Every European vulnerability scanner reviewed
Osnabrück, Germany
Free OpenVAS / Community Edition; Greenbone Enterprise entry-level OPENVAS BASIC at €2,524 per year, OPENVAS SCAN on request
Free Community Edition (OpenVAS)
Best for: Teams that want an open-source scanner they can self-host
Greenbone builds on OpenVAS, the open-source vulnerability scanning engine, and that lineage is the pitch: the engine can be inspected, self-hosted and tried at no licence cost through the free Community Edition, rather than trusted on the vendor's word.
The commercial layer sits on top. Greenbone Enterprise starts with the OPENVAS BASIC appliance at €2,524 per year, with OPENVAS SCAN quoted on request. For a public body or university with a rule against unauditable security software, an open engine with a paid, supported feed is a specific answer few competitors offer.
Greenbone AG is based at Neumarkt 12 in Osnabrück, Germany. The honest limit is that a scanner finds and reports weaknesses but does not block an attack, and running the open edition well needs someone who can interpret and prioritise the output.
What Greenbone does well
- Open-source scanning engine, inspectable and self-hostable
- Free Community Edition with no licence cost
- Published entry price of €2,524 per year
- German company, EU jurisdiction
- Covers networks and hosts, the Nessus use case
Where Greenbone falls short
- Finds weaknesses; does not block attacks
- Self-hosted use needs in-house expertise
- Only the entry appliance price is published
- Less web-application focus than Detectify
Standout feature. An open-source scanning engine you can audit yourself, with a paid feed on top rather than instead of it.
Stockholm, Sweden
Starter free / Standard from €2,500 / Professional from €5,000 / Enterprise from €15,000 per year (annual platform fee); API scanning and PCI ASV scanning (€500 per year) cost extra
Free Starter tier
Best for: Teams that want continuous web and attack-surface scanning with published prices
Detectify combines external attack surface mapping with application scanning, continuously discovering what an organisation exposes to the internet and then testing it. Its payloads come partly from Detectify's own research and partly from Crowdsource, a network of ethical hackers.
Pricing is published rather than quote-only: a free Starter tier, then Standard from €2,500, Professional from €5,000 and Enterprise from €15,000 as an annual platform fee. API scanning (REST and GraphQL) and PCI ASV scanning are extra, the latter at €500 per year, so the headline price is a floor, not a total.
Detectify AB is registered in Sweden with number 556985-9084, with its office at Kornhamnstorg 6 in Stockholm and a second office in Boston. It is a scanner and attack-surface tool, not a WAF, so it finds exposure rather than blocking it.
What Detectify does well
- Attack surface mapping plus application scanning
- Payloads sourced from the Crowdsource ethical hacker network
- Published prices from a free tier to €15,000 per year
- Swedish company with a registration number on the contact page
- PCI ASV scanning available
Where Detectify falls short
- API scanning costs extra
- A US office exists alongside the Stockholm one
- Prices are "from" amounts, not totals
- Focused on web, not network or host scanning
Standout feature. Published pricing from a free tier up to €15,000 a year, rare for enterprise application security.
London, United Kingdom
Founded 2015
Subscription plans billed monthly or annually (amounts are not in the page text); AI-powered web app pentests from $3,500 per test
Free trial offered ("Try free")
Best for: Small and mid-sized teams that want hands-off external and cloud scanning
Intruder is a vulnerability management platform covering external and internal infrastructure, web applications, APIs, cloud accounts and container images. It advertises more than 140,000 checks and, since 2018, emerging threat scans that look for newly published issues across a customer's targets.
The pricing page shows plans billed monthly or annually, but the amounts are not in the page text, so none is quoted here. What is shown is the price of its AI-powered web app pentests: from $3,500 per test. A free trial is offered. The site also lists Nuclei, OpenVAS and Tenable engines in its plan comparison, which tells you it builds on established scanners rather than only its own.
Intruder Systems Ltd is registered in England and based at 1 Mark Square in London, founded in 2015. That puts it under UK law, covered for EU transfers by an adequacy decision but outside the EEA.
What Intruder does well
- Infrastructure, web, API, cloud and container scanning in one platform
- Emerging threat scans for newly published issues
- AI pentest price published
- Free trial offered
- Founded in 2015 with a long track record
Where Intruder falls short
- Subscription amounts not in the page text
- UK jurisdiction, outside the EEA
- Builds on third-party scanning engines
- AI pentests priced separately
Standout feature. One platform for infrastructure, web, cloud and containers, with scans triggered by newly published issues.
Bucharest, Romania
Founded 2017
From $95 per month (NetSec), $140 per month (WebNetSec) and $190 per month (Pentest Suite) at 5 assets; price varies by asset count and billing cycle; yearly billing pays for 10 months
Light versions of several tools free to try
Best for: Consultants and small teams that pay per asset, not per seat
Pentest-Tools.com is a Bucharest platform of 25 online tools: website, API, network and cloud scanners next to reconnaissance and exploit tools. It was founded in 2017, says it has more than 2,100 customers in 119 countries, and lets you try light versions of several tools for free.
Pricing is published per asset: at five assets, NetSec starts at $95 per month, WebNetSec at $140 and Pentest Suite at $190, with the price rising with asset count and yearly billing paying for ten months. Unlimited scans on your own assets and unlimited team members are included on all plans.
The terms name PENTESTTOOLS S.A., a Romanian joint stock company with its registered office on Iancu de Hunedoara Boulevard in Bucharest. The site's structured data uses the older "SRL" form, so check the contract you receive. It is a toolbox for testers more than a risk-ranking platform for a CISO.
What Pentest-Tools.com does well
- Prices published per asset and month
- Unlimited team members on all plans
- Web, network and cloud scanners from the browser
- Light versions free to try
- Romanian company, EU jurisdiction
Where Pentest-Tools.com falls short
- Price rises with asset count
- Tester-oriented rather than management reporting first
- Legal form is "S.A." in the terms but "SRL" in structured data
- Amounts quoted in dollars
Standout feature. Priced per asset with unlimited scans and unlimited users, which suits consultants testing many small clients.
Karlskrona, Sweden
Quoted per customer; no price on the pages checked
Best for: Larger organisations that want a Swedish vulnerability and exposure management vendor
Outpost24 sells risk-based vulnerability management through Outscan NX, which assesses networks, cloud services and assets and ranks findings with threat intelligence rather than CVSS alone. It also sells external attack surface management and application security testing that combines penetration testing as a service with automated scanning.
Pricing is quoted per customer and no price appeared on the pages checked. Its contract is a published Master Agreement with service-specific terms, a service level agreement, a data processing agreement and a DORA appendix, which suits regulated buyers who need that paperwork up front.
The contracting entity is Outpost24 AB, company number 556615-2103, at Blekingegatan 1 in Karlskrona. The vendor's own site returned an access error to our fetch, so this comes from the Master Agreement as returned by search, not from a page we opened. Product details come from search results, not the vendor's pages.
What Outpost24 does well
- Vulnerability management, EASM and pentest as a service in one vendor
- Threat-intelligence-based prioritisation
- DORA appendix in the published contract set
- Swedish company, EU jurisdiction
Where Outpost24 falls short
- No published pricing
- Vendor site blocked automated checks, so fewer facts verified
- Aimed at larger buyers
- Entity details verified indirectly
Standout feature. A contract set with a DORA appendix, built for regulated buyers.
Bromma (Stockholm), Sweden
Request a quote; no amounts on the pricing page
Free trial offered
Best for: Nordic and EU organisations preparing for NIS2 and PCI scanning
Holm Security is a platform for system and network scanning, web application security, cloud security posture (CSPM), API scanning and phishing simulation, with Active Directory, OT and PCI ASV-certified scanning as features. Its site is built around NIS2, DORA and ISO 27001 compliance.
Pricing is by quote and the pricing page shows no amounts, though a free trial is offered. The site states that the VMP platform is hosted in Europe, which is more than most vendors in this directory say about data location.
The controller is H.O.L.M. Security Sweden AB, company registration number 5590304217, at Gustavslundsvägen 137 in Bromma, Stockholm, with Holm Security Benelux B.V. in Amsterdam as a joint controller in the same group. The honest limit: breadth across scanning, phishing and training means each module is a part of a larger suite, not a specialist.
What Holm Security does well
- Network, web, cloud, API and OT scanning in one platform
- PCI ASV-certified scanning
- States the platform is hosted in Europe
- Free trial offered
- Swedish company with a Dutch subsidiary
Where Holm Security falls short
- No published pricing
- Suite breadth may exceed what a small team needs
- Joint controller across two countries
- Compliance-led marketing
Standout feature. One of the few vendors here that states its scanning platform is hosted in Europe.
Ghent, Belgium
Founded 2022
Developer free (2 users) / Basic $300 per month / Pro $600 per month (each including 10 users) / Enterprise on request; prices exclude taxes
Free plan, no credit card
Best for: Developer teams that want code, dependency, container and cloud scanning in one tool
Aikido Security is a Ghent application security platform founded in 2022. It scans dependencies, secrets, source code (SAST), containers, cloud configuration and infrastructure as code, with DAST and domain scanning included. The free Developer plan covers two users within fair-usage limits.
Prices are published in dollars and exclude taxes: Basic at $300 per month and Pro at $600 per month, each including ten users, with Enterprise on request. That is among the clearest pricing in this directory, and the cheapest route into a managed scanner.
The contracting entity is Aikido Security BV, BE0792914919, headquartered at Coupure Rechts 88 in Ghent according to its privacy policy, while the site footer also lists offices in the United States and the United Kingdom. It scans code and cloud far more than it scans internal networks, so it complements rather than replaces a Nessus-style scanner.
What Aikido Security does well
- Code, dependency, container, cloud and domain scanning in one tool
- Free plan for two users
- Published monthly prices
- Belgian company with a stated VAT number
- Priced for small developer teams
Where Aikido Security falls short
- Not a network or host scanner
- Prices in dollars
- Offices in the US and UK as well
- Free tier limited to 10 repositories
Standout feature. The only scanner here with a free plan that covers code, containers and cloud together.
Paris, France
Not published
Best for: Organisations that need vulnerability scanning on premises or air-gapped
Cyberwatch is a Paris platform for vulnerability management and configuration management of endpoints, with Microsoft 365 and Entra ID coverage. Its distinguishing claim is deployment: SaaS, on premises, or fully air-gapped, so the findings can stay inside your own infrastructure.
The vendor states it is a member of Hexatrust and holds the Cybersecurity Made in Europe label. Pricing is not published on the pages checked, so a demo is the way to a quote.
The publisher is CYBERWATCH, a simplified joint-stock company registered at the Paris trade register under number 809 514 318, at 10 rue Penthièvre, 75008 Paris. One detail worth knowing: its legal notice says the marketing website is hosted by Webflow Inc. in San Francisco. That concerns the website, not the scanner, but it is stated on the page.
What Cyberwatch does well
- SaaS, on-premise and air-gapped deployment
- Vulnerability and configuration management together
- French company with a register number stated
- Cybersecurity Made in Europe label, as stated by the vendor
Where Cyberwatch falls short
- No published pricing
- Marketing site hosted by a US provider
- Endpoint-focused more than web-application-focused
- Smaller than the American suites
Standout feature. It will run fully air-gapped, which keeps scan data entirely inside your own walls.
France
Founded 2020
Not shown in the page text
Best for: API-heavy teams that need business-logic testing, not just known-CVE scanning
Escape is a French dynamic scanner that positions itself against legacy scanners. Its in-house AI-powered DAST targets business-logic flaws in web applications and APIs, and it adds continuous external network pentesting with a retest and attack surface management across apps, APIs and infrastructure.
Escape says it was founded in 2020. A pricing page exists but shows no amounts in the page text, so none is quoted here, and the site pushes visitors to book a demo. That makes a cost comparison impossible without a sales call.
The privacy policy names Escape Technologies SAS as the company and data controller; the street address printed there is incomplete, so only the country, France, is stated here. It is a specialist for modern application stacks and will not map an old internal network.
What Escape does well
- Business-logic-aware dynamic testing
- API-first scanning
- External pentesting with retest
- French company, EU jurisdiction
Where Escape falls short
- No amounts in the page text
- Address in the privacy policy is incomplete
- Not an internal network scanner
- Demo-led sales process
Standout feature. It targets the business-logic flaws that signature-based scanners cannot see.
Dublin, Ireland
Founded 2017
Demo on request; no price on the pages checked
Best for: Buyers who want automated scanning with a human validating the results
Edgescan is a Dublin platform for continuous security testing and exposure management, delivered as SaaS. It offers full-stack scanning and penetration testing as a service, a hybrid of automated breadth and human assessment, plus PCI-approved scanning.
Edgescan was founded in 2017 by Eoin Keary and has offices in Dublin and New York. No prices appeared on the pages checked, and a demo is requested.
The site is owned and operated by BCC Risk Advisory Limited, company registration number 497804, trading as Edgescan, with its registered office at Unit 701, Northwest Business Park, Ballycoolin, Dublin 15, Ireland. That makes it one of the few Irish vendors in the category and puts it under EU law. The human validation means more false-positive filtering but also slower turnaround than a pure scanner.
What Edgescan does well
- Automated scanning with human validation
- Irish company, EU jurisdiction
- Registration number stated in the privacy policy
- PCI-approved scanning
Where Edgescan falls short
- No published pricing
- New York office alongside Dublin
- Human validation costs more than pure scanning
- Demo-led sales
Standout feature. A human checks the findings, which cuts the false positives a pure scanner leaves you with.
Knutsford, United Kingdom
Burp Suite Community Edition free / Burp Suite Professional $499 (one-year subscription option on the buy page, per user) / Enterprise on request
Free Community Edition and a free trial of Professional
Best for: Penetration testers and developers who test web apps by hand
Burp Suite from PortSwigger is the manual web penetration tester's toolkit: an intercepting proxy, repeater and intruder tools, and a web vulnerability scanner in the paid Professional edition. The free Community Edition gives the manual tools, with no scanner.
Burp Suite Professional is listed at $499 on the product page, with a one-year subscription option on the buy page, per user. Enterprise editions are separate. Extensions come through the BApp store.
The legal entity is PortSwigger Ltd, 6 Booths Park, Chelford Road, Knutsford, WA16 8ZS, United Kingdom, under UK law with an adequacy decision for EU transfers but outside the EEA. It is a tool for a person who tests, not a platform that continuously monitors an estate, so it complements a scanner here rather than replacing one.
What Burp Suite does well
- The standard manual web testing toolkit
- Free Community Edition
- Price published at $499
- Extensible through the BApp store
Where Burp Suite falls short
- Manual tool, not continuous monitoring
- Scanner only in the paid edition
- UK jurisdiction, outside the EEA
- Priced per user
Standout feature. The tool human testers actually work in, with a free edition to learn on.
Montpellier, France
14-day free trial; plan prices are not in the page text
14-day free trial
Best for: French businesses wanting a web scanner and attack surface check from one vendor
HTTPCS is Ziwit's web vulnerability scanner, with dynamic application scanning and external attack surface evaluation. The site offers a 14-day free trial, and a "check in a few clicks if your site is vulnerable" entry point.
Plan prices are not in the page text we read, so none is quoted; the trial is how you see the real figure before committing. The site and support are French-first, with an English version, which is fine for a French buyer and a small friction for others.
HTTPCS is the exclusive property of Ziwit, a SAS with share capital of €1,140,000, registered at the Montpellier trade register under B 525 202 917, with its head office at 30 Rue Isabelle Eberhardt. It is smaller and less internationally known than Detectify or Greenbone.
What HTTPCS does well
- Web scanner and attack surface evaluation
- 14-day free trial
- French company with register number and capital stated
- English version of the site
Where HTTPCS falls short
- Plan prices not in the page text
- French-first site and support
- No independent certification checked
- Smaller than Detectify or Greenbone
Standout feature. A French web scanner you can try for 14 days before talking to anyone.