Comparisec
Vulnerability ManagementGreenbone OpenVAS
AdequateLimitedAdequateAdequate
4.3

VendorsVulnerability ManagementGreenbone OpenVAS

Greenbone OpenVAS logo

Greenbone OpenVAS

Greenbone AG

Founded 2008·Germany·Private
4.3

Combined score

G2
4.456

Editorial verdict

Greenbone OpenVAS has maintained genuine relevance in the vulnerability management category since its 2008 fork from the original Nessus codebase, and the free Community Edition offers real enterprise-grade scanning depth with over 170,000 test routines at zero licensing cost. For budget-constrained organisations, government agencies, and technical teams with the engineering capacity to self-host and maintain the infrastructure, this represents genuine vulnerability scanning capability that many organisations would otherwise go without entirely. The active German development community and available paid Enterprise editions mean organisations are not limited to purely unsupported open source if they eventually need commercial backing.

The honest trade-off mirrors every free and open source infrastructure tool in this comparison. Prioritisation is basic CVSS scoring without the exploit intelligence and attack path context that Tenable or Rapid7 provide, there is no native patch management or remediation workflow, and CI/CD integration is limited. Organisations choosing Greenbone are trading commercial platform convenience for zero licensing cost and full infrastructure control.

The verdict: Greenbone OpenVAS is right for budget-constrained organisations and technical teams wanting genuinely free, comprehensive vulnerability scanning with the capacity to build the surrounding workflow themselves. Organisations wanting integrated prioritisation and turnkey remediation should evaluate Tenable or Qualys instead.

Last reviewed: September 2026

G2

4.456 reviews

PeerSpot

8.030 reviews
Gartner MQ: Not in MQ

Vulnerability Management assessment

PROTECTIONAdequate
Asset & exposure coverage
4 / 5
Risk prioritisation
2 / 5
OPERATIONSLimited
Remediation workflows
2 / 5
ANALYTICSAdequate
Vuln metrics & KPIs
3 / 5
TRUST & ECOSYSTEMAdequate
Scan performance
3 / 5

Strongest: Asset & exposure coverage

Watch out for: Remediation workflows

Strengths & limitations

Strengths

Genuinely free and open source with over 170,000 vulnerability test routines, offering real enterprise-grade scanning depth at zero licensing cost for the community edition
Strong European heritage and active development community with a long track record dating to the original OpenVAS fork from Nessus in 2008
Paid Enterprise editions available for organisations wanting commercial support without abandoning the open source core

Watch out for

Basic CVSS-based prioritisation without exploit intelligence or attack path context that commercial platforms provide, meaning security teams must do more manual triage work
No native patch management, remediation workflow, or CI/CD integration, requiring significant additional tooling to build a complete vulnerability management program
Requires meaningful engineering investment to deploy and maintain at scale, consistent with open source infrastructure tools generally

Best for

Budget-constrained organisations and technical teams wanting genuinely free, comprehensive vulnerability scanning coverage with the engineering capacity to build the surrounding remediation workflow themselves.

Not suitable for: Organisations wanting integrated prioritisation intelligence, native patch management, or a turnkey vulnerability management program without significant additional tooling and engineering investment.

Compliance coverage

CIS Benchmarks
Essential Eight
AU Privacy Act
SOC 2
HIPAA
NIST CSF
PCI-DSS
CMMC
GDPR
NIS2
DORA
ISO 27001

Switching intelligence

Switching from

Common migration paths based on review data

Also considering

Vendors typically shortlisted alongside

← Back to Vulnerability ManagementCompare with other Vulnerability Management vendors ➲

Quick facts

Pricing modelFree open source; paid Enterprise editions available
Pricing rangeFree Community Edition; Enterprise from approximately $3,000/year
Free trialYes
Min seatsNo minimum
Deployment time1-2 weeks
Complexity3 / 5
Pricing transparency5 / 5
AU presenceNo
IRAP assessedNo
Open sourceFully open source

Deployment

ModelsSelf-hosted
OS supportLinux, Windows
CloudAWS, Azure
SupportEmail, Community
Data residencySelf-hosted anywhere

Company

Greenbone AG

Founded 2008 · 50-200 employees · Private

HQ: Germany

Not publicly disclosed

Integrations

Basic APITicketing systems via custom integration