Quick answer: scan wide first, then test deep
Vulnerability assessment vs penetration testing: what each finds, how often FTC, PCI DSS and HIPAA expect them, and which a VA, MD or DC office needs first.
Most small businesses should start with a vulnerability assessment
A vulnerability assessment is a broad, mostly automated scan that lists known weaknesses across all your devices. A penetration test is a manual, time-boxed attack that proves which weaknesses an intruder could actually use. Run the assessment first, fix the critical and high findings, then buy a penetration test. The comparison table, compliance schedule, decision guide and 12-month calendar below show how to sequence both.
Vulnerability assessment vs penetration testing at a glance
Both tests look for security holes. They answer different questions. A vulnerability assessment asks, "What known weaknesses exist on every system we own?" A penetration test asks, "If someone attacked us this week, how far would they get?" NIST SP 800-115, the federal guide to security testing, treats them as separate techniques with separate strengths, and so should your budget.
| Question | Vulnerability assessment | Penetration test |
|---|---|---|
| What it does | Scans systems and matches what it finds against databases of publicly known flaws | A tester tries to break in, chain weaknesses together and reach sensitive data |
| Coverage | Wide: every server, PC, firewall and cloud service in scope | Narrow and deep: a defined target, such as your internet-facing systems or internal network |
| Who does the work | Mostly software, with a person reviewing and ranking results | A skilled person using tools, judgment and creativity |
| Typical time | Hours to run, then a review of the results | Days to weeks, plus planning and a report |
| What you get | A ranked list of findings, usually scored with CVSS, and fixes for each | A narrative of attack paths, proof of what was reached, and business impact |
| How often | Monthly to quarterly, and after major changes | Once a year, and after major changes |
| Risk to operations | Low; scans are designed to be non-disruptive | Higher; needs written rules of engagement and a test window |
Why small businesses should usually scan first
A penetration test is the more expensive of the two because a person does the work. If your network still has missing patches, default passwords and an old VPN appliance, the tester will find those in the first hour and spend the rest of the engagement writing them up. You pay expert rates for findings a scanner would have handed you.
Running a vulnerability assessment first clears out that low-hanging fruit. Then the penetration test can spend its hours on the harder questions: can a phished user's account reach the file server, can the guest Wi-Fi see the accounting PC, can an attacker move from one compromised laptop to the whole domain.
Rule of thumb: if your last scan still shows critical or high findings older than 30 days, you are not ready for a penetration test yet. Fix those first, rescan, then book the test.
What the regulations actually require
Many Virginia, Maryland and DC businesses buy testing because a rule, a card processor or an insurer asks for it. Here is what the primary sources say as of October 2026.
| Rule | Who it applies to | Vulnerability scanning | Penetration testing |
|---|---|---|---|
| FTC Safeguards Rule, 16 CFR 314.4(d)(2) | Non-bank financial institutions, including tax preparation firms, mortgage brokers and many financial advisors | At least every six months, and after material changes (unless you run effective continuous monitoring) | At least annually (unless you run effective continuous monitoring) |
| PCI DSS v4.0.1, Requirements 11.3 and 11.4 | Any business that stores, processes or transmits card data | Internal and external scans at least every three months; external scans by a PCI SSC Approved Scanning Vendor; rescans after significant changes | Internal and external tests at least every 12 months, and after significant upgrades or changes |
| HIPAA Security Rule (current) | Covered entities and business associates | No fixed schedule; required risk analysis and periodic evaluation | No fixed schedule |
| HIPAA Security Rule (proposed, not final) | Same | Proposed: at least every six months | Proposed: at least every 12 months |
Two details trip people up. First, the FTC exempts financial institutions that hold customer information on fewer than 5,000 consumers from the testing requirement in 314.4(d)(2), so a small tax practice should count its client records before assuming it is covered. Our page on IT for financial services firms covers the rest of the Safeguards Rule. Second, HHS states that the current HIPAA Security Rule remains in effect while its December 2024 proposal is pending. A six-month scan and annual test are still a sensible target for healthcare practices, because they make the required risk analysis far easier to defend.
If you take cards in a shop or online, PCI DSS is the strictest schedule in the table. See how we support retail and eCommerce businesses with quarterly scanning and remediation.
Which test to buy first: a five-question decision guide
- Have you ever run an authenticated vulnerability scan of every device? If no, start with a vulnerability assessment. Stop here until the critical and high findings are fixed.
- Does a rule, contract or card processor name a penetration test? If yes, schedule one within the deadline it gives, after your first scan cycle.
- Do you have internet-facing systems you host yourself (a VPN, remote desktop gateway, web portal or camera system)? If yes, an external penetration test is your highest-value first test.
- Did you make a major change in the last 12 months (new office, new firewall, cloud migration, merger)? If yes, retest. Both PCI DSS and the FTC Safeguards Rule tie testing to significant or material changes.
- Is your cyber insurance renewal coming up? Applications often ask about vulnerability management and testing. A current scan report and remediation record answers those questions with evidence. Our guide to cyber insurance for small businesses covers what underwriters ask.
A 12-month testing calendar for a 10 to 50 person office
This schedule meets the FTC six-month and PCI DSS three-month scanning rules and the annual penetration test in both, without testing more than you need.
| Month | Activity | Output you keep |
|---|---|---|
| Month 1 | Full authenticated internal scan and external scan | Baseline report, ranked findings |
| Months 1–2 | Fix critical and high findings; rescan to confirm | Remediation log with dates |
| Month 3 | Quarterly scan (external by an ASV if you take cards) | Passing scan report |
| Month 4 | External and internal penetration test | Pen test report and executive summary |
| Month 5 | Fix pen test findings; tester retests | Retest letter |
| Months 6, 9, 12 | Quarterly scans; extra scan after any major change | Scan reports, change notes |
Between scans, patching is what actually closes the holes. Ongoing workstation and server management keeps the next report short, and managed EDR catches attackers who use a flaw before it is patched.
How to prepare for a penetration test
- Written authorization. Get a signed scope and rules-of-engagement document from the business owner before any testing starts.
- Exact scope. List public IP addresses, domains, web apps, Wi-Fi networks and any cloud tenants in scope. Note anything off limits, such as a medical device or a payment terminal.
- Third-party rules. Cloud providers set their own terms. Microsoft, for example, publishes Penetration Testing Rules of Engagement for its cloud services, and your tester should follow them.
- A test window and a contact. Pick dates, hours and one person who can be reached if something breaks.
- Backups confirmed. Make sure you have a recent, tested backup before the test, in case a system needs a restore.
- Remediation time booked. Reserve staff or provider hours for the weeks after the report. A report nobody acts on is a cost, not a control.
Free and low-cost starting points
CISA offers free Cyber Hygiene vulnerability scanning of internet-facing systems, with weekly reports. It is open to government bodies and to public and private critical infrastructure organizations, so check eligibility by emailing vulnerability@cisa.dhs.gov. It does not scan your internal network, so it complements an internal assessment rather than replacing one. Our small business cybersecurity checklist lists the other basics to put in place first.
How Genius Fixers handles testing in Virginia, Maryland and DC
We run vulnerability management from our office in Manassas for businesses across Northern Virginia, Maryland and Washington, DC. Our Complete IT plan, from $150 per workstation per month, includes vulnerability management, phishing training, an annual risk assessment and an improvement plan on top of everyday support. That means scanning, ranking and fixing happen on a schedule instead of once a year in a panic. See managed IT pricing or the full range of cybersecurity services.
When a penetration test is due, we help you set scope, prepare the environment and work through the findings afterward. We do not promise a compliance certification; we help you produce the evidence an auditor, insurer or card processor asks to see.
Not sure whether you need a scan, a pen test or both this year?
Book a free 10-minute call and we will map your requirements to a testing calendar.
Call 703-419-9000 or 1-800-949-6592 to discuss your testing plan.
Frequently asked questions
What is the main difference between a vulnerability assessment and a penetration test?
A vulnerability assessment scans many systems and lists known weaknesses. A penetration test uses a skilled person to exploit weaknesses and show how far an attacker could actually get.
Which should a small business do first?
Start with a vulnerability assessment and fix the critical and high findings. A penetration test is more useful, and better value, once the obvious holes are closed.
How often should a small business run a penetration test?
At least once a year, and after any major change to your network or applications. That matches the annual minimum in PCI DSS v4.0.1 and the FTC Safeguards Rule.
How often should vulnerability scans run?
At least every three months if you handle card data under PCI DSS, and at least every six months under the FTC Safeguards Rule. Monthly scanning is a practical target for most offices.
Does the FTC Safeguards Rule require penetration testing for tax preparers?
Yes, unless the firm runs effective continuous monitoring or holds customer information on fewer than 5,000 consumers. Covered firms need an annual penetration test and vulnerability assessments at least every six months.
Does HIPAA require penetration testing?
The current HIPAA Security Rule does not set a fixed testing schedule, but it requires a risk analysis and periodic evaluation. HHS has proposed requiring vulnerability scans every six months and penetration tests every 12 months; that proposal is not yet final.
Can a vulnerability scan replace a penetration test?
No. A scan finds known flaws but does not prove whether they can be chained into a real breach. Rules such as PCI DSS require both.
Sources
- eCFR: 16 CFR 314.4, FTC Safeguards Rule elements (testing requirements)
- eCFR: 16 CFR 314.6, exceptions for fewer than 5,000 consumers
- FTC: FTC Safeguards Rule, What Your Business Needs to Know
- Microsoft Learn: PCI DSS v4.0 Requirement 11 (requirement text for 11.3 and 11.4)
- HHS: HIPAA Security Rule NPRM fact sheet
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment
- CISA: Cyber Hygiene Services
- Microsoft: Penetration Testing Rules of Engagement, Microsoft Cloud
Last reviewed October 8, 2026 by the Genius Fixers IT Team, Manassas, VA.
