Vulnerability scanning tools and services
Download this document free
Get this document with your free trial. Choose from the full Complyzard library.
Try 1 month free30 days free, then $19/month. Trial terms apply. Card required. Cancel anytime.Document information
Advice on the choice, implementation and use of automated vulnerability scanning tools for organisations of all sizes.
Adapted edition
- Document type
- Reference Guide
- Format
- DOCX
- Pages
- 9
- Language
- English
- Version
- 1.0
- Updated
- 2026-09-16
- Category
- Information security
- Licence
- Open Government Licence v3.0
Description
Advice on the choice, implementation and use of automated vulnerability scanning tools for organisations of all sizes for organisational planning, review and training. NCSC guidance is advisory and should be applied to the organisation's own risks and obligations.
Contents
- Introduction
- Audience and structure
- Advantages of vulnerability scanning
- Relationship to manual testing
- 1. Evaluate your existing vulnerability management programme
- Supporting your VMP
- What features do you need?
- 2. Identify your assets
- 3. Choose an appropriate type of vulnerability scanner
- Infrastructure scanners
- Web application scanners
- Native software scanners
- Comparing infrastructure and web application scanners
- 4. Choose a deployment model
- On-premises solutions
- Vendor hosted solutions
- Source links
Source and licence
National Cyber Security Centre
AttributionNational Cyber Security Centre, “Vulnerability scanning tools and services” (19 January 2021), reused under the Open Government Licence v3.0.
ChangesAdapted 16 September 2026: converted the official HTML article into neutral text-only DOCX and PDF editions. Preserved article headings, paragraphs, lists and plain-text source-link destinations; normalized web whitespace and typographic punctuation; omitted site navigation, topic and download cards, images, logos, scripts, styles and page furniture.
Version history
- v1.016/09/2026