
Vulnerability assessment tools scan your laptops, servers, network equipment, cloud accounts and websites for known weaknesses, such as missing patches, outdated firmware, exposed services and risky settings, then rank what they find. For a small business, choose by what you need to see (endpoints, the office network, internet-facing systems or web applications), how the tool collects it (an agent on each device or a scan across the network), and whether someone will turn the findings into fixes every week. A scan that nobody acts on produces a report, not protection.
The six tools below are described from their vendors' own pages, checked October 2026, and listed in no particular order. Disclosure: NetSys runs vulnerability management for clients with Microsoft Defender Vulnerability Management plus network and external scanning, and some NetSys pages name Rapid7 InsightVM; no vendor paid for a mention. If you are deciding between a scan and a penetration test, read vulnerability assessment vs penetration testing first.
What types of vulnerability assessment tools are there?
Each type answers a different question, and most small businesses need more than one:
- Agent-based endpoint scanning. Software on each laptop and server reports installed applications, missing updates and configuration weaknesses continuously, even when the laptop is off the office network. Microsoft Defender and Rapid7 both work this way.
- Network scanners. A scanner probes the addresses on a network range, which is how you find weaknesses on printers, cameras, switches and firewalls that cannot run an agent. Nessus and OpenVAS are the classic examples.
- External and attack surface scanning. A cloud service scans your public addresses, websites and cloud accounts from the outside, the way an attacker sees them. Intruder focuses here.
- Web application scanners. Tools such as ZAP test a website or web application you own for common security flaws.
How do the six vulnerability assessment tools compare?
Prices are the vendors' published figures as of October 2026, or quote-based where noted. Effort to run is our engineering judgment of the ongoing work.
| Tool | Good fit for | What it scans | Deployment | Pricing (as of October 2026) | Effort to run |
|---|---|---|---|---|---|
| Microsoft Defender Vulnerability Management | Businesses on Microsoft 365 Business Premium or Defender for Endpoint | Devices onboarded to Defender: software inventory, missing updates, configuration, risk-based recommendations | Cloud, in the Microsoft Defender portal | Core features included in Defender for Business, which is part of Business Premium; premium add-on $2.00 per user per month for Defender for Endpoint Plan 2 | Low to moderate |
| Rapid7 Exposure Command (InsightVM) | Mid-sized firms that want agents, network scans and remediation tracking in one platform | Agent-based and network scanning across on-premises and cloud systems; policy and configuration checks | Rapid7 platform with agents and network scanning | Quote-based, by asset types and use cases | Moderate |
| Tenable Nessus Professional | IT staff and consultants who run their own network scans | Hosts and network devices the scanner can reach | Installed on Windows, macOS, Linux, a Raspberry Pi or Docker | $4,790 for one year | Moderate |
| Intruder | Small teams that want internet-facing systems watched without running a scanner | External infrastructure, web apps and APIs, cloud accounts; internal agents on higher plans | Cloud | Free plan for weekly external checks; Cloud and Pro are a base fee plus a fee per target, Enterprise by quote; 14-day trial | Low |
| Greenbone OpenVAS | Teams with Linux skills that want a free network scanner | Hosts and network devices, using a continuously updated feed of vulnerability tests | Self-hosted community edition, or Greenbone's paid products | Free community edition (listed as OPENVAS FREE); OPENVAS BASIC lists at 2,524 euros a year | High |
| ZAP | Checking your own websites and web apps | Web applications | Downloaded and run by you | Free and open source | Moderate; needs web testing skill |
What is each vulnerability assessment tool good at?
Microsoft Defender Vulnerability Management
If you run Microsoft 365 Business Premium, you already have Microsoft Defender Vulnerability Management in its core form: Microsoft lists core vulnerability management in Defender for Business, which Business Premium includes. That covers device discovery and inventory, vulnerability and configuration assessment, risk-based prioritization, remediation tracking and continuous monitoring for onboarded devices. Microsoft notes that the premium add-on, with security baselines and blocking of vulnerable applications, isn't currently available to Defender for Business customers; for Defender for Endpoint Plan 2 tenants it lists at $2.00 per user per month, as of October 2026. We pair it with network scans for printers, switches and other devices that cannot run the agent.
Rapid7 Exposure Command (InsightVM)
Rapid7 now sells InsightVM as part of Exposure Command. The Essentials package combines asset discovery with agent-based and network vulnerability scanning across on-premises and cloud systems, risk-based prioritization, policy and configuration assessment, and remediation workflows with service-level targets; the Ultimate package adds cloud, container and application security testing. It suits a mid-sized firm that wants one platform to track fixes against deadlines. Rapid7 prices by the asset types and use cases in scope and does not publish rates.
Tenable Nessus Professional
Nessus Professional is a network scanner you run yourself. You install it on Windows, macOS, Linux, a Raspberry Pi or in Docker, point it at your address ranges and get a ranked list of findings, with unlimited assessments. As of October 2026, Tenable lists it at $4,790 for one year, and Nessus Expert at $6,790. The free Nessus Essentials scans up to five IP addresses but is strictly for non-commercial use, so a business cannot rely on it. Nessus is a scanner, not a program: the scheduling, triage and follow-up are yours.
Intruder
Intruder is a cloud service aimed at small teams. It scans internet-facing infrastructure, web applications and APIs, and cloud accounts, and its Pro and Enterprise plans add agents for internal servers and employee devices. A free plan runs weekly external checks on ports 80 and 443 for up to five web apps and one cloud account. The paid Cloud and Pro plans charge a base fee plus a small fee per target, Enterprise is quoted, and the 14-day trial includes the Cloud plan's features.
Greenbone OpenVAS
OpenVAS is the GPL-licensed scanner behind the Greenbone Community Edition, and it runs a continuously updated feed of vulnerability tests against the hosts you point it at. Greenbone now lists the free version as OPENVAS FREE: you install and maintain it yourself, and Greenbone support comes only with its paid OPENVAS SCAN product. Greenbone's entry-level paid product, OPENVAS BASIC, lists at 2,524 euros a year. It suits a firm with an engineer who will run it on a schedule.
ZAP
ZAP, now branded ZAP by Checkmarx, is a free and open-source web app scanner. Point it at a website or web application you own and it reports common weaknesses, which makes it useful for checking a client portal or a company website between professional tests. It takes some web testing knowledge to use well, and it does not scan laptops or network equipment. For the wider set of testing tools, see our guide to penetration testing tools.
Vulnerability assessment selection checklist
- List what must be covered: laptops, servers, firewalls and VPN appliances, printers and cameras, cloud accounts and websites.
- Match collection to devices: agents for laptops that leave the office, network scans for devices that cannot run an agent, and external scans for anything public.
- Read the license terms: free tiers such as Nessus Essentials may be non-commercial, and asset-based pricing grows with every device.
- Look at prioritization: a tool should rank by exploitability and exposure, not only by a generic severity score.
- Confirm the fix path: how findings become tickets or patches, and who rescans to confirm they are closed.
- Test the report: ask for a sample showing open findings by severity and time to remediate, which is what auditors and insurers ask about.
- Set the schedule first: decide how often each asset type is scanned before you buy, and make sure the plan supports it.
What drives the cost of vulnerability assessment tools?
- The unit: per user for Microsoft, per asset type and use case for Rapid7, per scanner license for Nessus, and per target plus a base fee for Intruder.
- Scan types: external, internal, web application and cloud scanning are often separate tiers or add-ons.
- Infrastructure: self-hosted scanners need a machine to run on and someone to patch it.
- What is not included: triage, patching, firmware updates, exceptions and rescans. Those are labor, and they are where vulnerability management actually happens.
When should an IT provider run vulnerability assessment?
When nobody on staff has the time to fix what the scans find. The common failure is a scan that ranks thousands of findings by generic severity: the easy ones get fixed and the exploitable one sits further down the list. Our vulnerability management service runs the whole loop. Defender agents report from endpoints and servers continuously, network scans cover firewalls, switches, printers and cameras weekly, and external scans check public systems at least weekly. Each week an engineer marks which findings are exploitable and reachable and schedules the fix, through Intune pilot rings for workstations and maintenance windows for servers, and actively exploited flaws are handled the day they appear. A rescan confirms closure, and the monthly report shows time to remediate and the open exceptions, each with an owner.
For managed clients, scanning, prioritization, patching and reporting are part of the month-to-month agreement. Businesses with in-house IT can buy the program on its own; the price depends on asset count and on whether we fix the findings or hand over a ranked weekly list, and we quote after a short scoping call.
Book a call with a NetSys engineer to work out which of these your environment needs, and bring a rough count of laptops, servers, network devices and public websites.
Frequently asked questions
Which vulnerability assessment tools fit our systems and team size?
If you run Microsoft 365 Business Premium, start with the Defender vulnerability management you already own and add a network scanner for devices without an agent. A team that wants its public systems watched without running software fits Intruder. IT staff who scan for themselves fit Nessus Professional, or OpenVAS if they prefer open source. Mid-sized firms that want agents, scanning and remediation tracking in one platform fit Rapid7.
What is included in vulnerability assessment tool pricing?
The license covers the scanning engine and its vulnerability checks for the assets, users or targets you buy. It rarely covers the people work: deciding which findings matter, patching, updating firmware, documenting exceptions and rescanning. Ask whether external, internal, web application and cloud scanning are all in the quoted plan, and whether the price is per year or per month.
Who owns implementation and support?
The vendor supports the product. Someone on your side or your IT provider has to own the asset list, the scan schedule, the weekly review and the patching, plus the decision to accept a risk when a patch cannot be applied. Put that owner's name in writing, along with how quickly critical findings must be fixed.
Are there free or open-source vulnerability assessment tools?
Yes. OpenVAS from Greenbone and ZAP are free and open source, and Intruder has a free plan for basic external checks. Defender's core vulnerability management is included in Business Premium. Nessus Essentials is free but limited to five IP addresses and non-commercial use, so it is not an option for a business network.
Is a vulnerability scanner the same as a penetration testing tool?
No. A vulnerability scanner lists known weaknesses that might be exploitable. A penetration test uses findings like those, along with exploitation tools and a tester's judgment, to show what an attacker could actually reach. Run vulnerability assessment continuously and a penetration test periodically; the comparison linked at the top of this guide explains when each is worth paying for.
Sources and further reading
- Microsoft Learn: Compare Defender Vulnerability Management plans and capabilities and What is Microsoft Defender for Business, checked October 2026.
- Microsoft Defender Vulnerability Management pricing, checked October 2026.
- Rapid7 InsightVM and Exposure Command packages, checked October 2026.
- Tenable Nessus Professional, Nessus Essentials and Nessus installation options, checked October 2026.
- Intruder pricing, checked October 2026.
- Greenbone OPENVAS products and the OpenVAS scanner on GitHub, checked October 2026.
- ZAP.
Related reading
Buyer GuideAI Governance Tools for Small Business: 6 Options Compared
Read Article
Buyer GuideData Loss Prevention Tools for Small Business: 6 Options Compared
Read Article
Buyer GuideMobile Device Management Software for Small Business: 7 Options Compared
Read ArticleAlso on this topic: Privileged Access Management Solutions for Small Business: 6 Options Compared · Network Monitoring Tools for Small Business: 7 Options Compared
Discuss vulnerability management for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
