Qualys Patch Management
Cloud-native patch management (SaaS, no on-prem infrastructure)
Automate patch deployment across Windows, macOS, and Linux using the same Qualys Cloud Agent as VMDR, to reduce risk and speed vulnerability remediation.
- SaaS (cloud-native), Government cloud (FedRAMP)Deployment
- No / cloud-onlyOn-prem option
- Peer-to-peer (Windows)Distribution
- Quote onlyPublished price
- Classification
- Official/Verified: A cloud-native, agent-based patch-management module within the Qualys Cloud Platform, licensed alongside Qualys VMDR - VMDR discovers and prioritizes missing patches, and Patch Management deploys them.
- Operating systems patched
- Official/Verified: Windows, macOS, and Linux (documented distros include RHEL, CentOS, Oracle Linux, and Amazon Linux; the Supported Product Versions page holds the current authoritative lists). A single patch job cannot mix Windows, Linux, and Mac assets.
- Third-party application patching
- Official/Verified: Yes - the Cloud Agent patches the operating systems plus a catalog of third-party applications (grown from 55 at launch to 'over 300 third-party applications'; a current total is not printed, and the Supported Product Versions page is the authoritative list). macOS third-party patching is supported.
- Patch discovery / vulnerability visibility
- Official/Verified: Fully integrated with Qualys VMDR - VMDR discovers, assesses, and prioritizes missing patches using TruRisk (with threat context including CISA KEV), and Patch Management maps those vulnerabilities to patches and deploys them.
- Automation & scheduling
- Official/Verified: Zero-Touch Patching applies patches per predefined policies; run-once or recurring patch jobs; dynamic patch selection via QQL (qualifying patches are auto-associated to a job); one-off emergency jobs; configurable patch/maintenance windows; and 2025 additions of pre-action precondition checks and intelligent job chaining.
- Testing / staging
- Official/Verified: Deployment Rings - test candidate patches against test devices, then deploy the same tested patches into production with another job.
- Reboot management
- Official/Verified: Manages reboots - prompt the user or suppress the reboot when one is required after installation, with user notifications and deferral; a system reboot can also be set as a pre-action.
- Rollback / uninstall
- Official/Verified: Patch rollback jobs are supported for Windows assets, and the module can uninstall or upgrade end-of-life / end-of-support software.
- Content distribution
- Official/Verified: Peer-to-peer (P2P) patch distribution lets Windows agents share patch chunks over the LAN (Qualys cites a 99%+ reduction in external bandwidth; currently Windows agent-managed endpoints only), plus an optional Qualys Gateway Service appliance for local patch caching.
- Reporting & compliance
- Official/Verified: Custom dashboards and widgets (including patch-deployment counts for reporting to the business), detailed patch-data export for Windows assets, and a single-console view.
- ITSM / ticketing integration
- Official/Verified: An out-of-the-box closed-loop integration with ServiceNow change-management workflows, alongside broader Qualys-ServiceNow integrations. Jira is not stated.
- Remote control / remote access
- Not documented as an interactive remote-control or remote-desktop feature. Qualys documents remote patch remediation through the Cloud Agent (unattended deployment to remote and roaming endpoints), which is patch delivery, not interactive remote access.
- Agent model
- Official/Verified: The Qualys Cloud Agent - the same agent used for vulnerability and configuration assessment - deploys patches, including to remote and roaming endpoints outside the network. No customer on-prem servers are required (an optional Qualys Gateway Service appliance can cache patches).
- Scale
- Official/Verified: No specific supported-endpoint ceiling is published; Qualys cites efficiency figures (P2P bandwidth reduction, and VMDR+PM customers patching CISA's top KEVs up to 60% faster) rather than a scale limit.
- Data residency / certifications
- Official/Verified: Multiple regional Qualys Cloud Platforms, plus a FedRAMP-authorized Government Platform - FedRAMP Moderate (authorized since 2016) and FedRAMP High on the Qualys Government Platform (2025). SOC 2 / ISO 27001 were not stated on the pages fetched; confirm the full region list on Qualys's platform-identification page.
- Pricing
- No current public price. Qualys Patch Management is quote-based and does not display a current per-asset figure; the only official figure found is historical ($29.95 per asset at the 2019 launch).PM is a licensed module alongside VMDR; confirm current pricing and packaging directly with Qualys.
- Company-size fit
- EVULNABLE Assessment: Qualys Patch Management rides the Qualys Cloud Platform and is licensed alongside VMDR, so it fits organizations already using (or adopting) Qualys for vulnerability management - mid-market through global enterprise, and government (FedRAMP High). It makes most sense where Qualys is the vulnerability-management platform rather than as a standalone patch tool.
- How the vendor positions it
- Qualys frames Patch Management for 'IT and security teams' seeking to 'streamline and accelerate vulnerability remediation' across hybrid environments and remote/roaming endpoints, integrated with VMDR and TruRisk prioritization.
Last verified: September 6, 2026 Confirm current details directly with the vendor.
