Penetration testing vs vulnerability scanning: which one you need
By The PenTest Index · Prices and rule text checked October 8, 2026
Penetration testing vs vulnerability scanning comes down to proof: a vulnerability scan checks your systems against known weaknesses and lists what it finds, while a penetration test tries to exploit weaknesses inside an agreed scope and shows what an attacker could reach. They are different activities with different reports. Check which one you were asked for before paying for either.
Penetration testing vs vulnerability scanning at a glance
A scan finds and lists. A test tries to get in and shows how far it got. Think of a scan as checking every door and window against a list of known bad locks. A penetration test (pentest for short) is someone you hired actually trying the doors, then telling you which rooms they reached.
| Vulnerability scan | Penetration test | |
|---|---|---|
| Question it answers | "Which known weaknesses do these systems appear to have?" | "What could an attacker actually do with the weaknesses here?" |
| How it works | Software runs checks. People may set it up, review the results and rank them. | A tester works through attack scenarios inside an agreed scope. Tools, including scanners and AI, are often part of it. |
| What you receive | A list of findings with severity ratings. | A report on what was tried, what worked, what it exposed and how to fix it. |
| How long it takes | PCI SSC's guidance says seconds to minutes per scanned host. | The same guidance says days or weeks. Some AI-led offers now advertise same-day reports. |
| Published price examples | $199 a month or $1,999 a year for one target (Astra Scanner). | $3,400 for a black-box web app test (Pentest-Tools.com). $5,999 a year per target (Astra Pentest Expert). |
| What "no findings" means | Those checks found nothing under those conditions. | That work found nothing inside that scope. Neither one means "secure". |
| After you fix things | Run the scan again. | Ask for a retest. Check how many are included and the deadline to request one. |
Purpose, method and duration rows follow section 2.1 of the PCI SSC Penetration Testing Guidance (September 2017) and the NIST glossary definitions drawn from SP 800-115. Prices are each provider's own published figure, checked October 8, 2026. Details are in the price section below.
One caution on the labels. A "vulnerability assessment" usually means a scan plus a person reviewing and ranking the results. It sits closer to a scan than to a penetration test, but providers use these words differently. Read what the service says it does.
Which one do you need?
Start with who asked and what their words say. If nobody asked and you want fewer known holes, start with scanning. If someone asked for a penetration test report, a scan will not produce that document.
| Your situation | Likely route | What could change it | Do this first |
|---|---|---|---|
| A customer, contract or questionnaire says "penetration test". | Commission a scoped penetration test. Keep any scanning you have. | Your current provider already includes a suitable test. | Ask the requester the question below, then check your existing agreement. |
| Nobody asked. You want regular checks for known problems. | Scanning, plus a named person who fixes what it finds. | You have an app with logins and roles that a scanner can't reason about. | Check what your current tools already cover. |
| You handle card payments under PCI DSS. | Both, if both requirements apply to your environment. | Your assessor or acquirer confirms your exact obligations. | Confirm scope with them before buying. |
| An auditor's evidence list has a pentest line. | Whatever the auditor confirms in writing. | They accept scan results, or they require a test. | Send the question below. |
| Someone said "get security testing" and nothing more. | Don't buy yet. | They name the systems and the kind of report. | Send the question below. |
| A service you already pay for includes a "pentest". | Use it if it fits. You may not need to buy anything. | Its scope, date or method doesn't match the request. | Run it through the eight checks further down. |
The question to send whoever asked:
"Please confirm whether you need a vulnerability scan, a penetration test, or both. Which application, API or network must be covered? Is automated-only testing acceptable? Does the tester need to be independent of our team? What must the report contain, how recent must it be, and when do you need it?"
Their answer is your requirement. It is not a promise that they will accept the report, so keep it in writing. There are more questions for your report recipient in our scope checklist.
Already know you need a penetration test? See published offers and prices.
What do PCI DSS, SOC 2 and other rules actually ask for?
Of the rules we could read in their own words, PCI's guidance and New York's financial services rule name both activities as separate things. For most other requests, a person decides what is enough, so the useful move is to ask that person.
| Who is asking | Vulnerability scanning | Penetration testing | What we read, and when |
|---|---|---|---|
| PCI DSS (card payments) | PCI SSC's guidance describes scans at least quarterly and after significant changes. A PCI SSC FAQ says external scans under Requirement 11.3.2 must be done by a listed Approved Scanning Vendor (ASV) using that vendor's ASV solution. | The same guidance describes penetration tests at least annually and after significant changes. It also says that simply running an automated tool does not satisfy the penetration testing requirement. | Penetration Testing Guidance v1.1, September 2017, written for PCI DSS v3.2; FAQ 1604. Checked October 8, 2026. |
| New York DFS, 23 NYCRR 500.5 (covered financial firms not exempt under section 500.19) | Automated scans, with manual review of systems the scans don't cover, at a frequency set by the firm's risk assessment and promptly after material system changes. | Penetration testing from inside and outside the systems' boundaries, by a qualified internal or external party, at least annually. | Section 500.5 as published by Cornell's Legal Information Institute. Checked October 8, 2026. |
| HIPAA Security Rule | HHS published a proposed rule on January 6, 2025 that includes a vulnerability management standard. | Covered by the same proposal. | Federal Register notice, 90 FR 898. Checked October 8, 2026. A proposal is not a requirement. The 2026 Unified Agenda lists it under Long-Term Actions, with final action targeted for July 2027. |
| SOC 2 | Your auditor decides what evidence is enough. | Your auditor decides. | We could not read the AICPA criteria text for this check, so we don't quote it. Ask the auditor in writing. |
| A customer contract or questionnaire | Whatever their words say. | Whatever their words say. | Your own document. The customer decides. |
Two limits on the PCI row. The guidance is from 2017 and uses the numbering of an older version of the standard, so confirm the current wording with your assessor. And a passing ASV scan covers only that scan. PCI SSC's FAQ 1234 says the scan report is not an indication that any other PCI DSS requirements have been reviewed.
Outside these rules, your regulator or customer sets the bar. The same question applies.
How much does a vulnerability scan cost compared with a penetration test?
On the prices we checked, a scanner starts around $95 to $199 a month, and a people-led penetration test starts at $3,400 for one web app. These are single published offers, not a market average. Several larger firms on our comparison publish no price and ask you to request a quote.
| What you are buying | Published price (US dollars) | Who or what does the testing | The condition that matters |
|---|---|---|---|
| A scanner you run yourself | Astra Scanner: $199 a month or $1,999 a year, one target. | Software. Annual billing includes four expert-vetted scans. | You run it and you fix what it finds. It does not produce a penetration test report. |
| Pentest-Tools.com NetSec: advertised from $95 a month for five assets. | Software. | Price varies by asset count and billing cycle. | |
| An AI-led test | Astra Pentest Auto: $2,999 a year, one target. | Autonomous testing, plus one human re-scan under the conditions listed for Expert below. No human initial pentest listed in this plan. | Ask your report recipient whether automated-only testing is acceptable. |
| Intruder AI web app pentest: $3,500 per test. | "AI-powered" white-box testing, per Intruder. | You must connect a code repository. Our homepage notes a different new-customer figure in another Intruder source, so confirm the price for your purchase. | |
| A test led by people | Pentest-Tools.com managed web app test: $3,400 black box. Gray box starts at $3,400 plus $900 per user role. | Human testers. | The page does not mention API coverage or retests. Ask. |
| Astra Pentest Expert: $5,999 a year, one target. | Manual pentest by people, plus autonomous testing and scanning. | Two manual re-scans, requested within 30 days of the vulnerabilities being reported, after at least 50% of Critical and High findings are fixed. One web app and the APIs it uses count as one target. |
All prices are provider-published and were checked on October 8, 2026. They are advertised prices, not quotes for your scope.
View Intruder's pentest pricing
What the gap buys. Astra sells all three kinds for the same kind of target, which makes the difference easy to see:
- Scanner only: $1,999 a year.
- AI-led test: $2,999 a year.
- People-led test: $5,999 a year. That is $4,000 a year more than the scanner alone ($5,999 minus $1,999).
Two more sums from the same pages. Paying for Astra Scanner monthly costs $2,388 over a year ($199 times 12), which is $389 more than the annual price. And a Pentest-Tools.com gray-box test with two user roles starts at $5,200 ($3,400 plus two times $900). That is a starting amount, not a complete price.
We don't sell testing or scanners, and we have not bought or run these services. How we make money. For budgeting a full test, see penetration testing cost.
We already scan. What would a penetration test add?
A penetration test adds something when it looks at a question your scanner can't answer. If the new work covers the same ground as the old, you paid twice for one result.
Say you run a 30-person software company. You already pay for external scanning. A customer's security questionnaire asks for your most recent penetration test report covering your web app, its API and two user roles. This company is made up. The offers below are real, and we applied them to its request.
Our conclusion first: keep the scanner, and don't buy another one. The request needs a penetration test of the app. Which offer fits depends on one answer from the customer: is automated-only testing acceptable?
| What the request needs | Your existing scanner | Astra Pentest Expert, $5,999 a year | Pentest-Tools.com gray box, from $5,200 | Intruder AI pentest, $3,500 |
|---|---|---|---|---|
| A penetration test report (must-have) | Mismatch. It produces scan results. | Supported. Astra lists a manual pentest in this plan. | Supported. The service is a manual web app pentest. | Supported as described by Intruder. |
| The web app and its API (must-have) | Mismatch. | Supported. Astra counts one web app and the APIs it uses as one target. | Unresolved. The page doesn't mention APIs. | Unresolved. Confirm API coverage. |
| Two logged-in user roles (must-have) | Mismatch. | Unresolved. Not stated on the pricing page. | Supported. Priced at $900 per role. | Unresolved. The page says you provide credentials. Confirm roles. |
| The customer accepts the testing method (must-have, unknown) | Not applicable. | Unresolved until the customer answers. | Unresolved until the customer answers. | Unresolved. If the customer wants people-led testing, this is a mismatch. |
| You can share source code (depends on you) | Not applicable. | Not required on the page we read. | Not required on the page we read. | Required. If you can't connect a repository, this is a mismatch. |
This is the PenTest Index Purchase Check: we match each requirement to what the offer's own page says. "Supported" means that one condition is backed by the provider's published terms on October 8, 2026. It is not a quality rating, and it does not mean the customer will accept the report. A must-have mismatch takes an offer off the list. An unresolved must-have keeps it conditional.
How the customer's answer changes the choice:
- "It must be tested by people." Look at the two people-led offers. Ask Pentest-Tools.com about the API, and ask Astra about the two roles.
- "Automated is fine." Intruder becomes a candidate if you can share code. Its refund promise, if an auditor rejects the report, is a refund. It is not acceptance.
- No clear answer. Get one before you pay anyone.
Before buying anything new, ask your current provider:
"Does our agreement include a penetration test of our application and API covering these user roles, or only vulnerability scanning? Please point to the included scope and any extra charge."
If a suitable test is already included, use it. If it's clearly excluded, you have a gap to fill. If the answer is vague, ask for the scope in writing.
When you do go to providers, send each one the same scope so their answers line up. Our free checklist walks through what to write down: what needs testing, roles, exclusions, report needs and retest timing. You copy or print it. It needs no contact details, and it doesn't pick a provider for you.
The checklist is a buying aid. It does not give anyone permission to test. Written authorization has to cover the actual targets and activities.
Is an automated or AI pentest a scan or a penetration test?
It can be either, and the name doesn't settle it. What matters is whether the service only lists possible weaknesses or also tries to use them and shows the result.
Some AI-led offers say they attempt exploitation. The human role differs from one offer to the next: building the system, directing a test and checking a fix are three different jobs. PCI SSC's 2017 guidance calls penetration testing "essentially a manual endeavor", and it was written before these products existed. Whether an AI-led report meets your need is a call for the person receiving it.
Ask the seller: "What does this service attempt beyond detection, and what does a person do on my test?" Ask the recipient: "Is automated-only testing acceptable?"
How can you tell if a "penetration test" is really a vulnerability scan?
Look for two things: proof that someone tried to exploit the findings, and a plain statement of what was done by hand. A low price alone proves nothing. Run these eight checks on a quote or a report.
| Check | If the answer is no or missing |
|---|---|
| 1. Does each finding show an attempt to exploit it, with evidence you can follow, or explain why exploitation was not attempted? | It reads like scan output. Ask what was attempted. |
| 2. Does it say which work was automated and which was done by a person? | Ask for that split in writing. |
| 3. Does it name who tested and say they are independent of the team that runs the systems? | Ask. Some recipients require independence. |
| 4. Are the findings more than a list of CVE numbers with severity scores? (A CVE is a public ID for a known vulnerability.) | A bare CVE list is the usual shape of a scanner export. |
| 5. Did the tester log in as your user roles and try to reach another user's data? | Ask which access controls and app logic were tested. |
| 6. Do the test dates match the effort described? | Minutes of activity sold as a multi-day test is worth a question. |
| 7. Does it state scope, exclusions and limits? | You can't tell what was covered. |
| 8. Does the quote say how much human testing is included? | Ask before you sign. |
None of these proves quality. They tell you what to ask. Several come from ideas in section 5.4 of the PCI SSC guidance, a checklist for people who receive a pentest report. The same document says that merely reporting lists of vulnerabilities does not meet the intent of a penetration test.
Have a quote in hand? Put it through the same six questions we ask of every offer. For what a finished report should contain, see penetration testing report.
Which comes first, and how often?
If you have no regular checks and nobody is waiting on a report, start with scanning and fix what it finds. A penetration test of a system full of known, unpatched problems mostly tells you what a scanner would have. If a customer or auditor has set a deadline for a penetration test, book that now and keep scanning alongside it.
For timing, use the rule that applies to you from the table above. Where no rule applies, the UK's National Cyber Security Centre gives a reasonable starting point: scan infrastructure at least once a month, and scan an application any time it changes. That is NCSC guidance from January 2021, not a legal requirement.
For a penetration test, the trigger is change. A new login system, a new API, a new type of user or a new customer requirement can each make last year's report stale.
Questions people ask before testing
Can a scan or a penetration test disrupt production?
Yes, either can. PCI SSC's guidance notes that testing in production during business hours may affect operations, and that some older systems have known problems with automated scanning. Agree the targets, the hours, what is off limits and who to call before anything runs.
Can our own team do it?
Sometimes. PCI SSC's guidance allows a qualified internal tester who is organizationally independent of the people managing the systems. New York's rule allows a "qualified internal or external party". A customer may want an outside firm anyway, so ask before you rely on an internal report.
What is a PCI ASV scan?
It is an external vulnerability scan run by an Approved Scanning Vendor, a company listed by PCI SSC. It is a scan. It is not a penetration test, and it does not show that other PCI DSS requirements are met. PCI SSC explains who needs one, and points to its list of approved vendors, in FAQ 1604.
Do I need both?
Often, because they do different jobs. Scanning runs frequently and catches known problems as they appear. A test runs occasionally and shows what those problems, and the ones a scanner can't see, add up to. Buy the second one when someone needs its answer.
Sources and how we checked
We read each source below on October 8, 2026. We did not buy, run or test any service on this page. The 30-person company is an example we made up; the offers applied to it are the providers' own published terms.
- PCI Security Standards Council, Information Supplement: Penetration Testing Guidance v1.1, September 2017. Supplemental guidance written for PCI DSS v3.2. It does not replace the standard.
- PCI Security Standards Council, FAQ 1604 and FAQ 1234.
- NIST Computer Security Resource Center glossary: penetration testing and vulnerability scanning, citing SP 800-115 (2008).
- 23 NYCRR 500.5, as published by Cornell's Legal Information Institute.
- U.S. Department of Health and Human Services, proposed rule, 90 FR 898, January 6, 2025.
- UK National Cyber Security Centre, Vulnerability scanning tools and services, January 19, 2021.
- Provider pricing pages: Astra, Pentest-Tools.com managed testing, Pentest-Tools.com tools, Intruder.
We are not affiliated with PCI SSC, NIST, HHS, NCSC, New York DFS or any provider named here. Whether a report meets a requirement is decided by your auditor, assessor, customer or regulator.