The Quick Answer

A vulnerability assessment identifies potential security weaknesses and catalogues them. A penetration test attempts to exploit those weaknesses to prove they represent genuine risk. Both are valuable, but they answer different questions.

What Is a Vulnerability Assessment?

A VA uses automated scanning tools and manual review to identify known vulnerabilities across your environment, unpatched software, misconfigured services, weak cipher suites, and similar issues. VAs are typically faster and less expensive than penetration tests. They work best as a regular hygiene exercise, run quarterly or monthly to catch newly-disclosed vulnerabilities and configuration drift.

What Is a Penetration Test?

A penetration test takes VA output and goes further. Our engineers actively attempt to exploit discovered vulnerabilities, chain multiple weaknesses together, escalate privileges, and move laterally through the environment, exactly as a real attacker would. The result is a demonstrated narrative of what an attacker could actually accomplish.

Key Differences

  • Depth: A VA identifies issues; a pentest proves they're exploitable
  • Methodology: VAs rely heavily on automated tools; pentests are primarily manual
  • Output: VA produces an issue list; pentest produces an attack narrative with evidence
  • Compliance value: Many frameworks (PCI DSS, SOC 2, CMMC) specifically require penetration testing

Which Should You Choose?

For organizations at an early stage of security maturity, a vulnerability assessment is a good first step. For organizations past the basics, or that face compliance requirements, a penetration test provides the depth a VA cannot. Many organizations run both: regular VAs as an ongoing hygiene measure, with penetration tests annually for deeper validation.

Which Should You Run First?

If you have never tested, start with a vulnerability assessment to clear the obvious issues, then run a penetration test to prove what an attacker could still accomplish. Mature programs run both on a schedule: frequent automated scanning for hygiene, and an annual manual penetration test for depth. Compliance frameworks usually require the penetration test specifically, because a scan alone cannot demonstrate real exploitability. See our pricing guide for what each costs.

Not sure which you need?

We're happy to review your environment and recommend the right assessment, no obligation.

Talk to an Expert →