# DefectDojo vs Qualys VMDR

| Attribute | DefectDojo | Qualys VMDR |
|---|---|---|
| **Vioscale score** | 53.3 (26% (low)) | 5.6 (15% (low)) |
| deployment.options | `{"cloud":true,"on_prem":true,"self_hosted":true}` | `{"cloud":true,"on_prem":true,"self_hosted":true}` |
| description.long | DefectDojo is an open-source and commercial platform for managing vulnerabilities across organizations. It aggregates findings from 500+ security tools, automatically deduplicates and triages them, and enables teams to enforce remediation SLAs and automate security workflows. Available as both a free community edition and a paid professional version. | A vulnerability management platform that identifies security weaknesses, prioritizes them by business impact, and automates remediation workflows. It includes asset discovery, vulnerability scanning, compliance reporting, and integration with IT ticketing and remediation systems. |
| integrations.count | 500 | 3 |
| integrations.list | `[{"name":"Snyk"},{"name":"SonarQube"},{"name":"AWS"},{"name":"Horusec"},{"name":"Jira"},{"name":"GitHub Issues"},{"name":"ChatGPT"},{"name":"Claude"}]` | `[{"name":"ServiceNow ITSM"},{"name":"Jira"},{"name":"Amazon Inspector"}]` |
| market.availability | `{"hqCountry":"US","primaryMarkets":["US","EU"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"primaryMarkets":["US","EU","GB"],"availabilityScope":"global","availableCountries":["US","GB","EU","CA","IN","AE","AU","SA"],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"hybrid","plans":[{"free":true,"name":"Free","features":["Core finding import & deduplication","REST API & Swagger UI","Manual import & reimport","Basic dashboard & reporting","Role-based access control","Authentication (username, LDAP, SAML, OAuth)","Automation (Rules Engine)","Tunable deduplication","Background imports","CLI & integrations","Universal parser (CSV/JSON)","Customizable dashboards & dark mode"],"description":"Community Edition with core vulnerability management","contactSales":false},{"free":false,"name":"Pro","features":["All Free features","Cloud-hosted option","Multi-factor authentication (MFA)","Premium support & SLAs","SOC & AppSec integration","MCP integration","Tenant isolation & encryption at rest","AI-driven insights","Known Exploited Vulnerabilities (KEV) enrichment","Advanced rules engine"],"description":"Enterprise edition with cloud hosting, advanced features, and priority support","contactSales":true}],"summary":"Free community edition; Pro pricing available via custom quote","currency":"USD","freeTier":true,"sourceUrl":"https://defectdojo.com/pricing","retrievedAt":"2026-08-19T22:47:01.798Z"}` | `{"type":"subscription","currency":"USD","sourceUrl":"https://www.qualys.com/partners/qlu-pricing","retrievedAt":"2026-08-20T12:47:23.533Z"}` |
| pricing.free_tier | yes | - |
| pricing.model | freemium | commercial |
| pricing.price_level | low | unknown |
| pricing.transparent | no | no |
| security.gdpr | yes | - |

## Capabilities (Vulnerability Management)

| Capability | DefectDojo | Qualys VMDR |
|---|:--:|:--:|
| **Capabilities** |  |  |
| Authenticated scan | - | - |
| Agent based | - | - |
| Agentless cloud | - | - |
| Asset discovery | - | - |
| Scap oval | - | - |
| PCI asv | - | - |
| Remediation workflow | - | - |
| Fedramp | - | - |
| Open source | - | - |

*Source: Vioscale. Generated 2026-09-01T17:16:17.733Z. "-" = undocumented, not absent.*
