Skip to main content
Qualys logo

Qualys

Security and trust center evidence

qualys.comCompliance and GRCLast verified 17 Sep 2026

Summary

Qualys has 3 registry-verified rows and 1 third-party reported row in the CertReports index, last verified 17 Sep 2026. The strongest row is FedRAMP: FedRAMP Authorized. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.

Reviewer brief

As of 17 Sep 2026, Qualys is listed in the FedRAMP registry as FedRAMP Authorized since 02 Nov 2016, with the assessment conducted by Coalfire Systems, Inc. As of 17 Sep 2026, Qualys is listed in the CSA STAR registry with a STAR Level 2 certification and Trusted Cloud Provider status, issued 19 May 2019, which the registry notes is built on an ISO/IEC 27001 certification. As of 17 Sep 2026, no public evidence found for ISO/IEC 27001 as a directly verified certification separate from the CSA STAR registry entry. As of 17 Sep 2026, Qualys is listed in the EU-US Data Privacy Framework registry as active, covering SW-US, EU-US, and UK Extension Certifications, issued 14 Nov 2016 and expiring 04 May 2027. As of 17 Sep 2026, no public evidence found for SOC 2 or HIPAA compliance for Qualys in the supplied evidence rows.

  • FedRAMP: listed in fedramp registry as FedRAMP Authorized since 02 Nov 2016, assessed by Coalfire Systems, Inc. (as of 17 Sep 2026)
  • CSA STAR: listed in csa_star registry with STAR Level 2 certification and Trusted Cloud Provider status since 19 May 2019, noted as built on an ISO/IEC 27001 certification (as of 17 Sep 2026)
  • EU-US Data Privacy Framework: listed in dpf registry as active (SW-US, EU-US, UK Extension), issued 14 Nov 2016, expires 04 May 2027 (as of 17 Sep 2026)

Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.

Among compliance and grc vendors

3verified rows

Category median 1, across 118 indexed compliance and grc vendors. Qualys has more verified rows than 100 percent of them.

cloud securitycompliance scanningrisk assessmentvulnerability management

Similar vendors with evidence

Related by product tags and the Compliance and GRC category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.