Try our new research platform with insights from 80,000+ expert users

SecurityScorecard vs Tenable Nessus comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.1
SecurityScorecard enhances security visibility and efficiency, improving scores and reducing premiums, yielding 176% ROI over three years.
Sentiment score
2.5
Tenable Nessus excels in vulnerability management, boosting security, offering cost-efficiency, and enhancing threat detection and patch deployment.
This resulting in a lower insurance premium cost for us and considerable cost savings overall, which made our management very pleased with the progress.
Application security engineer at a media company with 51-200 employees
The biggest benefit is visibility, allowing organizations to understand their risks, vulnerabilities, and potential threats.
Regional Director at a tech services company with 51-200 employees
We have seen a clear return on investment, and in terms of the metrics, the time saver is in the reduction of time spent.
SOC analyst at BUSINESS IT
 

Customer Service

Sentiment score
7.4
SecurityScorecard's customer support is knowledgeable and available 24/7, but users report delayed response times despite improvements.
Sentiment score
3.8
Tenable Nessus support is knowledgeable and efficient but sometimes delayed, with high overall satisfaction despite occasional response speed issues.
They need better organization to support their customer volume.
Regional Director at a tech services company with 51-200 employees
they continue to assist us with bi-monthly sync-up calls whenever we face issues with the platform regarding risk and how to improve our security score
Application security engineer at a media company with 51-200 employees
I would rate the customer support for SecurityScorecard nine out of 10.
Technical Lead at M.TECH Solutions India Pvt. Ltd.
We received support within one to three hours.
CIO at a insurance company with 201-500 employees
Whenever any issue arises, we contact the support, and they are always there for us.
Information security engineer at Cyberisk
The technical support is good yet could improve in terms of response time.
SOC Engineer at a outsourcing company with 10,001+ employees
 

Scalability Issues

Sentiment score
6.3
SecurityScorecard offers a scalable, adaptable service ideal for medium to large enterprises, though not suited for Fortune 500 firms.
Sentiment score
5.6
Tenable Nessus is scalable, adaptable, and well-regarded, though larger environments may face server and cloud storage challenges.
The product is suitable for medium to large businesses, typically with a revenue range from $200 million to a couple of billion dollars.
Regional Director at a tech services company with 51-200 employees
My experience with SecurityScorecard is that it is highly scalable and can handle more vendors or users as my organization grows.
SOC analyst at BUSINESS IT
Whether managing 50 servers today or 500 tomorrow, performance or capacity are not hindered.
SOC Engineer at a outsourcing company with 10,001+ employees
Tenable Nessus is definitely scalable, especially for license formats designed for scalability.
Security Center Coordinator at a comms service provider with 1-10 employees
 

Stability Issues

Sentiment score
8.2
SecurityScorecard is highly stable, rated 9/10, with 99.99% uptime, appreciated for performance speed and reliable browser extension.
Sentiment score
5.7
Tenable Nessus is stable with reliable performance, minor update issues, occasional false positives, and rare network interference.
I find SecurityScorecard stable for our organization, as I have not encountered any downtime.
Application security engineer at a media company with 51-200 employees
We have not encountered any issues with missing network items or errors in API and webhook interactions.
SOC Engineer at a outsourcing company with 10,001+ employees
The stability of Tenable Nessus is extraordinary.
Founder at Cipheroot
 

Room For Improvement

SecurityScorecard requires better responsiveness, remediation guidance, integration, customization, pricing, insights, accuracy, interface, mobile capabilities, and third-party risk management.
Tenable Nessus needs improved reporting, integration, and user interface, along with expanded capabilities, flexible pricing, and better documentation.
If SecurityScorecard could improve anything, it would be making sure the algorithm pulls the right data for the right domain.
IT operations risk analyst at a energy/utilities company with 10,001+ employees
There is a need for more active rather than passive third-party risk management features to truly mitigate risks.
Regional Director at a tech services company with 51-200 employees
SecurityScorecard could enhance some of the integrations based on AI platforms, where I could receive suggestions from the AI tool regarding why SecurityScorecard rates specific issues as critical or high.
Application security engineer at a media company with 51-200 employees
This is Tenable's property. They want to sell Tenable Security Center, and they closed all the API capability for Tenable Nessus Professional.
Co-Founder at RSU Consultancy
The documentation is not well-organized, which can be confusing when searching for solutions or specific information related to Tenable Nessus Professional.
SOC Engineer at a outsourcing company with 10,001+ employees
The product's pricing has roughly tripled within the last couple of years, making us reconsider renewing the license for the scanner.
Security Center Coordinator at a comms service provider with 1-10 employees
 

Setup Cost

SecurityScorecard's mid-range pricing and flexible setup attract enterprises, offering transparency and support, though international cost varies.
Enterprise evaluations praise Tenable Nessus for competitive pricing, though licensing flexibility issues may increase costs for larger networks.
There are more expensive and cheaper options available.
Regional Director at a tech services company with 51-200 employees
I expected slightly lower pricing.
Application security engineer at a media company with 51-200 employees
Pricing is acceptable as per the Indian market.
Technical Lead at M.TECH Solutions India Pvt. Ltd.
The pricing for Tenable Nessus has increased significantly, tripling over the last few years.
Security Center Coordinator at a comms service provider with 1-10 employees
Tenable Nessus's pricing is adequate if it is fully utilized.
SOC Engineer at a outsourcing company with 10,001+ employees
My experience with the pricing, setup cost, and licensing of Tenable Nessus is that the installation is somewhat easier, but preparing the product, such as the SKU and license options, is quite tricky.
Senior Security Consultant at ITSEC Asia
 

Valuable Features

SecurityScorecard provides continuous monitoring, risk management, and visual insights, improving compliance and security conversations with stakeholders and vendors.
Tenable Nessus offers comprehensive vulnerability coverage, flexible scanning, ease of use, affordable pricing, and effective integration, enhancing security management.
It combines threat intel data with vulnerability information to increase risk ratings and provides insights into third-party supply chain risks.
Regional Director at a tech services company with 51-200 employees
I particularly value the Jira integration, so any issue identified as part of the threat intel activity can be directly updated through our Jira.
Application security engineer at a media company with 51-200 employees
It converts complex security issues into business-friendly language, which helps executives and the board understand cyber risk.
Technical Lead at M.TECH Solutions India Pvt. Ltd.
I mostly use the configuration audit feature for the audit configuration as a scan policy, and I will use it for credential audit, which helps me scan credentials access such as local administrator or root access, performing a deeper and more accurate check of local configuration settings and file systems, making it a highly recommended feature.
Founder at Cipheroot
The scanning and reporting features are the most valuable aspects of Tenable Nessus.
SOC Engineer at a outsourcing company with 10,001+ employees
The most valuable features of Tenable Nessus include its ease of access and quick usability.
Security Center Coordinator at a comms service provider with 1-10 employees
 

Categories and Ranking

SecurityScorecard
Average Rating
8.2
Reviews Sentiment
6.5
Number of Reviews
13
Ranking in other categories
IT Vendor Risk Management (1st), AI Legal & Compliance (3rd), AI Procurement & Supply Chain (3rd)
Tenable Nessus
Average Rating
8.4
Reviews Sentiment
6.0
Number of Reviews
87
Ranking in other categories
Vulnerability Management (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. SecurityScorecard is designed for IT Vendor Risk Management and holds a mindshare of 8.1%, down 11.3% compared to last year.
Tenable Nessus, on the other hand, focuses on Vulnerability Management, holds 5.2% mindshare, down 10.3% since last year.
IT Vendor Risk Management Market Share Distribution
ProductMarket Share (%)
SecurityScorecard8.1%
OneTrust GRC8.3%
RSA Archer8.0%
Other75.6%
IT Vendor Risk Management
Vulnerability Management Market Share Distribution
ProductMarket Share (%)
Tenable Nessus5.2%
Wiz7.5%
Qualys VMDR5.0%
Other82.3%
Vulnerability Management
 

Featured Reviews

AG
Application security engineer at a media company with 51-200 employees
Vendor risk monitoring has strengthened our security posture and reduced insurance costs
In terms of improvements, I feel SecurityScorecard could enhance some of the integrations based on AI platforms, where I could receive suggestions from the AI tool regarding why SecurityScorecard rates specific issues as critical or high. Details on the technical mitigation would help my non-technical teams understand the security issues better. I think improvements could be made on the reporting side as well, such as the ability to download customizable reports. While SecurityScorecard offers various kinds of reports now, they are limited to predefined formats. Having the ability to choose specific fields for an automated report would be very helpful.
MohammedJaffir - PeerSpot reviewer
Founder at Cipheroot
Has enabled me to reduce false positives and perform deep credential auditing with seamless integrations
I mostly use the configuration audit feature for the audit configuration as a scan policy, and I will use it for credential audit, which helps me scan credentials access such as local administrator or root access, performing a deeper and more accurate check of local configuration settings and file systems, making it a highly recommended feature. Regarding integration capabilities, we can integrate Tenable Nessus with SIM tools such as Splunk, IBM QRadar, and Azure Sentinel, as well as with ticketing systems such as ServiceNow, Jira, and Slack. There is no complexity as it is very easy to integrate everything. In terms of the reporting feature, while vulnerability scanning can throw some false positives, Tenable Nessus has very few, achieving a reduction of 75% to 80% false positives with manual analysis needed. We can generate standard Nessus reports that typically include host summaries and vulnerabilities by host and plugin, alongside solutions and remediation recommendations. The main benefits I get from Tenable Nessus are complete asset inventory and comprehensive attack surface management, allowing us to prioritize vulnerabilities based on risk, focusing on true risk and threat path analysis.
report
Use our free recommendation engine to learn which IT Vendor Risk Management solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
11%
Computer Software Company
10%
Insurance Company
6%
Financial Services Firm
10%
Government
10%
Manufacturing Company
10%
Computer Software Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise3
By reviewers
Company SizeCount
Small Business39
Midsize Enterprise19
Large Enterprise35
 

Questions from the Community

What do you like most about SecurityScorecard?
One of its most effective features for risk identification is its enterprise-ready automation for third-party risk measurements.
What is your experience regarding pricing and costs for SecurityScorecard?
I have seen a return on investment with SecurityScorecard as it is easy to use and has saved us some time, so we do not need to do the scans on our own.
What needs improvement with SecurityScorecard?
I suggest that SecurityScorecard could be improved by giving a little more specifics on how the scanning works and how you are able to detect those IPs, including more details on the privacy side a...
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
Tenable Nessus is a vulnerability assessment solution that is both easy to deploy and easy to manage. The design of the program is such that if a company should desire to handle the installation t...
What do you like most about Tenable Nessus?
We have around 500 virtual machines. Therefore, we conduct monthly scans and open tickets for our developers to address identified vulnerabilities. These scans cover the servers, other network equi...
 

Overview

 

Sample Customers

TriNet, USAA, Zurich, Gilt Groupe, McGraw Hill Financial
Bitbrains, Tesla, Just Eat, Crosskey Banking Solutions, Covenant Health, Youngstown State University
Find out what your peers are saying about SecurityScorecard, BitSight, OneTrust and others in IT Vendor Risk Management. Updated: January 2026.
881,082 professionals have used our research since 2012.