Testing
Your scan is clean. What does that let you tell a customer?
A green scan report arrives and the temptation is to answer the security questionnaire with it. The claim it actually supports is narrower than the question being asked, and stating the narrow version costs you nothing while the broad one can unravel later.
Facts checked — 2026-09-11
What does a clean vulnerability scan prove?
A clean scan says that at a point in time, against a database of known issues, an automated tool found nothing matching. That is genuinely worth saying: it evidences a vulnerability management process running on a cadence, which is what both ISO/IEC 27001 and SOC 2 actually expect to see.
What it does not support is "our application has been tested". A scanner has no way to judge whether one user can reach another user’s records, because that response looks perfectly valid, and it cannot chain three small weaknesses into one serious finding. So if a questionnaire asks whether you conduct penetration testing, a scan is not a yes — and answering yes is the version that comes apart when someone asks for the report.
The phrasing that holds: name what you run, its frequency, and what it covers. "Authenticated vulnerability scanning weekly across production, with an annual third-party penetration test" is specific, checkable and stronger than a vague claim, because a reviewer can tell you have understood the difference.
The bottom line
Claim the scan as evidence of vulnerability management, not as evidence the application was tested. Name the cadence and the scope — specificity reads as competence, and vagueness invites the follow-up question.
Related services
Vulnerability Assessment and Penetration Testing (VAPT)
Find what an attacker would find, ranked by what it would actually cost you — and get a report your auditor and your engineers can both use.
Related insights
Technical testing
The OWASP Testing Guide, and how to tell a real penetration test from a scan
Two tests can cost the same and cover entirely different ground. The methodology is how you tell, and it is checkable before you pay.
Technical testing
NIST SP 800-115: the four phases, and the one that is not a phase
The four-phase shape behind most credible test methodologies — and the phase that is not fourth at all.
Testing
What a CVSS score does and does not tell you about your risk
A shared scale for technical severity — deliberately context-free, which is exactly why it is not your priority order.