Qualys
Cloud-based vulnerability management, policy compliance, web application scanning and PCI ASV services.
Certifications & Accreditations
| Certification | Certifying Body | Scope | Achieved | Expiry | Status |
|---|---|---|---|---|---|
| ISO/IEC 27001 | Accredited third-party certification body | Qualys Cloud Platform and supporting ISMS | — | — | Current |
| SOC 2 Type II | Independent third-party auditor | Qualys Cloud Platform; report available to customers under NDA | — | — | Current |
| PCI Approved Scanning Vendor (ASV) | PCI Security Standards Council | Qualys external vulnerability scanning for PCI DSS compliance | — | — | Current |
| FedRAMP | US federal authorising body | Qualys Cloud Platform for US government customers | — | — | Current |
Compliance Frameworks
ISO/IEC 27001:2022
Full
SOC 2 Type 2
Full
PCI DSS v4.0
Full
Qualys is a PCI Approved Scanning Vendor
GDPR 2016/679
Full
Processor under its DPA; EU and UK platform regions available
CIS V8
Full
Certified CIS Benchmark content for configuration assessment
Copyright © 2026 SnapGRC