Try our new research platform with insights from 80,000+ expert users

BigFix vs Qualys Patch Management comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

BigFix
Ranking in Patch Management
2nd
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
96
Ranking in other categories
Configuration Management (6th), Endpoint Protection Platform (EPP) (22nd), Unified Endpoint Management (UEM) (4th)
Qualys Patch Management
Ranking in Patch Management
4th
Average Rating
9.0
Reviews Sentiment
7.5
Number of Reviews
33
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the Patch Management category, the mindshare of BigFix is 10.1%, down from 12.4% compared to the previous year. The mindshare of Qualys Patch Management is 4.4%, up from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Patch Management
 

Featured Reviews

Bella Yakoby - PeerSpot reviewer
Offers third-party patching feature, good scalability, and enhance endpoint management capabilities
From the perspective of the team that's handling the environment, it's not so user-friendly compared to other solutions, the competitors. We hire new teams from time to time, and they are complaining, look, although BigFix is very robust and cross-platform, it's not so fun to work with. The user interface for the technical teams is not so advanced. It's not so intuitive compared to SCCM, compared to ManageEngine. And this is the fact that they have, with the teams, because they have the rejection. The look and feel of the system are old-fashioned. For new employees, it's less easy to find someone I don't need to educate on how to work with BigFix. Although it's easy, it's not as intuitive as the other solutions, and the functionality of the other solutions is less advanced. Let's summarize: The user interface has to be changed from the perspective of the teams that are managing the product. It's old school.
Revathi VeeraRaghavan - PeerSpot reviewer
Provides a centralized platform for managing assets and vulnerabilities, enabling assessment, prioritization, and remediation
Qualys Patch Management system requires several improvements. Firstly, the inability to download asset patches and the lack of third-party application integration limit patch accessibility. Additionally, rollback options are unreliable, and pre-deployment patch testing is crucial. Reporting needs enhancement, particularly with group-based compliance percentages and clearer, VMDR-like reporting in the Patch Management module. Furthermore, detection speed should be improved, as patches are released 24 hours after QIDs are published. The user interface could be more functional, with dashboards for patch compliance visualization and simplified error code language. Finally, the Mac patch catalogue needs expansion, and automated workflows, policy enforcement, and testing procedures should be streamlined for seamless, user-independent operation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We receive the patches automatically, and BigFix spreads them automatically to our endpoints."
"The product is less costly when compared to other solutions, and this is a good solid solution for what we have paid."
"In terms of vulnerability management, it gives tough competition by providing a single management console with multiple benefits."
"It allows us to quickly deploy capabilities that we need, whether it be security or non-security. We use it to keep systems up to date, deploy new drivers, find the information we need in the case of security incidents. The capability allows us to gather a lot of information very quickly and it also allows us to have a centralized reporting feature and a centralized deployment capability which is nice."
"I like the inventory and life cycle management feature."
"The most valuable point is when you deploy an application, you have to make sure that the application has been deployed to all computers and that is working perfectly. This solution works well at deployments."
"The solution has many useful features. Its main advantage is simplicity - you can do everything from one console, regardless of the task. It supports many operating systems and is scalable to up to 250,000 clients."
"The most valuable and essential features of BigFix are all of them, they are needed when serving the purpose of the desktop operation framework. We cannot run operations without patching or without having an appropriate mechanism for deploying software, et cetera. The features all serve their purpose for our use case."
"Qualys Patch Management excels with its user-friendly interface and comprehensive reporting features."
"We have all the information on one page. The dashboard provides comprehensive information on one page, making it easy to apply patches and monitor pending updates."
"The most valuable features of Qualys Patch Management include its ability to automate patch deployment for hundreds or thousands of assets, reducing our reliance on the IT team to perform these tasks manually."
"The most valuable feature of Qualys Patch Management is the support and service provided by Qualys. The feedback that I got from our team is that Qualys' team is very supportive. They are always there to help us and solve queries in real-time. I liked the service aspect."
"Qualys allows us to automate and fix patches through the tool, achieving a compliance rate of over 95%."
"Qualys Patch Management's most valuable feature is its responsiveness."
"Qualys Patch Management has significantly reduced our organizational risks."
"Automated features streamline patch deployment and ensure compliance, effectively mitigating risks and bolstering organizational security."
 

Cons

"The product is quite buggy and complicated to use."
"I would like to see the integration of user security between the different products to be improved. There's separate security for compliance, separate security for web reports, and the console, and you have to manage those things separately."
"They need better integration."
"I would eventually like to see a SaaS offering, a cloud-hosted BigFix instance where we only have to put a relay in our environment."
"I'd definitely like to see additional feature parody in the web UI versus the console. There are certain things that you can only do in the console and they're very cumbersome to do, like secure parameters, for example. That's definitely something that has a wide degree of utility but it needs to be easier to surface. At this particular juncture between the transition, between the legacy console and the web UI, it's hard to justify dealing with the cumbersome aspects of the legacy console when theoretically everything's been through the web UI."
"The new EDR (Endpoint Detection and Response) feature, Detect, is new and still needs a few updates."
"BigFix can improve the way machines report back to the console. In the external relay management environment, it has become more of a hybrid environment with most of the machines not being on-site. The need of having public-facing reporting items interconnected is becoming more and more crucial. In general, the reporting could use some enhancement."
"I would like to see the Self Service section made more user-friendly."
"There are certain integration parts that could be improved. Sometimes, legacy operating systems are not supported by Qualys Patch Management, which is an issue."
"One area for improvement in Qualys Patch Management is knowing whether patches have been completely downloaded in a particular QGS appliance."
"The user interface could be more functional, with dashboards for patch compliance visualization and simplified error code language."
"There is room for improvement in terms of adding more patches. Not all patches are available for deployment on Qualys Patch Management, so collaborating with various vendors to provide new patches would be beneficial."
"Qualys Patch Management's pricing could be more competitive, as it presents a significant obstacle for many companies who find it unaffordable."
"It would be better if Qualys Patch Management identifies whether the process has failed at the first instance and provides a retry button or retry mechanism, allowing retries for failed patches. This feature would reduce my manual workload."
"Qualys's current response time for releasing solutions to zero-day vulnerabilities, which takes approximately 12 to 16 hours, needs improvement."
"There is room for improvement in terms of adding more patches."
 

Pricing and Cost Advice

"The license is subscription-based."
"The price is reasonable, but our customers find it expensive."
"The tool's price continues to go up. The cost per endpoint can vary, ranging from approximately 30 to 80 dollars per year. Compared to other products, pricing is in the middle. You need to buy an additional database license, but most users already have it."
"We have a subscription-based contract with BigFix."
"It might be about $23 a client."
"Compliance, inventory, and licensing are really pricey. They should lower the price. It discourages users from getting onboard."
"When purchasing, buying with other IBM tools provided us with a very good discount in pricing."
"I would stay with the Managed Virtual Server license model, which is a 1-to-1 license per OS whether it is virtual or physical."
"I'm unaware of Qualys' exact price, but it's more expensive than Nessus. With technological products, you need to pay to get the best."
"It is affordable, but they should provide features as per the rate they are charging. We have a big infrastructure with about 80,000 licenses. We expect better support from the Qualys team. So, it is affordable, but more features should be there, and the support should be better."
"While the cost of Qualys Patch Management is slightly high compared to alternative tools, it is not excessively expensive."
"Qualys Patch Management's pricing is competitive."
"Qualys is fairly priced."
"Qualys Patch Management offers a moderate price point, neither cheap nor expensive, considering its comprehensive functionality."
"From what I have heard, Qualys Patch Management is pricey, which is a main barrier to entry. Another aspect that I do not like about Qualys is that they do not add new patch management functionalities to the existing package. It is a separate SKU, so you have to pay more money."
"Qualys Patch Management's pricing could be more competitive, as it presents a significant obstacle for many companies who find it unaffordable."
report
Use our free recommendation engine to learn which Patch Management solutions are best for your needs.
850,834 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
44%
Financial Services Firm
9%
Government
7%
Computer Software Company
6%
Computer Software Company
17%
Manufacturing Company
11%
Government
11%
Financial Services Firm
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about BigFix?
The most valuable features of the solution are Windows patching and the hardware and software inventory.
What is your experience regarding pricing and costs for BigFix?
The pricing is competitive, but not the most competitive.
What needs improvement with BigFix?
Implementing a business solution with BigFix has some issues, primarily concerning the time required for distribution to clients if there are too many. Building a management console is quick and si...
What is your experience regarding pricing and costs for Qualys Patch Management?
Qualys Patch Management comes as part of a bundled package with several modules, making it a cost-effective deal for us. I cannot speak to the separate cost, as we have always used it as part of th...
What needs improvement with Qualys Patch Management?
I deploy patches to endpoints and servers every month. However, despite a job showing as successful, I need to examine the job in detail. For instance, if I have deployed patches to 100 endpoints, ...
What is your primary use case for Qualys Patch Management?
I use Qualys Patch Management as a single platform for patch management. We have Microsoft, Adobe, and various other apps. I create a scheduled task to push all the required patches to the laptops ...
 

Also Known As

Tivoli Endpoint Manager
No data available
 

Overview

 

Sample Customers

US Foods, Penn State, St Vincent's Health US Foods, Sabadell Bank, SunTrust, Australia Sydney, Stemac, Capgemini, WNS Global Services, Jebsen & Jessen, CenterBeam, Strauss, Christian Hospital Centre, Brit Insurance, Career Education Corporation
Information Not Available
Find out what your peers are saying about BigFix vs. Qualys Patch Management and other solutions. Updated: April 2025.
850,834 professionals have used our research since 2012.
OSZAR »