"We already run vulnerability scans, do we still need a penetration test?" is one of the most common questions we get from organizations preparing for ISO 27001, SOC 2, or PCI DSS. The short answer is yes — they answer different questions, and most compliance frameworks require evidence of both.
What each actually does
| Vulnerability Scanning | Penetration Testing |
| Method | Automated tools compare systems against known vulnerability databases | Skilled testers manually attempt to exploit weaknesses, often chaining multiple issues |
| Output | A list of known vulnerabilities, ranked by severity score | A narrative of what was actually exploitable, the attack path taken, and business impact |
| Coverage | Broad — every asset in scope, run repeatedly and cheaply | Deep — focused effort on the systems and paths most likely to matter to an attacker |
| Finds | Known CVEs, misconfigurations, missing patches | Logic flaws, chained exploits, business-logic bypasses that scanners can't detect |
| Frequency | Monthly or after significant changes | Annually at minimum, plus after major changes |
| Cost | Low — often subscription-based tooling | Higher — priced per engagement based on scope and duration |
Why you need both, not either
Vulnerability scanning is the smoke detector — cheap, continuous, and good at catching known issues before they become a problem. Penetration testing is the fire drill — it tells you what actually happens when someone tries to get in, including issues a scanner will never find: a login flow that lets one user access another's data, an API endpoint missing authorization checks, or a chain of low-severity findings that together create a critical path to sensitive data. Compliance frameworks that require security testing generally expect both, because they cover different risks.
What compliance frameworks require
✓
PCI DSS — requires both internal and external vulnerability scans (quarterly, by an Approved Scanning Vendor for external scans) and annual penetration testing, plus after significant changes.
✓
ISO 27001 — Annex A 8.8 (technical vulnerability management) is commonly evidenced through regular scanning plus periodic penetration testing, especially for internet-facing systems.
✓
SOC 2 — while not explicitly named in the criteria, penetration testing is one of the most common ways organizations evidence the Security and Availability trust service criteria to auditors.
✓
NESA/regional frameworks — critical infrastructure and financial-sector requirements across the UAE and GCC frequently mandate periodic penetration testing explicitly, not just vulnerability scanning.
How to decide when you need which
Run vulnerability scans continuously — they're cheap enough that there's no reason not to. Schedule a penetration test when: you're preparing for a certification audit that requires it, you're launching a new application or major feature, a significant infrastructure change has occurred, or it's simply been 12 months since the last one. Organizations building both into a single evidence pipeline — rather than treating them as separate one-off projects — spend far less time reassembling proof for each audit cycle.
Frequently asked questions
Can vulnerability scanning replace penetration testing for compliance?+
No. Most frameworks that require security testing — including PCI DSS and many ISO 27001 certification bodies' expectations — treat vulnerability scanning and penetration testing as distinct, complementary requirements. Scanning alone typically doesn't satisfy a control that specifically calls for penetration testing.
How often should each be performed?+
Vulnerability scans are typically run monthly or after any significant infrastructure change. Penetration testing is typically performed annually at minimum, and additionally after major application or infrastructure changes, or when required by a specific compliance milestone.
Does ISO 27001 require penetration testing?+
ISO 27001 doesn't mandate penetration testing by name, but Annex A control 8.8 is commonly evidenced through a combination of regular vulnerability scanning and periodic penetration testing, and many certification body auditors expect to see both for internet-facing systems.