Penetration test or vulnerability scan?
Short answer: a vulnerability scan checks for known flaws and misconfigurations broadly and frequently using automated tools; a penetration test is an in-depth exercise in which experts use a real attacker's methods to chain and exploit flaws and prove the real risk. Neither replaces the other: scanning is a regular health check, while a penetration test is a thorough examination done at intervals.
| Criterion | Vulnerability scan | Penetration test |
|---|---|---|
| How is it done? | With automated tools, based on signatures of known flaws and misconfigurations. | By experts, manually and with tools, chaining and exploiting flaws. |
| What does it find? | Missing updates, known flaws, weak settings; broad but shallow. | Business logic flaws, privilege escalation, chains of flaws; narrow but deep. |
| False positives | Possible; results need to be triaged by an expert. | Few; findings are reported with evidence (screenshots, requests, steps). |
| Frequency | Frequent: weekly, monthly or after every significant change. | At intervals: usually at least once a year and after major changes. |
| Cost | Low; can be run continuously. | Higher; depends on expert effort and scope. |
| Compliance | PCI DSS, for example, requires approved external scans every three months. | PCI DSS, for example, requires a penetration test at least once a year and after significant changes. |
- 01
Scanning covers the surface, a penetration test goes deep
A vulnerability scanner quickly checks your systems against a list of known flaws and misconfigurations: an old software version, an admin panel left open, a weak encryption setting. This check is broad but does not understand logic. In a penetration test, an expert shows, for example, that a user can see another customer's invoice by changing the number in the address, or that two small flaws combine to give administrator access. Business logic flaws like these are what automated tools mostly cannot see but attackers look for.
- 02
When is each one enough?
Regular vulnerability scanning is basic hygiene for every organisation: it catches newly announced flaws and forgotten systems early. A penetration test is needed before launching an application that processes customer data, after a major change, when a customer or auditor asks for evidence, or if you work with sensitive data such as payments and health. Running only a scan and calling it “tested” means never having tested flaws in business logic and authorisation.
- 03
What do compliance requirements say?
Some standards explicitly require both. For environments that process card data, PCI DSS requires external vulnerability scans by an approved scanning vendor at least every three months, and penetration testing at least once a year and after significant changes. ISO 27001 does not impose a specific testing method, but it expects technical vulnerabilities to be managed and the effectiveness of controls to be demonstrated; in audits, a penetration test report is strong evidence of this. Clarify from the start which standard applies to you and the scope of the test.
- 04
The right order: scan first, then test
Running a vulnerability scan and closing known flaws before a penetration test increases the test's value: experts spend their time looking for deep flaws instead of listing missing updates. After the test, findings are fixed and a retest confirms they are closed. Regular scanning then keeps catching newly announced flaws between tests. This cycle turns security into a continuous process rather than a one-off report.
- 05
Watch out when comparing quotes
Automated scan reports are sometimes sold under the name “penetration test”. When getting a quote, ask about the scope, the method, the time spent on manual testing, the user roles to be tested and whether the report will include evidence and remediation advice for each finding. Whether a retest is included in the price also matters. A very cheap, very short “penetration test” is often just a scan.
- 06
Doki's impartial note
We do not recommend a comprehensive penetration test every year for every organisation; for a small, static brochure site, regular scanning and good maintenance are often enough. In a system with customer logins, payments, personal data or an admin panel, however, settling for scanning means not seeing the real risk. We can review your systems and obligations together and clarify which one is needed, with what scope and how often.
Related pages
Articles that complete this topic, plus the matching service page.
Let's talk about your project.
Tell us what you need; we will define the scope together.