We are using Nessus Pro. Our operational security team is using it at the moment. It is being used in a couple of ways. In one instance, it is being used purely to scan the internal infrastructure. In the second instance, we're using it to scan the entire network range, including all endpoints. In the third instance, we're using it to do PCI DSS compliance scanning.
Information Security Manager at a transportation company with 1,001-5,000 employees
Comes at a great price, does exactly what you expect it to do, and never lets you down from a stability point of view
Pros and Cons
- "It does exactly what you expect it to do, and its pricing is great. We couldn't really ask for a better deal."
- "My advice to people who are looking into implementing this product would be to just go ahead and do it."
- "The interface is a little bit clunky, and the reporting is not marvelous. There should be better integration of reporting between instances. Currently, the instance stands alone, and it produces a report. Being able to amalgamate those reports with another instance will be useful."
- "The interface is a little bit clunky, and the reporting is not marvelous."
What is our primary use case?
What is most valuable?
It does exactly what you expect it to do, and its pricing is great. We couldn't really ask for a better deal.
What needs improvement?
The interface is a little bit clunky, and the reporting is not marvelous. There should be better integration of reporting between instances. Currently, the instance stands alone, and it produces a report. Being able to amalgamate those reports with another instance will be useful.
What do I think about the stability of the solution?
It has never let us down from a stability point of view.
Buyer's Guide
Tenable Nessus
July 2026
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,800 professionals have used our research since 2012.
What do I think about the scalability of the solution?
It is really scalable. It is great.
We have six people who are actually interacting with the tool itself, but obviously, it has been deployed against thousands of endpoints. There are three different roles of those six users.
How are customer service and support?
They are very good. Their formal support and the wider community support are excellent.
Which solution did I use previously and why did I switch?
We've used Rapid7 in the past. We switched because of the value for money and the fact that it feeds into the Tenable.io platform, which is where we ultimately want to be.
How was the initial setup?
It was straightforward and fast. It literally took a morning.
What about the implementation team?
It was done in-house. For its deployment and maintenance, there is just one person. He is an information security analyst.
What's my experience with pricing, setup cost, and licensing?
Its pricing is great and can't be improved. It is very cheap. It is less than 2,000 pounds a license, and you can't really ask for more.
It has unlimited IPs and unlimited scans. There are no particular pricing constraints. The only additional cost is the inherent cost of the people to actually review the actual scans.
What other advice do I have?
My advice to people who are looking into implementing this product would be to just go ahead and do it. Don't be frightened about it. It is great. It does exactly what you'd expect it to do. You can use it as a stepping stone to the other Tenable products.
I would rate it a nine out of 10. It is a lovely product. It just does what you need it to do, and lets you get on with your day.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Manager at a retailer with 10,001+ employees
Tests against cloud providers, database profiles, several types of telecom devices, and other highly customizable scans
Pros and Cons
- "Scanners and reports using CIS templates ("de-facto" standard, easy to fix and to locate correction tips at documentation), tests against cloud providers, database profiles, several types of telecom devices, and others highly customizable scans."
- "Nessus has more plugins/add-ons, tests, and templates than previous tools and it is faster and customizable using CLI/API features, offering enough resources for an interesting cost-benefit rating and fewer false-positive events per type of asset while helping us quickly produce a QuickWin report that guided vulnerability management actions and plans for the next three to five years using the same tool, investment, and team for all companies in the group."
- "Model OS costs (and its segregation schema for individual modules)."
- "Offer a more flexible strategic and high-level dashboards based on previous comments (minus technical and more business-oriented)."
What is our primary use case?
Over 15.000 active assets|inside 10 companies belonging to the group, the biennium recurrent project mapped the real situation, in parallel with photography of IT/Security maturity through three main domains: processes, people, and technology. 5 TOEs: Infrastructure, Databases (SQL and Oracle in deep), AWS Cloud, Connectivity (Routers, Switches, and Firewalls against/based CIS) and Web Application instances (partial tests). Nessus running over a hardened Linux customized with HA (High Availability).
How has it helped my organization?
Nessus has more plugins/add-ons, tests, and templates than previous tools (OpenVas) and it is faster and customizable using CLI/API features. It offers enough resources for an interesting cost-benefit rating (for small and medium companies) and minus false-positive events per type of asset.
It helped us to quickly produce a QuickWin report that guided the VulnerabilityMgmt actions and plans within the company's during the next 3-5 years using the same tool/investment/team for all companies inside the de group.
What is most valuable?
Scanners and reports using CIS templates ("de-facto" standard, easy to fix and to locate correction tips in the documentation), tests against cloud providers, database profiles, several types of telecom devices, and other highly customizable scans. You can scale your environment to gradually increase the quality, depth, and quantity of the tests, enabling you to learn and gradually optimize your vulnerability management platform(s)/instance(s). The possibility of integration with other market tools (Kenna, Archer...) is another differential.
What needs improvement?
- Add the possibility to customize attributes that define the assets critical level based on the company's "business sense".
- Improve integration and tests for OT platforms, OT application, OT hardware, and non-Ethernet protocols.
- Improve the exchange of info/insights/attributes with RM (Risk Management) domain.
- Offer a more flexible strategic and high-level dashboards based on previous comments (minus technical and more business-oriented)
- Model OS costs (and its segregation schema for individual modules).
For how long have I used the solution?
7+ years with Tenable and more than 15y with others.
What do I think about the stability of the solution?
Excellent. No one problem during operation time and deployment.
What do I think about the scalability of the solution?
Enough (faster than OpenVAS engine).
How are customer service and support?
It SLA/support are enough.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
OpenVAS. We reached the previous level/threshold/maturity using OpenVas (more limited tool when compared with Nessus). I/We believe that, the change to a better tool (in this and in others categories) should be carried out when these indicators are reached.
How was the initial setup?
Very simple and fast.
What about the implementation team?
In-house.
What was our ROI?
Good. Nessus Pro combined with other xLAP solutions to offer a presentation/grouping layer is great. Using SC this curve/point of ROI is slower.
What's my experience with pricing, setup cost, and licensing?
Start small, learn about your problems/fixing time and grow up gradually.
Which other solutions did I evaluate?
Several. OpenVas, Rapid7, Qualys, CORE* and Retina.
What other advice do I have?
A cost/benefit interesting tool.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Tenable Nessus
July 2026
Learn what your peers think about Tenable Nessus. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,800 professionals have used our research since 2012.
Chief information security officer at a financial services firm with 201-500 employees
Anyone can deploy it, even the managers, the technical teams, and the engineers
Pros and Cons
- "With the Tenable Nessus enterprise edition, you have unlimited licenses to scan the device."
- "Tenable Nessus is good. It's the best vulnerability solution in the industry."
- "In terms of what could be improved, I would say that the reporting feature needs to be improved."
What is our primary use case?
We are using it to find out the vulnerabilities in our critical servers and to patch them.
We are using the latest version.
What is most valuable?
Tenable Nessus is good. It's the best vulnerability solution in the industry. Most organizations are using it.
What needs improvement?
In terms of what could be improved, I would say that the reporting feature needs to be improved.
Additionally, although it has the features, the enterprise edition is very limited. They need to add multiple reporting features in the enterprise edition.
For how long have I used the solution?
I have been using Tenable Nessus for the last two years.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
Tenable Nessus is a vulnerability product. We have two to three users who are running it, but in terms of the end devices, because it's intended for vulnerabilities scanning and you have to scan your end devices, we have around hundred devices who are scanning with it.
It is a scalable solution.
How are customer service and support?
We contacted support for some scenarios, like upgrades, new security patches, and for some customized reports.
We were satisfied with the speed of the answers. It is good support.
How was the initial setup?
The initial setup is very easy.
Anyone can deploy it, even the managers, the technical teams, the engineers.
I think it took five minutes.
What about the implementation team?
We installed with the help of a consultant. You can do it one time and then you will learn it very easily.
What's my experience with pricing, setup cost, and licensing?
We have an annual subscription.
Which other solutions did I evaluate?
We also evaluated the Rapid7 Nexpose product, but it has a limitation that it supports 128 users then you have to buy another 128, but with the Tenable Nessus enterprise edition, you have unlimited licenses to scan the device.
What other advice do I have?
I would recommend Tenable Nessus.
On a scale of one to ten, I would rate it an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Partner
Overall great solution, plenty of features, and free options
Pros and Cons
- "Overall Zoom is a good solution."
- "I have found it is sometimes difficult to control the Zoom meeting sessions. For example, it is difficult to know who is talking and when trying to mute everyone but the speaker you end up muting everyone. When using multiple screens it is laborious to find the control buttons, such as to start a session. Additionally, when a recording is done I have found it difficult to find them, there should be an easier way to retrieve them."
What is our primary use case?
I use Zoom for virtual meetings.
What is most valuable?
Overall Zoom is a good solution.
What needs improvement?
I have found it is sometimes difficult to control the Zoom meeting sessions. For example, it is difficult to know who is talking and when trying to mute everyone but the speaker you end up muting everyone. When using multiple screens it is laborious to find the control buttons, such as to start a session. Additionally, when a recording is done I have found it difficult to find them, there should be an easier way to retrieve them.
In a future release, the recordings should be able to be enhanced. I am not fully sure if it is the speed of the network or what the challenge is but we record our Zoom meetings and then I edit them to make them into a presentation. There are times when people are grainy, or their sound is not the best. Zoom should have an optimization option for those wanting to do recordings to allow them to receive the best experience. Alternatively, they could give tips on the best configuration settings for the highest recording output quality. For example, Is the user using the most current version of Zoom, or have they blocked out the background noise.
For how long have I used the solution?
I have been using Zoom for approximately 10 years.
Which solution did I use previously and why did I switch?
I have used Teams, ON24, and Citrix.
What's my experience with pricing, setup cost, and licensing?
The solution has free options.
What other advice do I have?
Zoom is a great solution. I did appreciate during the pandemic they offered it for free for a certain amount of callers. I thought that gesture was really great.
I rate Zoom a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Delivery Manager at alascom
Useful report, responsive technical support, and installation straightforward
Pros and Cons
- "I have found the vulnerability assessment and the reports to be useful."
- "The solution could improve by having better integration with different vendors' IPS solutions. The ACLs and IPS policies signatures should be enabled based on the results of Tenable Nessus automatically, we currently have to do it manually which is very time-consuming. It has done a good job integrating with Fortinet but we would like it to be better integrated with other solutions that we have."
What is our primary use case?
We use Tenable Nessus for vulnerability assessments.
What is most valuable?
I have found the vulnerability assessment and the reports to be useful.
What needs improvement?
The solution could improve by having better integration with different vendors' IPS solutions. The ACLs and IPS policies signatures should be enabled based on the results of Tenable Nessus automatically, we currently have to do it manually which is very time-consuming. It has done a good job integrating with Fortinet but we would like it to be better integrated with other solutions that we have. Additionally, After Tenable Nessus was able to recognize the vulnerability it would be great to have it virtually batch the systems if you are not able to update the different systems.
For how long have I used the solution?
I have been using Tenable Nessus within the last 12 months.
What do I think about the stability of the solution?
While doing the scans we have not had any issues, the solution is stable.
What do I think about the scalability of the solution?
Tenable Nessus is scalable.
How are customer service and technical support?
The technical support was responsive and helpful. We were trying different integrations and needed some assistance.
Which solution did I use previously and why did I switch?
How was the initial setup?
The initial setup is very easy and straightforward. The VM can be done very quickly and the whole process takes approximately 30 minutes. The installation is quicker than others solutions, such as Qualys.
What's my experience with pricing, setup cost, and licensing?
The price of the solution is reasonable.
What other advice do I have?
I rate Tenable Nessus an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Cyber Security Expert at a security firm with 11-50 employees
Easy to install, reliable, helpful support, and has a good assessment tool
Pros and Cons
- "Tenable Nessus is one of the best vulnerability assessment tools, that I know."
- "They need more flexible pricing."
- "In general, it is extremely expensive. If they have a higher price, that's fine, but if there were one or two solutions where you can buy something for a cheaper price then that would make sense for many users."
What is our primary use case?
We use this solution for information gathering and as an assessment tool.
What is most valuable?
Tenable Nessus is one of the best vulnerability assessment tools, that I know.
What needs improvement?
The price could be improved. They need more flexible pricing.
If they had a very creative idea, maybe they could add a special feature. Even extending functions, or exploring new areas. If they were able to integrate it with the existing solution, that would be fine.
I would like to see more integrations, more ideas or services, and functions offered.
It's about wider functionality and not a question of integration. It's more a question of, creativity. If they have other ideas such as what could be added to the vulnerability management.
For how long have I used the solution?
I have been using Tenable Nessus for five years.
What do I think about the stability of the solution?
Tenable Nessus is a stable product.
What do I think about the scalability of the solution?
It's a scalable solution.
Nessus we either use Nessus for projects for ourselves in many situations, and they also deliver Nessus as a solution for at least five clients. We also have approximately 10 users in our organization.
How are customer service and technical support?
My experience with technical support is very positive.
How was the initial setup?
The installation was easy.
It took approximately six hours to install and deploy.
We need two for the deployment and maintenance, we have two or three people.
What's my experience with pricing, setup cost, and licensing?
In general, it is extremely expensive. If they have a higher price, that's fine, but if there were one or two solutions where you can buy something for a cheaper price then that would make sense for many users.
I understand why it's expensive, but it would be good to have a limited solution with cheaper prices.
There are different solutions for purchasing Nessus, which is not possible with Datadog.
What other advice do I have?
I would recommend this solution to others.
I would rate Tenable Nessus a nine out of ten because it has many dimensions.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Cybersecurity Manager at a manufacturing company with 10,001+ employees
Excellent at identifying vulnerabilities and accessing information related to that
Pros and Cons
- "Ease of reviewing scores, identifying vulnerabilities, and getting information on them."
- "The valuable feature for me is being able to ping the computers to do the automated scan and to come back and be able to see everything."
- "We find that some devices aren't pinged and the scans aren't done properly."
What is most valuable?
The valuable feature for me is being able to ping the computers to do the automated scan and to come back and be able to see everything. That's definitely a huge plus, but then there's also the ease of reviewing the scores, identifying vulnerabilities, and getting the information on the vulnerabilities; the ability to review all that within one tool has been phenomenal. When we're reviewing those Nessus scores, the solution works well.
What needs improvement?
I think there's still some things that need to be ironed out to ensure that we can have a one-stop shop to do both ACAS, SCAP automated assessments in. We've been trying to do that and they say you can, the capability is integrated into the system. But in most instances, especially when you're dealing with some systems that are standalone or a network that we built ourselves, we find that some devices aren't pinged and the scans aren't done properly. That also comes down to the hardening of the systems where the password or the privileges weren't taken, so therefore it didn't do the scan properly.
For how long have I used the solution?
I've been using this solution for the past six or seven years.
What do I think about the stability of the solution?
The solution is stable. We haven't run into any issues other than some passwords that don't take, but that's the way we set up the system. If it's set up properly and configured appropriately, there won't be any issues.
What do I think about the scalability of the solution?
We could definitely make the adjustment to scale it left, right, up and down, depending on what we're using it for and we haven't run into any issues on that. It's pretty flexible.
How was the initial setup?
The setup itself is pretty straightforward. Because these are standalone systems, there are some additional steps that the IT team needs to do, but they pretty much have it down to where they could install the tools pretty easily and have it running reasonably quickly.
What other advice do I have?
I would recommend making sure that the solution meets your needs for automated scans and the SCAP. If you're looking for a one-stop shop, I think it's a great tool for that. I would recommend some form of training if you don't have experience with this kind of solution. There's a bit of a learning curve involved in terms of configuring and using Nessus.
I rate this solution an eight out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Owner at a tech services company with 1-10 employees
Easy to use, good support, and gives full reports of what's vulnerable per device
Pros and Cons
- "I like its ease of use. It has the script that is pre-built in it, and you just got to know which ones you're looking for."
- "To me, that was a better selling point because it was real: it wasn't demo data, it was our own network showing, "Hey, we're vulnerable because of this, and here's the tool that did it," which got us the buy-in we needed from upper management."
- "The price could be more reasonable. I used the free Nessus version in my lab with which you can only scan 16 IP addresses. If I wanted to put it in the lab in my network at work, and I'm doing a test project that has over 30 nodes in it, I can't use the free version of Nessus to scan it because there are only 16 IP addresses. I can't get an accurate scan. The biggest thing with all the cybersecurity tools out there nowadays, especially in 2020, is that there's a rush to get a lot of skilled cybersecurity analysts out there. Some of these companies need to realize that a lot of us are working from home and doing proof of concepts, and some of them don't even offer trials, or you get a trial and it is only 16 IP addresses. I can't really do anything with it past 16. I'm either guessing or I'm doing double work to do my scans. Let's say there was a license for 50 users or 50 IP addresses. I would spend about 200 bucks for that license to accomplish my job. This is the biggest complaint I have as of right now with all cybersecurity tools, including Rapid7, out there, especially if I'm in a company that is trying to build its cybersecurity program. How am I going to tell my boss, who has no real budget of what he needs to build his cybersecurity program, to go spend over $100,000 for a tool he has never seen, whereas, it would pack the punch if I could say, "Let me spend 200 bucks for a 50 user IP address license of this product, do a proof of concept to scan 50 nodes, and provide the reason for why we need it." I've been a director, and now I'm an ISO. When I was a director, I had a budget for an IT department, so I know how budgets work. As an ISO, the only thing that's missing from my C-level is I don't have to deal with employees and budgets, but I have everything else. It's hard for me to build the program and say, "Hey, I need these tools." If I can't get a trial, I would scratch that off the list and find something else. I'm trying to set up Tenable.io to do external PCI scans. The documentation says to put in your IP addresses or your external IP addresses. However, if the IP address is not routable, then it says that you have to use an internal agent to scan. This means that you set up a Nessus agent internally and scan, which makes sense. However, it doesn't work because when you use the plugin and tell it that it is a PCI external, it says, "You cannot use an internal agent to scan external." The documentation needs to be a little bit more clear about that. It needs to say if you're using the PCI external plugin, all IP addresses must be external and routable. It should tell the person who's setting it up, "Wait a minute. If you have an MPLS network and you're in a multi-tenant environment and the people who hold the network schema only provide you with the IP addresses just for your tenant, then you are not going to know what the actual true IP address that Tenable needs to do a PCI scan." I've been working on Tenable.io to set up PCI scans for the last ten days. I have been going back and forth to the network thinking I need this or that only to find out that I'm teaching their team, "Hey, you know what, guys? I need you to look past your MPLS network. I need you to go to the edge's edge. Here's who you need to ask to give me the whitelist to allow here." I had the blurb that says the plugin for external PCI must be reachable, and you cannot use an internal agent. I could have cut a few days because I thought I had it, but then when I ran it, it said that you can't run it this way. I wasted a few hours in a day. In terms of new features, it doesn't require new features. It is a tool that has been out there for years. It is used in the cybersecurity community. It has got the CV database in it, and there are other plugins that you could pass through. It has got APIs you can attach to it. They can just improve the database and continue adding to the database and the plugins to make sure those don't have false positives. If you're a restaurant and you focus on fried chicken, you have no business doing hamburgers."
- "The price could be more reasonable. I used the free Nessus version in my lab with which you can only scan 16 IP addresses."
What is our primary use case?
We use it for vulnerability management. We have the latest version because we're using it in the cloud right now. I have a public cloud and a private cloud version.
How has it helped my organization?
When we do our scans, I'm able to give full reports of what's vulnerable per device. I could group them and say, "Hey, here's a vulnerability in the infrastructure. Here's all the host that needs to be addressed," by showing the report. When I give a report or a request for change, I would include the report so that they are undisputed. Instead of the sys admins giving the excuse of, "Hey, we don't have enough time," or, "We've already done it," or some other poor excuse, now I have a report behind it that says, "Hey, you're vulnerable with this. Here's the CVE, and here's the POC of the CVE," and then if I want to be a little bit more obnoxious, I provide them the POC that I ran with the proof that the POC is there, and then I'm able to say, "Hey, you need to patch this now."
My executives now are able to say, "Hey, you know what? The ISO gave you a directive to patch this with proof. Why haven't you done it?" Because now, as we know, all C-levels are ultimately responsible. If you have an ISO that is interfacing with sys admins saying, "Hey, here's a change that you need to patch it. Here's my proof that even has POC with proof and the report," then there is no benign, "Why haven't you done it?"
What is most valuable?
I like its ease of use. It has the script that is pre-built in it, and you just got to know which ones you're looking for.
What needs improvement?
The price could be more reasonable. I used the free Nessus version in my lab with which you can only scan 16 IP addresses. If I wanted to put it in the lab in my network at work, and I'm doing a test project that has over 30 nodes in it, I can't use the free version of Nessus to scan it because there are only 16 IP addresses. I can't get an accurate scan. The biggest thing with all the cybersecurity tools out there nowadays, especially in 2020, is that there's a rush to get a lot of skilled cybersecurity analysts out there. Some of these companies need to realize that a lot of us are working from home and doing proof of concepts, and some of them don't even offer trials, or you get a trial and it is only 16 IP addresses. I can't really do anything with it past 16. I'm either guessing or I'm doing double work to do my scans. Let's say there was a license for 50 users or 50 IP addresses. I would spend about 200 bucks for that license to accomplish my job. This is the biggest complaint I have as of right now with all cybersecurity tools, including Rapid7, out there, especially if I'm in a company that is trying to build its cybersecurity program. How am I going to tell my boss, who has no real budget of what he needs to build his cybersecurity program, to go spend over $100,000 for a tool he has never seen, whereas, it would pack the punch if I could say, "Let me spend 200 bucks for a 50 user IP address license of this product, do a proof of concept to scan 50 nodes, and provide the reason for why we need it." I've been a director, and now I'm an ISO. When I was a director, I had a budget for an IT department, so I know how budgets work. As an ISO, the only thing that's missing from my C-level is I don't have to deal with employees and budgets, but I have everything else. It's hard for me to build the program and say, "Hey, I need these tools." If I can't get a trial, I would scratch that off the list and find something else.
I'm trying to set up Tenable.io to do external PCI scans. The documentation says to put in your IP addresses or your external IP addresses. However, if the IP address is not routable, then it says that you have to use an internal agent to scan. This means that you set up a Nessus agent internally and scan, which makes sense. However, it doesn't work because when you use the plugin and tell it that it is a PCI external, it says, "You cannot use an internal agent to scan external." The documentation needs to be a little bit more clear about that. It needs to say if you're using the PCI external plugin, all IP addresses must be external and routable. It should tell the person who's setting it up, "Wait a minute. If you have an MPLS network and you're in a multi-tenant environment and the people who hold the network schema only provide you with the IP addresses just for your tenant, then you are not going to know what the actual true IP address that Tenable needs to do a PCI scan."
I've been working on Tenable.io to set up PCI scans for the last ten days. I have been going back and forth to the network thinking I need this or that only to find out that I'm teaching their team, "Hey, you know what, guys? I need you to look past your MPLS network. I need you to go to the edge's edge. Here's who you need to ask to give me the whitelist to allow here." I had the blurb that says the plugin for external PCI must be reachable, and you cannot use an internal agent. I could have cut a few days because I thought I had it, but then when I ran it, it said that you can't run it this way. I wasted a few hours in a day.
In terms of new features, it doesn't require new features. It is a tool that has been out there for years. It is used in the cybersecurity community. It has got the CV database in it, and there are other plugins that you could pass through. It has got APIs you can attach to it. They can just improve the database and continue adding to the database and the plugins to make sure those don't have false positives. If you're a restaurant and you focus on fried chicken, you have no business doing hamburgers.
For how long have I used the solution?
I've been using Nessus for about eight years.
What do I think about the stability of the solution?
Internally, it is stable. Externally also, from what I've seen, it is stable. The only problem that I've had with it was if you have a network and internet blip, you get disconnected, but that happens with anything. Right now, I would say that a lot of cloud companies are having problems because COVID has got a lot of people working from home remotely in VPN. This is the biggest problem we have. You went from 35 people using VPN to over 2,000 people using VPN. You're trying to go to a cloud that wasn't set up for VPN, or you don't have the necessary routes or bandwidth to it. The average person is going to say, "This cloud application sucks." It doesn't really suck. It means that you don't have enough bandwidth in your infrastructure.
What do I think about the scalability of the solution?
We haven't had to scale it yet. We haven't scaled internal Nessus because we have our own version of it. I'm not sure how many IP addresses we're feeding, but I know we only have one server. I looked at the processes, and it's only doing 50% of the process.
We have 13 people who are capable or licensed to use it, which would be all of our risk management information, information security, and risk management office, but I would say only half or about six of us are actually using it daily.
How are customer service and technical support?
I've used the tech support a couple of times. I would say they are very good because they were able to say, "Hey, let's stop the chatting. Let's get on a Webex, and we will Webex you and ask the questions directly." They were able to get to the engineers on the Webex at the same time, and within 30 minutes, they solved our problem. I would rate them a ten out of ten.
How was the initial setup?
If I was installing Nessus just by itself, it is straightforward simply because I've done it before. If you're setting up Nessus from the cloud version, there's a little bit more to it because, for one, it's in the cloud version, and you got to open up ports for your network. You got network people who get all scary because they don't understand what you're doing. Other than that, once you get it set up, then it is pretty much straightforward.
What's my experience with pricing, setup cost, and licensing?
Nowadays, your vulnerability applications are going to be kind of pricey because lots of them, including Rapid7, are based upon a base price, but then they add in the nodes. That's where they get you. If you're a big network, obviously, you need to scan everything. Therefore, it's going to be costly.
The risk and insurance money associated with having ransomware on my networks is going to cost me more money, time, and marketing than the price of the tool. That's why I'm speaking only as an information security officer to security operations. This is the tool that is there in my toolbox to say whether we vulnerable or not. At this point, I don't care about how much it costs my company to have it because if I wasn't able to report it and we got ransomware, then who cares? I'm probably going to be out of business because it happened. That's why I don't care about the price. I have it, and I could use it effectively and do my report. At the end of the day, even if we get ransomware, as long as I reported it, followed my protocol, and put in the change, irrespective of whether it was ignored or denied, I did my job.
What other advice do I have?
The advice would be definitely doing your proof of concept because that's what you're going to need for your buy-in for your upper management because it is going to cost some money. I would do a hybrid version, where your own Nessus is internal, and then you have your cloud. If you lose connection to the internet, you could still run an internal Nessus scan to save the scan and then input the scan into Tenable.sc. Do your proof of concepts, get your reports, and use your proof of concepts when you do your presentation to upper management to purchase. If you use your own nodes and your own network as your proof of concept, it gives them an eye view of, "Hey, we're vulnerable because of this, and here's the tool that did it." To me, that was a better selling point because it was real. It wasn't the demo data. Once you have purchased it and get it all set up, use it continuously, meaning include your scanned reports with your change control. This way, it shuts all the administrators who have been there over 20 years and say, "Hey, I don't want to patch right now because it takes the network down." Yes, it's going to take the network down. However, the longer you wait, the more vulnerable you are because if I'm doing change requests every week, and I'm calling on more and more risk and you start to find the same nodes in the same reports, then somebody up high is going to say to the network administrator guy to fix it.
I would rate Tenable Nessus a ten out of ten right now. If you had asked me last year, Rapid7 would have been the same and on top, but now that I've been using Tenable and I'm comparing the jobs that I'm doing right now, Tenable is cut and clear to what the report is saying. My favorite report is the VPR report. Instead of just looking at CVS numbers, it has a VPR report that ranks, whereas, in Rapid7, it's just focused on CVS. It is CVS version 2 or 3, which kind of gets confusing. For example, in Tenable, I can run a scheduled scan and have my report, but let's say, for instance, I did patching in the middle before my scheduled scan. I could kick off a new scan specifically for that vulnerability and get a report, whereas, in Rapid7, you could not easily do that. Therefore, you were stuck waiting for the scan to go again and to see if your mitigation efforts fixed it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director at Monal Tech Pvt.Ltd.
Beneficial website scanning, reliable, and scales well
Pros and Cons
- "The most valuable feature of Tenable Nessus is website scanning."
- "The solution could improve security updates."
What is our primary use case?
Our clients use Tenable Nessus to find vulnerabilities in websites and infrastructure.
What is most valuable?
The most valuable feature of Tenable Nessus is website scanning.
What needs improvement?
The solution could improve security updates.
For how long have I used the solution?
I have been using Tenable Nessus for approximately three years.
What do I think about the stability of the solution?
The solution is stable.
I rate the stability of Tenable Nessus a seven out of ten.
What do I think about the scalability of the solution?
I am the only one using this solution.
I rate the scalability of Tenable Nessus a seven out of ten.
How are customer service and support?
I rate the support of Tenable Nessus a six out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The setup is easy. We use the deployment manual and followed the steps.
I rate the initial setup of Tenable Nessus a nine out of ten.
What's my experience with pricing, setup cost, and licensing?
The price is high for the solution. There are free tools with similar functionality available. The solution cost approximately $3,500.
I rate the price of Tenable Nessus a six out of ten.
What other advice do I have?
I would recommend this solution to others.
I rate Tenable Nessus a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
Manager (Information Security) at Girnarsoft Private Limited
High availability, useful scanning and assessments
Pros and Cons
- "The most valuable features of Tenable Nessus are the scanning option. Advanced scanning is highly useful. The offline config audits and application assessments are useful."
- "The price and scalability of the solution could improve."
What is our primary use case?
Tenable Nessus is used to perform process and network assessments and sometimes for reviews.
What is most valuable?
The most valuable features of Tenable Nessus are the scanning option. Advanced scanning is highly useful. The offline config audits and application assessments are useful.
What needs improvement?
The price and scalability of the solution could improve.
For how long have I used the solution?
I have been using the solution for six years and seven months.
What do I think about the stability of the solution?
I rate the stability of Tenable Nessus a ten out of ten.
What do I think about the scalability of the solution?
The scalability of Tenable Nessus has been scalable. I am able to scan a large number of IPs.
We have all our three security staff using the solution.
How are customer service and support?
I have not contacted the support.
How was the initial setup?
The initial setup of Tenable Nessus is easy. The deployment took approximately 4 hours for the policies and the setup was not long.
I rate the initial setup of Tenable Nessus a nine out of ten.
What's my experience with pricing, setup cost, and licensing?
The price of the solution is reasonable.
What other advice do I have?
I would recommend others use this solution.
I rate Tenable Nessus a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Product Categories
Vulnerability ManagementPopular Comparisons
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Checkmarx One
Tanium
Qualys VMDR
NinjaOne
TrendAI Vision One – Cloud Security
Orca Security
Zafran Security
JFrog Xray
FortiCNAPP
Acunetix
Tenable Security Center
Buyer's Guide
Download our free Tenable Nessus Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Qualys VM vs Tenable Nessus: Comparison
- How would you choose between Rapid7 InsightVM and Tenable Nessus?
- What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
- How does Tenable Nessus compare with Qualys VM?
- What are the main differences between Qualys VMDR and Tenable Nessus?
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?





















Authenticated users are a excellent way for you increase the quality and depth of your scanner. You can add/use cloud providers API-keys during tests, local or AD users/credentials with database, telecom devices and other types of digital assets. Normally, the difference between non/authenticated-scans is widely big.