European Alternatives to Nessus, Qualys and Rapid7 - Vulnerability Scanners (2026) | European Purpose

European Vulnerability Scanners Alternatives

A vulnerability scanner probes servers, networks, web applications and cloud accounts for known weaknesses before an attacker does, and tells you what to fix first.

The best-known names, Nessus, Qualys, Rapid7 and Invicti, are American, and a scanner is a sensitive tool to hand to a foreign vendor: it holds a map of everything you run and everything that is broken.

This list covers twelve European scanners and testing platforms, ten from inside the EU (Germany, Sweden, Romania, Belgium, France and Ireland) and two from the United Kingdom. They range from an open-source engine you can host yourself to SaaS platforms and a manual penetration testing toolkit. Each one is a European alternative to Nessus, Qualys or Rapid7, and each entry says plainly where the company sits and what it publishes about price.

How we rank these tools — 4-step process
  1. 1
    European ownership, verified

    The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.

  2. 2
    Category fit and hands-on review

    What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.

  3. 3
    Compliance and pricing check

    GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.

  4. 4
    Position on this page

    Placement on this page can be paid, and that can affect the order tools appear in. It never buys a listing: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.

Vendors can pay for visibility on this page. It never changes what an entry says about a product, including the criticism, and we earn nothing when you click through to a vendor. Paid placement can affect the order in which tools appear; it never affects whether a tool is listed. Editorial policy

12 European Vulnerability Scanners

Greenbone

Osnabrück maker of OpenVAS, the open-source vulnerability scanning engine, with a free Community Edition and paid appliances with a maintained feed

Germany Free Community Edition / Enterprise appliances from €2,524 per year
Open-source scanning engine (OpenVAS) you can inspect and self-hostPaid appliances add a maintained vulnerability feed and supportEntry-level OPENVAS BASIC appliance at €2,524 per year

Detectify

Stockholm external attack surface and web application scanner with payloads from a network of ethical hackers and published annual prices

Sweden Free Starter / Standard from €2,500 / Professional from €5,000 / Enterprise from €15,000 per year
Attack surface mapping plus application scanning in one platformPayloads partly sourced from the Crowdsource ethical hacker networkREST and GraphQL API scanning as an add-on

Intruder

London vulnerability management platform for external, internal and cloud scanning, with emerging threat scans and a dedicated AI pentest offer

United Kingdom Plans in the page script, not the page text / AI pentests from $3,500 per test
More than 140,000 checks across infrastructure, web apps, APIs and cloudEmerging threat scans, launched in 2018, for newly published issuesAttack surface monitoring, container image scanning and secrets detection

Pentest-Tools.com

Bucharest toolbox of 25 online scanners and exploit tools for web, network and cloud testing, priced per asset and month

Romania Network scanning from $95 per month, with web from $140, full suite from $190 (5 assets)
Network, website, API and cloud scanners run from the browserLight versions of several tools free to tryUnlimited scans on your assets and team access on all plans

Outpost24

Karlskrona security group with Outscan NX vulnerability management, external attack surface management and penetration testing as a service

Sweden Quoted per customer, no price on the pages checked
Risk-based vulnerability management for networks, cloud and assetsExternal attack surface management and web application testingContract set out in a published Master Agreement with a DORA appendix

Holm Security

Bromma platform covering network, web, cloud and API scanning plus phishing simulation, hosted in Europe and sold by quote

Sweden Request a quote, free trial offered
System and network, web application, cloud (CSPM) and API scanningPCI ASV-certified scanning and OT and Active Directory checksPhishing simulation and awareness training in the same platform

Aikido Security

Ghent application security platform that scans code, dependencies, containers, cloud and domains, with a free tier for two users

Belgium Free for 2 users / Basic $300 per month / Pro $600 per month (incl. 10 users)
Dependency, secrets, SAST, container and cloud scanning in one toolDAST and domain scanning on the free tier, within limitsFounded in 2022, with offices in Belgium, the United States and the United Kingdom

Cyberwatch

Paris vulnerability and configuration management platform that runs as SaaS, on premises or fully air-gapped

France Not published, demo on request
Vulnerability and configuration management for endpoints and Microsoft 365Deployable as SaaS, on-premise or fully air-gappedMember of Hexatrust, with the Cybersecurity Made in Europe label

Escape

French dynamic scanner built around business-logic testing of web apps and APIs, with external network pentesting and attack surface management

France Not shown in the page text
AI-powered DAST aimed at business-logic flawsContinuous external network pentesting with retestAttack surface discovery across apps, APIs and infrastructure

Edgescan

Dublin continuous testing platform that combines automated scanning with human validation, run by BCC Risk Advisory Limited

Ireland Demo on request, no price on the pages checked
Full-stack scanning from a SaaS platformPenetration testing as a service, mixing automation and human assessmentFounded in 2017, with offices in Dublin and New York

Burp Suite

Knutsford web penetration testing toolkit from PortSwigger with a built-in vulnerability scanner, a free Community Edition and a paid Professional licence

United Kingdom Free Community Edition / Professional $499 (1-year subscription)
Intercepting proxy, scanner and manual tools in one applicationProfessional adds the automated web vulnerability scannerExtensions through the BApp store

HTTPCS

Montpellier web vulnerability scanner from Ziwit SAS with attack surface evaluation and a 14-day free trial

France 14-day free trial, plan prices not in the page text
Dynamic web application scanningExternal attack surface evaluationFrench-first site, with an English version

Key takeaways

  • Greenbone ranks #1 among the European vulnerability scanners in this directory, because it is the only one whose scanning engine, OpenVAS, is open source, free to try and self-hostable, with paid appliances from €2,524 per year from a company registered in Germany.
  • Ten of the twelve are inside the EU: Germany, Sweden (three), Romania, Belgium, France (three) and Ireland. The other two, Intruder and Burp Suite, are British, which is European but outside the EU and the EEA.
  • Only Greenbone is open source. The other eleven are proprietary, and well-known open-source scanners with no company behind them were left out because a buyer has nobody to sign a contract with.
  • Price transparency is thin. Only Detectify, Pentest-Tools.com, Aikido, Burp Suite and Greenbone show amounts in the page text; Holm Security, Outpost24, Cyberwatch, Edgescan and Escape sell by quote or demo, and Intruder shows only its AI pentest price.
  • Scope differs sharply: Greenbone, Outpost24, Holm Security and Cyberwatch scan infrastructure, Detectify, Escape and HTTPCS focus on web applications, Aikido scans code and cloud, and Burp Suite is a manual tester's toolkit.
  • Only Cyberwatch states that it deploys as SaaS, on premises or fully air-gapped, and only Holm Security says its platform is hosted in Europe, so data location is the question to ask every other vendor.

A European vulnerability scanner is software that checks servers, networks, web applications, APIs or cloud accounts for known weaknesses, sold or operated by a company established in Europe, so that the vendor and the map of your weak points sit under European law rather than American. The category is mixed.

It covers an open-source engine, SaaS platforms for infrastructure and web scanning, a code-to-cloud platform, penetration-testing-as-a-service providers and a manual testing toolkit. This directory lists twelve, ten inside the EU and two in the United Kingdom, and says for each where the company sits and what the vendor publishes about price.

European vulnerability scanners compared

European vulnerability scanners compared on position, country, entry price and best use
PositionToolEstablishedEntry priceBest for
#1 Greenbone Germany Free OpenVAS / Community Edition; Greenbone Enterprise entry-level OPENVAS BASIC at €2,524 per year, OPENVAS SCAN on request Teams that want an open-source scanner they can self-host
#2 Detectify Sweden Starter free / Standard from €2,500 / Professional from €5,000 / Enterprise from €15,000 per year (annual platform fee); API scanning and PCI ASV scanning (€500 per year) cost extra Teams that want continuous web and attack-surface scanning with published prices
#3 Intruder United Kingdom Subscription plans billed monthly or annually (amounts are not in the page text); AI-powered web app pentests from $3,500 per test Small and mid-sized teams that want hands-off external and cloud scanning
#4 Pentest-Tools.com Romania From $95 per month (NetSec), $140 per month (WebNetSec) and $190 per month (Pentest Suite) at 5 assets; price varies by asset count and billing cycle; yearly billing pays for 10 months Consultants and small teams that pay per asset, not per seat
#5 Outpost24 Sweden Quoted per customer; no price on the pages checked Larger organisations that want a Swedish vulnerability and exposure management vendor
#6 Holm Security Sweden Request a quote; no amounts on the pricing page Nordic and EU organisations preparing for NIS2 and PCI scanning
#7 Aikido Security Belgium Developer free (2 users) / Basic $300 per month / Pro $600 per month (each including 10 users) / Enterprise on request; prices exclude taxes Developer teams that want code, dependency, container and cloud scanning in one tool
#8 Cyberwatch France Not published Organisations that need vulnerability scanning on premises or air-gapped
#9 Escape France Not shown in the page text API-heavy teams that need business-logic testing, not just known-CVE scanning
#10 Edgescan Ireland Demo on request; no price on the pages checked Buyers who want automated scanning with a human validating the results
#11 Burp Suite United Kingdom Burp Suite Community Edition free / Burp Suite Professional $499 (one-year subscription option on the buy page, per user) / Enterprise on request Penetration testers and developers who test web apps by hand
#12 HTTPCS France 14-day free trial; plan prices are not in the page text French businesses wanting a web scanner and attack surface check from one vendor

Every European vulnerability scanner reviewed

#1 Greenbone

Osnabrück, Germany Free OpenVAS / Community Edition; Greenbone Enterprise entry-level OPENVAS BASIC at €2,524 per year, OPENVAS SCAN on request Free Community Edition (OpenVAS)

Best for: Teams that want an open-source scanner they can self-host

  • Operating company. Greenbone AG
  • Jurisdiction. EU (Germany)
  • Where the data sits. Germany (company, Neumarkt 12, 49074 Osnabrück)
  • Source code. Open source
  • Replaces. Tenable Nessus, Qualys VMDR, Rapid7 InsightVM

Greenbone builds on OpenVAS, the open-source vulnerability scanning engine, and that lineage is the pitch: the engine can be inspected, self-hosted and tried at no licence cost through the free Community Edition, rather than trusted on the vendor's word.

The commercial layer sits on top. Greenbone Enterprise starts with the OPENVAS BASIC appliance at €2,524 per year, with OPENVAS SCAN quoted on request. For a public body or university with a rule against unauditable security software, an open engine with a paid, supported feed is a specific answer few competitors offer.

Greenbone AG is based at Neumarkt 12 in Osnabrück, Germany. The honest limit is that a scanner finds and reports weaknesses but does not block an attack, and running the open edition well needs someone who can interpret and prioritise the output.

What Greenbone does well

  • Open-source scanning engine, inspectable and self-hostable
  • Free Community Edition with no licence cost
  • Published entry price of €2,524 per year
  • German company, EU jurisdiction
  • Covers networks and hosts, the Nessus use case

Where Greenbone falls short

  • Finds weaknesses; does not block attacks
  • Self-hosted use needs in-house expertise
  • Only the entry appliance price is published
  • Less web-application focus than Detectify

Standout feature. An open-source scanning engine you can audit yourself, with a paid feed on top rather than instead of it.

#2 Detectify

Stockholm, Sweden Starter free / Standard from €2,500 / Professional from €5,000 / Enterprise from €15,000 per year (annual platform fee); API scanning and PCI ASV scanning (€500 per year) cost extra Free Starter tier

Best for: Teams that want continuous web and attack-surface scanning with published prices

  • Operating company. Detectify AB, Swedish reg. no. 556985-9084
  • Jurisdiction. EU (Sweden)
  • Where the data sits. Sweden (company, Kornhamnstorg 6, Stockholm); a US office exists in Boston
  • Source code. Closed source
  • Replaces. Invicti, Tenable, Qualys

Detectify combines external attack surface mapping with application scanning, continuously discovering what an organisation exposes to the internet and then testing it. Its payloads come partly from Detectify's own research and partly from Crowdsource, a network of ethical hackers.

Pricing is published rather than quote-only: a free Starter tier, then Standard from €2,500, Professional from €5,000 and Enterprise from €15,000 as an annual platform fee. API scanning (REST and GraphQL) and PCI ASV scanning are extra, the latter at €500 per year, so the headline price is a floor, not a total.

Detectify AB is registered in Sweden with number 556985-9084, with its office at Kornhamnstorg 6 in Stockholm and a second office in Boston. It is a scanner and attack-surface tool, not a WAF, so it finds exposure rather than blocking it.

What Detectify does well

  • Attack surface mapping plus application scanning
  • Payloads sourced from the Crowdsource ethical hacker network
  • Published prices from a free tier to €15,000 per year
  • Swedish company with a registration number on the contact page
  • PCI ASV scanning available

Where Detectify falls short

  • API scanning costs extra
  • A US office exists alongside the Stockholm one
  • Prices are "from" amounts, not totals
  • Focused on web, not network or host scanning

Standout feature. Published pricing from a free tier up to €15,000 a year, rare for enterprise application security.

#3 Intruder

London, United Kingdom Founded 2015 Subscription plans billed monthly or annually (amounts are not in the page text); AI-powered web app pentests from $3,500 per test Free trial offered ("Try free")

Best for: Small and mid-sized teams that want hands-off external and cloud scanning

  • Operating company. Intruder Systems Ltd, registered in England
  • Jurisdiction. United Kingdom (adequacy decision, outside the EEA)
  • Where the data sits. United Kingdom (company, 1 Mark Square, London EC2A 4EG)
  • Source code. Closed source
  • Replaces. Tenable Nessus, Qualys, Rapid7

Intruder is a vulnerability management platform covering external and internal infrastructure, web applications, APIs, cloud accounts and container images. It advertises more than 140,000 checks and, since 2018, emerging threat scans that look for newly published issues across a customer's targets.

The pricing page shows plans billed monthly or annually, but the amounts are not in the page text, so none is quoted here. What is shown is the price of its AI-powered web app pentests: from $3,500 per test. A free trial is offered. The site also lists Nuclei, OpenVAS and Tenable engines in its plan comparison, which tells you it builds on established scanners rather than only its own.

Intruder Systems Ltd is registered in England and based at 1 Mark Square in London, founded in 2015. That puts it under UK law, covered for EU transfers by an adequacy decision but outside the EEA.

What Intruder does well

  • Infrastructure, web, API, cloud and container scanning in one platform
  • Emerging threat scans for newly published issues
  • AI pentest price published
  • Free trial offered
  • Founded in 2015 with a long track record

Where Intruder falls short

  • Subscription amounts not in the page text
  • UK jurisdiction, outside the EEA
  • Builds on third-party scanning engines
  • AI pentests priced separately

Standout feature. One platform for infrastructure, web, cloud and containers, with scans triggered by newly published issues.

#4 Pentest-Tools.com

Bucharest, Romania Founded 2017 From $95 per month (NetSec), $140 per month (WebNetSec) and $190 per month (Pentest Suite) at 5 assets; price varies by asset count and billing cycle; yearly billing pays for 10 months Light versions of several tools free to try

Best for: Consultants and small teams that pay per asset, not per seat

  • Operating company. PENTESTTOOLS S.A., Romanian joint stock company
  • Jurisdiction. EU (Romania)
  • Where the data sits. Romania (company, 48 Iancu de Hunedoara Bvd, Bucharest)
  • Source code. Closed source
  • Replaces. Nessus, Qualys, Invicti

Pentest-Tools.com is a Bucharest platform of 25 online tools: website, API, network and cloud scanners next to reconnaissance and exploit tools. It was founded in 2017, says it has more than 2,100 customers in 119 countries, and lets you try light versions of several tools for free.

Pricing is published per asset: at five assets, NetSec starts at $95 per month, WebNetSec at $140 and Pentest Suite at $190, with the price rising with asset count and yearly billing paying for ten months. Unlimited scans on your own assets and unlimited team members are included on all plans.

The terms name PENTESTTOOLS S.A., a Romanian joint stock company with its registered office on Iancu de Hunedoara Boulevard in Bucharest. The site's structured data uses the older "SRL" form, so check the contract you receive. It is a toolbox for testers more than a risk-ranking platform for a CISO.

What Pentest-Tools.com does well

  • Prices published per asset and month
  • Unlimited team members on all plans
  • Web, network and cloud scanners from the browser
  • Light versions free to try
  • Romanian company, EU jurisdiction

Where Pentest-Tools.com falls short

  • Price rises with asset count
  • Tester-oriented rather than management reporting first
  • Legal form is "S.A." in the terms but "SRL" in structured data
  • Amounts quoted in dollars

Standout feature. Priced per asset with unlimited scans and unlimited users, which suits consultants testing many small clients.

#5 Outpost24

Karlskrona, Sweden Quoted per customer; no price on the pages checked

Best for: Larger organisations that want a Swedish vulnerability and exposure management vendor

  • Operating company. Outpost24 AB, company number 556615-2103
  • Jurisdiction. EU (Sweden)
  • Where the data sits. Sweden (company, Blekingegatan 1, 371 57 Karlskrona); data location not checked
  • Source code. Closed source
  • Replaces. Tenable, Qualys, Rapid7

Outpost24 sells risk-based vulnerability management through Outscan NX, which assesses networks, cloud services and assets and ranks findings with threat intelligence rather than CVSS alone. It also sells external attack surface management and application security testing that combines penetration testing as a service with automated scanning.

Pricing is quoted per customer and no price appeared on the pages checked. Its contract is a published Master Agreement with service-specific terms, a service level agreement, a data processing agreement and a DORA appendix, which suits regulated buyers who need that paperwork up front.

The contracting entity is Outpost24 AB, company number 556615-2103, at Blekingegatan 1 in Karlskrona. The vendor's own site returned an access error to our fetch, so this comes from the Master Agreement as returned by search, not from a page we opened. Product details come from search results, not the vendor's pages.

What Outpost24 does well

  • Vulnerability management, EASM and pentest as a service in one vendor
  • Threat-intelligence-based prioritisation
  • DORA appendix in the published contract set
  • Swedish company, EU jurisdiction

Where Outpost24 falls short

  • No published pricing
  • Vendor site blocked automated checks, so fewer facts verified
  • Aimed at larger buyers
  • Entity details verified indirectly

Standout feature. A contract set with a DORA appendix, built for regulated buyers.

#6 Holm Security

Bromma (Stockholm), Sweden Request a quote; no amounts on the pricing page Free trial offered

Best for: Nordic and EU organisations preparing for NIS2 and PCI scanning

  • Operating company. H.O.L.M. Security Sweden AB, company registration number 5590304217 (with Holm Security Benelux B.V., Amsterdam)
  • Jurisdiction. EU (Sweden)
  • Where the data sits. Sweden (company, Gustavslundsvägen 137, Bromma); the site says the VMP platform is hosted in Europe
  • Source code. Closed source
  • Replaces. Tenable, Qualys, Rapid7

Holm Security is a platform for system and network scanning, web application security, cloud security posture (CSPM), API scanning and phishing simulation, with Active Directory, OT and PCI ASV-certified scanning as features. Its site is built around NIS2, DORA and ISO 27001 compliance.

Pricing is by quote and the pricing page shows no amounts, though a free trial is offered. The site states that the VMP platform is hosted in Europe, which is more than most vendors in this directory say about data location.

The controller is H.O.L.M. Security Sweden AB, company registration number 5590304217, at Gustavslundsvägen 137 in Bromma, Stockholm, with Holm Security Benelux B.V. in Amsterdam as a joint controller in the same group. The honest limit: breadth across scanning, phishing and training means each module is a part of a larger suite, not a specialist.

What Holm Security does well

  • Network, web, cloud, API and OT scanning in one platform
  • PCI ASV-certified scanning
  • States the platform is hosted in Europe
  • Free trial offered
  • Swedish company with a Dutch subsidiary

Where Holm Security falls short

  • No published pricing
  • Suite breadth may exceed what a small team needs
  • Joint controller across two countries
  • Compliance-led marketing

Standout feature. One of the few vendors here that states its scanning platform is hosted in Europe.

#7 Aikido Security

Ghent, Belgium Founded 2022 Developer free (2 users) / Basic $300 per month / Pro $600 per month (each including 10 users) / Enterprise on request; prices exclude taxes Free plan, no credit card

Best for: Developer teams that want code, dependency, container and cloud scanning in one tool

  • Operating company. Aikido Security BV, BE0792914919
  • Jurisdiction. EU (Belgium)
  • Where the data sits. Belgium (company, Coupure Rechts 88, Ghent per the privacy policy); offices also in the United States and the United Kingdom
  • Source code. Closed source
  • Replaces. Snyk, Qualys, Tenable

Aikido Security is a Ghent application security platform founded in 2022. It scans dependencies, secrets, source code (SAST), containers, cloud configuration and infrastructure as code, with DAST and domain scanning included. The free Developer plan covers two users within fair-usage limits.

Prices are published in dollars and exclude taxes: Basic at $300 per month and Pro at $600 per month, each including ten users, with Enterprise on request. That is among the clearest pricing in this directory, and the cheapest route into a managed scanner.

The contracting entity is Aikido Security BV, BE0792914919, headquartered at Coupure Rechts 88 in Ghent according to its privacy policy, while the site footer also lists offices in the United States and the United Kingdom. It scans code and cloud far more than it scans internal networks, so it complements rather than replaces a Nessus-style scanner.

What Aikido Security does well

  • Code, dependency, container, cloud and domain scanning in one tool
  • Free plan for two users
  • Published monthly prices
  • Belgian company with a stated VAT number
  • Priced for small developer teams

Where Aikido Security falls short

  • Not a network or host scanner
  • Prices in dollars
  • Offices in the US and UK as well
  • Free tier limited to 10 repositories

Standout feature. The only scanner here with a free plan that covers code, containers and cloud together.

#8 Cyberwatch

Paris, France Not published

Best for: Organisations that need vulnerability scanning on premises or air-gapped

  • Operating company. CYBERWATCH SAS, RCS Paris 809 514 318
  • Jurisdiction. EU (France)
  • Where the data sits. France (company, 10 rue Penthièvre, 75008 Paris); the platform runs as SaaS, on premises or fully air-gapped; the marketing site is hosted by Webflow in the United States
  • Independent checks. Hexatrust member, Cybersecurity Made in Europe label (as stated by the vendor)
  • Source code. Closed source
  • Replaces. Tenable Nessus, Qualys, Rapid7

Cyberwatch is a Paris platform for vulnerability management and configuration management of endpoints, with Microsoft 365 and Entra ID coverage. Its distinguishing claim is deployment: SaaS, on premises, or fully air-gapped, so the findings can stay inside your own infrastructure.

The vendor states it is a member of Hexatrust and holds the Cybersecurity Made in Europe label. Pricing is not published on the pages checked, so a demo is the way to a quote.

The publisher is CYBERWATCH, a simplified joint-stock company registered at the Paris trade register under number 809 514 318, at 10 rue Penthièvre, 75008 Paris. One detail worth knowing: its legal notice says the marketing website is hosted by Webflow Inc. in San Francisco. That concerns the website, not the scanner, but it is stated on the page.

What Cyberwatch does well

  • SaaS, on-premise and air-gapped deployment
  • Vulnerability and configuration management together
  • French company with a register number stated
  • Cybersecurity Made in Europe label, as stated by the vendor

Where Cyberwatch falls short

  • No published pricing
  • Marketing site hosted by a US provider
  • Endpoint-focused more than web-application-focused
  • Smaller than the American suites

Standout feature. It will run fully air-gapped, which keeps scan data entirely inside your own walls.

#9 Escape

France Founded 2020 Not shown in the page text

Best for: API-heavy teams that need business-logic testing, not just known-CVE scanning

  • Operating company. Escape Technologies SAS
  • Jurisdiction. EU (France)
  • Where the data sits. France (company, per the privacy policy; the street address there is incomplete)
  • Source code. Closed source
  • Replaces. Invicti, Rapid7 InsightAppSec

Escape is a French dynamic scanner that positions itself against legacy scanners. Its in-house AI-powered DAST targets business-logic flaws in web applications and APIs, and it adds continuous external network pentesting with a retest and attack surface management across apps, APIs and infrastructure.

Escape says it was founded in 2020. A pricing page exists but shows no amounts in the page text, so none is quoted here, and the site pushes visitors to book a demo. That makes a cost comparison impossible without a sales call.

The privacy policy names Escape Technologies SAS as the company and data controller; the street address printed there is incomplete, so only the country, France, is stated here. It is a specialist for modern application stacks and will not map an old internal network.

What Escape does well

  • Business-logic-aware dynamic testing
  • API-first scanning
  • External pentesting with retest
  • French company, EU jurisdiction

Where Escape falls short

  • No amounts in the page text
  • Address in the privacy policy is incomplete
  • Not an internal network scanner
  • Demo-led sales process

Standout feature. It targets the business-logic flaws that signature-based scanners cannot see.

#10 Edgescan

Dublin, Ireland Founded 2017 Demo on request; no price on the pages checked

Best for: Buyers who want automated scanning with a human validating the results

  • Operating company. BCC Risk Advisory Limited, trading as Edgescan, company registration number 497804
  • Jurisdiction. EU (Ireland)
  • Where the data sits. Ireland (company, Unit 701 Northwest Business Park, Ballycoolin, Dublin 15); also an office in New York
  • Source code. Closed source
  • Replaces. Qualys, Rapid7, Tenable

Edgescan is a Dublin platform for continuous security testing and exposure management, delivered as SaaS. It offers full-stack scanning and penetration testing as a service, a hybrid of automated breadth and human assessment, plus PCI-approved scanning.

Edgescan was founded in 2017 by Eoin Keary and has offices in Dublin and New York. No prices appeared on the pages checked, and a demo is requested.

The site is owned and operated by BCC Risk Advisory Limited, company registration number 497804, trading as Edgescan, with its registered office at Unit 701, Northwest Business Park, Ballycoolin, Dublin 15, Ireland. That makes it one of the few Irish vendors in the category and puts it under EU law. The human validation means more false-positive filtering but also slower turnaround than a pure scanner.

What Edgescan does well

  • Automated scanning with human validation
  • Irish company, EU jurisdiction
  • Registration number stated in the privacy policy
  • PCI-approved scanning

Where Edgescan falls short

  • No published pricing
  • New York office alongside Dublin
  • Human validation costs more than pure scanning
  • Demo-led sales

Standout feature. A human checks the findings, which cuts the false positives a pure scanner leaves you with.

#11 Burp Suite

Knutsford, United Kingdom Burp Suite Community Edition free / Burp Suite Professional $499 (one-year subscription option on the buy page, per user) / Enterprise on request Free Community Edition and a free trial of Professional

Best for: Penetration testers and developers who test web apps by hand

  • Operating company. PortSwigger Ltd
  • Jurisdiction. United Kingdom (adequacy decision, outside the EEA)
  • Where the data sits. United Kingdom (company, 6 Booths Park, Chelford Road, Knutsford, WA16 8ZS)
  • Source code. Closed source
  • Replaces. Invicti Netsparker, Acunetix, Rapid7 InsightAppSec

Burp Suite from PortSwigger is the manual web penetration tester's toolkit: an intercepting proxy, repeater and intruder tools, and a web vulnerability scanner in the paid Professional edition. The free Community Edition gives the manual tools, with no scanner.

Burp Suite Professional is listed at $499 on the product page, with a one-year subscription option on the buy page, per user. Enterprise editions are separate. Extensions come through the BApp store.

The legal entity is PortSwigger Ltd, 6 Booths Park, Chelford Road, Knutsford, WA16 8ZS, United Kingdom, under UK law with an adequacy decision for EU transfers but outside the EEA. It is a tool for a person who tests, not a platform that continuously monitors an estate, so it complements a scanner here rather than replacing one.

What Burp Suite does well

  • The standard manual web testing toolkit
  • Free Community Edition
  • Price published at $499
  • Extensible through the BApp store

Where Burp Suite falls short

  • Manual tool, not continuous monitoring
  • Scanner only in the paid edition
  • UK jurisdiction, outside the EEA
  • Priced per user

Standout feature. The tool human testers actually work in, with a free edition to learn on.

#12 HTTPCS

Montpellier, France 14-day free trial; plan prices are not in the page text 14-day free trial

Best for: French businesses wanting a web scanner and attack surface check from one vendor

  • Operating company. Ziwit SAS, RCS Montpellier B 525 202 917
  • Jurisdiction. EU (France)
  • Where the data sits. France (company, 30 Rue Isabelle Eberhardt, Montpellier)
  • Source code. Closed source
  • Replaces. Invicti, Qualys, Acunetix

HTTPCS is Ziwit's web vulnerability scanner, with dynamic application scanning and external attack surface evaluation. The site offers a 14-day free trial, and a "check in a few clicks if your site is vulnerable" entry point.

Plan prices are not in the page text we read, so none is quoted; the trial is how you see the real figure before committing. The site and support are French-first, with an English version, which is fine for a French buyer and a small friction for others.

HTTPCS is the exclusive property of Ziwit, a SAS with share capital of €1,140,000, registered at the Montpellier trade register under B 525 202 917, with its head office at 30 Rue Isabelle Eberhardt. It is smaller and less internationally known than Detectify or Greenbone.

What HTTPCS does well

  • Web scanner and attack surface evaluation
  • 14-day free trial
  • French company with register number and capital stated
  • English version of the site

Where HTTPCS falls short

  • Plan prices not in the page text
  • French-first site and support
  • No independent certification checked
  • Smaller than Detectify or Greenbone

Standout feature. A French web scanner you can try for 14 days before talking to anyone.

What does "European vulnerability scanner" actually mean?

It means the company that sells or operates the scanner is established in Europe, checked in its own terms, privacy policy or imprint. That is narrower than "built by Europeans" and broader than "scan data stays in Europe". The legal entity tells you who you contract with, and which court a dispute goes to.

It matters more for scanners than for most software. A scan produces a list of every exposed host, outdated component and exploitable flaw in your estate, which is exactly the document an attacker would want. Handing it to a vendor under foreign law is a risk worth weighing.

The honest summary is that Europe has a good spread of focused scanners and a few full platforms, but none matches the largest American suites in every respect. The ranking reflects fit and transparency, not a claim that any of them equals Nessus or Qualys in every case.

Which one replaces Nessus, which replaces Qualys, and which replaces Invicti?

For Nessus, Greenbone is the match: an open-source engine for network and host scanning with a paid, supported feed. Holm Security, Outpost24, Cyberwatch and Intruder cover the same ground as managed platforms.

For Qualys and Rapid7, the platform vendors are the match. Outpost24, Holm Security and Cyberwatch sell risk-based vulnerability management across networks, cloud and endpoints, and Edgescan adds human validation on top of automated scanning.

For Invicti and Acunetix, look at web application scanners. Detectify, Escape and HTTPCS scan web apps and APIs, Pentest-Tools.com offers website and API scanners from the browser, and Burp Suite Professional is the manual tester's tool with a scanner built in.

What is the difference between a scanner and a penetration test?

A scanner automatically compares what it finds against a database of known weaknesses and misconfigurations and reports them. It is fast and repeatable, and it produces false positives that someone must triage.

A penetration test adds a human who tries to chain weaknesses into a real break-in. Several vendors here sell both: Edgescan mixes automation with human assessment, Intruder offers AI-powered pentests from $3,500 per test, Outpost24 lists penetration testing as a service, and Pentest-Tools.com offers AI pentests next to its scanners. Burp Suite is the tool human testers work in.

Run scans continuously and tests periodically. A scanner will not find a business-logic flaw, which is why Escape builds its scanner around exactly that.

Where does my scan data go?

A scan stores your asset list, findings and sometimes proof of exploitation. Where it is stored depends on the vendor, and most say little on their public pages. Holm Security states that its platform is hosted in Europe. Cyberwatch can run on premises or air-gapped, which keeps the data entirely with you. Greenbone can be self-hosted.

Several vendors also operate outside Europe. Detectify and Aikido list offices in the United States, Edgescan lists one in New York, and Cyberwatch's marketing site is hosted by Webflow in the United States, although that site is not the scanner.

Ask for the sub-processor list and the storage region before you scan production systems, and prefer self-hosted or on-premise deployment where the data is sensitive.

Where do scanner choices go wrong?

The first failure is buying by feature count instead of by scope. A web application scanner will not map your network, and a network scanner will not find a broken access control in an API. Decide what you need to cover first.

The second is assuming a free tier is enough. Greenbone Community Edition, Detectify Starter, the Aikido free plan and Burp Community all limit scope, users or automation, and the limits differ.

The third is assuming European means EU. Intruder and Burp Suite are British, covered for EU transfers by an adequacy decision but outside the EEA.

The fourth is ignoring the owner. Probely, a Portuguese scanner, was acquired by Snyk in 2024, so a product built in Europe can sit under an American parent.

How we selected and ranked these 12 tools

Every tool on this page is in the European Purpose directory, which means the operating company is established in Europe and we have verified that from the company register or the vendor's own legal notice rather than from a marketing page. Tools headquartered outside Europe are not eligible, however good they are.

  1. Feature verification (weight: 40%). We check each capability against the vendor's own documentation and product pages, and record what the tool does rather than what the category is assumed to include.
  2. Ease of adoption (weight: 30%). Integrations, published API access, trial availability and how much configuration stands between signing and a usable result.
  3. Value and transparency (weight: 30%). Published pricing counts in a vendor's favour; quote-only pricing is recorded as quote-only rather than estimated. We weigh what a buyer gets for the entry price, not the headline feature count.
  4. Editorial review. Three people touch every page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's documentation. The three weights above decide the order; a position is a ranking against the other European tools in this category, not an absolute score.

Vendor-reported outcomes — ROI figures, margin uplift, time saved — are labelled as vendor claims wherever they appear on this page. We have not audited them, and neither has anyone else who quotes them. Read our full editorial process for how pages are re-verified.

Frequently asked questions

Greenbone holds #1 among the European vulnerability scanners in this directory, because its OpenVAS engine is open source, a free Community Edition exists and paid appliances start at €2,524 per year. The right answer depends on scope: Detectify for web applications and attack surface, Cyberwatch for on-premise or air-gapped infrastructure, Aikido for code-to-cloud scanning.

Yes. Greenbone (Germany) is the closest, with an open-source scanning engine and a paid feed. Holm Security, Outpost24 (both Sweden), Cyberwatch (France) and Intruder (United Kingdom) offer managed alternatives.

Outpost24, Holm Security and Cyberwatch sell risk-based vulnerability management across networks, cloud and endpoints. Cyberwatch can also run on premises or air-gapped.

For web applications, Detectify (Sweden), Escape and HTTPCS (France) and Pentest-Tools.com (Romania). Burp Suite (United Kingdom) is the manual tester's toolkit with a paid scanner. Acunetix belongs to an American group and is not listed.

Greenbone has a free Community Edition, Detectify a free Starter tier, Aikido a free plan for two users and Burp Suite a free Community Edition. HTTPCS and Holm Security offer trials, and Pentest-Tools.com offers light versions of some tools.

Greenbone is, through its OpenVAS engine, which can be self-hosted. The other eleven are proprietary.

Ten: Greenbone (Germany), Detectify, Outpost24 and Holm Security (Sweden), Pentest-Tools.com (Romania), Aikido (Belgium), Cyberwatch, Escape and HTTPCS (France), and Edgescan (Ireland). Intruder and Burp Suite are in the United Kingdom.

No. Only Holm Security says its platform is hosted in Europe on the pages checked, and Cyberwatch and Greenbone can run on your own infrastructure. For the rest, ask for the storage region and sub-processors.

Detectify (from €2,500, €5,000 and €15,000 per year), Pentest-Tools.com (from $95, $140 and $190 per month), Aikido ($300 and $600 per month), Burp Suite Professional ($499) and Greenbone (from €2,524 per year). The rest quote on request.