What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is an automated assessment that checks your systems for known vulnerabilities, such as missing patches and configuration errors. A penetration test is a manual investigation in which ethical hackers approach your application or infrastructure like a real attacker, including vulnerabilities that scanners cannot find.

What a vulnerability scan does

A vulnerability scan automatically compares your systems against databases of known vulnerabilities. The scan is fast, repeatable and affordable, making it an excellent first security check and a good fit for continuous monitoring of your external attack surface. The result is a technical report with identified vulnerabilities and recommendations.

What a penetration test adds

A penetration test continues where the scanner stops. Our OSCP-certified pentesters manually investigate what automated tools systematically miss: business logic flaws, authorization issues such as IDOR, multi-tenant data leakage and combinations of small weaknesses that together lead to full compromise. A pentest also demonstrates real impact: not just that a vulnerability exists, but what an attacker could achieve with it. Regulators and standards such as NIS2, DigiD and ISO 27001 therefore require periodic penetration testing, not just scanning.

When to choose which

Choose a vulnerability scan for a first assessment, continuous monitoring or after smaller changes. Choose a penetration test for business-critical applications, compliance obligations and periodic in-depth testing. In practice they complement each other: continuous scanning for breadth, a periodic pentest for depth. See our plans and pricing for both.