Penetration Test vs Vulnerability Scan.
A vulnerability scan tells you what is broken according to a signature database. A penetration test tells you what an adversary would actually do with what is broken.
A vulnerability scan tells you what is broken according to a signature database. A penetration test tells you what an adversary would actually do with what is broken.
File · Answer first
You run both, on different clocks, because they answer different questions. A scan runs weekly and tells you which known issues are present right now. A pentest runs annually or per release and tells you which of those issues an operator can chain into something that actually hurts the business. Drop the scan and you lose coverage of the known class between tests. Drop the pentest and you never learn what the chain looks like. The rest of this page is how to place each one in a program.
File · What each
File · How to
Run continuous scans for hygiene. Commission a manual pentest at the cadence your audit or risk program requires. The scan catches the known class. The pentest catches what the scan structurally cannot see. One warning when you buy the pentest: if the deliverable is a Burp or Nessus export under a nicer cover page, what you paid for was the cover page. That is the scan you could have run yourself.
File · FAQ
Q1 Can I skip the scan if I do an annual pentest?
No. The scan covers volume between tests; the pentest covers depth at a point in time. You need the running coverage and the annual depth, not one or the other.
Q2 Does SOC 2 accept a scan instead of a pentest?
No. SOC 2 examiners expect manual testing with attack-path narrative.
Q3 What does a scan cost vs a pentest?
A scanner subscription is a low recurring line item; a pentest is scoped per engagement and runs higher because senior operator time is the cost. See what a pentest costs in 2026 for the ranges we actually quote.
Talk to an Operator
Real operators. Real attack paths. Real business impact. Talk to us about your security goals.