Penetration Test vs Vulnerability Scan, Which Assessment Do You Need?
What is this about?
Penetration tests and vulnerability scans are regularly confused in the DACH market, but technically and commercially they are two very different security assessments. A vulnerability scan is an automated, signature-based inventory of known security gaps. A penetration test is a manual, targeted attack simulation by certified testers following OWASP, PTES or OSSTMM. Both assessments have their place, but they meet different compliance and risk requirements, and they cost very different amounts.
Direct comparison at a glance
| Dimension | Vulnerability scan | Penetration test |
|---|---|---|
| Methodology | Automated, signature-based | Manual, targeted, rule-based (OWASP, PTES, OSSTMM) |
| Output | List of known vulnerabilities with CVSS score | Validated findings including exploit proof, business-logic flaws, privilege escalation |
| Detects zero-days? | No | Limited, through manual code or architecture analysis |
| Detects logic flaws? | No | Yes |
| False positives | Frequent, manual validation required | Rare, each finding is verified |
| Duration | Hours to one day | Three days to several weeks, depending on scope |
| Repetition cadence | Recommended quarterly or monthly | Recommended annually or upon material change |
| Entry price (SIDD) | from CHF 5,000 per scan | by scope, indicative from CHF 15,000 (web/mobile) up to CHF 80,000+ (complex infrastructure) |
| Compliance anchor | Annex A.8.8 ISO/IEC 27001:2022 (Vulnerability Management) | Annex A.8.29 ISO/IEC 27001:2022 (Security Testing), PCI DSS, FINMA audits, DORA |
| Suited for | Standardised IT landscapes with known components | In-house developments, critical applications, regulated industries |
When does a vulnerability scan suffice?
A vulnerability scan is the right choice when you need a periodic baseline check of your infrastructure, patch status, configuration drift, known CVE gaps. For an SME (small and medium-sized enterprise) with a standardised cloud landscape (Microsoft 365, AWS standard services, off-the-shelf applications), the scan covers the most common risks at a fraction of the cost of a penetration test.
For ISO/IEC 27001:2022, a quarterly scan meets the requirements of Annex A.8.8 (Management of technical vulnerabilities). A documented, regular scan process is also sufficient for PCI DSS and many cyber insurance policies. The scan is also the tool with which you can detect configuration drift between two penetration tests.
If you have never carried out a security assessment, the vulnerability scan is also a good, cost-effective entry point to understand the rough maturity level, before you invest in a penetration test.
When do you need a penetration test?
A penetration test is required when you need a defensible statement about the security of a critical application, an in-house development or a complex architecture. Banks, insurers, regulated pharmaceutical companies, critical infrastructures (KRITIS/NIS2), and all organisations that process personal data at scale or special categories of data cannot avoid regular penetration tests.
SaaS providers also typically need an annual penetration test, enterprise customers demand the penetration test report in the vendor due diligence process. With in-house developments, the penetration test finds business-logic flaws (authorisation bypass, IDOR, race conditions) that an automated scan will systematically miss.
For DORA-regulated financial institutions, Art. 26 DORA prescribes Threat-Led Penetration Testing (TLPT) for critical functions. For FINMA-regulated institutions, the annual penetration test is de facto standard.
Do I need both?
As a rule yes, in combination. The typical setup for a mid-sized DACH company is: a quarterly vulnerability scan as ongoing baseline monitoring, an annual penetration test on the critical applications and infrastructure components, plus event-driven penetration tests on material architectural changes, new critical releases or before audit cut-off dates. This combination covers both the breadth (scan) and the depth (penetration test) and is straightforward to justify to supervisory authorities and customers.
The scan validates that your ongoing patch and configuration processes are working. The penetration test validates that your security design also holds up under active attack pressure.
How SIDD operates
For a vulnerability scan we deploy established commercial scanners, validate the findings manually, eliminate false positives and prioritise the real vulnerabilities by CVSS and business context. The output is a readable report with concrete remediation recommendations and an optional re-scan verification.
For a penetration test we follow the PTES methodology with pre-engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation and reporting. Our testers hold OSCP/CEH certifications and work under responsible-disclosure principles. You receive a management summary for the executive level plus a technical appendix with reproducible proof-of-concept steps. A re-test option after remediation is included in the fixed price.
Frequently asked questions
Does a vulnerability scan suffice for ISO/IEC 27001:2022? For Annex A.8.8 (Vulnerability Management) a documented, regular scan process is sufficient. For Annex A.8.29 (Security Testing) and for assessing effectiveness under A.5.35, a penetration test is recommended, though depending on maturity and risk profile not strictly required.
How often should we scan, and how often penetration test? Scan: quarterly as a minimum, monthly with high change frequency. Penetration test: annually plus upon material architectural changes (new cloud provider, new central application, M&A integration).
What does a penetration test actually cost? Penetration test prices depend strongly on scope. A web application with limited functionality starts at around CHF 15,000. Complex infrastructures with Active Directory, cloud and in-house developments can cost CHF 80,000 or more. SIDD quotes a fixed price with defined deliverables after a complimentary scoping call.
Can we buy an automated penetration test? No, what is sold as an "automated penetration test" is typically an extended vulnerability scan. Real penetration tests require manual analysis by a person who understands the business logic.
Which report is audit-grade? Both. The scan report documents the finding status at point in time X with a CVSS rating. The penetration test report additionally contains the methodology, test cases and proof-of-concept evidence, and is therefore the stronger document for FINMA, DORA or ISO audits.
How SIDD supports you
SIDD offers both assessments as standalone services: the vulnerability scan from CHF 5,000 and the penetration test by scope. For most mandates we recommend the combined setup (quarterly scan plus annual penetration test). For ongoing ISO 27001 / ISMS support we integrate both assessments into the annual audit programme. See also our Article 27 GDPR Compliance Guide for the link between technical security and data protection due diligence.
