Qualys VMDR, Tenable One, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, CrowdStrike Falcon, Wiz, Orca, Ivanti Neurons, ManageEngine and Greenbone/OpenVAS compared side by side — capabilities, deployment models, published pricing and 72 enterprise RFP questions.
Research date: August 27, 2026
Filter platforms
10 of 10 platforms match the selected filters. The Cisco/Kenna lifecycle warning above is shown separately and is never in these filters or the comparison table.
Executive comparison
Vulnerability management platforms matching the current filters
Mid-market through very large global enterprise — large hybrid networks, distributed endpoints, multiple countries, strong compliance requirements, agent + scanner strategy, and mature VM teams wanting asset inventory + VM + patch in one platform.
Mid-market through very large enterprise — especially organizations familiar with Nessus, hybrid environments, scanner + agent models, on-prem Security Center needs, and regulated/high-security environments.
SMB through very large enterprise — especially organizations already standardized on Microsoft 365, Defender for Endpoint, Defender for Servers, Defender XDR, Intune, and Azure/Defender for Cloud.
Mid-market through very large enterprise — especially existing CrowdStrike customers, CTEM programs, endpoint-heavy estates, and enterprises wanting vulnerability data tied to adversary intelligence.
Large and very large enterprise, especially organizations with multiple vulnerability scanners, AppSec scanners, pen-test findings, cloud-security tools, multiple business units, and a need for one normalized enterprise risk view.
Small and mid-size organizations, labs, security researchers, privacy-conscious environments, organizations with Linux/security-engineering expertise, and teams needing a lower-cost self-hosted scanner.
Scroll sideways for more columns →
* Built-in patch requires the separately licensed Qualys Patch Management module. Qualys VMDR alone identifies missing patches but does not deploy them.
Pricing snapshot
Pricing basis and published or estimated figure per platform
Platform
Pricing basis
Published / estimated figure
Qualys VMDR
Published Price (SMB packages) + quote-based enterprise
Published Price: VMDR TruRisk from $2,195; TruRisk FixIT from $2,995; TruRisk ProtectIT from $4,645 (SMB packages). Enterprise VMDR pricing is quote-based and per asset.
Tenable One Vulnerability Management
Published Price
Published Price: 100 assets — 1 year $3,500, 2 years $6,825, 3 years $9,975.
Rapid7 InsightVM / Exposure Command
Published Price
Published Price: starts at $1.62/asset/month at 500 assets (~$9,720/year for 500 assets before add-ons, services, taxes, or discounts).
Microsoft Defender Vulnerability Management
Published Price
Published Price: Standalone $3.00/user/month (annual commitment); add-on $2.00/user/month (annual commitment) for eligible Defender for Endpoint Plan 2 / Microsoft 365 E5 customers.
CrowdStrike Falcon Exposure Management
Estimated (quote-driven)
Estimated: quote/demo-driven; budget as a five-figure-or-larger annual enterprise purchase depending on endpoint count/modules. Do not treat any specific number as official.
Wiz Unified Vulnerability Management
Quote-based (modular)
Wiz's pricing page states licensing is modular and scales on metrics such as workloads, developers, log ingestion, or sensors depending on product. No simple public per-asset VM price should be assumed.
Orca Security Cloud Vulnerability Management
Quote-based
Commercial pricing is quote/demo-driven. Do not assume or invent a public list price.
Ivanti Neurons for Risk-Based Vulnerability Management
Quote-based
Quote-based. Estimated: budget as an enterprise risk-management/orchestration layer; final cost depends heavily on asset volume, modules, and bundled Ivanti products.
ManageEngine Vulnerability Manager Plus
Published Price
Published Price (100 computers/1 technician): Professional — on-prem annual $695, cloud annual $895. Enterprise — on-prem annual $1,195, cloud annual $1,545. Product page also lists Professional from ~$0.90/device/month and Enterprise from ~$1.55/device/month.
Greenbone / OpenVAS
Published Price + open source
Published Price: OPENVAS BASIC (entry-level enterprise product) — €2,524/year. The underlying Greenbone Community Edition / OpenVAS stack is open source and free to run, though operating it still incurs infrastructure and labor costs.
Scroll sideways for more columns →
Before you rely on this
Important disclaimer
Vulnerability Management Vendor Disclaimer: EVULNABLE provides independent informational comparisons of vulnerability-management and exposure-management platforms. Product capabilities, licensing, integrations, deployment models, pricing, data residency, security authorizations, and product lifecycle status can change. Information labeled Official/Verified is based on official vendor documentation available as of the listed verification date. Information labeled Published Price is a price the vendor currently displays and may not reflect enterprise discounts, minimum commitments, add-ons, taxes, or professional services. Values labeled Estimated are independent planning estimates and are not vendor quotes or service-level commitments. Company-size fit and "Best Product by Scenario" recommendations are labeled EVULNABLE Assessment because they are this tab's own independent judgment, not a vendor claim or endorsement. Organizations should validate current entitlements, licensing, regional availability, compliance authorization, and technical coverage directly with the vendor before purchase.
Independent Comparison Notice: EVULNABLE is an independent informational resource and is not affiliated with, sponsored by, endorsed by, or acting on behalf of the vendors listed on this page unless explicitly stated otherwise. Vendor names and trademarks are used solely to identify the products and services being discussed.
Lifecycle warning — Cisco Vulnerability Management (formerly Kenna.VM / Kenna Security). Do not shortlist this as a new strategic purchase without a lifecycle review. Cisco Vulnerability Management (formerly Kenna.VM), Vulnerability Intelligence (formerly Kenna.VI), and the Application Security Module (formerly AppSec) are in their end-of-life cycle.
Historically provided strong risk-based vulnerability aggregation and prioritization under the Kenna Security name before Cisco's acquisition and rebrand.
Official/Verified (per Cisco's End-of-Sale and End-of-Life bulletin, verified against Cisco's own page as part of this tab's fact-check pass): End-of-life announcement — December 10, 2025. End-of-sale date (last day to order) — March 10, 2026. End of service-contract renewal — June 11, 2026. Last date of support — June 30, 2028, after which all subscription and support services become unavailable.
The source research handed off for this tab stated the announcement was "updated May 6, 2026" — that date did not match Cisco's own official EOL bulletin during this tab's fact-check pass, so the dates shown here use Cisco's page directly.
What was independently fact-checked before publishing
Spot-checked against primary/official sources before publishing: Rapid7 InsightVM's published $1.62/asset/month at 500 assets and Greenbone's OPENVAS BASIC €2,524/year figure both matched the vendor's current page. One correction was made to the source research: Cisco's own End-of-Sale/End-of-Life bulletin lists the EOL announcement date as December 10, 2025 (not May 2026 as the source research stated), with an end-of-sale date of March 10, 2026 and last date of support June 30, 2028 — the figures below use Cisco's official dates. Other pricing and capability figures reflect the handed-off research as sourced from official vendor pages; given how quickly vendor pricing pages change, treat every figure here as provisional and confirm directly with the vendor before relying on it.
Market pricing context
Vendors in this market use very different license metrics, which makes
head-to-head pricing comparison difficult: per-asset, per-user/month,
per-device/month, flat annual packages, and pure quote-based enterprise
deals all appear below. Figures labeled **Published Price** are numbers a
vendor currently displays publicly; figures labeled **Estimated** are
independent planning/budget guidance only and are not a vendor quote.
- Qualys VMDR TruRisk SMB packages start around **$2,195–$4,645**, but
enterprise VMDR pricing is primarily quote-based and per asset.
- Tenable One VM publishes **$3,500** (1 year) to **$9,975** (3 years) at
100 assets.
- Rapid7 InsightVM starts at **$1.62 per asset/month at 500 assets**
(roughly **$9,720/year** for 500 assets before discounts/add-ons).
- Microsoft Defender VM lists **$3.00 user/month** standalone, or
**$2.00 user/month** as an add-on for eligible Defender for Endpoint
Plan 2 / Microsoft 365 E5 customers.
- ManageEngine Vulnerability Manager Plus publishes Professional and
Enterprise on-prem/cloud tiers starting around **$695–$1,545/year**
for 100 computers.
- Greenbone's OPENVAS BASIC entry-level enterprise product is
**€2,524/year**; the underlying Greenbone Community Edition / OpenVAS
stack is open source, though running it still has infrastructure and
labor costs.
- CrowdStrike Falcon Exposure Management, Wiz, Orca Security, and Ivanti
Neurons for RBVM are quote/demo-driven; no reliable public per-asset
price should be assumed for these four.
Category definitions
Traditional enterprise vulnerability management
Designed to directly scan large heterogeneous infrastructures using combinations of network scanners, authentication, agents, cloud connectors, asset inventories, risk scoring, reporting, and remediation workflow. Qualys, Tenable, and Rapid7 are the clearest direct competitors to one another.
Endpoint-led exposure / vulnerability management
Vulnerability intelligence is deeply integrated with an endpoint/security agent and broader endpoint telemetry (Microsoft Defender VM, CrowdStrike Falcon Exposure Management). Can be extremely strong where the endpoint platform is already broadly deployed, but architecture and non-endpoint coverage should be compared carefully against traditional VM.
Cloud-native vulnerability management / CNAPP
Designed primarily around cloud workloads, cloud control-plane context, containers, identities, public exposure, data sensitivity, and attack paths (Wiz, Orca). May complement or partially replace traditional VM in cloud-heavy enterprises but should not automatically be treated as a one-for-one replacement for network-focused VM across legacy on-premises infrastructure.
Risk aggregation / prioritization / orchestration
Aggregates findings from multiple scanners and security tools, normalizes them, applies risk intelligence, and drives remediation (Ivanti Neurons RBVM). Usually sits above or alongside existing scanners rather than replacing them.
Endpoint vulnerability + patch management
Combines vulnerability identification with built-in remediation and endpoint patching (ManageEngine Vulnerability Manager Plus).
Scanner-centric / self-hosted open source
Focuses on active vulnerability testing and scanning with self-hosted/open-source options (Greenbone / OpenVAS).
Request a correction — See outdated information? Product capabilities, pricing, certifications, and lifecycle status can change. If you represent a vendor or notice information that may be outdated, use the link below to request a review or correction.
Export comparison
Pick the platforms to include, then download a self-contained PDF or Excel comparison. Each carries its own Methodology section, a Sources & Verification section with links, and the disclaimer, so the file stands on its own for procurement, management or legal review.
Platform profile
Cells in the table above are trimmed to five lines; each platform's full text is in the profile below, which the table's platform names link to. One profile at a time. Every profile is its own URL, so a link to one is a link you can send.
CrowdStrike Falcon Exposure Management
Endpoint-led exposure / vulnerability management
Reuses the Falcon sensor to add vulnerability, network, and exposure visibility without deploying another agent.
YesGov / FedRAMP
No / integrationBuilt-in patch
NoOpen source
SaaSDeployment
Classification
Endpoint-led exposure management / CTEM / vulnerability intelligence / network vulnerability assessment, built on the single-agent Falcon platform.
Discovery / scanning
Official/Verified: Visibility across endpoints, cloud, networks, OT/IoT, external assets, and shadow AI; Network Vulnerability Assessment adds continuous network visibility without waiting for a traditional full rescan. Existing Falcon Exposure Management customers may receive NVA coverage for up to 10% of licensed managed assets, subject to CrowdStrike's stated terms and caps.
Agent model
Official/Verified: Single Falcon sensor/agent model — a major operational benefit for existing Falcon customers since exposure capability reuses already-deployed telemetry.
Asset inventory
Official/Verified: CAASM/asset-discovery capability as part of the broader exposure-management surface.
Risk prioritization
Official/Verified: ExPRT.AI and an Exposure Prioritization Agent, incorporating live telemetry, exploit conditions, asset criticality, real-world threat intelligence, adversary behavior, endpoint/identity/cloud/network context.
Remediation
Official/Verified: Automated remediation workflows; patch capabilities depend on the broader Falcon ecosystem/offering rather than a dedicated built-in patch server.
ITSM / ticketing integration
Not itemized in source research. Confirm current ServiceNow/Jira depth directly with CrowdStrike.
Cloud / container / OT coverage
Official/Verified: Cloud security coverage and OT/IoT exposure visibility are both referenced; External Attack Surface Management (EASM) and security configuration assessment are dedicated capabilities.
Data residency
Official/Verified: FedRAMP High authorized government platform; 2026 regional/data-sovereignty expansion announced for Saudi Arabia, India, and UAE.
Pricing
Estimated: quote/demo-driven; budget as a five-figure-or-larger annual enterprise purchase depending on endpoint count/modules. Do not treat any specific number as official.No public list price is published.
Time to initial data
Estimated: Potentially hours if the Falcon sensor is already deployed.
Typical production rollout
Estimated: Days to 4 weeks — existing Falcon customers can realize value quickly; NVA/cloud/ASM expansion adds scope.
Best-fit company size
EVULNABLE Assessment: Mid-market through very large enterprise — especially existing CrowdStrike customers, CTEM programs, endpoint-heavy estates, and enterprises wanting vulnerability data tied to adversary intelligence.
Strong = central product strength. Yes = supported. Partial = available but not a defining equivalent. Integration = primarily handled through an external system. No / Not primary = not a core capability. * = requires a separately licensed add-on module.
Capability comparison across the platforms matching the current filters
Capability
Qualys VMDR
Tenable One Vulnerability Management
Rapid7 InsightVM / Exposure Command
Microsoft Defender Vulnerability Management
CrowdStrike Falcon Exposure Management
Wiz Unified Vulnerability Management
Orca Security Cloud Vulnerability Management
Ivanti Neurons for Risk-Based Vulnerability Management
ManageEngine Vulnerability Manager Plus
Greenbone / OpenVAS
Enterprise network scanning
Strong
Strong
Strong
Partial
Yes / expanding (NVA)
Partial
No / not primary
Integration
Yes
Strong
Endpoint agent
Strong
Strong
Strong
Strong
Strong
Optional / agentless-first
Optional / agentless-first
Source-dependent
Strong
No / not primary
Cloud-native agentless VM
Cloud capabilities
Cloud capabilities
Exposure/cloud modules
Defender for Cloud
Cloud security
Strong
Strong
Aggregates
Limited
No
Containers
Yes
Yes / related products
Yes / broader platform
Defender for Cloud
Cloud security
Strong
Strong
Aggregates
Limited
Scan-dependent
OT/IoT
Yes / VMDR OT
Tenable OT ecosystem
Limited / other platform
Limited
Yes / exposure visibility
Varies by cloud/IoT context
Cloud-oriented
Aggregates
Network-device focus
Scan-dependent
External Attack Surface Mgmt (EASM)
Qualys CSAM/EASM
Tenable One ASM
Surface Command
Separate Microsoft EASM
Yes
Wiz ASM
Cloud attack surface
Connectors
Limited
No
CISA KEV context
Yes
Yes
Yes
Yes (via threat context)
Yes / adversary intel
Emerging-threat context
Emerging-CVE context
Threat engine
Yes / attack context
Feed-dependent
EPSS
Available in Qualys context/products
Available in broader data
May be used in analysis
Not a central public scoring term
Not a central public scoring term
Contextual
Contextual
Source-dependent
Yes, explicitly
Feed-dependent
Built-in patch deployment
Yes*
Yes, with Tenable Patch Management add-on
Integration/workflows
Intune ecosystem
Broader remediation/patch ecosystem
Guidance/workflows
Guidance/workflows
Ivanti Patch integration
Yes, Enterprise edition
No
ServiceNow
Yes
Yes / integrations
Yes
Microsoft/ITSM ecosystem
Integrations
Workflows/integrations
Yes
Yes
Integrations
External
Jira
Yes
Integrations
Yes
External/integration
Integrations
Workflows
Yes
Connectors/workflows
Integrations
External
On-prem management option
Private Platform options
Yes, Security Center
Yes, Security Console
No classic VM server
No classic VM server
No classic appliance
No classic appliance
Subscription-dependent
Yes
Strong
Open source
No
No
No
No
No
No
No
No
No
Yes
Public transparent pricing
Limited (SMB package)
Yes
Yes
Yes
Quote
Quote
Quote
Quote
Yes
Yes (BASIC)
Scroll sideways for more columns →
Deployment / time-to-value
Estimated figures, not vendor SLAs.
Estimated time to initial data and to a production rollout
Platform
Time to Initial Useful Data
Typical Production Rollout Estimate
Qualys VMDR
Estimated: Hours to days for initial data once agents/scanners are configured (based on Qualys's documented agent/scanner setup steps).
Estimated: 2–8 weeks typical production rollout — large enterprises need agent rollout, scanner placement, auth records, tags, and integrations.
Tenable One Vulnerability Management
Estimated: Hours to days.
Estimated: 2–6 weeks — scanner/agent architecture and credentials drive the timeline.
Estimated: Potentially hours if Defender is already deployed.
Estimated: Days to 4 weeks — fast for existing Defender for Endpoint customers; longer for new endpoint onboarding.
CrowdStrike Falcon Exposure Management
Estimated: Potentially hours if the Falcon sensor is already deployed.
Estimated: Days to 4 weeks — existing Falcon customers can realize value quickly; NVA/cloud/ASM expansion adds scope.
Wiz Unified Vulnerability Management
Estimated: Often minutes/hours for a first cloud inventory after connecting a cloud account.
Estimated: Days to 4 weeks — the agentless architecture speeds cloud onboarding; workflow integration takes longer.
Orca Security Cloud Vulnerability Management
Estimated: Often minutes/hours after connecting a cloud account.
Estimated: Days to 4 weeks — agentless SideScanning simplifies initial cloud deployment.
Ivanti Neurons for Risk-Based Vulnerability Management
Estimated: Days, after first connector ingestion.
Estimated: 2–8+ weeks — quality depends on connector setup, normalization, business context, and workflow design.
ManageEngine Vulnerability Manager Plus
Estimated: Hours to days.
Estimated: Days to 3 weeks — agent rollout and patch policies are the main effort.
Greenbone / OpenVAS
Estimated: Hours to days.
Estimated: Days to 3 weeks — simple scanner setup can be quick, but tuning/scaling/credentials require expertise.
Scroll sideways for more columns →
Selection guidance
How EVULNABLE Evaluates Platforms: Rankings and recommendations below (including "Best Product by Scenario" and "Overall Recommendations") are independent assessments based on documented product capabilities, deployment options, discovery/scanning architecture, remediation functionality, workflow integration, data residency, pricing transparency, and intended organizational fit. They do not represent vendor endorsements, paid placement, or guaranteed suitability for every organization.
Best platform by scenario
Closest overall competitors to Qualys VMDR
Tenable One Vulnerability Management
Rapid7 InsightVM / Exposure Command
CrowdStrike Falcon Exposure Management (especially where Falcon is already deployed)
Microsoft Defender Vulnerability Management (especially in Microsoft-standardized estates)
Best traditional hybrid enterprise VM
Qualys VMDR
Tenable One Vulnerability Management
Rapid7 InsightVM
Best for very large cloud-native environments
Wiz
Orca Security
Qualys with cloud modules
CrowdStrike Cloud/Exposure ecosystem
Microsoft Defender for Cloud + DVM, depending on architecture
Best if already heavily invested in Microsoft
Microsoft Defender Vulnerability Management — reuses the existing Defender sensor, Intune remediation workflow, Microsoft 365 integration, Defender for Cloud integration, and can carry lower incremental licensing in some Microsoft contracts.
Best vulnerability-data aggregation / prioritization layer
Ivanti Neurons for RBVM — especially where the organization has multiple scanners and AppSec/cloud tools to normalize into one view.
Best lower-cost commercial VM + integrated patching
ManageEngine Vulnerability Manager Plus
Best open-source / self-hosted scanner
Greenbone / OpenVAS
Best for on-premises data-control requirements
Tenable Security Center
Greenbone / OpenVAS
ManageEngine on-premises
Qualys Private Platform where commercially/architecturally applicable
Rapid7 Security Console architecture
Overall recommendations
If the problem is primarily cloud vulnerability risk
Wiz
Orca Security
CrowdStrike Cloud/Exposure ecosystem
Microsoft Defender for Cloud + DVM
Qualys cloud capabilities
If the problem is prioritizing data from many scanners
Ivanti Neurons for RBVM
Also evaluate the broader exposure-management aggregation capabilities of Wiz, CrowdStrike, Tenable One, and Rapid7 Exposure Command depending on architecture.
If patching is a major selection factor
Qualys VMDR + Patch Management
Tenable One VM + Tenable Patch Management
ManageEngine Vulnerability Manager Plus Enterprise
Microsoft DVM + Intune/Microsoft patch ecosystem
Ivanti RBVM + Ivanti Neurons Patch Management
If budget/open source is the priority
Greenbone / OpenVAS
ManageEngine Vulnerability Manager Plus
Key strategic takeaway
The modern vulnerability-management market is splitting into several layers.
**Traditional VM.** Qualys, Tenable, and Rapid7 remain the clearest direct
infrastructure vulnerability-management competitors to one another.
**Security-platform VM.** Microsoft and CrowdStrike increasingly provide
vulnerability/exposure capabilities through endpoint platforms that may
eliminate a separate VM agent and correlate vulnerability information with
EDR/XDR data.
**Cloud-native VM.** Wiz and Orca provide cloud context, identity
relationships, data sensitivity, attack paths, and agentless workload
analysis that traditional network scanners were not originally designed to
provide.
**Aggregation / RBVM.** Ivanti is strongest when the problem is not "how do
I scan?" but "how do I combine Qualys, Tenable, Rapid7, AppSec, cloud,
pen-test, and business data into one remediation priority?"
**VM + patch consolidation.** Qualys, Tenable, and ManageEngine now all have
significant patch/remediation capabilities, which means modern RFPs should
compare vulnerability **closure**, not just vulnerability detection.
Suggested enterprise RFP questions (72 items)
Asset coverage
Which operating systems are fully supported?
Are network devices supported?
Which hypervisors are supported?
How are unmanaged devices discovered?
Is passive discovery available?
How are remote endpoints assessed?
How are IoT and OT assets handled?
Are mobile devices covered?
Are containers/Kubernetes covered?
Are serverless workloads covered?
Does the platform discover external attack surface/shadow IT?
Scanner architecture
Is scanning agent-based, network-based, agentless, or hybrid?
How many scanner appliances are required?
How are scanner updates handled?
Can scanners operate in disconnected/restricted networks?
Is an air-gapped deployment supported?
Can scans originate from specific geographic regions?
Are authenticated scans supported?
Which credential vaults are supported?
How does the platform avoid duplicate assets between agents/scanners/cloud connectors?
Prioritization
Does scoring incorporate CISA KEV?
Does it incorporate EPSS?
Does it incorporate exploit availability?
Does it incorporate active exploitation?
Does it incorporate ransomware association?
Is asset criticality included?
Is internet exposure included?
Is attack-path context included?
Is identity/privilege context included?
Is sensitive-data context included?
Can the organization customize prioritization?
Remediation
Does the platform deploy patches itself?
Is patch management an add-on?
Which OSs are supported for patch deployment?
Which third-party applications are supported?
Can patches be rolled back?
Are maintenance windows supported?
Can test/pilot groups be configured?
Is supersedence handled automatically?
Can non-patch mitigations/scripts be deployed?
Workflow
Is ServiceNow natively supported?
Is Jira supported?
Are tickets bidirectional?
Can tickets auto-close after a clean rescan?
Is there an API?
Are webhooks supported?
Is bulk export available?
Can business ownership/CMDB data be imported?
Can remediation SLAs be defined?
Is exception/risk-acceptance workflow included?
Reporting
Can the tool report by business unit, geography, OS, asset criticality, internet exposure, CISA KEV, vulnerability age, risk score, CVSS, and EPSS/EOL software?
Can executive reports show risk reduction over time?
Can historical findings be retained after remediation?
Can compliance evidence be generated?
Global / sovereignty
Where is customer data hosted?
Can region be selected?
Are US, EU, UK, Canada, Australia, India, UAE, and Saudi-region options available?
Is a government/FedRAMP environment available?
Can the platform support strict national data residency?
Does support staff access cross borders?
What subprocessors have access?
Can scanner traffic stay entirely local?
Licensing
Is licensing based on assets, IP addresses, users, workloads, cloud resources, agents, FQDNs, or data ingestion?