The tool's reports are bad. They're not very customizable or flexible. During audits, we often have to exclude things that aren't relevant to our organization, but we can't do that easily with the reports. They come in HTML or PDF format, and we can't compare current results with previous ones in Excel because we never receive reports in Excel.
Useful for penetration testing but reporting functionality needs improvement
Pros and Cons
- "It's a recommended tool for penetration testers because it's effective for that purpose."
- "The tool's reports are bad. They're not very customizable or flexible. During audits, we often have to exclude things that aren't relevant to our organization, but we can't do that easily with the reports. They come in HTML or PDF format, and we can't compare current results with previous ones in Excel because we never receive reports in Excel."
What needs improvement?
For how long have I used the solution?
I have been using the product for a year, and my organization has been using it for six to seven years.
What do I think about the stability of the solution?
Tenable Vulnerability Management is stable.
What do I think about the scalability of the solution?
I rate the tool's scalability a seven out of ten.
Buyer's Guide
Tenable Vulnerability Management
February 2026
Learn what your peers think about Tenable Vulnerability Management. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,933 professionals have used our research since 2012.
How are customer service and support?
The solution's support is okay, but it could be more customer-friendly. The people providing support have knowledge, but they could improve customer interaction.
How was the initial setup?
The tool's deployment can be challenging, especially for those unfamiliar with Kali Linux, as it operates on this platform. This might make the setup process difficult for users accustomed to other operating systems like Windows. It may take a couple of tries to get comfortable with the process. However, once you have set it up a few times, it becomes easier.
What other advice do I have?
Sometimes, we use the tool for tasks like configuration and running scans. However, it's a bit difficult to use compared to Qualys. One issue we've noticed is that it takes up a lot of space, which customers often complain about. They promised more system coverage and updates, but it isn't happening.
I rate Tenable Vulnerability Management a seven out of ten. It might be challenging if you're used to working on Windows. However, it's a recommended tool for penetration testers because it's effective for that purpose.
We use it for audit and PT.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CTO at ABM Info. tech
An easy-to-manage solution to gain visibility into all IPs
Pros and Cons
- "It is easy to manage. Most of the information the tool provided helped to further investigate the vulnerability and its impact."
- "The solution’s pricing could be improved."
What is our primary use case?
The product operates on a license-based model, where you purchase a license based on the number of IP addresses you intend to scan. For example, if you purchase a license for 50 IP addresses and your network has 200 users, it will only scan for those 50 IPs. You can gain visibility into all IPs within your environment, including subnets with a full license. Also, you can geographically segment your scanning targets based on the number of IPs allocated for each location.
How has it helped my organization?
The product is very friendly. It is easy to manage. Most of the information the tool provided was correct and helped to further investigate the vulnerability and its impact.
What is most valuable?
The most important feature is network scanning.
What needs improvement?
The solution’s pricing could be improved.
For how long have I used the solution?
I have been using Tenable Vulnerability Management for one year.
What do I think about the stability of the solution?
I rate the solution’s stability an eight out of ten.
What do I think about the scalability of the solution?
The solution is very scalable. It allows you to adjust according to your needs. You can add more features if you wish to purchase additional tools.
How was the initial setup?
The initial setup is very easy. To deploy, run the setup command, and then it can deploy on your Linux and Windows platforms. I did it by myself.
What's my experience with pricing, setup cost, and licensing?
The product is expensive but manageable.
What other advice do I have?
I recommend the solution. Although, it varies from person to person experience. Rapid7 users can use free tools. I'm very satisfied with the product.
Overall, I rate the solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Tenable Vulnerability Management
February 2026
Learn what your peers think about Tenable Vulnerability Management. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,933 professionals have used our research since 2012.
Information Security Manager at a international affairs institute with 10,001+ employees
An easy-to-use and stable solution that helps organizations to find vulnerabilities in their systems
Pros and Cons
- "The product is easy to use."
- "The solution must be promoted more in the market."
What is our primary use case?
We use the tool to find loopholes in the system.
What is most valuable?
The product fulfills our needs. It gives reports and finds vulnerabilities in our system. The product is easy to use. It is easy to integrate the tool with other products.
What needs improvement?
The solution must be promoted more in the market. It will make the customers more aware of the product.
For how long have I used the solution?
My organization has been using the solution for a month.
What do I think about the stability of the solution?
The tool is stable.
What do I think about the scalability of the solution?
Around 20 people use the product in our organization. We have one to three administrators. We are most likely to increase the usage of the product in the future.
How was the initial setup?
It was easy to deploy the solution.
What's my experience with pricing, setup cost, and licensing?
The tool is reasonably priced. There are no additional costs associated with the product.
What other advice do I have?
I have known the product for some time. So, I implemented it. Overall, I rate the solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. Director - Group Head - IT Security (CISO) at Jubilant Organosys Ltd., India, Leading Chemical M
The dashboard is pretty intuitive, and it lets you do a drill-down analysis
Pros and Cons
- "The dashboard is pretty intuitive, and it lets you do a drill-down analysis of each vulnerability. That is something that brings a lot of value to the organization."
- "Tenable could improve visibility into assets, including automated asset tagging. You should be able to automatically tag assets based on location, function, ownership, etc. That would help us because we spend a lot of time identifying and tagging assets by hand."
What is our primary use case?
Vulnerability Management is used to discover assets and identify vulnerabilities across our IT landscape.
What is most valuable?
The dashboard is pretty intuitive, and it lets you do a drill-down analysis of each vulnerability. That is something that brings a lot of value to the organization.
What needs improvement?
Tenable could improve visibility into assets, including automated asset tagging. You should be able to automatically tag assets based on location, function, ownership, etc. That would help us because we spend a lot of time identifying and tagging assets by hand.
For how long have I used the solution?
I have used Vulnerability Management since February 2021.
What do I think about the stability of the solution?
There are factors within the organization that affect stability. Ultimately, your Tenable.io performance depends on your on-prem network infrastructure.
How are customer service and support?
I haven't used Tenable.io support, but my team has, and I haven't heard any complaints thus far.
Which solution did I use previously and why did I switch?
I used Qualys at my previous job for vulnerability validation, but I have used Tenable.io VM for quite a while now.
How was the initial setup?
Deploying Tenable.io VM is neither straightforward nor particularly complex. We run gateways in North America and India, respectively that talk to the Tenable.io console. It's not too complex. It was in place when I joined, but I believe it took no more than two weeks to deploy.
You need to create a tenant in the Tenable Cloud SaaS and configure user access. We have five analysts using the solution and one or two admins.
What was our ROI?
We see a return by identifying vulnerabilities and converting them into actionable items. The solution provides a lot of visibility into your environment.
What's my experience with pricing, setup cost, and licensing?
We pay an annual subscription, and I feel the cost is reasonable. The license covers everything, including support.
What other advice do I have?
I rate Tenable.io Vulnerability Management nine out of 10. It's an excellent product that's scalable, stable, and intuitive. It helps you to drill down into vulnerabilities.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Lead Information Security at Australian OpCo Pty Ltd.
Easy to deploy, simple to maintain, and very user-friendly
Pros and Cons
- "The interface is fine."
- "The solution is a bit slow."
What is our primary use case?
Before, they did not have an agent-based solution. Last year, they developed one. For example, before, when users were roaming or working from home, we wouldn't be able to scan previously. Now, we can cover anyone, even off-site.
What is most valuable?
The most valuable feature is the configuration audit.
The interface is fine.
We haven't had issues with support.
The solution is easy to deploy and maintain.
The solution can scale well.
The entire product is very easy to use.
What needs improvement?
The solution is a bit slow. It should be faster. They could improve the performance.
For how long have I used the solution?
We primarily use the solution for vulnerability management and confidential information detection, for example, credit card information. We also use it for configuration management.
What do I think about the scalability of the solution?
The scalability is great. I'd rate it nine out of ten. A company can expand it if they would like to.
How are customer service and support?
Technical support is okay. The issue is they don't have a team based in India. Sometimes, it's hard to get support on time. However, they are pretty helpful.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We are also using Tenable.sc, version 6.0.
How was the initial setup?
The initial setup is pretty straightforward. I'd rate the process eight out of ten overall. It is not overly complex.
We can implement the solution in one week in one region.
In terms of maintenance, we only really need one person. That's enough.
What's my experience with pricing, setup cost, and licensing?
I do not manage the licensing or pricing. My team handles this aspect.
Which other solutions did I evaluate?
We did test multiple other solutions.
What other advice do I have?
I'm an end-user.
This is an agent-based solution. There isn't a specific version we use.
The solution is very user-friendly if you compare it to other tools. I'd rate it eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Consultant at Tata Consultancy
Reliable with good scanning and good performance
Pros and Cons
- "It is quite straightforward to set up."
- "We'd like to see a bit more user-friendliness."
What is our primary use case?
The solution is mainly for vulnerability scanning management. It's more like an extension of the Nessus.
What is most valuable?
I like the ten points of scanning.
The performance is good.
It is quite straightforward to set up.
The solution is stable, and it is quite scalable.
What needs improvement?
We'd like to see a bit more user-friendliness. They need to work on that aspect of the solution.
For how long have I used the solution?
We've recently adopted the solution and have been dealing with it for just over a year or so.
What do I think about the stability of the solution?
The product offers good performance. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
This is a scalable solution. It's easy to expand.
I'm not sure how many users there are, however, my understanding is there are more than ten people.
How are customer service and support?
We've never had any real difficulties, and therefore we haven't really dealt with support.
How was the initial setup?
The solution is easy to set up. It's straightforward. It's not overly complex.
It's based on landscape dependencies. However, it's easily deployed. It can take a few weeks to set up. If you are deploying across the globe, it might take longer.
What was our ROI?
I don't work in an area that would keep track of ROI. I can't say we have been following that.
What's my experience with pricing, setup cost, and licensing?
We pay for an annual license.
If there are extra fees, it depends on what use cases you want to deploy. If you want to use simple vulnerability management and you want to extend it to application scanning, then pricing modules will be different.
What other advice do I have?
I'd recommend the solution to others.
I would rate the solution nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Manager -Cloud Security at Capgemini
Full-service solution that gives a good ROI
Pros and Cons
- "The initial setup is straightforward so long as your infrastructure, components, and networks are in place."
- "Tenable.io Vulnerability Management could be improved with an increased number of dashboards and MSSP integration."
What is our primary use case?
Tenable.io Vulnerability Management is used as a unified platform for vulnerability management.
What needs improvement?
Tenable.io Vulnerability Management could be improved with an increased number of dashboards and MSSP integration.
For how long have I used the solution?
I've been working with Tenable.io Vulnerability Management for five years.
What do I think about the stability of the solution?
Tenable.io Vulnerability Management is stable.
What do I think about the scalability of the solution?
Tenable.io Vulnerability Management is scalable.
How are customer service and support?
Tenable doesn't provide support beyond documentation.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup is straightforward so long as your infrastructure, components, and networks are in place. There are also a few teaching issues post-migration, like integration with third parties and SEO integrations.
What was our ROI?
Tenable.io Vulnerability Management gives a good ROI in the long run, though it would be better with a pay-as-you-go model.
What's my experience with pricing, setup cost, and licensing?
Tenable.io Vulnerability Management's pricing solution model isn't great. Providing a pay-as-you-go option would be an improvement.
What other advice do I have?
Tenable is a full-service product, but it still has a lot of improvements to make, so I'd recommend exploring other products before implementing it. I would give Tenable.io Vulnerability Management a rating of nine out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Intake Specialist at Maxtec
A powerful product that provides visibility across the entire tech surface and helps you to focus on the vulnerabilities that pose immediate risks
Pros and Cons
- "Tenable.io, in particular, is quite a powerful product. It looks at your traditional environment, which is pretty much anything that is on-premises, and it also goes a step ahead and covers your modern assets, which is anything that is currently sitting in the cloud. You get complete visibility of your entire environment and tech operation. The ability to give you visibility across the entire tech surface is one of the biggest advantages that Tenable.io has."
- "They've been able to think about everything in terms of where the world is going and the type of assets that you've got. They've everything sorted out in that aspect, but you have to pay for most of the other components that they've got to give you complete visibility across your tech surface. If it already had those capabilities in-built, without having to add them on to take advantage of them, it would be a very compelling value proposition."
What is our primary use case?
I work for a company called Maxtec, and we are a distributor. One of the solutions that we used to distribute, not anymore, is Tenable. I've worked as the product manager for Tenable, and it is one of the products on which I've worked quite extensively. We stopped its distribution last year, and I stopped working with it at the beginning of 2022. We were using its latest version.
How has it helped my organization?
One of the biggest cutting-edge technologies that they were able to introduce is predictive prioritization. It has helped a lot of IT teams enormously that were heavily under the weight of vulnerabilities that they needed to remediate. Just in 2019, over 19,000 vulnerabilities were discovered, and about 10,000 of those vulnerabilities were rated between high and critical. The way predictive prioritization works is that it adds a lot of context and granularity, and it helps you understand which vulnerabilities actually pose an immediate risk to your environment. It eliminates the pressure that the IT teams were under in terms of remediation because now, they don't have to focus on 10,000 vulnerabilities. They can only focus on 3% of vulnerabilities that pose an immediate risk to their environment. That, for me, has been a cutting-edge technology and a game-changer in helping a lot of IT teams in focusing more on the risk that they need to address, at least within the next 30 days.
What is most valuable?
Tenable.io, in particular, is quite a powerful product. It looks at your traditional environment, which is pretty much anything that is on-premises, and it also goes a step ahead and covers your modern assets, which is anything that is currently sitting in the cloud. You get complete visibility of your entire environment and tech operation. The ability to give you visibility across the entire tech surface is one of the biggest advantages that Tenable.io has.
The use of agents comes in very handy when a lot of the workforce is working from home, such as during COVID-19. Some of the traditional tools would not be able to monitor any of those devices that people would be working with, such as laptops, because they are remote. You can only audit their machines if they are on the business premises, but with Tenable.io agents, you can maintain that level of continuous monitoring, even if they are not on-premises at the time of the scan. The agents run the scans locally on the machine.
Tenable.io is a cloud-managed solution, but the scanners are sitting on-premises. They've also got some public cloud scanners that are sitting all over the world. They've got something called frictionless assessments, which is quite an interesting approach for vulnerability scanning of anything that is sitting in your AWS. You don't have to deploy the scanners. They've got sensors in there that are able to give you continuous monitoring without deploying scanners, doing any configurations, or inputting any credentials.
What needs improvement?
They've been able to think about everything in terms of where the world is going and the type of assets that you've got. They've everything sorted out in that aspect, but you have to pay for most of the other components that they've got to give you complete visibility across your tech surface. If it already had those capabilities in-built, without having to add them on to take advantage of them, it would be a very compelling value proposition.
Their support needs to be improved in terms of turnaround time.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is a cloud solution. Therefore, it is highly scalable. There is no limit to how many assets and devices you can handle.
In terms of verticals, in the public sector, we've seen a huge uptake. That could be because of compliance reasons. We've also seen it being used quite extensively within the banking and financial verticals. Those are the biggest users of the product. There has also been an uptake in other verticals but just not as big or as vast as the public sector and the finance and banking sector.
How are customer service and support?
One area that they could improve is technical support. Oftentimes, it's not as good as it should be. The turnaround time could be improved quite significantly.
How was the initial setup?
It is pretty easy and straightforward. For the cloud, you don't have to do anything on the management console. That is already set up for you. The only thing that you need to configure is your scanners that are sitting on-premise. For that, you just need a linking key that you obtain from Tenable.io so that there is directional communication between the cloud, your cloud instance, and various scanners that are sitting on-premises. It would be the same process if you want to install an agent, for example, on a machine. It would apply the same way. The only difference is that instead of choosing a scanner, you'd choose an agent.
What other advice do I have?
For future users of Tenable.io, I would recommend using a layered approach. Tenable.io has an open API. So, it can be integrated with SIEM solutions. You can look at integrating it with privileged access management or any SIEM solution so that you've got all the data being pumped into a centralized location, and you are able to read the data alongside other security events coming from the SIEM and privileged access management solutions.
Companies that are currently using Tenable.io can definitely start looking at integrating some of their security solutions for a much more robust security approach.
I would rate it a solid eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Download our free Tenable Vulnerability Management Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2026
Popular Comparisons
Microsoft Defender for Cloud
Checkmarx One
Zafran Security
Tenable Nessus
Orca Security
Tenable Security Center
Claroty Platform
Rapid7 InsightVM
Buyer's Guide
Download our free Tenable Vulnerability Management Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Can you recommend API for Tenable Connector into ServiceNow
- What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
- Which one to buy out of the following products: Tenable SC, Tenable.io, Tenable.ep or Tenable.ad?
- What are the differences between Tenable.sc and Tenable.io?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?




















