Try our new research platform with insights from 80,000+ expert users

Pentera vs Tenable Nessus comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 20, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Pentera
Average Rating
7.8
Reviews Sentiment
7.2
Number of Reviews
9
Ranking in other categories
Penetration Testing Services (2nd), Breach and Attack Simulation (BAS) (1st)
Tenable Nessus
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
81
Ranking in other categories
Vulnerability Management (3rd)
 

Mindshare comparison

Pentera and Tenable Nessus aren’t in the same category and serve different purposes. Pentera is designed for Breach and Attack Simulation (BAS) and holds a mindshare of 30.2%, up 27.4% compared to last year.
Tenable Nessus, on the other hand, focuses on Vulnerability Management, holds 9.8% mindshare, down 13.2% since last year.
Breach and Attack Simulation (BAS)
Vulnerability Management
 

Featured Reviews

Richard Marlow - PeerSpot reviewer
Provides good features and helps monitor the status of ransomware protection in an organization
The tool is quite scalable. There's a one-to-one relationship between the engine and how many scans we can do. We can only do one scan with one engine. We had some issues around the password assessments because we added a lot of users. It took a long time. I rate the scalability a seven out of ten. We have three users in our organization.
HarshBhardiya - PeerSpot reviewer
Provided increased visibility across the organization's servers
The user interface of Tenable Nessus feels outdated and could be more user-friendly. Additionally, the documentation is not well-organized, which can be confusing when searching for solutions or specific information related to Tenable Nessus Professional. The reporting feature could be improved by allowing users to create their own templates instead of relying on predefined ones.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of Pentera is that you can do continuous vulnerability assessment, which is automated."
"Pentera has many authentic features."
"The solution is SaaS-based. From a cloud perspective, it has Pentera Surface and Pentera Core. The Core is the on-prem deployed solution, while the Surface is the cloud-hosted solution that scans your public infrastructure. From the Surface perspective, the most valuable feature so far has been the attack surface mapping."
"Maybe there are some remediation steps on the website, we can mask sensitive information on the website better."
"The product is easy to use."
"Pentera has many authentic features."
"What I like the most about Pentera is its solution-oriented approach."
"The vulnerability scanner, exploit achievements, and remediation actions are all great."
"Tenable Nessus is cheap and flexible."
"The features I personally like include host discovery."
"I have found the vulnerability assessment and the reports to be useful."
"The reports are pretty nice and easy to understand."
"The most valuable feature is the installation of Tenable which is incredibly easy."
"The most valuable aspect of this solution is that you receive the entire report, which details the breakdown, especially in terms of critical, high, low, and mediums."
"The most valuable feature of Tenable Nessus is website scanning."
"We have around 500 virtual machines. Therefore, we conduct monthly scans and open tickets for our developers to address identified vulnerabilities. These scans cover the servers, other network equipment, and appliances in our infrastructure."
 

Cons

"Pentera's general dashboards could be improved and made more specific in terms of vulnerabilities that I'm discovering."
"One of the big issues we have is that the tool has an additional license for compromised credentials. Suppose compromised credentials for any of your domains appear in leaks, dumps, or are being sold. In that case, they try to aggregate that data and highlight that, for example, ten users appeared in recent dumps as compromised credentials. However, they don't provide much information about where those compromises came from or their source information, probably to protect their sources."
"The automated penetration testing features must be improved."
"The price could be improved."
"The licensing and IP management need improvement. When the IP is imported into a system, we cannot withdraw or revoke the license."
"There is room for improvement in virtualization compatibility."
"One area for product improvement could be the inclusion of a dashboard to cover multiple branches and subsidiaries, allowing for centralized monitoring."
"The licensing and IP management need improvement."
"The solution could improve security updates."
"We use credentialed scans. They need more permissions and more changes or settings on Windows and Linux."
"The professional version is not very scalable."
"Tenable Nessus is not feasible for a large company."
"The product could have unique features similar to one of its competitors."
"The reports are okay, but the interface is a bit difficult to navigate in some cases."
"In terms of what could be improved, I would say its reporting portion."
"Tenable Nessus could include a broader range of IT assets."
 

Pricing and Cost Advice

"The product's cost is reasonable. I rate the pricing a three out of ten."
"The tool is relatively cheap."
"We have to pay a yearly licensing cost for Pentera."
"It's not that expensive, but it could be more cost-effective."
"The price of Tenable Nessus is much more competitive versus other solutions on the market."
"We incurred a single cost for a perpetual license, although I cannot comment on the price as this is above my management level."
"It has a fair cost and very good cost-benefit ratio."
"Nowadays, your vulnerability applications are going to be kind of pricey because lots of them, including Rapid7, are based upon a base price, but then they add in the nodes. That's where they get you. If you're a big network, obviously, you need to scan everything. Therefore, it's going to be costly. The risk and insurance money associated with having ransomware on my networks is going to cost me more money, time, and marketing than the price of the tool. That's why I'm speaking only as an information security officer to security operations. This is the tool that is there in my toolbox to say whether we vulnerable or not. At this point, I don't care about how much it costs my company to have it because if I wasn't able to report it and we got ransomware, then who cares? I'm probably going to be out of business because it happened. That's why I don't care about the price. I have it, and I could use it effectively and do my report. At the end of the day, even if we get ransomware, as long as I reported it, followed my protocol, and put in the change, irrespective of whether it was ignored or denied, I did my job."
"I would like to see better discounts."
"Our organization is huge so our license costs $30,000."
"The price is high for the solution. There are free tools with similar functionality available. The solution cost approximately $3,500."
"Nessus is affordable, but its licensing model could be improved with more flexibility for adding assets."
report
Use our free recommendation engine to learn which Breach and Attack Simulation (BAS) solutions are best for your needs.
851,604 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
13%
Manufacturing Company
10%
Educational Organization
6%
Educational Organization
34%
Computer Software Company
9%
Financial Services Firm
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Pentera?
What I like the most about Pentera is its solution-oriented approach.
What needs improvement with Pentera?
The licensing and IP management need improvement. When the IP is imported into a system, we cannot withdraw or revoke the license.
What is your primary use case for Pentera?
I am using the OpenIntra solution for pentesting and managing candidates in my environment. I also use this solution for house customers.
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
Tenable Nessus is a vulnerability assessment solution that is both easy to deploy and easy to manage. The design of the program is such that if a company should desire to handle the installation t...
What do you like most about Tenable Nessus?
We have around 500 virtual machines. Therefore, we conduct monthly scans and open tickets for our developers to address identified vulnerabilities. These scans cover the servers, other network equi...
 

Overview

 

Sample Customers

Blackstone Group Caterpillar Apria Healthcare Taylor Vinters Sandler Capital Management Drawbridge BNP Paribas British Red Cross
Bitbrains, Tesla, Just Eat, Crosskey Banking Solutions, Covenant Health, Youngstown State University
Find out what your peers are saying about Pentera vs. Tenable Nessus and other solutions. Updated: January 2025.
851,604 professionals have used our research since 2012.