Qualys

Security and compliance for your global IT assets.

Team size
1000+
Founded
1999
Request a quoteContactVisit website

Overview of Qualys

Specializations
Computer and Network SecurityTelecomSecurity SaaSContinuous Security

Qualys is a cloud-based information security and compliance company founded in 1999 as an early software-as-a-service security provider. Its Enterprise TruRisk Platform delivers integrated applications for vulnerability management, threat detection, web application scanning, asset inventory, and compliance automation, helping organizations identify and remediate cyber risk across IT environments. The company serves more than 10,000 subscription customers across over 130 countries, including a large share of the Forbes Global 50 and major healthcare, technology, and telecom enterprises. Qualys also partners with AWS, Microsoft Azure, Google Cloud, and consulting firms such as Accenture, IBM, and Infosys.

  • Email: sales_sth_asia@qualys.com
  • Website: https://www.qualys.com
  • Best for: Security and compliance for your global IT assets.
  • Services: Security SaaS, Continuous Security, Network Security, IT Asset Visibility, Cloud Security
  • Capabilities: Security SaaS, Continuous Security, Network Security, IT Asset Visibility, Cloud Security, Web Application Security, PCI Compliance, CyberSecurity Asset Management, VMDR, EDR

Profile updated 26 Jun 2026 Report incorrect data

Locations

Other office locations

  • Foster City, USA (Global headquarters)
  • Washington, DC, USA
  • Raleigh, USA
  • Pune, India
  • London, UK
  • Paris, France
  • Munich, Germany
  • Tokyo, Japan
  • Sydney, Australia
  • Dubai, UAE
  • Singapore
  • Sao Paulo, Brazil

Buyer Decision Checklist

Cybersecurity buying in Singapore turns on PDPA, the CSA Cybersecurity Act, and sector mandates from MAS and MOH. Use this checklist before you shortlist.

How to evaluate a cybersecurity vendor in Singapore

  • Confirm scope, rules of engagement, and who owns remediation before you sign.
  • Treat ISO 27001 / SOC 2 Type II / CREST as a baseline — ask for the auditor name and audit date, not just a logo.
  • Separate 'managed' from 'monitored': ask exactly what the vendor does at 3am when an alert fires, and whose name is on the on-call roster.
  • Check which reports are board-, audit-, or regulator-ready (MAS TRM, HCSF, or IM8 as applicable to you).
  • Get a fixed-fee scope for the first 90 days with unit pricing for extra endpoints, log volume, or incident-response hours.

Verify for Qualys

  • Confirm key details directly with the vendor — this listing isn't vendor-managed yet.
  • Ask for two recent Singapore client references you can speak with.
  • Request evidence of relevant certifications and their current validity.

Questions to ask

  • What is included in scope and retest, and what is explicitly excluded?
  • Can you share two Singapore clients in my sector and size that I can speak to?
  • How do you meet PDPC's 72-hour breach-notification window contractually?

Prepared under the TechDirectory editorial byline with review credit June C; this label is not proof of identity, credentials, or a completed human review. This directory-authored checklist is not attributed to Qualys; editorial independence has not been independently audited. Editorial standards

8/100

Profile signal score

Based on recorded profile signals. It is not a certification or independent verification of every claim, and it does not measure vendor quality or endorsement; paid plans do not affect it. How it works.

  • UEN recorded on profile No UEN recorded 0/20
  • Owner-claimed profile No owner claim recorded 0/10
  • Recorded grant eligibility None recorded 0/15
  • Recorded CSA trustmark None / expired 0/15
  • Listed certifications None listed 0/10
  • Approved reviews No approved reviews yet 0/20
  • Profile completeness 8/10 completeness 8/10

Similar vendors to compare