Greenbone review covering OpenVAS vulnerability scanning, appliance and cloud pricing, GDPR compliance, key features, pros, cons and alternatives for 2026.
Category
Security
Pricing
Open source plus commercial appliances and subscriptions (quote-based), from Free (OpenVAS/GVM open source); paid appliances via quote, free 14-day trial available
Verified
Not yet
Last updated
July 18, 2026
Founded
2008
Headquarters
Osnabruck, Germany
Web AppFree TrialAPIOpen SourceFreemiumSelf-Hosted
Overview
Greenbone was founded in 2008 in Osnabruck, Germany to lead development of OpenVAS, an open-source fork of the Nessus vulnerability scanner, and has since grown that project into a full vulnerability management platform sold as appliances and software.
The company converted to a German stock corporation (Greenbone AG) in 2023 and now operates as the Greenbone Group with subsidiaries in the UK, Italy and the Netherlands, reporting more than 100,000 protected installations across over 150 countries.
Key Features
Greenbone's core scan engine runs more than 200,000 vulnerability tests to identify missing patches, misconfigurations and known CVEs across an organization's IT assets.
Its product line spans an entry-level OpenVAS Basic tier, the flagship OpenVAS Scan appliance available in hardware or virtual form, and newer centralized management and on-premises AI prioritization capabilities.
Pricing
Greenbone does not publish list prices for its commercial appliances; customers submit a product request and receive a custom quote, with a free 14-day trial available for the entry-level OpenVAS Basic tier.
The underlying open-source Greenbone Vulnerability Management (GVM) engine, historically branded OpenVAS, remains free to self-host for organizations that only need the core scanning capability.
Key Features
200,000+ vulnerability tests — A continuously updated feed of vulnerability tests covering known CVEs, missing patches and common misconfigurations.
Hardware and virtual appliances — OpenVAS Scan is available as a physical appliance or a virtual machine, supporting flexible on-premises deployment.
GDPR-compliant architecture — Scan data can be kept entirely within the customer's own infrastructure, aligning with strict European data protection requirements.
Centralized multi-scanner management — OpenVAS Security Intelligence consolidates reporting from multiple distributed scan instances into one risk view.
CSAF and SBOM integration — Ingests CSAF security advisories and software bill of materials data for a more complete vulnerability and supply-chain picture.
On-premises AI prioritization — OpenVAS AI turns raw scan results into prioritized remediation plans without sending data outside the customer's network.
Open-source community edition — The core GVM/OpenVAS engine is free and open source, allowing self-hosted use without a commercial license.
ISO-certified operations — ISO 9001, ISO 27001 and ISO 14001 certifications support procurement in regulated and public-sector environments.
Pros & Cons
Pros
Free, actively maintained open-source scan engine with a long track record dating back to 2008
Strong GDPR and data-residency positioning, with on-premises deployment options for sensitive environments
Close historical ties to Germany's BSI federal security authority lend added credibility
Flexible deployment via hardware appliance, virtual appliance, or self-hosted open source
Cons
Commercial pricing is not published and requires going through a sales quote process
Hardware appliance procurement can be slower and less flexible than pure cloud-based competitors
Smaller global brand recognition than Tenable, Qualys or Rapid7 outside Europe
Newer AI and centralized intelligence features are still rolling out and less mature than the core scanner
Pricing
Community Edition (GVM/OpenVAS) Free N/A (self-hosted, open source)
OpenVAS Basic Contact for pricing (free 14-day trial) Custom
OpenVAS Scan Contact for pricing Custom
OpenVAS Security Intelligence Contact for pricing Custom
Frequently Asked Questions
Is Greenbone the same as OpenVAS
Greenbone is the company that leads development of OpenVAS (now formally the Greenbone Vulnerability Management framework) and sells commercial appliances and services built on top of that open-source engine.
Is Greenbone free to use
The core open-source scanning engine can be self-hosted for free, and the entry-level OpenVAS Basic commercial tier offers a free 14-day trial, but the full appliance and enterprise product lines are paid and quote-based.
How much does Greenbone cost
Greenbone does not publish list prices; customers request a quote based on appliance type, number of scanned assets and support level.
Is Greenbone GDPR compliant
Yes. Greenbone markets its products as fully GDPR-compliant and supports on-premises deployments so vulnerability scan data never has to leave the customer's own infrastructure.
Where is Greenbone based
Greenbone is headquartered in Osnabruck, Germany, and operates as the Greenbone Group with subsidiaries in the United Kingdom, Italy and the Netherlands.
Who competes with Greenbone
Greenbone competes with Tenable (Nessus), Qualys, Rapid7 InsightVM and Microsoft Defender Vulnerability Management in the vulnerability management space.