The difference between a vulnerability scan and a penetration test is the difference between finding unlocked doors and walking through them. A scan is an automated sweep for known weaknesses such as missing patches. A penetration test is people trying to break in. NIST's Technical Guide to Information Security Testing and Assessment (SP 800-115) treats them as separate techniques with different jobs, and most small businesses need a scan, and an honest assessment, before they need a pen test.
This guide explains what each one does, what rules in the US and Canada say about them, and how to decide which to buy first.
What is a vulnerability scan?
A vulnerability scan is an automated check of your computers, servers, network devices or website against databases of known weaknesses. NIST's SP 800-115 describes scanning as a way to identify hosts and their attributes, such as operating systems and open ports, and find known vulnerabilities, and calls a vulnerability scanner "a relatively fast and easy way to quantify an organization's exposure to surface vulnerabilities." It groups scanning with its target identification and analysis techniques.
A good scan report tells you which systems are missing which patches, which services are exposed to the internet, and which settings are weak. What it cannot tell you is whether those findings can be chained together into a real break-in. NIST also warns that scanners "can have a high false positive error rate," so someone needs to review the results rather than forward a 200-page export.
What is a penetration test?
A penetration test is security testing in which skilled people try to get around your defences the way an attacker would. NIST SP 800-115 describes it as testing in which "assessors mimic real-world attacks to identify methods for circumventing the security features of an application, system, or network," and lists it among its target vulnerability validation techniques, meaning it confirms which weaknesses are real.
NIST also notes that penetration testing "usually relies on performing both network port/service identification and vulnerability scanning" first. In other words, a pen test starts where a scan ends. The value is in the human judgment: combining a weak password, an exposed service and an overly broad permission into a path that an automated tool would score as three separate medium findings.
Vulnerability scan vs penetration test: how do they compare?
- Question answered: a scan asks "what known weaknesses do we have?" A pen test asks "what could an attacker actually do with them?"
- Method: scans are automated and repeatable. Pen tests are manual, scoped and time-boxed.
- Frequency: scans can run continuously, weekly or monthly. Pen tests are usually annual or after major changes.
- Output: a scan produces a list of findings by severity. A pen test produces a narrative of attack paths, evidence and prioritized fixes.
- Best for: scans keep patching honest between changes. Pen tests validate that a mature environment holds up.
What do US and Canadian rules require?
Some businesses have a written requirement. Most do not. In the US, the FTC's Safeguards Rule (16 CFR 314.4) covers non-bank financial institutions under FTC jurisdiction. The rule's definition of a financial institution gives examples including tax preparation services, mortgage brokers and auto dealerships that lease vehicles. Absent effective continuous monitoring, the rule requires "annual penetration testing" and vulnerability assessments "at least every six months," and again after material changes. There is an important carve-out: section 314.6 exempts institutions holding customer information on fewer than 5,000 consumers from that testing requirement.
Businesses that accept payment cards on either side of the border fall under PCI DSS, whose Requirement 11.3.2 covers external vulnerability scanning by a PCI-approved scanning vendor (ASV). Your acquiring bank or payment processor can tell you which validation applies to you.
In Canada, there is no general law requiring small businesses to pen test. The Canadian Centre for Cyber Security's baseline controls for small and medium organizations instead recommend enabling automatic patching "OR establish full vulnerability and patch management solutions," and making sure websites address the OWASP Top 10. A regular scan is the simplest way to show that patching is actually working.
Contracts and insurers fill the gap. Cyber insurers increasingly ask how quickly you patch and whether you can prove it, as our guide to what insurers check before quoting explains.
Which should a small business do first?
For most small businesses, the order is assessment, then scanning, then a penetration test. A pen test bought before the basics are in place mostly tells you what a scan or a checklist would have told you for less: patches are behind, MFA has gaps, admin accounts are shared. With exploit timelines now measured in hours (see our post on the shrinking CVE-to-exploit window), fast patching backed by regular scanning closes more risk per dollar than an annual test.
- Assess: get a clear picture of controls across people, process and technology. Our explainer on what a small business cybersecurity assessment covers walks through what that should include.
- Scan: run external and internal vulnerability scans on a schedule, and fix critical findings on internet-facing systems first.
- Test: once the basics hold, commission a scoped penetration test, especially before a major launch, after a big infrastructure change, or when a customer or regulator asks for one.
What should you ask before buying either one?
Before you sign, ask your IT lead or the vendor one question: "When this is done, what exactly will we receive, and who will help us fix what it finds?" A scan without someone to triage it, or a pen test report without a remediation plan, is a cost, not a control.
If you are not sure where your business stands yet, start with our free quick security assessment. It takes under five minutes and shows which of 20 security areas need attention before you spend money on testing.
This article is intended for general informational purposes only and does not constitute professional security, legal, or compliance advice. Regulatory requirements such as the FTC Safeguards Rule and PCI DSS depend on your business type, card volume and validation method; details are based on published rules and guidance as of the date of publication. Organizations should confirm their specific obligations with qualified compliance and cybersecurity professionals.