We use Nessus for vulnerability assessment. Three or four engineers at my company are using it currently.
Threat Intelligence Engineer at a tech services company with 11-50 employees
It's easy to set up and integrate
Pros and Cons
- "Nessus is effortless to integrate."
- "If you are implementing it as part of an ongoing VA or retention operation, you should probably use Tenable."
- "The reporting could be improved. The reporting in Rapid7 is much better."
What is our primary use case?
What is most valuable?
Nessus is effortless to integrate.
What needs improvement?
The reporting could be improved. The reporting in Rapid7 is much better.
What do I think about the stability of the solution?
Nessus performs well.
Buyer's Guide
Tenable Nessus
August 2026
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,683 professionals have used our research since 2012.
What do I think about the scalability of the solution?
Nessus is scalable.
How are customer service and support?
I'm happy with Tenable's technical support.
How was the initial setup?
Nessus is easy to set up, and it only takes about two hours to deploy.
What other advice do I have?
I rate Tenable Nessus nine out of 10. Nessus isn't suitable for everyone. It depends on the case. If you need reporting for the COs and stuff, Rapid7 is better. However, if you are implementing it as part of an ongoing VA or retention operation, you should probably use Tenable.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Founder & CEO at a tech services company with 1-10 employees
Highly stable, easy to use, and useful self updating
Pros and Cons
- "The most valuable feature of Tenable Nessus is the self-updating engine."
- "Tenable Nessus is very easy to support and manage and this is why I have not needed to contact support."
- "Tenable Nessus could improve the reporting."
What is our primary use case?
Tenable Nessus can be deployed on the cloud and on-premise.
I use Tenable Nessus for an internal secured scale.
What is most valuable?
The most valuable feature of Tenable Nessus is the self-updating engine.
What needs improvement?
Tenable Nessus could improve the reporting.
For how long have I used the solution?
I have been using Tenable Nessus for approximately three years.
What do I think about the stability of the solution?
Tenable Nessus is highly stable.
What do I think about the scalability of the solution?
The scalability of Tenable Nessus is good.
I am the only one in cybersecurity using this solution in my organization.
How are customer service and support?
Tenable Nessus is very easy to support and manage and this is why I have not needed to contact support.
How was the initial setup?
The initial setup of Tenable Nessus is easy.
What's my experience with pricing, setup cost, and licensing?
The is a free version of Tenable Nessus available.
In Brazil, it is about $3,500 per year.
What other advice do I have?
My advice to others is for them to start using the free version to get used to the solution.
I rate Tenable Nessus an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Tenable Nessus
August 2026
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,683 professionals have used our research since 2012.
Security Engineer at a media company with 10,001+ employees
Helpful support, reliable, and effective real-time monitoring
Pros and Cons
- "The most valuable feature of Tenable Nessus is real-time monitoring."
- "Tenable Nessus could improve by having more steady updates which will reduce the vulnerabilities."
What is our primary use case?
We are using Tenable Nessus real-time monitoring.
What is most valuable?
The most valuable feature of Tenable Nessus is real-time monitoring.
What needs improvement?
Tenable Nessus could improve by having more steady updates which will reduce the vulnerabilities.
For how long have I used the solution?
I have been using Tenable Nessus for approximately 10 years.
What do I think about the stability of the solution?
Tenable Nessus is a stable solution, we are fairly satisfied.
What do I think about the scalability of the solution?
I rate the scalability of Tenable Nessus an eight out of ten.
Most of the people using this solution at this time are managers.
How are customer service and support?
The technical support has been very useful. They are helpful.
I rate the technical support from Tenable Nessus a four out of five.
How was the initial setup?
The initial setup has been straightforward. However, we are trying to roll out our agents and find all of our devices which we have experienced some challenges. The whole process has taken us approximately three months.
What about the implementation team?
We are doing the implementation in-house.
What other advice do I have?
I would advise others that if this solution fits your use case then I would try it out. Different environments require different solutions.
I rate Tenable Nessus an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Manager at a retailer with 10,001+ employees
Tests against cloud providers, database profiles, several types of telecom devices, and other highly customizable scans
Pros and Cons
- "Scanners and reports using CIS templates ("de-facto" standard, easy to fix and to locate correction tips at documentation), tests against cloud providers, database profiles, several types of telecom devices, and others highly customizable scans."
- "Nessus has more plugins/add-ons, tests, and templates than previous tools and it is faster and customizable using CLI/API features, offering enough resources for an interesting cost-benefit rating and fewer false-positive events per type of asset while helping us quickly produce a QuickWin report that guided vulnerability management actions and plans for the next three to five years using the same tool, investment, and team for all companies in the group."
- "Model OS costs (and its segregation schema for individual modules)."
- "Offer a more flexible strategic and high-level dashboards based on previous comments (minus technical and more business-oriented)."
What is our primary use case?
Over 15.000 active assets|inside 10 companies belonging to the group, the biennium recurrent project mapped the real situation, in parallel with photography of IT/Security maturity through three main domains: processes, people, and technology. 5 TOEs: Infrastructure, Databases (SQL and Oracle in deep), AWS Cloud, Connectivity (Routers, Switches, and Firewalls against/based CIS) and Web Application instances (partial tests). Nessus running over a hardened Linux customized with HA (High Availability).
How has it helped my organization?
Nessus has more plugins/add-ons, tests, and templates than previous tools (OpenVas) and it is faster and customizable using CLI/API features. It offers enough resources for an interesting cost-benefit rating (for small and medium companies) and minus false-positive events per type of asset.
It helped us to quickly produce a QuickWin report that guided the VulnerabilityMgmt actions and plans within the company's during the next 3-5 years using the same tool/investment/team for all companies inside the de group.
What is most valuable?
Scanners and reports using CIS templates ("de-facto" standard, easy to fix and to locate correction tips in the documentation), tests against cloud providers, database profiles, several types of telecom devices, and other highly customizable scans. You can scale your environment to gradually increase the quality, depth, and quantity of the tests, enabling you to learn and gradually optimize your vulnerability management platform(s)/instance(s). The possibility of integration with other market tools (Kenna, Archer...) is another differential.
What needs improvement?
- Add the possibility to customize attributes that define the assets critical level based on the company's "business sense".
- Improve integration and tests for OT platforms, OT application, OT hardware, and non-Ethernet protocols.
- Improve the exchange of info/insights/attributes with RM (Risk Management) domain.
- Offer a more flexible strategic and high-level dashboards based on previous comments (minus technical and more business-oriented)
- Model OS costs (and its segregation schema for individual modules).
For how long have I used the solution?
7+ years with Tenable and more than 15y with others.
What do I think about the stability of the solution?
Excellent. No one problem during operation time and deployment.
What do I think about the scalability of the solution?
Enough (faster than OpenVAS engine).
How are customer service and support?
It SLA/support are enough.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
OpenVAS. We reached the previous level/threshold/maturity using OpenVas (more limited tool when compared with Nessus). I/We believe that, the change to a better tool (in this and in others categories) should be carried out when these indicators are reached.
How was the initial setup?
Very simple and fast.
What about the implementation team?
In-house.
What was our ROI?
Good. Nessus Pro combined with other xLAP solutions to offer a presentation/grouping layer is great. Using SC this curve/point of ROI is slower.
What's my experience with pricing, setup cost, and licensing?
Start small, learn about your problems/fixing time and grow up gradually.
Which other solutions did I evaluate?
Several. OpenVas, Rapid7, Qualys, CORE* and Retina.
What other advice do I have?
A cost/benefit interesting tool.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager at a financial services firm with 201-500 employees
Affordable, stable, and easy to set up vulnerability scanner with a responsive technical support
Pros and Cons
- "Easy to set up vulnerability scanner with good stability and a responsive technical support team."
- "What I like most about Tenable Nessus is its vulnerability scanning feature."
- "The inventory management function in this solution needs improvement."
What is our primary use case?
We're using Tenable Nessus to manage vulnerabilities.
What is most valuable?
What I like most about Tenable Nessus is its vulnerability scanning feature.
What needs improvement?
A room for improvement which I see in Tenable Nessus is the inventory management function.
For how long have I used the solution?
I've been working with Tenable Nessus for two years now.
What do I think about the stability of the solution?
I'm satisfied with the stability of Tenable Nessus.
What do I think about the scalability of the solution?
We have not tried to scale up Tenable Nessus. The number of users we have when we started using it is still the same.
How are customer service and support?
Technical support for this solution was good. They were responsive.
How was the initial setup?
The initial setup for this solution was easy.
What about the implementation team?
We implemented Tenable Nessus through a vendor team, and the process took one month to complete. They were good.
What's my experience with pricing, setup cost, and licensing?
This solution is affordable. We pay a standard fee. We pay for the license yearly.
What other advice do I have?
I work with different products, e.g. firewalls, PAM technology, antivirus, WAF, and proxy. I'm handling information security in the government, not as a consultant. I deal with government procedures.
We deployed this solution on hardware, on VM.
We have 10 users of Tenable Nessus, and they are a mix of engineers and managers.
I'm scoring Tenable Nessus a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Independ consultant
Highly scalable and reliable
Pros and Cons
- "The stability is very good."
- "The reports should be improved in Tenable Nessus. For example, when you are auditing compliance with CIS standards. It provides very poor reports."
What needs improvement?
The reports should be improved in Tenable Nessus. For example, when you are auditing compliance with CIS standards. It provides very poor reports.
For how long have I used the solution?
I have been using Tenable Nessus for approximately one year.
What do I think about the stability of the solution?
The stability is very good.
What do I think about the scalability of the solution?
Tenable Nessus has been scalable.
What other advice do I have?
My advice to others is for them to focus on the cloud solution, and do as much as possible in the cloud.
I rate Tenable Nessus an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Consultant - Cyber Security Services at a computer software company with 10,001+ employees
The most dynamic solution on the market
Pros and Cons
- "The solution is the most dynamic one I have seen thus far."
- "EQA's and dashboards should be addressed in the next release."
- "While Tenable Nessus is a good enterprise solution, the high price would likely make it prohibitive to smaller organizations."
What is our primary use case?
We primarily use the solution for our customer vApp, the dynamic application testing using NetWeb application and security and the infra scanning. It allows us to do a weekly scan for our customers.
How has it helped my organization?
The solution was a great help during the pandemic for closing down all those open vulnerabilities. Continuous scanning of the infra was helpful for identification on the web applications level.
What is most valuable?
The solution is the most dynamic one I have seen thus far. It is one of the best available solutions. It is the best vulnerability tool that is available at present.
What needs improvement?
While Tenable Nessus is a good enterprise solution, the high price would likely make it prohibitive to smaller organizations.
We feel the licensing cost to be too high for our customers and us.
EQA's and dashboards should be addressed in the next release.
For how long have I used the solution?
We have been using Tenable Nessus for four or five years. I believe that our practice team is doing so.
What do I think about the stability of the solution?
The solution is highly reliable.
What do I think about the scalability of the solution?
Scalability is not an issue.
How are customer service and support?
Tech support is good. I think we are now partnered with Tenable.
How was the initial setup?
The initial setup was straightforward. The solution was very easy to set up and configure.
What's my experience with pricing, setup cost, and licensing?
We have a yearly subscription license.
We have a partnership for filling Tenable Nessus as a manager product for our customers.
Though it is a good enterprise solution, it is likely too highly priced for smaller organizations.
We feel the licensing cost to be too high for our customers and us.
What other advice do I have?
We have both on-premises and cloud-based deployment in our organization.
The solution is good.
I rate Tenable Nessus as a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Founder & CEO at a tech services company with 1-10 employees
Very user friendly and affordable
Pros and Cons
- "The trial version is very good for testing whether it will suit your needs."
- "I have chosen Nessus because it's very simple to use and install."
- "The report for counters is too simple and would be improved by a dashboard."
What is our primary use case?
I'm currently using the Nessus essentials for testing, it's installed on my Notebook. My company has only been in operation for one month so as soon as I close with my first client, I will buy the professional version. I used the solution in my previous job.
What is most valuable?
I have chosen Nessus because it's very simple to use and install. Depending on the number of assets you scan, Nessus is also an affordable solution. Products such as Tenable IO and RapidLab, can become expensive depending on the number of IPs. So Nessus Pro is perfect for my needs right now.
What needs improvement?
I'd like to see a dashboard for this product because the report for counters is too simple. There needs to be something better for the client.
For how long have I used the solution?
I've been using this solution for five years.
What do I think about the stability of the solution?
This solution is stable.
What do I think about the scalability of the solution?
The solution is definitely scalable.
How are customer service and support?
I've never needed to contact Tenable support, I've been able to resolve any issues myself.
How was the initial setup?
The initial setup is very easy. Deployment takes less than two hours, it's simple.
What other advice do I have?
It's important to test the solution so you know that it works for your situation. They have a trial version so it's easy to test before you purchase it.
I rate this solution eight out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Assistant Engineer at Harel Mallac Technologies Ltd
User-friendly, easy to use, and good performance
Pros and Cons
- "Tenable Nessus has a good performance, is very user-friendly, and is easy to use."
- "The solution should be able to support more devices."
What is most valuable?
Tenable Nessus has a good performance, is very user-friendly, and is easy to use.
What needs improvement?
The solution should be able to support more devices.
For how long have I used the solution?
I have been using Tenable Nessus for approximately one year.
What do I think about the scalability of the solution?
I have one customer that is using this solution.
How was the initial setup?
The installation of Tenable Nessus is straightforward, and it can take a couple of hours.
What about the implementation team?
I am able to do the deployment myself.
What's my experience with pricing, setup cost, and licensing?
There is an annual license required to use this solution.
What other advice do I have?
I would recommend this solution to others.
I rate Tenable Nessus a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Information Technology Security Specialist at NAKIT s.p.
A remote security scanning tool that's pretty good to optimize
Pros and Cons
- "I have experience with it on my attack stations, and it's pretty good to optimize. Personally, I think Nessus is quite a good product."
- "Personally, I think Nessus is quite a good product."
- "Some things in the user interface could be better. The user interface could allow more adjustments to plugins. The price could also be better."
- "Technical support could be more knowledgeable. Their support right now goes from awkward to funny."
What is our primary use case?
I'm using Tenable Nessus for my personal projects and vulnerability assessment, but I can't discuss what I do at work with you.
What is most valuable?
I have experience with it on my attack stations, and it's pretty good to optimize. Personally, I think Nessus is quite a good product.
What needs improvement?
Some things in the user interface could be better. The user interface could allow more adjustments to plugins. The price could also be better.
For how long have I used the solution?
I have been using Tenable Nessus as a worker in America for about 15 years now.
How are customer service and support?
Technical support could be more knowledgeable. Their support right now goes from awkward to funny. Sorry to say that, but Tenable Nessus support isn't working as it should. They act fast, but their solutions don't always work. I've been in several situations at work where I had to find my own solutions.
How was the initial setup?
The initial setup and installation are pretty straightforward. Let's say 15 minutes to compile the plugin. It would take about half an hour to an hour to set up and deploy.
What's my experience with pricing, setup cost, and licensing?
One problem with Tenable is its pricing policy. Optimal results can be achieved with Greenbone Solutions which has much more friendly pricing policies.
What other advice do I have?
On a scale from one to ten, I would give Tenable Nessus an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Vulnerability ManagementPopular Comparisons
Microsoft Defender for Cloud
SentinelOne Singularity Cloud Security
Qualys TotalCloud
Checkmarx One
Qualys Exposure Management
Tanium
NinjaOne
TrendAI Vision One – Cloud Security
Orca Security
FortiCNAPP
JFrog Xray
Zafran Security
Acunetix
Tenable Security Center
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Qualys VM vs Tenable Nessus: Comparison
- How would you choose between Rapid7 InsightVM and Tenable Nessus?
- What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
- How does Tenable Nessus compare with Qualys VM?
- What are the main differences between Qualys VMDR and Tenable Nessus?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?


















Authenticated users are a excellent way for you increase the quality and depth of your scanner. You can add/use cloud providers API-keys during tests, local or AD users/credentials with database, telecom devices and other types of digital assets. Normally, the difference between non/authenticated-scans is widely big.