Qualys External Attack Surface Management gives security teams an outside-in view of internet-facing infrastructure and continuously tracks connected assets. It discovers domains, subdomains, cloud workloads, web applications, APIs, certificates and exposed services, identifies organizational ownership, and maps relationships. It can flag unapproved cloud services, test environments and abandoned assets, as well as detect new exposure and changes to existing services. Qualys TruRisk scores help prioritize assets using vulnerabilities, misconfigurations, asset criticality and external exposure. Teams can add discovered assets to inventory and scan them with VMDR for vulnerabilities, exposed services, certificates and configuration weaknesses. Native integrations include VMDR, Certificate View, Policy Compliance and Web Application Scanning. CSAM with EASM can produce PCI-DSS and FedRAMP asset security health reports and provides bidirectional ServiceNow CMDB integration. The managed service runs from a public or private cloud and is accessed through a browser without local installation. Its listed CSAM with EASM offer is no cost for 30 days; other pricing is on request. Shodan discovery on leased IPv4 netblocks requires contacting a Qualys Technical Account Manager.
Who it is for
It suits security teams that need to identify, track and prioritize internet-facing assets, including unmanaged resources. Organizations using Qualys VMDR or ServiceNow can also use its listed integrations and asset reporting.
What is good
- Continuously monitors internet-connected assets.
- Finds domains, cloud workloads, APIs and exposed services.
- Prioritizes assets with Qualys TruRisk scores.
- Supports PCI-DSS and FedRAMP asset health reports.
- Browser-based managed service needs no local installation.
What to know first
- Shodan discovery on leased IPv4 netblocks requires contacting a Technical Account Manager.
- Other pricing is on request.
- Listed 30-day offer is no cost only for 30 days.
Freedom251 review
Qualys External Attack Surface Management: the full review
Qualys EASM combines asset discovery, ownership mapping, change detection and risk prioritization for external infrastructure. Check the Shodan discovery requirement and pricing terms against your needs before choosing it.
Qualys External Attack Surface Management is an outside-in asset discovery and monitoring service for security teams. It suits organizations that need to connect external exposure findings to Qualys vulnerability and compliance workflows. Its asset attribution and prioritization are useful strengths, while Shodan discovery requires an extra enablement step and the no-cost offer lasts only 30 days.
Overview
EASM continuously identifies internet-facing domains, subdomains, cloud workloads, web applications, APIs, certificates and public services, then maps which assets belong to an organization and how they relate. That ownership context helps teams separate their estate from the surrounding internet and spot unapproved cloud services, test environments, abandoned assets and other unmanaged resources.
Change detection catches newly exposed assets and shifts in existing services. Qualys TruRisk scores weigh vulnerabilities, misconfigurations, asset criticality and external exposure, giving teams a basis for deciding what to address first. Discovered assets can be added to inventory and scanned with VMDR for vulnerabilities, exposed services, certificates and configuration weaknesses, which makes EASM a stronger fit for organizations already using Qualys security products.
Key features
- Continuous discovery and attribution: Coverage spans external infrastructure, including certificates and APIs, while ownership mapping helps make a broad inventory actionable. Shodan data can enumerate exposed assets on leased IPv4 netblocks, but a Technical Account Manager must enable that discovery. Teams needing that coverage should account for the added coordination.
- Risk and vulnerability workflow: TruRisk prioritization combines several exposure factors rather than treating every discovered asset equally. Sending assets into VMDR creates a path from discovery to scanning, but this workflow is most valuable to teams prepared to operate within Qualys.
- Integrations and reporting: Native integrations include VMDR, Certificate View, Policy Compliance and Web Application Scanning. CSAM with EASM can produce asset security health reports for PCI-DSS and FedRAMP, and provides enriched, bidirectional ServiceNow CMDB integration for a continuously updated asset view.
- Deployment and controls: The managed service runs from public or private cloud, needs no server or software installation, and is accessed through a browser. Qualys documents end-to-end encryption, strong access controls and SAML 2.0 enterprise SSO for CSAM. Extensible XML APIs and integrations with GRC, ticketing, SIEM, ERM and IDS systems support wider workflows.
Pricing
The CyberSecurity Asset Management 3.0 with External Attack Surface Management plan costs 0.00 USD per free, billed 30 days, and includes CSAM with EASM at no cost for 30 days. That is a time-limited evaluation, not a continuing free plan. A free trial is available, and ongoing pricing is custom pricing.
The 30-day offer is suited to teams assessing whether discovery and Qualys workflows match their needs; it is not a durable option for maintaining monitoring without a paid arrangement. Teams should also confirm whether they need Shodan enumeration and arrange its activation before relying on that coverage.
Platforms
The service is accessed through a browser and supports API and Linux platforms. Its managed cloud deployment avoids installing servers or software, which favors teams seeking centrally delivered coverage rather than a locally installed scanner.
Who it's for
Qualys EASM is best for organizations with external-facing infrastructure to monitor and security teams that want ownership mapping, continuous change detection and risk-based prioritization tied to Qualys VMDR and related products. Its compliance reporting and ServiceNow integration also suit teams maintaining asset inventories alongside PCI-DSS or FedRAMP reporting. It is a weaker fit for buyers seeking a lasting free tier or who need leased-netblock Shodan discovery without an enablement dependency.
Pros and cons
- Pro: Broad discovery across domains, cloud workloads, applications, APIs, certificates and public services can expose unmanaged assets as well as known infrastructure.
- Pro: TruRisk prioritization and VMDR scanning connect external findings to vulnerability work rather than leaving them as a separate inventory.
- Pro: ServiceNow CMDB integration, compliance reports and native Qualys integrations support established asset and security workflows.
- Con: The 0.00 USD offer ends after 30 days, so it cannot serve as an ongoing free monitoring option.
- Con: Shodan discovery for leased IPv4 netblocks requires contacting a Qualys Technical Account Manager, adding a dependency for teams that need it.
Alternatives
For another attack-surface option, compare runZero and FullHunt. runZero has a free Community Edition covering 100 assets, one organization, 10 recurring tasks and 30 days of data retention, making it worth considering when a capped ongoing free plan matters more than Qualys's 30-day offer. FullHunt's free plan provides 10 credits per month for evaluation or internal use, including discovery, enrichment, exposure and vulnerability or exploit intelligence; its Builder plan costs 149.00 USD, a possible fit for buyers seeking a credit-based entry point.
Censys Attack Surface Management is another paid, quote-based option with assets-under-management pricing, while Check Point External Risk Management is another paid alternative. Outpost24 Attack Surface Management uses custom packages based on cybersecurity goals, teams and timelines, which may suit buyers seeking a tailored scope. For adjacent needs, consider Bitdefender Total Security, ImmuniWeb or Ivanti Neurons for Zero Trust Access; these are alternatives to assess against their respective use cases.
Browse Attack Surface Management Software, SaaS Security Posture Management Software, Dynamic Application Security Testing Software, Certificate Management Software, Database Vulnerability Scanners and Vulnerability Management Software for related categories.
Verdict
Choose Qualys EASM if your organization needs continuous external asset discovery and wants to carry findings into Qualys risk and vulnerability workflows. Its attribution, change detection and prioritization make it a coherent choice for that operating model. Look elsewhere if you require an ongoing free plan or cannot accommodate the Technical Account Manager step for Shodan discovery.
Qualys External Attack Surface Management plans and pricing
All plansCompared on patch management software
- Free plan
- No
- External asset discovery
- Yes
- Cloud asset discovery
- Yes
- Monitoring frequency
- continuous
- API access
- Yes




