Guide

Vulnerability scan vs penetration test: the difference, plainly

Updated

These terms get used interchangeably by people selling both, and the price difference is roughly ten to one. Buying the wrong one wastes money or, worse, fails the requirement you were trying to meet.

The plain difference

Vulnerability scan
An automated tool checks systems against a database of known weaknesses and produces a findings list. Fast, repeatable, cheap: from free (open-source tooling) to a few hundred pounds per scan, or a subscription. It cannot chain findings together, understand business logic, or confirm what is actually exploitable.
Penetration test
A qualified human attempts to compromise the scoped systems the way an attacker would: chaining weaknesses, testing logic, and proving impact. Priced in days at £700–£1,200 (typical 2026 quotes) and delivering an evidenced report. A scan is often run inside a penetration test as one early step; it is never the whole test.

The NCSC describes penetration testing as gaining assurance by attempting to breach systems the way an attacker would, using the same tools and techniques (ncsc.gov.uk penetration testing guidance). An unattended tool run does not meet that description, whatever the invoice says.

Where Cyber Essentials fits

Cyber Essentials is a separate NCSC-backed certification of baseline security controls, not a penetration test. Cyber Essentials Plus includes a technical audit and some scanning-based verification, but certifying does not mean your systems have been penetration tested, and a penetration test does not certify you for Cyber Essentials. Contracts sometimes require both; read the wording carefully before buying either.

Which one does your requirement mean?

  • "Evidence of penetration testing" in a contract or ISO 27001 / SOC 2 / PCI DSS context: almost always a human-led test with a report, scoped in days. A scan report will usually be rejected.
  • "Regular vulnerability scanning": the automated kind, run monthly or continuously. Cheap and worth doing regardless.
  • Public sector systems: departments are commonly required to use NCSC CHECK approved companies; ask the contracting authority.
  • Unsure: ask the party imposing the requirement to confirm in writing which they mean, before you buy. It is a one-line email that can save four figures.

If a quote for a "penetration test" is a few hundred pounds, it is priced like a scan and it almost certainly is one. Ask how many tester days are included; a real answer has a day count in it. Get scoped quotes from accredited providers.

Questions, answered directly

Is a vulnerability scan the same as a penetration test?

No. A vulnerability scan is an automated tool run that lists known weaknesses, typically free to a few hundred pounds. A penetration test is a human-led attempt to actually compromise the scoped systems, priced in days at £700–£1,200 (typical 2026 UK quotes). Compliance requirements that say penetration test almost never accept a scan report.

Does Cyber Essentials include a penetration test?

No. Cyber Essentials certifies baseline security controls; Cyber Essentials Plus adds a technical audit with some scanning-based checks. Neither is a penetration test, and requirements for one are not satisfied by the other.

Get a day count for your scope, not a list price.

Describe what needs testing; accredited providers quote your scope directly. Free, no obligation.

Get testing quotes