Skip to content
All guidesSecurity & asset platforms

Connect Qualys VMDR to Cybermatic

Create a dedicated Reader account with API access, set its password policy, find your platform's API URL, and connect — hosts and detections flow into Cybermatic.

  1. 1Phase 0 — Confirm prerequisites. Before configuring anything, verify: • You have Qualys VMDR. • Your Qualys subscription allows API access. • At least one vulnerability scan has completed. • You can sign into Qualys using a Manager account or have someone with Manager permissions create the service account. Qualys documents that Manager users can create users and assign roles. • You have Cybermatic Growth plan or higher. • You can access Cybermatic → Connections. • You have access to your organization's password/secrets manager.
  2. 2Step 1 — Create the Cybermatic Qualys account. 1. Sign into Qualys. Use your normal administrative/Manager Qualys account. Do not use your own account as the permanent Cybermatic integration account. The goal is to create something similar to: First name: Cybermatic Last name: Scanner Role: Reader 2. Open user administration. Depending on your Qualys interface, go to the application picker and open Administration, then navigate to User Management. Qualys' current documentation describes creating Reader users through: Administration → User Management → Create User → Create Reader User. 3. Create the user. Select Create User. Enter something like: First name → Cybermatic Last name → Scanner Title → Scanner Phone → [Enter your Company Phone] Email → [A monitored security/IT mailbox] Address → [Your company street address] Country → [Country where your company resides] On the menu on your left go to User Role. Make sure of the following: Role → Reader Allow Access to → GUI and API are both checked Business Unit → You may leave that as "Unassigned" On the menu on your left go to Asset Groups. Choose the Asset Group(s) that Cybermatic will scan. Cybermatic can only ingest assets and groups the Qualys account is permitted to see. On the menu on your left go to Options. On the latest Vulnerabilities select Daily. Leave all Scan and Map options as On. Click Save. Important SSO consideration: if your organization normally forces SSO for Qualys, verify that this dedicated account can authenticate using Qualys username + password. Qualys states that its traditional API authentication using user credentials does not support an account relying solely on SSO authentication. This matters because Cybermatic specifically requires username + password.
  3. 3Step 2 — Activate the Qualys account. Qualys should send an account/activation message to the email address you entered. Complete the activation process and establish a strong unique password. Record the Username and Password. Do not place the password in Teams, Slack, email, Jira, or configuration documentation.
  4. 4Step 3 — Edit password expiration. This is important for avoiding an integration mysteriously failing months later. For current Qualys configurations, check the user from Administration → User Management. Check the user Cybermatic Scanner. Quick Actions → Edit Basic Details. Go to User Role and uncheck GUI. Go to Security: under Password Never Expire - API Access, check "Password for this account will never expire, unless a password change request is initiated via the Qualys UI or via the Qualys user password change API". Click Save. Important consideration: if your organization requires rotation instead, record your Qualys Cybermatic password rotation date (for example: November 7, 2026) and rotate it before expiration. When you change the Qualys password, you will also need to update the credentials stored in Cybermatic.
  5. 5Step 4 — Find your Qualys API URL. Do not assume that your API URL is qualysapi.qualys.com. Qualys accounts are hosted on different platforms. Sign into Qualys. Select Help → About. Look for your platform/API server information. Qualys' current documentation explicitly says the correct API server depends on the platform hosting your account and that you can determine it from Help → About. You may see something similar to: https://qualysapi.qualys.com https://qualysapi.qg2.apps.qualys.com https://qualysapi.qg1.apps.qualys.eu Copy the exact API URL shown for your account, and record it. Do not choose an endpoint based merely on your geographic location.
  6. 6Step 5 — Sign into Cybermatic. Sign into your Cybermatic tenant. Open Connections. Find the area labeled Security & asset platforms. Select Qualys VMDR.
  7. 7Step 6 — Enter the Qualys API server and credentials. For API Server URL, paste the exact value you copied from Qualys → Help → About. For example: https://qualysapi.qg2.apps.qualys.com Enter the dedicated credentials: Username: your dedicated Cybermatic Qualys Reader account (the User Login, not an email address). Password: the unique password you created. Verify the password carefully before proceeding. Click Connect. Cybermatic should query Qualys for the assets and vulnerability detections accessible to that account. The first scan starts immediately.
  8. 8What Cybermatic checks. • Removed at the source? Devices you delete in Qualys disappear from Cybermatic automatically on the next scan. • Every Qualys-scanned host joins your asset inventory, risk-rated from its worst active detection (severity 5 → Critical, 4 → High, 3 → Medium). • Active vulnerability detections (severities 3–5, confirmed vulnerabilities only — informational items are excluded), grouped by QID and resolved to titles and CVEs through the Qualys KnowledgeBase. • Volume control: the highest-severity 200 detections. Vulnerabilities are owned by their source: each closes automatically once Qualys marks the detection Fixed on a following scan.
  9. 9Troubleshooting. "username or password rejected (401)" — first, confirm the username is the Qualys User Login (system-generated, like abcde3xy), not the email address. Then: has the account signed in to the web console once to complete activation? Is it temporarily locked from failed attempts? Has the password expired on the rotation schedule? Fix in Qualys, then use Connections → Update credentials. "access denied (403) — the account lacks API access" — edit the user in Qualys and enable API access under its permissions (Step 1, item 5). Authentication fails with correct credentials — the API server URL is for a different pod than your account; re-check Help → About (Step 2). Findings show QIDs without CVE numbers — some Qualys detections (especially configuration-style checks) have no CVE; the QID title still describes the issue precisely. Counts look low — Cybermatic imports severities 3–5 only, capped to the top 200 by severity; Qualys remains the system of record for the full detection list.

Tip: The two settings that prevent 401 mysteries months later: API access checked on the User Role, and the password set to never expire for API access (Step 3). And always copy the API URL from Help → About — never guess it from geography.

More in Security & asset platforms