Primarily, I use this for assessment and administration testing.
Security Professional at a tech vendor with 10,001+ employees
An affordable product that needs to improve the reporting function
Pros and Cons
- "I find the features that are most valuable are the policies that help us identify the vulnerabilities. These policies are then used for scanning instabilities and then identifying the particular vulnerabilities."
- "I find the features that are most valuable are the policies that help us identify the vulnerabilities, and these policies are then used for scanning and identifying instabilities."
- "We have had some false positives in the past, which we hope can improve in the future."
- "We have had some false positives in the past, which we hope can improve in the future."
What is our primary use case?
What is most valuable?
I find the features that are most valuable are the policies that help us identify the vulnerabilities. These policies are then used for scanning and identifying instabilities.
What needs improvement?
The reporting functionality needs improvement. I think it would be beneficial to have a high level explanation for a particular user.
For how long have I used the solution?
Three to five years.
Buyer's Guide
Tenable Nessus
February 2026
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,976 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is very stable, based on our past experience. We have had some false positives in the past, which we hope can improve in the future.
What do I think about the scalability of the solution?
The scalability is fine. It is tied to the licensing agreement. We currently have 20 people using this tool in our organization. It is primarily used by people in our cellular team. If we see a need to add more users in the future, we will renegotiate our licensing agreement to do so.
How are customer service and support?
We have not needed to contact tech support much. We contacted them about the false positives, and they were helpful.
Which solution did I use previously and why did I switch?
We also evaluated Netplus.
How was the initial setup?
The installation is very straightforward and easy. We did not use a third-party installer.
What's my experience with pricing, setup cost, and licensing?
I think the price is fairly affordable. It provides a license that is fair.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Consultant at a tech company with 1,001-5,000 employees
Reduces the amount of time spent on finding vulnerabilities.
Pros and Cons
- "Tenable Nessus streamlines the process of scanning for our organization."
- "The price of Tenable Nessus is much more competitive versus other solutions on the market."
- "This is still a maturing product. Tenable is only a scanner for one ability, while other solutions like Rapid7 have more tools for verification. We still have to manually verify to see if the vulnerability is a false positive or not."
- "This is still a maturing product. Tenable is only a scanner for one ability, while other solutions like Rapid7 have more tools for verification."
What is our primary use case?
My primary use case of this solution is for scanning internal networks.
How has it helped my organization?
We use Tenable Nessus for scanning. We find lots of vulnerabilities and then we reduce the time spent on finding inbox vulnerabilities. Of course, Tenable streamlines the process. It has been a positive experience overall.
Tenable can scan for missing patches for the endpoints. We can scan it and then, once we can support any endpoint without patching, we inform our users.
What is most valuable?
We wanted to do a lot of Hardening and we have to make sure that all endpoints are up to the certain Hardening standard and we propose the CIS benchmark to do this. That's why we use Tenable to do scanning frequency and to ensure the quality of the endpoints.
What needs improvement?
This is still a maturing product. Tenable is only a scanner for one ability, while other solutions like Rapid7 have more tools for verification. We still have to manually verify to see if the vulnerability is a false positive or not.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
It is stable. We have not had any major issues. It performs as scheduled and scans as needed.
What do I think about the scalability of the solution?
In terms of scalability, there is an issue with cloud servers. You need the internet bandwidth to do the testing. They consume a lot of bandwidth and they use the cloud scanners for the scanning.
How is customer service and technical support?
I usually use the dashboard for support. It shows the critical vulnerabilities from low to high. They are very responsive when necessary.
How was the initial setup?
The implementation was straightforward. First, we noticed whether everything was ready, then we got a license key, set up some basic scanning using a default template, and finally, we scheduled time.
What's my experience with pricing, setup cost, and licensing?
The price of Tenable Nessus is much more competitive versus other solutions on the market.
Which other solutions did I evaluate?
We were manually scanning before using Tenable Nessus. We looked at Rapid7 but we are satisfied with Tenable Nessus.
What other advice do I have?
I would suggest that people considering this solution should choose the cloud-based solution versus the on-premise version.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Tenable Nessus
February 2026
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,976 professionals have used our research since 2012.
Managing partner at a tech services company with 51-200 employees
We can deliver a high level of consulting using this product.
Pros and Cons
- "We looked at Tenable, Qualys and Rapid7. We found Tenable was the best of all three."
- "We can now deliver highly professional consulting using the product."
- "From my point of view the solution basically is not for the big enterprise."
- "From my point of view, the solution basically is not for large enterprises."
How has it helped my organization?
This is something that allows us to quickly get a really important information context. We can now deliver highly professional consulting using the product.
What needs improvement?
From my point of view, the solution basically is not for large enterprises. I also think there should be built-in plugins for the public cloud vendors.
What do I think about the stability of the solution?
I'm happy with stability, there's no problem from my point of view.
What do I think about the scalability of the solution?
For an average sized company or for smaller enterprises, this solution is suitable. But, for large enterprises it's not a good choice. We have one customer with more than 5,000 servers. I do not think it will be suitable for that customer.
How are customer service and technical support?
We communicated via email to solve our issue. The experience was quite good for us.
Which solution did I use previously and why did I switch?
We switched because our previous solution was too expensive for us.
What's my experience with pricing, setup cost, and licensing?
My advice when choosing a vendor is to always consider:
- Trustworthiness
- Quality
- Price
Which other solutions did I evaluate?
We looked at Tenable, Qualys and Rapid7. We found Tenable was the best of all three.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at Medmen
Provides multiple recommendations towards the remedy of vulnerabilities
Pros and Cons
- "It provides multiple recommendations towards the remedy of vulnerabilities."
- "It allows me to prioritize efforts and utilize effective technical resources."
- "It provides actionable recommendations to the implementation team towards security remedies."
- "They should improve the I/O reporting and the customized spreadsheet export feature."
- "Multiple steps to create an actionable plan will be a great addition to Nessus."
- "They should improve the I/O reporting and the customized spreadsheet export feature."
What is our primary use case?
I use Tenable Nessus to evaluate the security posture of multiples acquisitions before integrating them to our network.
How has it helped my organization?
Tenable Nessus has helped us visualize the security posture of acquisitions. It provides actionable recommendations to the implementation team towards security remedies.
What is most valuable?
I have found the remedy recommendation feature helpful, as it:
- Provides multiple recommendations towards the remedy of vulnerabilities.
- Allows me to prioritize efforts and utilize effective technical resources.
What needs improvement?
- They should improve the I/O reporting and the customized spreadsheet export feature.
- Multiple steps to create an actionable plan will be a great addition to Nessus.
For how long have I used the solution?
One to three years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Cybersecurity Consultant at CIA Botswana
Helps to discover and patch vulnerabilities proactively
Pros and Cons
- "Nessus' most valuable feature is vulnerability management because it helps to discover vulnerabilities proactively and integrates with patch management solutions so you can push patches."
- "Nessus' reporting could be more user-friendly."
What is our primary use case?
I primarily use Nessus for vulnerability management, including scanning, identifying, and assessing risks.
What is most valuable?
Nessus' most valuable feature is vulnerability management because it helps to discover vulnerabilities proactively and integrates with patch management solutions so you can push patches.
What needs improvement?
Nessus' reporting could be more user-friendly.
For how long have I used the solution?
I've been using Nessus for more than three years.
What do I think about the stability of the solution?
I would rate Nessus' stable five out of five.
What do I think about the scalability of the solution?
Nessus is scalable.
How are customer service and support?
Tenable's technical support has a very good turnaround time.
How was the initial setup?
The initial setup is straightforward, and deployment takes up to five days.
What was our ROI?
The ROI from Nessus is good - it allows us to proactively discover vulnerabilities and deploy patches before the worst-case scenario happens. I would rate the ROI five out of five.
What's my experience with pricing, setup cost, and licensing?
Nessus is affordable, but its licensing model could be improved with more flexibility for adding assets.
What other advice do I have?
I would advise anybody thinking of implementing Nessus that they should be competent with risk management language and do some training on the solution, otherwise, they won't understand anything. I would rate Nessus ten out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Infrastructure Engineer at IP Protocol INC
Provides good scalability, but there could be more learning documentation
Pros and Cons
- "The product's most valuable features are vulnerability and asset management. It can define the rules and validate the configuration."
- "There could be an integration between Tenable Nessus and other Tenable products. It will help us manage all the solutions using one dashboard."
What is our primary use case?
We use Tenable Nessus for asset and vulnerability management.
What is most valuable?
The product's most valuable features are vulnerability and asset management. It can define the rules and validate the configuration.
What needs improvement?
There could be an integration between Tenable Nessus and other Tenable products. It will help us manage all the solutions using one dashboard. Additionally, they should include more learning material to know about the product.
For how long have I used the solution?
We have been using Tenable Nessus for one year.
What do I think about the stability of the solution?
The product has good stability.
What do I think about the scalability of the solution?
We have more than 50 Tenable Nessus users in our organization. It is a scalable platform.
How was the initial setup?
Tenable Nessus is easy to deploy and manage.
What other advice do I have?
I recommend Tenable Nessus to others and rate it a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Engineer at a tech services company with 11-50 employees
Easy to deploy and use, and integrates well with our systems
Pros and Cons
- "Tenable integrates well with other solutions such as SIEM and batch management."
- "Pricing is one of the most important features, and it is something that they can improve on."
What is our primary use case?
We are a solution provider and Tenable Nessus is one of the products that we implement for our clients.
The primary task that Tenable is focused on is vulnerability management.
What is most valuable?
This solution is easy to use.
It has a powerful set of features.
Tenable integrates well with other solutions such as SIEM and batch management. This is one of the things that we do to add value for our customers.
For how long have I used the solution?
I have been working with Tenable Nessus for approximately nine years. This included six years with my previous company and another three years in my current organization.
What do I think about the stability of the solution?
The stability is good.
What do I think about the scalability of the solution?
This is a scalable product.
How are customer service and support?
The support, as well as the portal, is very good.
How was the initial setup?
The deployment is very easy to do. It takes less than one hour to complete.
What's my experience with pricing, setup cost, and licensing?
Pricing is one of the most important features, and it is something that they can improve on.
Which other solutions did I evaluate?
In my region, our customers prefer Tenable over other products, like those offered by Qualys. They have approximately 80% of the market share.
What other advice do I have?
Tenable is the best vulnerability management product in the world, and I recommend it.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
CyberSecurity Specialist at a tech services company with 11-50 employees
Easy to set up with scanning capabilities and good integration options
Pros and Cons
- "Its initial setup was simple and straightforward."
- "The scanning capabilities are very good."
- "Online learning could be a bit better."
- "Online learning could be a bit better."
What is our primary use case?
We're mainly doing vulnerability scanning with Nessus.
What is most valuable?
The scanning capabilities are very good.
The integration is very easy.
Its initial setup was simple and straightforward.
The solution is stable.
What needs improvement?
I haven't explored a lot of features just yet.
Online learning could be a bit better. It would help people understand the product better.
I'd like it to have an easier wizard, for example, "click here and this will deploy everything" or "this would help you get the correct things in place for correct scanning," et cetera.
For how long have I used the solution?
I've been using the solution for two years.
What do I think about the stability of the solution?
The stability has been good. Its performance is reliable. There are no bugs or glitches. it doesn't crash or freeze.
What do I think about the scalability of the solution?
I'm the only person using the solution.
I don't have plans to increase usage.
How was the initial setup?
The solution is easy to implement. It's not difficult or complex.
I was trying to do Tenable SC at some point, however, I gave up on that one.
The deployment takes about two weeks.
What's my experience with pricing, setup cost, and licensing?
I don't really deal with the pricing aspect of the product. I can't speak to the exact price.
What other advice do I have?
I'm a partner and customer.
I'd rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2026
Product Categories
Vulnerability ManagementPopular Comparisons
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Qualys VMDR
Tanium
Zafran Security
JFrog Xray
Orca Security
Tenable Security Center
Claroty Platform
Tenable Vulnerability Management
Acunetix
TrendAI Vision One – Cloud Security
Rapid7 InsightVM
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Qualys VM vs Tenable Nessus: Comparison
- How would you choose between Rapid7 InsightVM and Tenable Nessus?
- What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
- How does Tenable Nessus compare with Qualys VM?
- What are the main differences between Qualys VMDR and Tenable Nessus?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
















