IT support. Cybersecurity. Business continuity.
Let’s talk

Vulnerability Assessment vs Penetration Testing: What a Small Business Needs First

Vulnerability assessment vs penetration testing: what each finds, how often FTC, PCI DSS and HIPAA expect them, and which a VA, MD or DC office needs first.

Side-by-side comparison of a vulnerability scan report and a penetration test attack path for a small office network
Published October 8, 2026

Quick answer: scan wide first, then test deep

Vulnerability assessment vs penetration testing: what each finds, how often FTC, PCI DSS and HIPAA expect them, and which a VA, MD or DC office needs first.

Most small businesses should start with a vulnerability assessment

A vulnerability assessment is a broad, mostly automated scan that lists known weaknesses across all your devices. A penetration test is a manual, time-boxed attack that proves which weaknesses an intruder could actually use. Run the assessment first, fix the critical and high findings, then buy a penetration test. The comparison table, compliance schedule, decision guide and 12-month calendar below show how to sequence both.

Vulnerability assessment vs penetration testing at a glance

Both tests look for security holes. They answer different questions. A vulnerability assessment asks, "What known weaknesses exist on every system we own?" A penetration test asks, "If someone attacked us this week, how far would they get?" NIST SP 800-115, the federal guide to security testing, treats them as separate techniques with separate strengths, and so should your budget.

QuestionVulnerability assessmentPenetration test
What it doesScans systems and matches what it finds against databases of publicly known flawsA tester tries to break in, chain weaknesses together and reach sensitive data
CoverageWide: every server, PC, firewall and cloud service in scopeNarrow and deep: a defined target, such as your internet-facing systems or internal network
Who does the workMostly software, with a person reviewing and ranking resultsA skilled person using tools, judgment and creativity
Typical timeHours to run, then a review of the resultsDays to weeks, plus planning and a report
What you getA ranked list of findings, usually scored with CVSS, and fixes for eachA narrative of attack paths, proof of what was reached, and business impact
How oftenMonthly to quarterly, and after major changesOnce a year, and after major changes
Risk to operationsLow; scans are designed to be non-disruptiveHigher; needs written rules of engagement and a test window
How the two tests differ

Why small businesses should usually scan first

A penetration test is the more expensive of the two because a person does the work. If your network still has missing patches, default passwords and an old VPN appliance, the tester will find those in the first hour and spend the rest of the engagement writing them up. You pay expert rates for findings a scanner would have handed you.

Running a vulnerability assessment first clears out that low-hanging fruit. Then the penetration test can spend its hours on the harder questions: can a phished user's account reach the file server, can the guest Wi-Fi see the accounting PC, can an attacker move from one compromised laptop to the whole domain.

Rule of thumb: if your last scan still shows critical or high findings older than 30 days, you are not ready for a penetration test yet. Fix those first, rescan, then book the test.

What the regulations actually require

Many Virginia, Maryland and DC businesses buy testing because a rule, a card processor or an insurer asks for it. Here is what the primary sources say as of October 2026.

RuleWho it applies toVulnerability scanningPenetration testing
FTC Safeguards Rule, 16 CFR 314.4(d)(2)Non-bank financial institutions, including tax preparation firms, mortgage brokers and many financial advisorsAt least every six months, and after material changes (unless you run effective continuous monitoring)At least annually (unless you run effective continuous monitoring)
PCI DSS v4.0.1, Requirements 11.3 and 11.4Any business that stores, processes or transmits card dataInternal and external scans at least every three months; external scans by a PCI SSC Approved Scanning Vendor; rescans after significant changesInternal and external tests at least every 12 months, and after significant upgrades or changes
HIPAA Security Rule (current)Covered entities and business associatesNo fixed schedule; required risk analysis and periodic evaluationNo fixed schedule
HIPAA Security Rule (proposed, not final)SameProposed: at least every six monthsProposed: at least every 12 months
Testing requirements by rule (primary sources listed below)

Two details trip people up. First, the FTC exempts financial institutions that hold customer information on fewer than 5,000 consumers from the testing requirement in 314.4(d)(2), so a small tax practice should count its client records before assuming it is covered. Our page on IT for financial services firms covers the rest of the Safeguards Rule. Second, HHS states that the current HIPAA Security Rule remains in effect while its December 2024 proposal is pending. A six-month scan and annual test are still a sensible target for healthcare practices, because they make the required risk analysis far easier to defend.

If you take cards in a shop or online, PCI DSS is the strictest schedule in the table. See how we support retail and eCommerce businesses with quarterly scanning and remediation.

Which test to buy first: a five-question decision guide

  1. Have you ever run an authenticated vulnerability scan of every device? If no, start with a vulnerability assessment. Stop here until the critical and high findings are fixed.
  2. Does a rule, contract or card processor name a penetration test? If yes, schedule one within the deadline it gives, after your first scan cycle.
  3. Do you have internet-facing systems you host yourself (a VPN, remote desktop gateway, web portal or camera system)? If yes, an external penetration test is your highest-value first test.
  4. Did you make a major change in the last 12 months (new office, new firewall, cloud migration, merger)? If yes, retest. Both PCI DSS and the FTC Safeguards Rule tie testing to significant or material changes.
  5. Is your cyber insurance renewal coming up? Applications often ask about vulnerability management and testing. A current scan report and remediation record answers those questions with evidence. Our guide to cyber insurance for small businesses covers what underwriters ask.

A 12-month testing calendar for a 10 to 50 person office

This schedule meets the FTC six-month and PCI DSS three-month scanning rules and the annual penetration test in both, without testing more than you need.

Twelve-month calendar showing quarterly vulnerability scans and one annual penetration test for a small business
MonthActivityOutput you keep
Month 1Full authenticated internal scan and external scanBaseline report, ranked findings
Months 1–2Fix critical and high findings; rescan to confirmRemediation log with dates
Month 3Quarterly scan (external by an ASV if you take cards)Passing scan report
Month 4External and internal penetration testPen test report and executive summary
Month 5Fix pen test findings; tester retestsRetest letter
Months 6, 9, 12Quarterly scans; extra scan after any major changeScan reports, change notes
Sample annual testing calendar

Between scans, patching is what actually closes the holes. Ongoing workstation and server management keeps the next report short, and managed EDR catches attackers who use a flaw before it is patched.

How to prepare for a penetration test

  • Written authorization. Get a signed scope and rules-of-engagement document from the business owner before any testing starts.
  • Exact scope. List public IP addresses, domains, web apps, Wi-Fi networks and any cloud tenants in scope. Note anything off limits, such as a medical device or a payment terminal.
  • Third-party rules. Cloud providers set their own terms. Microsoft, for example, publishes Penetration Testing Rules of Engagement for its cloud services, and your tester should follow them.
  • A test window and a contact. Pick dates, hours and one person who can be reached if something breaks.
  • Backups confirmed. Make sure you have a recent, tested backup before the test, in case a system needs a restore.
  • Remediation time booked. Reserve staff or provider hours for the weeks after the report. A report nobody acts on is a cost, not a control.

Free and low-cost starting points

CISA offers free Cyber Hygiene vulnerability scanning of internet-facing systems, with weekly reports. It is open to government bodies and to public and private critical infrastructure organizations, so check eligibility by emailing vulnerability@cisa.dhs.gov. It does not scan your internal network, so it complements an internal assessment rather than replacing one. Our small business cybersecurity checklist lists the other basics to put in place first.

How Genius Fixers handles testing in Virginia, Maryland and DC

We run vulnerability management from our office in Manassas for businesses across Northern Virginia, Maryland and Washington, DC. Our Complete IT plan, from $150 per workstation per month, includes vulnerability management, phishing training, an annual risk assessment and an improvement plan on top of everyday support. That means scanning, ranking and fixing happen on a schedule instead of once a year in a panic. See managed IT pricing or the full range of cybersecurity services.

When a penetration test is due, we help you set scope, prepare the environment and work through the findings afterward. We do not promise a compliance certification; we help you produce the evidence an auditor, insurer or card processor asks to see.

Not sure whether you need a scan, a pen test or both this year?

Book a free 10-minute call and we will map your requirements to a testing calendar.

Book a free consultation

Call 703-419-9000 or 1-800-949-6592 to discuss your testing plan.

Frequently asked questions

What is the main difference between a vulnerability assessment and a penetration test?

A vulnerability assessment scans many systems and lists known weaknesses. A penetration test uses a skilled person to exploit weaknesses and show how far an attacker could actually get.

Which should a small business do first?

Start with a vulnerability assessment and fix the critical and high findings. A penetration test is more useful, and better value, once the obvious holes are closed.

How often should a small business run a penetration test?

At least once a year, and after any major change to your network or applications. That matches the annual minimum in PCI DSS v4.0.1 and the FTC Safeguards Rule.

How often should vulnerability scans run?

At least every three months if you handle card data under PCI DSS, and at least every six months under the FTC Safeguards Rule. Monthly scanning is a practical target for most offices.

Does the FTC Safeguards Rule require penetration testing for tax preparers?

Yes, unless the firm runs effective continuous monitoring or holds customer information on fewer than 5,000 consumers. Covered firms need an annual penetration test and vulnerability assessments at least every six months.

Does HIPAA require penetration testing?

The current HIPAA Security Rule does not set a fixed testing schedule, but it requires a risk analysis and periodic evaluation. HHS has proposed requiring vulnerability scans every six months and penetration tests every 12 months; that proposal is not yet final.

Can a vulnerability scan replace a penetration test?

No. A scan finds known flaws but does not prove whether they can be chained into a real breach. Rules such as PCI DSS require both.

Sources

Last reviewed October 8, 2026 by the Genius Fixers IT Team, Manassas, VA.

Need a hand with this?
Talk to a Genius Fixers engineer, free.
Book a Phone / Zoom Call
Keep reading

Related posts

All articles →

In-house IT administrator and a managed service provider technician reviewing a shared task list for co-managed IT
Managed IT · October 7, 2026

Co-Managed IT vs Fully Managed IT: Which Fits a Business With One IT Person?

Co-managed IT vs fully managed IT for a business with one IT person: a who-does-what matrix, real cost math and a 30-day plan for VA, MD and DC offices.

Read More
Genius Fixers Managed Wi-Fi for Small Business guide with purple branding and a wireless access point
Managed IT · October 6, 2026

Managed Wi-Fi for Small Business: What You’re Actually Paying For

Business Wi-Fi supports cloud applications, voice, video, guest access and mobile devices, so reliability depends on more than the access point itself. A managed service should provide centralized administration, consistent configuration, monitoring, security oversight and a clear support path when connectivity problems occur.

Read More
Genius Fixers small business cybersecurity checklist in purple and black, featuring a laptop and protective shield.
Cybersecurity · October 4, 2026

Small Business Cybersecurity Checklist: 7 Practical Steps

Use this small business cybersecurity checklist to review accounts, updates, phishing, backups and response readiness with Genius Fixers.

Read More