# Vulnerability Scan vs Pentest, When Is Each Enough?

> Vulnerability scan or penetration test? What each delivers, common tools, a decision matrix and which requirements call for which.

- Source: https://www.sidd.swiss/en/insights/vulnerability-scan-vs-pentest/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Oliver Stutz
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

Vulnerability scans and penetration tests are routinely confused in the Swiss mid-market, yet they are two fundamentally different tools with different strengths, costs and purposes. A vulnerability scan is automated, broad, shallow detection of known security flaws. A penetration test is manual, deep, contextualised assessment with exploitation and business-risk translation. Anyone who does not grasp the distinction either overpays for a scan or gets too little depth from a "pentest" that is in truth just a scan.

**This article covers:**

- A clear definition and demarcation of both concepts.
- Market-standard tools (Tenable, Qualys, Rapid7, OpenVAS) and their strengths.
- When a scan suffices and when a pentest is needed, a decision matrix.
- How both are combined (vulnerability management lifecycle).
- Compliance requirements from ISO 27001, FINMA, DORA and NIS2.

Normative anchors are ISO/IEC 27001:2022 Annex A.8.8 (management of technical vulnerabilities), A.8.29 (security testing in development and acceptance), NIST SP 800-40r4 (Guide to Enterprise Patch Management Planning), CIS Critical Security Controls v8 Control 7 (Continuous Vulnerability Management), Art. 21(2)(e) NIS2 and DORA Art. 25.

## What a vulnerability scan delivers

A vulnerability scan is the automated identification of known security flaws by a scanning tool. The tool sends defined tests to target systems, analyses responses and compares them against a database of known vulnerabilities (CVE, vendor advisories, configuration benchmarks like CIS or DISA STIG).

Key characteristics:

- **Breadth:** thousands of systems in hours, hundreds of thousands of tests per scan, complete coverage of defined asset sets.
- **Frequency:** continuous or at least monthly, often daily for external assets.
- **Depth:** shallow, finds known CVEs, missing patches, misconfigurations; does NOT find business-logic bugs, auth-bypass logic, chained attacks or zero-days.
- **False positives:** market standard 5-15%, depending on tooling and asset type. Requires human triage.
- **Cost:** tooling typically CHF 10,000-80,000 per year depending on asset count, plus 0.2-1.0 FTE for operation and triage.

Typical findings: unpatched operating systems (e.g. outdated Windows Server versions), missing browser updates, open default ports, weak TLS configurations (TLS 1.0/1.1, weak cipher suites), default credentials, configuration drift versus hardening baselines, exposed admin interfaces.

## What a penetration test delivers

A penetration test is the manual, contextualised assessment of a defined target by ethical security specialists. Unlike the scan, the pentest is deep, targeted, narrative and assesses not merely the presence of a flaw but exploitability, business impact and the chaining of several weaknesses.

Key characteristics:

- **Breadth:** narrow, a defined target (a web app, a network segment, an API).
- **Frequency:** rare, typically annually or at each major release.
- **Depth:** high, finds business-logic bugs, auth bypass, privilege escalation, race conditions, data-exfiltration paths, combinations of several medium weaknesses into one critical path.
- **Signal:** high, with proof-of-concept code, reproduction steps and business-impact translation.
- **Cost:** high, CHF 15,000 for a small web test up to CHF 100,000+ for complex multi-asset engagements.

Typical findings: SQL injection, IDOR (Insecure Direct Object Reference), broken access control, server-side request forgery, race conditions in business-logic code, defective security controls on privileged operations, flaws that only become critical via chaining of several medium findings.

## Market-standard tools

In the vulnerability-scan segment there are four dominant market players in DACH (2025):

- **Tenable (Nessus, Tenable.io, Tenable.sc):** market leader in vulnerability scanning, good coverage across IT, OT, cloud, containers. From CHF 3,000-5,000 per year for Nessus Professional (small footprint) up to CHF 50,000+ for Tenable.io Enterprise.
- **Qualys (VMDR, Cloud Platform):** cloud-native, strong asset inventory and compliance modules. Price indication: CHF 15,000-100,000+ depending on asset count and modules.
- **Rapid7 (InsightVM):** strong UX, integrated patch management and remediation workflows. Price indication: CHF 12,000-80,000.
- **OpenVAS / Greenbone (GVM):** open source, decent baseline coverage, weaker than commercial tools in currency and UX. Suitable for SMEs with tight budget and in-house IT know-how.

Web-application scanners are a category of their own: Burp Suite Enterprise, OWASP ZAP, Acunetix, Detectify. They complement infrastructure scanners with HTTP/HTTPS-specific tests (XSS, SQL injection, CSRF, etc.). Cloud specialists like Wiz, Lacework and Orca Security specifically address cloud misconfiguration and CSPM requirements.

## Decision matrix

When does a scan suffice and when do you need a pentest? Practical decision logic:

- **Scan suffices:** monthly continuity monitoring of internal servers, patch verification, compliance reporting to the management body, asset inventory, external perimeter monitoring (e.g. daily scans for new exposed services).
- **Pentest required:** new web application before go-live, new mobile app, new cloud tenant after major migration, M&A due diligence, regulatory compliance evidence (FINMA, DORA, SOC 2), after a material architecture change, before important contract negotiations with key accounts.
- **Both required:** mature organisations combine the two, scans deliver the continuous overview and drive patch discipline; pentests deliver depth on critical assets and compliance evidence.

A proven SME architecture: monthly external vulnerability scan (investment: CHF 8,000-20,000 annually), quarterly internal scan (CHF 5,000-12,000 annually), annual pentest on the most important web application (CHF 20,000-40,000) and a biennial pentest on the internal infrastructure (CHF 30,000-60,000). Total annual CHF 50,000-130,000 for a robust programme, significantly less than the cost of a single real data breach.

## Vulnerability management lifecycle

Vulnerability scans and pentests are building blocks of a continuous vulnerability-management programme per CIS Control 7 or NIST SP 800-40r4. The typical lifecycle:

1. **Asset discovery:** what do we have? Inventory of all systems, enriched with CMDB data.
2. **Scan / test:** regular scans plus annual pentests.
3. **Triage:** false-positive filtering, rating by CVSS plus organisation-specific risk factor (exposure, data criticality, compensating controls).
4. **Prioritisation:** risk-based, not CVSS-based. A CVSS-10 flaw on an internal test system is prioritised lower than a CVSS-6 flaw in an internet-exposed production environment.
5. **Remediation:** patch, configuration change or compensating control. SLA: typically 24h critical, 7 days high, 30 days medium, 90 days low.
6. **Verification:** retest that the flaw is closed.
7. **Reporting:** monthly to IT leadership, quarterly to the management body with KPIs (Mean Time to Patch, backlog age, trend).

The KPI layer is decisive for credibility with audit and management body. Without MTTP metrics and trend data, the programme stays anecdotal.

## Compliance requirements

Several regimes explicitly require vulnerability management and/or regular testing:

- **ISO/IEC 27001:2022:** Annex A.8.8 (management of technical vulnerabilities) requires timely identification, assessment and remediation; Annex A.8.29 requires security testing in development and acceptance of new systems.
- **FINMA Circular 23/01 paras 59-65:** regular security testing including vulnerability scans and penetration tests, frequency by risk profile.
- **DORA Art. 25:** "general" resilience testing (vulnerability assessments, penetration tests, source-code reviews, scenario-based tests) for all financial entities; TLPT additionally for significant entities.
- **Art. 21(2)(e) NIS2:** security measures in acquisition, development and maintenance of network and information systems, including vulnerability handling.
- **PCI DSS v4.0:** regular vulnerability scans (internal quarterly, external via ASV) and annual pentests.
- **SOC 2 Type II:** Trust Services Criteria CC7.1 requires vulnerability management.

In Swiss audits a documented vulnerability-management programme with MTTP KPIs and pentest reports is increasingly demanded. Pure scan reports without a triage process are insufficient. More on our offering at [vulnerability scanning](https://www.sidd.swiss/en/services/vulnerability-scan).

## How SIDD supports you

SIDD builds combined vulnerability-management programmes for Swiss companies. We start with a maturity assessment (CIS Control 7), select fitting tooling (Tenable, Qualys, Rapid7, OpenVAS, by asset mix, budget and cloud strategy) and establish triage and remediation processes with clear SLAs and KPIs.

For the depth component we deliver [penetration tests](https://www.sidd.swiss/en/services/penetration-test) per OWASP WSTG, PTES and MITRE ATT&CK. For scan operations we take over the entire lifecycle (managed vulnerability management) or coach your internal team. For regulatory embedding in ISO 27001, FINMA, DORA or NIS2 we can place an [external CISO or ISO](https://www.sidd.swiss/en/services/vciso).

Arrange a non-binding initial conversation at [/kontakt](https://www.sidd.swiss/en/contact) or request a fixed-price quote for a pilot programme (three months managed vulnerability management plus initial pentest) at [/offerte](https://www.sidd.swiss/en/quote). That way you get a robust baseline and can demonstrate impact quantitatively.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
