Penetration Test vs Vulnerability Scan, Which Assessment Do You Need?

4 min readLast updated By Dr. Dominic Staiger

What is this about?

Penetration tests and vulnerability scans are regularly confused in the DACH market, but technically and commercially they are two very different security assessments. A vulnerability scan is an automated, signature-based inventory of known security gaps. A penetration test is a manual, targeted attack simulation by certified testers following OWASP, PTES or OSSTMM. Both assessments have their place, but they meet different compliance and risk requirements, and they cost very different amounts.

Direct comparison at a glance

DimensionVulnerability scanPenetration test
MethodologyAutomated, signature-basedManual, targeted, rule-based (OWASP, PTES, OSSTMM)
OutputList of known vulnerabilities with CVSS scoreValidated findings including exploit proof, business-logic flaws, privilege escalation
Detects zero-days?NoLimited, through manual code or architecture analysis
Detects logic flaws?NoYes
False positivesFrequent, manual validation requiredRare, each finding is verified
DurationHours to one dayThree days to several weeks, depending on scope
Repetition cadenceRecommended quarterly or monthlyRecommended annually or upon material change
Entry price (SIDD)from CHF 5,000 per scanby scope, indicative from CHF 15,000 (web/mobile) up to CHF 80,000+ (complex infrastructure)
Compliance anchorAnnex A.8.8 ISO/IEC 27001:2022 (Vulnerability Management)Annex A.8.29 ISO/IEC 27001:2022 (Security Testing), PCI DSS, FINMA audits, DORA
Suited forStandardised IT landscapes with known componentsIn-house developments, critical applications, regulated industries

When does a vulnerability scan suffice?

A vulnerability scan is the right choice when you need a periodic baseline check of your infrastructure, patch status, configuration drift, known CVE gaps. For an SME (small and medium-sized enterprise) with a standardised cloud landscape (Microsoft 365, AWS standard services, off-the-shelf applications), the scan covers the most common risks at a fraction of the cost of a penetration test.

For ISO/IEC 27001:2022, a quarterly scan meets the requirements of Annex A.8.8 (Management of technical vulnerabilities). A documented, regular scan process is also sufficient for PCI DSS and many cyber insurance policies. The scan is also the tool with which you can detect configuration drift between two penetration tests.

If you have never carried out a security assessment, the vulnerability scan is also a good, cost-effective entry point to understand the rough maturity level, before you invest in a penetration test.

When do you need a penetration test?

A penetration test is required when you need a defensible statement about the security of a critical application, an in-house development or a complex architecture. Banks, insurers, regulated pharmaceutical companies, critical infrastructures (KRITIS/NIS2), and all organisations that process personal data at scale or special categories of data cannot avoid regular penetration tests.

SaaS providers also typically need an annual penetration test, enterprise customers demand the penetration test report in the vendor due diligence process. With in-house developments, the penetration test finds business-logic flaws (authorisation bypass, IDOR, race conditions) that an automated scan will systematically miss.

For DORA-regulated financial institutions, Art. 26 DORA prescribes Threat-Led Penetration Testing (TLPT) for critical functions. For FINMA-regulated institutions, the annual penetration test is de facto standard.

Do I need both?

As a rule yes, in combination. The typical setup for a mid-sized DACH company is: a quarterly vulnerability scan as ongoing baseline monitoring, an annual penetration test on the critical applications and infrastructure components, plus event-driven penetration tests on material architectural changes, new critical releases or before audit cut-off dates. This combination covers both the breadth (scan) and the depth (penetration test) and is straightforward to justify to supervisory authorities and customers.

The scan validates that your ongoing patch and configuration processes are working. The penetration test validates that your security design also holds up under active attack pressure.

How SIDD operates

For a vulnerability scan we deploy established commercial scanners, validate the findings manually, eliminate false positives and prioritise the real vulnerabilities by CVSS and business context. The output is a readable report with concrete remediation recommendations and an optional re-scan verification.

For a penetration test we follow the PTES methodology with pre-engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation and reporting. Our testers hold OSCP/CEH certifications and work under responsible-disclosure principles. You receive a management summary for the executive level plus a technical appendix with reproducible proof-of-concept steps. A re-test option after remediation is included in the fixed price.

Frequently asked questions

Does a vulnerability scan suffice for ISO/IEC 27001:2022? For Annex A.8.8 (Vulnerability Management) a documented, regular scan process is sufficient. For Annex A.8.29 (Security Testing) and for assessing effectiveness under A.5.35, a penetration test is recommended, though depending on maturity and risk profile not strictly required.

How often should we scan, and how often penetration test? Scan: quarterly as a minimum, monthly with high change frequency. Penetration test: annually plus upon material architectural changes (new cloud provider, new central application, M&A integration).

What does a penetration test actually cost? Penetration test prices depend strongly on scope. A web application with limited functionality starts at around CHF 15,000. Complex infrastructures with Active Directory, cloud and in-house developments can cost CHF 80,000 or more. SIDD quotes a fixed price with defined deliverables after a complimentary scoping call.

Can we buy an automated penetration test? No, what is sold as an "automated penetration test" is typically an extended vulnerability scan. Real penetration tests require manual analysis by a person who understands the business logic.

Which report is audit-grade? Both. The scan report documents the finding status at point in time X with a CVSS rating. The penetration test report additionally contains the methodology, test cases and proof-of-concept evidence, and is therefore the stronger document for FINMA, DORA or ISO audits.

How SIDD supports you

SIDD offers both assessments as standalone services: the vulnerability scan from CHF 5,000 and the penetration test by scope. For most mandates we recommend the combined setup (quarterly scan plus annual penetration test). For ongoing ISO 27001 / ISMS support we integrate both assessments into the annual audit programme. See also our Article 27 GDPR Compliance Guide for the link between technical security and data protection due diligence.

Need help putting this into practice? SIDD operates the matching service.
See service →

Penetration Test vs Vulnerability Scan, Which Assessment Do You Need?

INSIGHT

Pillar · InfoSec
18 June 2026
Dr. Dominic Staiger
Penetration test vs vulnerability scan, methodology, costs, compliance fit and when you need which assessment. Comparison table and 2026 guide.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.