Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What is the difference between a penetration test and a vulnerability scan?
Last verifiedA vulnerability scan is automated breadth across known checks. A penetration test is a scoped attempt to exploit, usually with a human methodology. PCI DSS treats them as different requirements (11.3 vs 11.4). A scan is not a pen test. This page is not legal advice.
Pen test versus scan, last verified 10 September 2026 against NIST SP 800-115, PCI DSS v4.0.1 Requirements 11.3 and 11.4, and CISA / NCSC vulnerability-scanning guidance (agency guidance, not a statute). It is not legal advice and does not determine that PCI or any framework applies to YOU.
Two different questions
Audience: an engineering or security lead buying the right control. This page is not legal advice. Kind of text: PCI DSS 11.3 and 11.4 are program requirements only if PCI applies. NIST SP 800-115 is methodology guidance. CISA and NCSC scanning pages are agency guidance, not law. Industry best practice treats scan and pen test as complementary. ShipReady Metrics recommendation: run continuous ingest and first-party SAST/DAST between point-in-time tests; do not treat that layer as an independent pen test.
Side-by-side comparison
Scope, frequency, cost, output, and framework fit differ. Last verified 10 September 2026. Not legal advice.
| Dimension | Vulnerability scan | Penetration test | Kind of text |
|---|---|---|---|
| Scope | Authenticated or unauthenticated checks against a catalog of known issues. | Rules of engagement, in-scope assets, and an attempt to chain and exploit. | NIST SP 800-115 methodology guidance. |
| Frequency | Often continuous or at least quarterly (PCI 11.3.1 / 11.3.2 if PCI applies). | Often annually and after significant change (PCI 11.4 if PCI applies); otherwise by contract or auditor practice. | PCI: program requirement if applicable. Otherwise best practice. |
| Cost | Tooling and operator time; usually lower per cycle than a scoped engagement. | Days of qualified testers; cost tracks scope and seniority, not a catalog price. | Market observation / industry practice — not a quote. |
| Output | A list of findings with scanner severity, often noisy without triage. | A report with methodology, risk-rated findings, reproduction, and (ideally) retest status. | Best practice (NIST SP 800-115 reporting; PTES / CREST reporting guidance). |
| Framework fit | PCI Req. 11.3 (including ASV for external). Supports ISO A.8.8 and SOC 2 CC7.1 evidence. | PCI Req. 11.4. Common SOC 2 auditor practice. One way to evidence ISO A.8.29. | See kind-of-text on each instrument. This page does not apply them to YOU. |
What to do now
Operational steps. Not a determination. Last verified 10 September 2026. Not legal advice.
- If a contract or PCI 11.4 applies, budget a scoped pen test. Do not file a scan PDF as if it were that test.
- Keep scanning continuous. CISA and NCSC guidance treat regular scanning as hygiene, not as exploitation testing.
- Layer SAST, DAST, and SCA in CI. Open the SAST vs DAST vs SCA guide on this site.
- Treat continuous testing as the gap-cover between point-in-time tests, not a replacement.
Checklist
Question list, not YOUR file. Not legal advice.
- Does the buyer or auditor actually ask for a penetration test, or for a scan attestation (for example ASV)?
- Is PCI 11.3 in play, 11.4, both, or neither? This page does not decide YOUR PCI scope.
- Are scan findings triaged with KEV / EPSS / CVSS, or dumped unreviewed?
- Is first-party SAST/DAST running in CI as the continuous layer?
Where this shows up in ShipReady Metrics
Vulnerability management ingest (Dependabot, code-scanning, secret-scanning) with KEV, EPSS, CVSS, cross-source dedup, and blast radius is the scanning layer. First-party SAST and DAST are first-party testing. This product does not replace an independent pen test and does not determine that a framework applies to YOU.
If you already have a session: signed-in app → Compliance → Evidence holds accepted artifacts. Naming that surface is not a public href.
Primary sources (last verified 10 September 2026)
NIST SP 800-115 is methodology guidance. PCI DSS v4.0.1 Req. 11.3 (scanning) and 11.4 (penetration testing) are program requirements only if PCI applies. CISA and NCSC scanning materials are agency guidance, not statutes. Not legal advice.