What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is an automated assessment that checks your systems for known vulnerabilities, such as missing patches and configuration errors. A penetration test is a manual investigation in which ethical hackers approach your application or infrastructure like a real attacker, including vulnerabilities that scanners cannot find.

What a vulnerability scan does

A vulnerability scan automatically compares your systems against databases of known vulnerabilities. The scan is fast, repeatable and affordable, making it an excellent first security check and a good fit for continuous monitoring of your external attack surface. The result is a technical report with identified vulnerabilities and recommendations.

What a penetration test adds

A penetration test continues where the scanner stops. Our OSCP-certified pentesters manually investigate what automated tools systematically miss: business logic flaws, authorization issues such as IDOR, multi-tenant data leakage and combinations of small weaknesses that together lead to full compromise. A pentest also demonstrates real impact: not just that a vulnerability exists, but what an attacker could achieve with it. The test method needed depends on your risks and applicable requirements. A scan does not replace a pentest where one is explicitly required, for example within a DigiD assessment. NIS2 and ISO 27001 do not automatically impose the same pentest obligation on every organization.

When to choose which

Choose a vulnerability scan for a first assessment, continuous monitoring or after smaller changes. Choose a penetration test for business-critical applications, compliance obligations and periodic in-depth testing. In practice they complement each other: continuous scanning for breadth, a periodic pentest for depth. See our pentest cost and plans for both.