Qualys TruRisk Platform vs. Tenable Nessus

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Qualys TruRisk Platform
Score 6.0 out of 10
N/A
Qualys TruRisk Platform (formerly Qualys Cloud Platform, or Qualysguard), from San Francisco-based Qualys, is network security and vulnerability management software featuring app scanning and security, network device mapping and detection, vulnerability prioritization schedule and remediation, and other features to provide vulnerability management and network attack surface reduction.N/A
Tenable Nessus
Score 8.9 out of 10
N/A
Tenable headquartered in Columbia offers Nessus, a vulnerability scanning and security assessment solution used to analyze an entity's security posture, vulnerability testing, and provide configuration assessments.
$2,790
Pricing
Qualys TruRisk PlatformTenable Nessus
Editions & Modules
No answers on this topic
1 Year
$2,790.00
1 Year + Advanced Support
$3,190.00
2 Years
$5,440.00
2 Years + Advanced Support
$6,240.00
3 Years
$7,951.00
3 Years + Advanced Support
$9,151.00
Offerings
Pricing Offerings
Qualys TruRisk PlatformTenable Nessus
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Qualys TruRisk PlatformTenable Nessus
Considered Both Products
Qualys TruRisk Platform
Chose Qualys TruRisk Platform
As described before Qualys is used to scan periodically the environment in order to check if there are some packages (Linux) or Applications (Windows) outdated, generating reports to the Service Owners, fulfilling what's is expected from us, attending all our expectations …
Chose Qualys TruRisk Platform
When making the decision to use Qualys Cloud Platform we considered ManageEngine Patch Manager Plus and Kaseya VSA. We moved forward with Qualys Cloud Platform as it had multiple other options and features along with the costing provided as compared to others. Qualys Cloud …
Chose Qualys TruRisk Platform
I have not used other products like qualys cloud platform so I can't comment on how it compares, but I can say that we are happy with this solution that we currently have in place.
Chose Qualys TruRisk Platform
Qualys is quite user friendly and gives more easy information related to asset and risk an asset possess. Plus high quality of support as well as ease of use. Qualys is single suite for multiple task for your organization like VMDR rather than using multiple tools for different …
Chose Qualys TruRisk Platform
We find that Nessus is a great product, on par if not slightly better compared to Qualys in terms of their pricing model. However, Qualys Cloud Platform has better quality reporting, and offers great tips and suggestions on quickly closing a gap and eliminating the risk. In our …
Chose Qualys TruRisk Platform
As compared with Tenable, Qualys has multiple benefits and features which help ease the management of compliance. Tenable has only vulnerability management, but the Qualys tools landscape comprises a bouquet of tools spanning endpoint security, network security, compliances, …
Chose Qualys TruRisk Platform
Qualys Cloud Platform is the best tool available in the market considering the following factors - (1) simplify security operations and lower the cost of compliance (2) Visibility of cloud security configuration issues (3)User friendly interface with flexible options …
Chose Qualys TruRisk Platform
Qualys is more user friendly than tenable in view of creating and managing assets, option profiles as well as remediation provision and reporting service. As far as cost of these tools concern, qualys is less costlier than tenable vm tool. Qualys UI is better than tenable. You …
Chose Qualys TruRisk Platform
The VMware Carbon Black suite of products is highly superior than Qualys. This is what our organization has switched to and we couldn't be happier. It feels much more modern and easier to use/naviagte than Qualys. They also offer great threat detection on the end-user's …
Chose Qualys TruRisk Platform
We actually moved out of Qualys Web Application Scanning to a different product as we found better options that helped us address the specific concerns we had. The concerns were around scan duration, coverage, and the ability of the scanner to learn an application's nature and …
Chose Qualys TruRisk Platform
Azure Security Center
Chose Qualys TruRisk Platform
Identity Automation RapidIdentity
Chose Qualys TruRisk Platform
Deploying Qualys is really easy, in less than a day you can have everything ready for scanning. Also, Qualys has tons of reports and has tons of extension apps (such as the Asset Management App, which I love).
Chose Qualys TruRisk Platform
We really have not used or evaluated other commercial platforms other the Qualys. This was the only comprehensive platform that was in use in the organization for many years. Prior to a greater adoption by IT personnel in the use of Qualys, IT staff would routinely help to …
Chose Qualys TruRisk Platform
Qualysguard gave us the tools we needed that were benificial to our job without us having to do too much manual interaction such as with NMap, Metasploit , etc. It was a very efficient platform that I would go to again.
Chose Qualys TruRisk Platform
My previous organization was in the healthcare industry and we actually had Qualysguard, eEye, and Nessus because our customers required specific scan reports from those solutions. However, from a usability perspective, Qualysguard was the best solution.
Chose Qualys TruRisk Platform
While all of the alternative solutions mentioned here are great products, the features and usability that Qualys Private Cloud brought to the table worked out to be the best fit for my organization.
Tenable Nessus
Chose Tenable Nessus
Comparing other products, Nessus has a lot of plus points. Not only for PCIDSS, Nessus is great for other compliance bodies such as HIPAA, NIST etc.
Chose Tenable Nessus
We looked at AlienVault since it can be a SIEM and scanner all in one. Ultimately, we decided AlienVault didn't stack up well against Nessus so we decided to purchase Nessus. Glad we did.
Chose Tenable Nessus
Sometimes when we identify a vulnerability with Nessus that has an exploit, we made a proof of concept with Metasploit in order to show to the IT managers the importance of the software/hardware hardening.
Chose Tenable Nessus
Tools like Qualys, Rapid7 stack up well against Nessus, but I think Nessus is superior overall when compared to them, given the features it has.
Chose Tenable Nessus
Nessus is much easier to use.
Chose Tenable Nessus
Nessus is standard vulnerabilities assessment tool, i would recommend for mid or higher level organization to have their personalised tool from Nessus for day to day managing of their network security with continuous improvements.
Chose Tenable Nessus
Nessus is the smallest product in the Tenable stable and is also the first vulnerability scanner to be created almost 20 years ago. Great tool for once off scans. But you need the other products if you want real time monitoring etc
Chose Tenable Nessus
Defender provides lots of insight into missing patches and vulnerabilities on Windows devices but doesn't provide much help for other platforms.
Chose Tenable Nessus
Ease of deployment and use even for junior analysts, strong plugin support, and up-to-date CVE coverage, cost-effective licensing, especially for mid-size companies, and seamless integration with the SIEM tool. Overall, Nessus hit the right balance between functionality, …
Features
Qualys TruRisk PlatformTenable Nessus
Threat Intelligence
Comparison of Threat Intelligence features of Product A and Product B
Qualys TruRisk Platform
8.7
Ratings
9% above category average
Tenable Nessus
5.1
Ratings
43% below category average
Network Analytics8.90 Ratings8.20 Ratings
Threat Recognition8.30 Ratings4.50 Ratings
Vulnerability Classification8.80 Ratings8.20 Ratings
Automated Alerts and Reporting9.00 Ratings1.00 Ratings
Threat Analysis8.20 Ratings5.50 Ratings
Threat Intelligence Reporting8.90 Ratings7.30 Ratings
Automated Threat Identification8.70 Ratings1.00 Ratings
Vulnerability Management Tools
Comparison of Vulnerability Management Tools features of Product A and Product B
Qualys TruRisk Platform
8.5
Ratings
5% above category average
Tenable Nessus
8.0
Ratings
1% below category average
IT Asset Realization8.80 Ratings9.10 Ratings
Authentication7.90 Ratings9.10 Ratings
Configuration Monitoring8.50 Ratings9.10 Ratings
Web Scanning8.80 Ratings4.50 Ratings
Vulnerability Intelligence8.60 Ratings8.20 Ratings
Best Alternatives
Qualys TruRisk PlatformTenable Nessus
Small Businesses
Action1
Action1
Score 9.5 out of 10
Action1
Action1
Score 9.5 out of 10
Medium-sized Companies
Action1
Action1
Score 9.5 out of 10
Action1
Action1
Score 9.5 out of 10
Enterprises
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.0 out of 10
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Qualys TruRisk PlatformTenable Nessus
Likelihood to Recommend
8.6
(0 ratings)
9.0
(0 ratings)
Likelihood to Renew
-
(0 ratings)
9.1
(0 ratings)
Usability
2.0
(0 ratings)
9.7
(0 ratings)
Support Rating
5.0
(0 ratings)
7.1
(0 ratings)
User Testimonials
Qualys TruRisk PlatformTenable Nessus
Likelihood to Recommend
It is well suited for environments that are looking for a solution that is top notch for vulnerability scanning, and is the most accurate at doing so. It would also fit environments that have a lot of endpoints to scan or like to have scanning done on an automatic basis. It is less appropriate in environments that want to use a platform right away, without getting training in how to use it, or reading documentation on the product.
Read full review
Nessus is perfectly suitable for performing comprehensive vulnerability assessment scans being a vulnerability scanner. It is less appropriate for performing penetration testing since it is not a penetration testing tool, it does not have the ability and modules to exploit the vulnerabilities of the system.
Read full review
Pros
  • Attestation is so easy with Qualys. I find this one feature makes the investment worth the cost
  • Ease of use. Within an hour of first installing, a person can be running compliance tests without a hitch.
  • Great training materials and support. I have never had to take more than twenty minutes to solve a problem either through support or the forums.
Read full review
  • Shows you how to fix certain vulnerabilities and the commands to run.
  • Gives you the CVEs that the vulnerabilities are matched to.
  • Easy to understand the vulnerabilities list, giving reasons why the issues need to be patched or fixed.
Read full review
Cons
  • Notices some findings which were not clear why they appear(suspected false positive).
  • Working with Qualys support(for example due to the previous point) wasn't the best experience. the response was very slow.
  • Qualys limit the daily API requests. In case you need more, it will cost.
Read full review
  • Could use an upgrade within reports.
  • Scans can take a long time to complete. Have to break them down in small sections.
Read full review
Likelihood to Renew
No answers on this topic
Nessus is best and easy to use application for Vulnerabilities finding and reporting, it has multiple platforms and wide scope covering almost all devices for security improvement so far, thus we are very likely to continue its services.
Read full review
Usability
Again, the usability of Qualys has been a pinpoint for this entire review. It was easily the worst thing about the product and because of this, I would not recommend Qualys to anybody in my field. This should be something that Qualys strives to improve if they wish to stay in business.
Read full review
Tenable Nessus is a great product and provides a lot of value, but it is difficult to set up and use and the amount of data it generates can be overwhelming. It does help us prioritize based on the severity of the detection, however there are sometimes mitigating factors that we have implemented that Nessus does not account for, which causes lots of noise in the reports.
Read full review
Support Rating
They had a support page within the WAS to report any concerns or seek help. But the UI of that is not smooth. Regardless support staff were pretty responsive and helpful. They scheduled calls to understand and address our problems. Email support is good as well.
Read full review
I haven't needed to contact support yet. But issues are easily solved with a quick internet search which means support and by extension, the larger community are involved and knowledgeable.
Read full review
Alternatives Considered
We find that Nessus is a great product, on par if not slightly better compared to Qualys in terms of their pricing model. However, Qualys Cloud Platform has better quality reporting, and offers great tips and suggestions on quickly closing a gap and eliminating the risk. In our organization, both products are great and meet our expectations, but due to pricing, we favor Nessus slightly more.
Read full review
Ease of deployment and use even for junior analysts, strong plugin support, and up-to-date CVE coverage, cost-effective licensing, especially for mid-size companies, and seamless integration with the SIEM tool. Overall, Nessus hit the right balance between functionality, performance, and total cost of ownership for our needs and usability.
Read full review
Return on Investment
  • The most important thing that happens with this program is to automate one hundred percent the security of my system since this program is in charge of supervising each of the applications and websites in detail.
  • One of the purposes for which we trust Qualys Cloud Platform is to keep our system clean and secure; the ability of this software to manage our vulnerability makes us more cautious about working with it.
Read full review
  • It has helped identify security flaws in our infrastructure that has helped better secure our client's data. It did so quickly and efficiently so I was able to move on to other tasks.
Read full review
ScreenShots