Listing Thumbnail

    Qualys TotalCloud

     Info
    Sold by: Qualys 
    Deployed on AWS
    Free Trial
    AWS Free Tier
    Qualys TotalCloud: Making your cloud secure by providing the only solution that assesses, communicates and eliminates an organization's security risk.
    4.3

    Overview

    TotalCloud is a Cloud Native Application Protection Platform (CNAPP) built to detect, prioritize, and mitigate risks within multi-cloud and hybrid-cloud environments. As the most thorough cloud security solution, TotalCloud identifies, ranks, and facilitates the remediation of risks from key vulnerabilities, misconfigurations, and threats that other tools might miss, including potential attack paths and lateral movements targeting critical cloud resources. By integrating a wide range of solutions, including CSPM, KSPM, CWPP, CIEM, CDR, Workflow Automation and Remediation, TotalCloud provides a seamless cloud security management experience, without the complexity of managing multiple tools. For more details: https://www.qualys.com/apps/totalcloud/ 

    *Qualys provides custom pricing for customers via Private Offer. Please contact https://www.qualys.com/forms/request-a-call/  for a better understanding of our pricing model and products.

    Highlights

    • 6 Sigma Accurate Vulnerability Prioritization:Combines threat feeds from over 25 sources to create a unified vulnerability score. This score dynamically adjusts risk priorities based on patch availability, vulnerability criticality, and organizational context.
    • Integrated no-code/low-code remediation: Enable custom remediation workflows out of the box with Qualys QFlow Cloud Workflow Automation, allowing drag and drop of no-code/low-code workflows.
    • FlexScan : Allows security teams to combine agent and agentless scanning for workload protection across ephemeral and long-lived environments, including hosts, VMs, Containers, Kubernetes, and Serverless setups.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    Qualys TotalCloud

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    Total Cloud package 16
    Package of 16 Hosts for Total Cloud
    $5,400.00

    Vendor refund policy

    Licensed Qualys customers should refer to their Service User Agreement (SUA) or contact their Qualys Technical Account Manager if they have questions about refund or cancellation policies which would apply to them

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Qualys' policy is to respond to all Qualys customer cases promptly as per SLA. An incident ticket is assigned a priority number based on the nature of the issue. || Service Level Agreement (SLA): https://www.qualys.com/support/sla/  https://www.qualys.com/support/  || support@qualys.com  || US/Canada: +1 (866) 801-6161 (toll free) or +1 (650) 801-6161 || UK/Europe/International: +44 (0)1753 872102 || France: +33 1 41 97 35 81

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.3
    44 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    50%
    48%
    2%
    0%
    0%
    14 AWS reviews
    |
    30 external reviews
    External reviews are from G2  and PeerSpot .
    PankajKumar24

    Risk-based insights have improved cloud posture and now streamline remediation across teams

    Reviewed on Jul 27, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Qualys TotalCloud  is security posture management and vulnerability management. Day-to-day, we use it to continuously discover and assess cloud assets, identify misconfiguration and vulnerabilities against security policies, and prioritize remediation based on risk.

    A recent example was when we used Qualys TotalCloud  to assess our Google Cloud , and it identified several misconfigured resources and vulnerabilities that could have increased our security exposure.

    Beyond vulnerability management, we also use Qualys TotalCloud for continuous cloud asset visibility, security posture monitoring, compliance assessment, and prioritizing remediation based on risk.

    What is most valuable?

    We have been using Qualys TotalCloud for approximately two years to manage cloud security posture.

    Qualys TotalCloud helped us identify vulnerabilities and misconfigurations earlier, prioritize the most critical issues, and improve collaboration between security and IT teams. One example was during a cloud security assessment where Qualys TotalCloud identified a set of high-risk vulnerabilities and misconfigurations. Because the findings were prioritized and assigned to the right teams, we were able to reduce the remediation cycle from roughly two to three weeks to about five to seven business days for high-priority issues. Overall, it helps us respond faster and made the remediation process more structured and measurable.

    Qualys TotalCloud provides a more unified view of security posture across infrastructure, cloud-based services including IaaS  and SaaS-related environments where supported. We have seen better risk visibility, faster identification of high-risk issues, more consistent remediation processes, and improved compliance reporting.

    The True Risk insights capability helped us identify a relatively small number of assets with high vulnerability and risk scores. With these insights, we were able to prioritize critical assets for immediate remediation, assign actions to the appropriate IT and security teams, apply patches or configuration changes, and track the remediation progress.

    Overall, True Risk insights has had a positive impact on our security posture. It has helped us move from a broad vulnerability management approach to a more risk-based prioritization model. This has helped us reduce exposure more efficiently, improve remediation timelines, and make better use of security resources.

    Our experience with True Risk has been positive in reducing the noise from raw CVEs. Instead of treating every vulnerability as equally important, it helps us prioritize findings based on overall risk and asset context, allowing the security team to focus on vulnerabilities that are more likely to have a meaningful business impact.

    What needs improvement?

    Qualys TotalCloud could be improved by making the user interface and dashboard more intuitive, especially for quickly understanding the most critical cloud risks. It would also be helpful to have more advanced automation for remediation, stronger out-of-the-box integration with cloud-native tools, and more detailed, real-time reporting.

    As cloud environments grow, it would be helpful to have a more streamlined workflow for prioritizing findings, assigning remediation tasks, and tracking them across multiple teams. More customizable dashboards would also be helpful.

    A few areas where Qualys TotalCloud could improve are a simpler user interface and navigation for faster access to critical findings, better integration with cloud-native security tools, DevOps platforms, and improved AI-driven recommendations with more context-specific remediation guidance.

    For how long have I used the solution?

    I have worked in the current field for eight years or more.

    What do I think about the stability of the solution?

    Qualys TotalCloud is stable.

    What do I think about the scalability of the solution?

    I rate Qualys TotalCloud's scalability as very good.

    How are customer service and support?

    Our experience with Qualys customer support has been generally positive. The support team is responsive and knowledgeable.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution.

    How was the initial setup?

    We have seen a positive return on investment. The main benefits have been time-saving and improved operational efficiency rather than a direct reduction in headcount. We estimated that the security team saved roughly fifteen to twenty percent of time previously spent on vulnerability triage and reporting.

    What was our ROI?

    Our experience with Qualys TotalCloud pricing, setup cost, and licensing has been generally positive.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing Qualys TotalCloud.

    What other advice do I have?

    The accuracy and reliability of Qualys TotalCloud AI-driven insights are generally good. We typically validate high-risk findings and recommendations against our environment and security policies before taking action. Overall, I would rate the AI reliable for day-to-day security operations and risk prioritization, but with human validation still important for complex or high-impact cases.

    My advice would be to clearly define cloud security requirements and asset scope before deploying Qualys TotalCloud. Take advantage of risk-based prioritization and centralized visibility rather than focusing only on the volume of raw vulnerabilities.

    I rate this product an eight out of ten overall.

    reviewer2815095

    Reporting has improved visibility into risk exposure but still needs fewer false positives and better support

    Reviewed on Jul 20, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Qualys TotalCloud  is vulnerability management and exposure management. I use this tool to evaluate the exposure risk of the environment and identify all the weaknesses present in the environment.

    What is most valuable?

    I depend heavily on the reports that I have from this tool. In fact, this is the main tool that I use for reporting in the environment across most of the customer environments. However, I encounter a lot of false positives that require extensive testing to ensure the tool is reporting accurately. This process takes a significant amount of time. Additionally, the number of possible vulnerabilities that the tool identifies is not comparable to other players on the market. This impacts my ability to deliver the exact exposure view or risk that I am looking for.

    What needs improvement?

    To be totally honest, I do not have any best features because I have had a bad experience using this tool, especially regarding vulnerability management and exposure management.

    Getting all the information together in the tool is challenging. When I try to reach out to the support teams to get help and feedback to understand how the tool works in greater depth, the quality of support and knowledge of the people who work on the support team, as well as the supposed senior engineers, has not been satisfactory.

    I spend a lot of time doing reviews because I perform a mix of agent scans and authenticated scans. Sometimes the merge of data between those two scans does not work properly, resulting in a lot of false positives that require manual validation. I spend considerable time reviewing the content that comes from the tool. I do not have one hundred percent confidence that I am getting the real output from the tool.

    First of all, I believe that the support team needs to be more senior and not engage in robotic interactions with customers. Additionally, regarding feature requests and issues that I am working on with the support team, I see a lack of care from the support team in dealing with those issues.

    To be honest, I would move out from this tool because it does not give a full view of vulnerability. It does not provide a full perspective of the risk to my environment or the possible ways that I would be exploited by a hacker. It does not give me a full perspective of the exposure view for vulnerability management. If I consider the cloud aspects, I also need to get insights from other modules from the tool to give me a full perspective of my risk in the environment.

    For how long have I used the solution?

    I have been using Qualys TotalCloud  for four years.

    What do I think about the scalability of the solution?

    To me and my perspective, it is too hard to get what I am looking for and build reports from the tool to get the visibility and view that I need. Most of the time I need to export the data and use it in another third-party tool, such as Power BI, to get the visibility and view that I am looking for.

    How are customer service and support?

    Regarding Qualys TotalCloud's AI capabilities, I do see that it is not true AI. It feels to me that I am working with a chat that does not give insights based on the findings or the information that I get from the tool. It is not a real agentic AI. It is more a chatbot.

    How was the initial setup?

    Qualys TotalCloud is deployed in my organization as a public cloud.

    What other advice do I have?

    My overall review rating for Qualys TotalCloud is seven out of ten.

    NishantKandpal

    Centralized monitoring has simplified vulnerability testing for cloud, internet, and internal assets

    Reviewed on Apr 07, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Our use case involves the assets that we have under cloud, the assets exposed to the internet, and the internal applications that we create for our organization purposes, where we perform application security testing.

    What is most valuable?

    Qualys TotalCloud  is an excellent platform. The beauty of the platform is that we can get all the vulnerabilities. For example, if we test multiple IPs or multiple applications via Qualys TotalCloud , we can get all the reports in a single dashboard, and we can also see them segregated. Anybody can check that platform and easily learn about critical, high, and medium findings. They also provide remediation steps in a very appropriate manner.

    The main part I love about Qualys TotalCloud is the continuous monitoring and providing legitimate insights. If our management allows, we will document our technical evaluation and provide it to the purchase team for costing. This decision will depend on how expensive the solution is.

    What needs improvement?

    Areas that need improvement in every solution include the remediation part. The remediation steps should be simple enough for everyone to understand. For example, if we find a critical or high vulnerability on an IP or server, the remediation steps should be communicated clearly so that different departments, such as marketing and sales, can remediate their servers using simple steps.

    For how long have I used the solution?

    This evaluation is under POC and started about 15 to 20 days ago.

    What do I think about the stability of the solution?

    Regarding stability, I have tested a few servers, and I believe stability is good right now, so I rate it a nine.

    What do I think about the scalability of the solution?

    For scalability, I would give it an eight.

    How are customer service and support?

    Based on our evaluation, I would rate the support a nine.

    What about the implementation team?

    There is a team of four to five members involved in this testing and evaluation.

    Which other solutions did I evaluate?

    Right now, we are using Tenable, specifically Tenable Nessus , as our VAPT  tool, and we are seeking different options, which is why we have started the evaluation for Qualys TotalCloud.

    What other advice do I have?

    You can review the Radware DDoS  and Radware WAF . We are evaluating Qualys TotalCloud solution for our VAPT , which deals with vulnerability assessment and penetration testing. This evaluation is under POC and started about 15 to 20 days ago, focusing on our number of assets, servers, and IPs for the VAPT part, as well as the application security part.

    It does not exactly provide unified vulnerability and threat assessment for SaaS. We are working under the guidelines of ISO 27001. We generally give the critical IPs and server names to test, and they provide us with the findings which we patch accordingly, as per the remediations.

    I have not yet tried the TruRisk Insights feature, but I would love to get those insights.

    In terms of detection, they are doing very well. I am more concerned about the detection feature because if anybody detects vulnerabilities effectively, that will benefit our organization. The findings they provide are legitimate vulnerabilities, and regarding prevention, that is on our side. They recommend steps for prevention on particular IPs, and we can only take actions after multiple approvals.

    I consider Qualys TotalCloud a premium product, and I have no issues with that. If a product is premium, it typically offers better findings and opportunities. However, if the pricing is excessively high, we need to consider alternatives. A normal price or slightly more expensive is acceptable, but they should also provide good services.

    I recommend this product because it supports both on-premises and cloud environments. The report format they provide after VAPT is very accessible, easy to learn, and beautifully presented. This is the best feature of the product. While I think Qualys TotalCloud is premium, I am concerned about the pricing details, particularly the cost per license.

    I rate this product a nine overall.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Robert Orłowski

    Unified risk scoring has improved our cloud visibility and simplifies remediation priorities

    Reviewed on Mar 31, 2026
    Review provided by PeerSpot

    What is our primary use case?

    At the moment, the organization where I work, Alior Bank, is using Qualys TotalCloud , although in the past we used Nessus Professional , which we dropped about two years ago. It was Professional , not the enterprise Tenable version, just Nessus.

    I have been familiar with Qualys TotalCloud  from the beginning of the implementation in our bank, which was in 2024 when we purchased it and started implementing it. I am part of the implementation and current management of Qualys TotalCloud.

    Regarding Kubernetes  and containers, I don't recall if it's part of Qualys TotalCloud or a different component.

    We are utilizing Azure  and GCP with Qualys TotalCloud.

    What is most valuable?

    Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS.

    This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score.

    The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified.

    Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.

    What needs improvement?

    Improvements in Qualys TotalCloud could include technologies to cover compliance scanning, such as CIS benchmark scanning. It is somewhat difficult to set up Qualys TotalCloud properly for certain technologies. Additionally, while they moved to UI4, which is nicer, some parts of Qualys TotalCloud dashboards still look very old. You can switch between those interfaces and adopt them because some things are better in the new one, while others are not.

    What do I think about the stability of the solution?

    Overall, Qualys TotalCloud is a stable solution. I remember encountering a problem once, which was an issue for the whole EU2 platform and affected tenants on Qualys TotalCloud placed in EU2 areas. As I saw on the status page, it was only a problem in Europe, not in America or Asia.

    How are customer service and support?

    Regarding technical support from Qualys, they respond, but the response time can be too long. Sometimes we need to wait weeks for solutions to simple questions.

    If I had to rate Qualys support based on my experience from one to ten, I would say around six or weak seven, perhaps six plus.

    Which solution did I use previously and why did I switch?

    It is difficult to compare the helpfulness of written explanations with other solutions as we used Nessus for a few years. We only had two or three years of experience with that support, and it was simply Nessus Professional and not Tenable Enterprise, so I could not make a comparison. However, currently we have very good support from our integrator, plus the support from Qualys itself.

    How was the initial setup?

    Regarding deployment of Qualys TotalCloud, the installation of Cloud agents was given to administrators from each team who manage servers and workstations, including components in Azure  or GCP cloud. This was not handled by me or my team, as I work in the cybersecurity department. We manage the use of Qualys TotalCloud, but installation is up to the administrators, and we provide them support.

    Currently, in the cybersecurity department, we have two people involved in the deployment of Qualys TotalCloud, along with over one hundred administrators involved in implementing and installing agents on the machines.

    What about the implementation team?

    The deployment of Qualys TotalCloud within our organization was a continuous process. However, the installation of Cloud agents on the machines took place within two to three months, about a quarter.

    What was our ROI?

    The benefits we see are related to cost reductions.

    Which other solutions did I evaluate?

    For a mid-size bank like ours, the licensing cost for Qualys TotalCloud is cheap. Tenable Enterprise costs double that of Qualys TotalCloud and Rapid7. We explored those three solutions and decided to go with Qualys TotalCloud.

    What other advice do I have?

    Qualys TotalCloud provides written explanations to help guide remediation paths and eliminate cyber risks in our organization. I would rate this review an eight overall.

    Mahmoud Younes

    Accurate vulnerability reports have improved patch management and strengthened security posture

    Reviewed on Mar 18, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I am working with Qualys TotalCloud  for vulnerability management, and the major use cases are patch management and scanning.

    What is most valuable?

    If I had to say something positive about the product that brings me the biggest benefit, I would say it has accurate reports, gets new update CVEs, zero-day attack detection, and is easy to manage with its GUI. Qualys TotalCloud  does provide written explanations to help guide remediation paths and thus eliminate cyber risk. When it provides written explanations with guidance to remediate a path and eliminate cyber risk, it helps in general and helps a lot. The product does have a so-called TruRisk Insights feature, but I do not have experience with it. Qualys TotalCloud for vulnerability management provides unified vulnerability and threat assessment across both IaaS  and SaaS, and I think overall it helps with security posture management. It is very good for patching vulnerabilities and getting zero-day attacks with accurate reports, not like Nessus. With Nessus, if you start to scan, it gives you many vulnerabilities, but it is not accurate and shows old vulnerabilities. If you compare it with Qualys TotalCloud, it is accurate and has updated CVEs. It saves a lot of time.

    What needs improvement?

    If Qualys could add some new features to Qualys TotalCloud in future releases, the results for the report and remediation should be more clear and very straightforward. Once we export the report, sometimes we do not get the correct path to patching the vulnerability.

    For how long have I used the solution?

    I have been working with the product for around two years, and in general, I have been in this domain with security products for around 12 or 13 years.

    What do I think about the stability of the solution?

    Qualys TotalCloud is stable.

    What do I think about the scalability of the solution?

    Regarding scalability, I would rate it seven out of ten. The reason I rate it seven points, not ten points, is that it is not that easy to manage. The problem when I manage it basically is that you need someone who has some experience to manage it, as it is not user-friendly.

    How are customer service and support?

    The technical support from Qualys is good, to be honest.

    Which solution did I use previously and why did I switch?

    Apart from Tenable and Qualys, I did not work with any other competitors. I only worked with these two and OpenVAS, which is an open-source solution for vulnerability assessment.

    How was the initial setup?

    The installation of Qualys TotalCloud is very straightforward, and you can easily install the agent for Windows, Linux, and Mac.

    What was our ROI?

    I cannot provide information about seeing ROI with Qualys TotalCloud.

    What's my experience with pricing, setup cost, and licensing?

    The price is very expensive, actually.

    Which other solutions did I evaluate?

    If I compare Qualys TotalCloud with other vendors, I compare it with Nessus and Tenable. If I compare Qualys TotalCloud and Tenable, I would say Qualys TotalCloud is better in terms of functionality, and Tenable is better in terms of price.

    What other advice do I have?

    We are using Qualys TotalCloud Vulnerability Management  and web applications, enterprise solutions, plus Nessus also. For vulnerability management, we installed an agent for each machine and servers and start scanning to get the vulnerabilities.

    If I speak about some negative sides of Qualys TotalCloud, I think the negative side is the license. It accounts for approximately 30 percent of the concerns.

    View all reviews