
Qualys
Outside some pretty arcane apps or OS this is painless. The problem - and self-inflicted - is that older stuff is not supported.
Read full review
Tenable
No answers on this topic
Return on Investment
Qualys
  • Cut down on manual efforts to investigate or remediate vulnerabilities, which can be a big driver of ROI
  • Avoidance of potential incidents with upfront risk mitigation
  • Patching efficiency gains
Read full review
Tenable
  • Nessus certainly has a positive impact while me while performing my job, either as security research, or performing vulnerability assessments for clients. It gives a lot of information about the system/application after performing scans. The number of false positives is also less compared to other vulnerability scanners.
  • The professional edition is very useful as policy templates available in this edition are very handy and useful even to perform compliance scan like PCI DSS scan.
  • Also, the ability to export the scan results into reports in formats like HTML, PDF is very useful which could be for performing system/application reviews.
Read full review
ScreenShots