Greenbone

Osnabrück's open-source OpenVAS vulnerability scanner, with enterprise appliances on top

Quick Overview

Company Greenbone AG
Category Web Security
Headquarters Osnabrück, Germany
Founded 2008
EU Presence EU (Germany)
Data Location Germany
Open Source Yes
Compliance ISO 9001, ISO 27001
Pricing Free OpenVAS / Community Edition; Greenbone Enterprise appliances from OPENVAS BASIC at €2,524 per year
Free Option Free Community Edition (OpenVAS)
Replaces Tenable Nessus, Qualys VMDR, Rapid7 InsightVM

Detailed Review

Greenbone builds on OpenVAS, the vulnerability scanning engine it has maintained as open source since the company's founding in 2008, and that lineage is the whole pitch: the scanning engine and its vulnerability tests can be inspected, self-hosted and run at no licence cost, rather than trusted on the vendor's word. OpenVAS Free and the Community Edition let anyone try the same core engine that the paid appliances run.

The commercial layer sits on top rather than replacing the open core: Greenbone Enterprise appliances add a maintained vulnerability feed, support and management tooling, starting with OPENVAS BASIC at €2,524 a year as the entry point into that feed. For a public body or university with a procurement rule against unauditable security software, that combination of an open engine and a paid, supported feed is a specific answer few competitors offer.

Greenbone AG is based in Osnabrück, Germany, and holds ISO 9001 and ISO 27001 certification of its own management systems; it converted into a stock company (AG) in 2023. The honest limit: OpenVAS finds and reports vulnerabilities, it does not block an attack in progress, and running the open-source edition well still requires someone with real vulnerability-management expertise to interpret and prioritise the output.

What Greenbone does well

  • Open-source scanning engine (OpenVAS/GVM), inspectable by anyone
  • Free Community Edition with no licence cost
  • Enterprise appliances with maintained feed from €2,524/year
  • ISO 9001 and ISO 27001 certified
  • German company, EU jurisdiction

Where Greenbone falls short

  • Finds vulnerabilities; does not block attacks itself
  • Self-hosted use requires real in-house expertise
  • Enterprise appliance pricing is on top of the free core
  • Less polished interface than SaaS-first competitors

Standout feature. An open-source scanning engine you can audit yourself, with a paid feed on top rather than instead of it.

Pros and Cons

Pros

  • Open-source scanning engine (OpenVAS/GVM), inspectable by anyone
  • Free Community Edition with no licence cost
  • Enterprise appliances with maintained feed from €2,524/year
  • ISO 9001 and ISO 27001 certified
  • German company, EU jurisdiction

Cons

  • Finds vulnerabilities; does not block attacks itself
  • Self-hosted use requires real in-house expertise
  • Enterprise appliance pricing is on top of the free core
  • Less polished interface than SaaS-first competitors

Alternatives to Greenbone

See all web security →

Frequently Asked Questions

What is Greenbone?

Greenbone builds on OpenVAS, the vulnerability scanning engine it has maintained as open source since the company's founding in 2008, and that lineage is the whole pitch: the scanning engine and its vulnerability tests can be inspected, self-hosted and run at no licence cost, rather than trusted on the vendor's word. OpenVAS Free and the Community Edition let anyone try the same core engine that the paid appliances run.

Where is Greenbone based?

Greenbone operates from Osnabrück, Germany, which places it under EU (Germany). Compliance: ISO 9001, ISO 27001.

What does Greenbone cost?

Free OpenVAS / Community Edition; Greenbone Enterprise appliances from OPENVAS BASIC at €2,524 per year. Free Community Edition (OpenVAS).

Who is Greenbone best for?

Organisations that want an open-source vulnerability scanner they can run themselves. An open-source scanning engine you can audit yourself, with a paid feed on top rather than instead of it.

What are the drawbacks of Greenbone?

Finds vulnerabilities; does not block attacks itself. Self-hosted use requires real in-house expertise. Enterprise appliance pricing is on top of the free core. Less polished interface than SaaS-first competitors.

Is Greenbone a good alternative to Tenable Nessus?

Greenbone is built as a European alternative to Tenable Nessus: Osnabrück's open-source OpenVAS vulnerability scanner, with enterprise appliances on top. It will not be a like-for-like feature match in every respect, so check the review above for where the two genuinely differ before switching.

How does Greenbone compare to other Web Security tools?

Greenbone is one of several European Web Security tools we cover. It is most often compared with Tenable Nessus, Qualys VMDR, Rapid7 InsightVM.

About the author

One person researches and writes every tool page on European Purpose and checks the compliance and pricing claims against the vendor's own documentation.

Sebastiaan Smits

Sebastiaan Smits

Founder · Amsterdam, Netherlands

Founder of European Purpose. Researches and writes the reviews and checks where each company is actually established.

Read our editorial process for how we source, verify and update these pages, and how paid placement works.

Go to Greenbone