A vulnerability scanner finds the known holes in what you already run, which is a different job from stopping an attack in progress.
This guide ranks the scanners on what they can actually see, how much of the output is real, and what the licence counts when your estate grows: assets, targets, domains or developers.
Vendors can pay for visibility on this page. It never changes what an entry
says about a product, including the criticism, and we earn nothing when you click through to a
vendor. How that works.
In short
What vulnerability scanning software does
A vulnerability scanner checks systems, applications and dependencies against a feed of known flaws, then reports which ones your environment appears to have.
Five things, in this order. Feature counts are not among them: they are the least useful
comparison in software, because every vendor ticks every box.
01
Setup effort in vulnerability scanning software
What the first ninety days of a vulnerability scanning software rollout cost in hours, not in licence fees. A product that needs a partner engagement before it does anything is a different purchase from one a team configures in an afternoon.
02
What vulnerability scanning software really costs
What the bill becomes once the modules a normal buyer of vulnerability scanning software needs are added, and whether you can read that number without a sales conversation.
03
Getting your data out of vulnerability scanning software
How your own data comes back out, in what format, and whether that export is included in the vulnerability scanning software contract or billed as a project.
04
Independence from the vendor
Whether you can buy vulnerability scanning software, run it and leave it on your own terms. This test decides most of the order on this page, and it is why the largest vendors in vulnerability scanning software often sit below the smaller ones.
05
Who the product is built for
The size and shape of company each vulnerability scanning software product was actually built for. Most regret in software comes from buying for a company you are not yet.
The fourth test decides most of the order on this page, and it is the reason the largest
vulnerability scanning software vendors sit below the smaller ones. A product with a published price, an export
that works and no mandatory implementation partner is a product you can leave.
A platform suite that arrives with a quote, a partner and a two-year commitment may well be
the better software and is still the harder decision to reverse. We rank vulnerability scanning software for the
buyer who has to live with that decision without a procurement department, which is a stated
bias rather than a hidden one.
We do not publish a score out of ten. A number like 8.4 is a judgement dressed as a
measurement, and nobody can check it.
What you can check is on this page: what each vulnerability scanning tool costs, where the vendor is
established, whether the price is published, and what we think it is bad at. Our full method
is on the how we work page.
Per asset per year, quoted; modules priced separately
—
Large distributed estates that need agents everywhere and compliance reports
Small organisations wanting a scanner without a project
Country is where the vendor is headquartered or contracts from, which is a
different question from where your data is hosted. Where the two tell different stories, the
entry says so.
Greenbone is the only entry here you can run entirely on your own hardware, with no vendor holding a list of your unpatched machines. For a hospital, a utility or anyone with an air-gapped segment, that is the deciding fact.
In exchange you accept an interface built by engineers for engineers, a feed that is good on infrastructure and weak on modern web stacks, and no help with triage. Budget staff time instead of licence fees.
What stands out
Open source
Self-hosted
German vendor
Where it costs you
No meaningful web application scanning
Community feed lags the paid enterprise feed
Right for
Teams that must keep scan results inside their own network
Wrong for
Organisations that need application and dependency coverage too
GermanyFree community edition; appliance and feed subscription quoted
Continuous external scanning with findings a non-specialist can act on
Ranked #2 of 12 in Best Vulnerability Scanner in 2026.
Published pricingEurope
Intruder is the best purchase for a company whose entire security function is one engineer with other responsibilities. It watches the internet-facing estate continuously, rescans when something new is disclosed, and writes findings in language a developer can act on without a translation layer.
The limits arrive when you grow: internal authenticated scanning across thousands of hosts, custom check tuning and detailed compliance evidence all push you towards the platforms lower on this page.
What stands out
Published price
External surface
Low noise
Where it costs you
Limited depth for large internal networks
Advanced tuning options are intentionally hidden
Right for
Small companies with an external footprint and no security team
Wrong for
Mature security teams needing deep configuration control
Hosted scanner toolkit and reporting for very small teams
Ranked #3 of 12 in Best Vulnerability Scanner in 2026.
Published pricingEurope
This is a toolkit with reporting, not a management platform, and it is honest about that. For an agency producing client assessments, or an internal team that scans quarterly and needs a document at the end, the economics are excellent and the reports need little rewriting.
What is missing is everything that makes scanning a programme: who owns each asset, what changed since last month, and which ticket is tracking the fix.
What stands out
Published price
Report templates
Consultant friendly
Where it costs you
Little asset inventory or remediation tracking
Scan volume is capped by plan
Right for
Consultants and tiny teams running periodic external assessments
Wrong for
Running a continuous programme across a large estate
The infrastructure scanner every other vendor is measured against
Ranked #4 of 12 in Best Vulnerability Scanner in 2026.
Published pricingNorth America
Nessus is where most people start and many stay: the check feed is the broadest in the industry, and a professional licence costs less than a day of consultancy. The trouble starts at scale.
The managed platform prices per asset, cloud instances that live for an hour still count somewhere, and the default output is enormous. Plan for a quarter of tuning, exclusions and ownership mapping before anyone believes the dashboard.
What stands out
Largest check feed
Published Nessus price
Wide integrations
Where it costs you
Findings volume needs real tuning effort
Web application scanning is a separate purchase
Right for
Infrastructure teams that want the widest check coverage available
Wrong for
Buyers wanting one tool to cover apps and dependencies
United StatesPer licence per year for Nessus, published; per asset for the platform
Swedish platform covering network assets, web apps and phishing
Ranked #5 of 12 in Best Vulnerability Scanner in 2026.
Pricing on requestEurope
The argument for Holm Security is jurisdiction plus breadth: a single European supplier covering network assets and web applications, hosting the results in the EU, which matters because a vulnerability database is a target list for your own estate.
Against it, the depth on custom applications does not reach Burp Suite Enterprise or Detectify, and the infrastructure feed does not match Tenable. Suitable as the main platform for a mid-sized estate, not for a bank's public application.
What stands out
EU hosting
Systems and web
Nordic vendor
Where it costs you
Check feed is smaller than the American platforms'
No published pricing
Right for
Nordic and EU organisations wanting scan data hosted in Europe
Scanning, external attack surface and threat intelligence from one supplier
Ranked #6 of 12 in Best Vulnerability Scanner in 2026.
Pricing on requestEurope
Outpost24 works as a supplier relationship rather than as a tool. If you want European scanning, external attack surface discovery and some threat intelligence on one contract, with an analyst you can call, that is a real and reasonable purchase.
If you want one scanner, the modular structure makes you pay for a platform. Ask precisely which module contains each capability in the demonstration, because the boundaries are not obvious from the marketing.
What stands out
EU vendor
Modular platform
Managed option
Where it costs you
Acquired modules do not feel like one product
Cost escalates as modules are added
Right for
Mid-market European buyers consolidating several security services
Wrong for
Teams that only need one scanner and a clean price
SwedenQuoted per organisation; modules priced separately
Application scanning built on real payloads, not version banners
Ranked #7 of 12 in Best Vulnerability Scanner in 2026.
Pricing on requestEurope
Detectify made a specific bet: verify by exploiting, not by fingerprinting, and buy the research from a community of testers. The consequence is a low false positive rate, which is the single thing that decides whether developers keep reading the reports.
The consequences are also narrow coverage and awkward economics. It scans what faces the web and nothing else, and an estate of two hundred marketing domains prices badly under a per-domain model.
What stands out
Web application focus
Crowdsourced research
Few false positives
Where it costs you
No network or host scanning at all
Per-domain pricing hurts organisations with many small sites
Right for
Product teams protecting a handful of important web applications
Wrong for
Covering servers, endpoints or internal infrastructure
The tester's scanner, automated across an entire application estate
Ranked #8 of 12 in Best Vulnerability Scanner in 2026.
Published pricingEurope
PortSwigger publishes its prices per scanning agent, so the cost is driven by how much you scan rather than by how many applications you own, which suits a company with many small services.
The crawler handles single-page applications and authenticated flows better than anything else here. The maintenance burden is the recorded logins: they break when the application changes, and a broken login means a clean report that scanned only the front page.
What stands out
Deep DAST
Published price
CI integration
Where it costs you
Application scanning only
Login sequences must be recorded and maintained per target
Right for
Engineering organisations scanning authenticated applications in the pipeline
Wrong for
Infrastructure teams needing network and host coverage
United KingdomPer scanning agent per year, published
Every finding validated by an analyst before it reaches you
Ranked #9 of 12 in Best Vulnerability Scanner in 2026.
Pricing on requestEurope
Edgescan's product is a person. Findings are checked before they reach you, so a critical in the queue is a critical, and the conversation with engineering changes completely as a result.
That is worth paying for when nobody internally has time to separate the real from the theoretical. It is money wasted when you do have that capacity, and the validation step means you learn about an exposure hours later than a raw scanner would tell you.
What stands out
Validated findings
Irish vendor
Managed service
Where it costs you
Higher cost per asset than self-service tools
Validation adds delay between scan and report
Right for
Teams with no capacity to triage raw scanner output themselves
Wrong for
Organisations with their own analysts already doing triage
IrelandPer asset per year, quoted; validation included
Dependency and container scanning inside the developer's pull request
Ranked #10 of 12 in Best Vulnerability Scanner in 2026.
Free tierPublished pricingNorth America
Software composition analysis is a separate discipline from scanning machines, and Snyk is the most widely adopted way to do it. Its advantage is placement: the finding appears in the pull request, with the version to upgrade to, before the code merges.
The weaknesses are noise from vulnerabilities in code paths you never call, and a licence model tied to contributing developers, which turns a growing engineering team into a growing security bill.
What stands out
Dependency scanning
Free tier
Developer workflow
Where it costs you
Says nothing about network or host vulnerabilities
Per-developer pricing rises steeply with engineering headcount
Right for
Engineering teams fixing vulnerable dependencies during code review
Wrong for
Anyone trying to cover servers and network devices
United StatesFree tier; per contributing developer per month, published
Asset-based scanning with remediation tracked as assigned work
Ranked #11 of 12 in Best Vulnerability Scanner in 2026.
Published pricingNorth America
InsightVM's distinguishing feature is that it treats fixing as the workflow rather than as an afterthought: projects, owners, deadlines and progress against them, exported to the ticket system engineering actually uses.
The published per-asset price makes budgeting honest. Against that, the product assumes a dedicated security function, the learning curve is steep for a team of one, and Rapid7's account managers will propose the detection and response platform within the first quarter.
What stands out
Published per-asset price
Remediation projects
Agent-based
Where it costs you
Console and data model take weeks to learn
Heavy cross-selling of the wider platform
Right for
Security teams that need remediation ownership, not just findings
Wrong for
Small estates where a simple external scanner suffices
United StatesPer asset per year, published price list
Scanning at estate scale, with a module for everything
Ranked #12 of 12 in Best Vulnerability Scanner in 2026.
Pricing on requestNorth America
At tens of thousands of assets, Qualys does things the smaller tools cannot: agents that report from anywhere, scanning appliances per site, and compliance evidence in the format auditors expect. It earns its place in a large regulated estate.
The purchase is a negotiation about modules rather than a price, the console is a museum of interface generations, and rolling it out is a programme with a project manager, not an afternoon of configuration.
What stands out
Large estates
Cloud agents
Module pricing
Where it costs you
Every capability is a separately licensed module
Interface shows two decades of accumulated features
Right for
Large distributed estates that need agents everywhere and compliance reports
Wrong for
Small organisations wanting a scanner without a project
United StatesPer asset per year, quoted; modules priced separately
A vulnerability scanner checks systems, applications and dependencies against a feed of known flaws, then reports which ones your environment appears to have. The differences that matter are rarely in the feature list, so this is
the order we would work through them.
01
Decide whether you need a published price
7 of the 12 tools here publish what they cost; the other 5 quote per organisation, which means a sales conversation before you can compare anything. If you are buying without a procurement function, start with the ones that publish: Greenbone, Intruder, Pentest-Tools.com, Tenable Nessus and Vulnerability Management, Burp Suite Enterprise Edition, Snyk, Rapid7 InsightVM.
02
Work out what the first ninety days cost in time
Licence cost is the number in the contract; setup effort is the number that surprises people. Ask every shortlisted vendor who does the configuration, how long it took the last customer of your size, and what happens if that person leaves halfway.
03
Check the exit before the entry
Ask for an export of your own data in a format you can open, and ask whether it is included or billed as a project. A vendor that hesitates here is telling you what renewal negotiations will feel like in three years.
04
Match the tool to the size you are, not the size you plan to be
Most regret in this category comes from buying for a headcount that never arrived. The entry-level products here are not worse; they are aimed at a different company.
05
Decide how much the jurisdiction matters
These 12 vendors are established in 6 countries across 2 regions (Europe 8, North America 4). Where a vendor is established decides which government can compel access to what it holds, which is a different question from where the servers are. For most buyers that is a factor, not a veto.
06
Consider whether you want the source
1 of these are open source, which means you can host them yourself and read what they do with your data. That control is real, and so is the maintenance it hands you.
Three different scanners share the same word
Buyers ask for a vulnerability scanner and mean one of three products. Infrastructure scanning checks servers, network devices and operating systems against a feed of known flaws: Greenbone, Tenable Nessus, Rapid7 InsightVM and Qualys VMDR. Application scanning drives your web application like an attacker and watches what happens: Burp Suite Enterprise Edition and Detectify.
Dependency scanning reads your manifests and container images and finds the vulnerable library you shipped: Snyk. No single product does all three well, and the vendors who claim to do so are strong in one and adequate in the others. Decide which risk keeps you awake, buy the specialist for that, and add the second scanner in the next budget round.
Write down which of the three you are actually buying before the first demo.
Check whether application scanning is included or a separate line item.
Ask what the tool sees about a container that never touches your network.
Authenticated scanning shows a completely different machine
An unauthenticated scan sees what an outsider sees: open ports, banners, exposed services. An authenticated scan logs in and reads the installed package versions, and it typically finds several times more issues, most of them real. The gap is not marginal, it is the difference between guessing from a version string and reading the patch level.
Every serious platform here supports it, and getting it working is the actual project: service accounts, credential storage, and a change advisory board that does not want a scanner holding domain credentials. Rapid7 InsightVM and Qualys VMDR sidestep part of it with agents on the host. Greenbone and Tenable do it with credentials you must manage yourself.
Compare an authenticated and an unauthenticated scan of the same host during the trial.
Decide early whether you deploy agents or hand out scanning credentials.
Store scanner credentials in the vault, and rotate them like any other privileged account.
The false positive rate decides whether anyone reads the output
A scanner that reports four thousand issues, of which six hundred are wrong, does not get fixed. It gets ignored, then muted, then cancelled. This is the quiet reason Detectify verifies with a payload instead of a version banner, and the entire commercial argument for Edgescan, which pays analysts to validate findings before you see them.
Intruder attacks the same problem by reporting less. The platforms with the broadest feeds, Tenable and Qualys VMDR, produce the most noise by design, because the feed is their strength. Whichever you buy, measure it: take fifty findings from the trial, verify them by hand, and count how many were real.
Verify fifty trial findings manually and record the false positive count.
Ask how the vendor confirms a finding: version match, or working payload.
Check whether a suppressed finding stays suppressed after the next rescan.
What the licence counts, and what that does at scale
Every vendor here counts something different, and the unit decides your three-year bill. Intruder counts targets. Detectify counts domains. Rapid7 InsightVM, Qualys VMDR and Holm Security count assets, which raises the question of what a short-lived cloud instance counts as. Burp Suite Enterprise Edition counts scanning agents.
Snyk counts contributing developers, so a hiring plan is a security budget. Greenbone counts nothing, which is why it opens this list. Ask the counting question before the feature questions, then model it against your estate in three years, not today. Ask about exit at the same time: findings history should leave through an API in a format you can read without the vendor.
Model the licence unit against your projected estate, not the current one.
Ask specifically how ephemeral cloud instances and containers are counted.
Confirm the finding history exports through an open API before you sign.
What goes wrong most often when buying vulnerability scanning software
Scanning only the perimeter. Most incidents move sideways inside the network, where an unauthenticated external scan sees nothing at all.
Buying on the number of checks in the feed. A large feed produces a large queue, and the queue is the thing that kills the programme.
Leaving scanning unauthenticated because credentials were hard to arrange. It halves what you see and makes the clean report meaningless.
Measuring the programme by scans run rather than by issues closed. Nobody was ever breached through a vulnerability that was merely detected.
07
Frequently asked questions
11 answers
What is the best vulnerability scanning in 2026?
Greenbone leads our ranking of 12. The scanner behind OpenVAS, maintained in Germany, with a feed of network vulnerability tests you can run inside your own network and never send a result outside it.
Nothing else here is that independent. The interface is dated, the free community feed lags the paid one, and there is no serious application scanning, so it covers one third of the problem.
How did you rank these vulnerability scanning tools?
On what separates products after the demo: how much setup the first ninety days take, what the price becomes once the modules a normal buyer needs are added, how your data comes back out, whether you can buy and leave it without a partner engagement, and who the product is genuinely for.
That fourth test is why the large platform suites usually sit lower here than their market share would suggest. Not on feature counts, and not on a score we invented.
Which vulnerability scanning tools publish their pricing?
7 of the 12, with the pricing model each one publishes:
Greenbone: Free community edition; appliance and feed subscription quoted.
Intruder: Per target per month, published.
Pentest-Tools.com: Per month, published; scan volume by plan.
Tenable Nessus and Vulnerability Management: Per licence per year for Nessus, published; per asset for the platform.
Burp Suite Enterprise Edition: Per scanning agent per year, published.
Snyk: Free tier; per contributing developer per month, published.
Rapid7 InsightVM: Per asset per year, published price list.
The other 5 quote per organisation.
Is there a free vulnerability scanning tool?
Greenbone, Snyk offer a free tier or a free self-hosted edition. Read what the free tier excludes before you plan around it.
Which vulnerability scanning tools are open source?
Greenbone. Open source means you can read what the product does with your data and run it yourself. It does not mean the hosted edition is free.
Which vulnerability scanning tools can you host yourself?
Greenbone. The other 11 are sold as a hosted service only, which means the question of where your data sits is answered by the vendor, not by you.
Where are these vulnerability scanning vendors established?
In 6 countries across 2 regions: Europe 8, North America 4.
Greenbone is established in Germany.
Intruder is established in the United Kingdom.
Pentest-Tools.com is established in Romania.
Tenable Nessus and Vulnerability Management is established in the United States.
Holm Security is established in Sweden.
Outpost24 is established in Sweden.
Detectify is established in Sweden.
Burp Suite Enterprise Edition is established in the United Kingdom.
Edgescan is established in Ireland.
Snyk is established in the United States.
Rapid7 InsightVM is established in the United States.
Qualys VMDR is established in the United States.
Establishment decides whose courts and whose disclosure laws apply, which is a separate question from where the data is hosted.
What should you use instead of Greenbone?
Intruder and Pentest-Tools.com are the next two on this page.
Intruder is for small companies with an external footprint and no security team; Pentest-Tools.com is for Consultants and tiny teams running periodic external assessments. All 12 are ranked here with what each one is bad at.
Who should not buy Greenbone?
Organisations that need application and dependency coverage too. No meaningful web application scanning.
Do you get paid for these rankings?
Vendors can pay for visibility, which affects where and how prominently a product appears. It does not change a word of what the entry says about that product, including the criticism, and it cannot buy inclusion for something that does not belong in the category.
We take no commission when you click through to a vendor and we do not know whether you bought anything. The full arrangement is on our disclosure page.
How often is this vulnerability scanning guide updated?
Whenever the facts move: a price change, an acquisition, a product that stops being maintained. The published and updated dates at the top of the page are real, and a review means someone went back to the vendor documentation rather than bumping a date.
These 12 products are the ones we judged worth ranking in vulnerability scanning. If yours belongs here and is missing, tell us what it does and who it is for, and we will look at it. Inclusion is an editorial call and it is not for sale — but nobody gets considered for a list they were never put in front of.
People land on this page with a shortlist to make, not a browsing habit to feed. That is a narrower audience than a banner reaches and a far more decided one.
Written by us, about you
We describe the product in our own words, say who it suits and say who it does not. A vendor never writes the entry and never sees it before it goes up.
A correction costs nothing
If a fact about your product is wrong here, tell us and we fix it, whether or not there is any money between us. That offer is older than any commercial arrangement on this site.
Placement is separate, and disclosed
Where a product sits in the ranking can be paid for, and the notice above the list says so on every page. What the entry says about the product is not for sale at any price.
We use analytics cookies only if you agree. See our privacy policy.