Your public infrastructure does not stay still between audits. A release adds an endpoint. A firewall rule changes. A service moves to a different port. The scan you ran last month cannot tell you what is exposed today.
Continuous external vulnerability scanning keeps that work moving: discover reachable services, assess findings, fix what matters and scan again. NoxScan brings those steps into a recurring workflow. Start with weekly scans from €10/month, or choose daily scanning when your operating pace calls for it.
Continuous scanning is a process you keep running
Automated vulnerability scanning takes care of the repeat checks, while your team reviews findings and applies fixes. On standard NoxScan plans, that means weekly or daily scheduled assessments, supported by manual reruns. The value comes from keeping the loop active as your infrastructure changes.
A shorter interval reduces the wait for the next check
If a service becomes exposed just after a scheduled scan, the next scheduled assessment may be almost a full interval away. A daily cadence brings that next check closer than a weekly cadence. A manual check after a significant change can bring it closer still.
Daily vulnerability scanning is useful when your public systems change frequently and you want a fresh assessment each day. Weekly scanning can suit a steadier surface. Add a manual run after a meaningful deployment, network change or remediation. NoxScan’s scanner workflow separates broad port discovery from service fingerprinting and vulnerability assessment.
Choose the cadence and capacity your team needs
Full TCP-port discovery is included on every paid plan. Standard plan differences are about capacity and workflow: assets, people, schedule and manual credits. The prices below are monthly subscriptions in euros.
Manual runs use one credit per selected asset. A ten-asset manual run uses ten credits; rerunning only two selected assets uses two. Included manual allowances reset by calendar month. Scheduled scanning is separate from those manual allowances. See pricing and scan-pack terms for annual billing, additional credits and current limits.
Build a routine that survives a busy week
Attack surface management for small business starts with ownership: which public assets belong in scope, who reviews the results, and how a finding reaches the person who can fix it. Keep the process small enough that it still happens during a release week.
For example, a small team can review its weekly run at the start of the week and reserve manual credits for the services changed during a release. A faster-moving team can use daily scheduling while keeping the same review and remediation habits. The workflow stays familiar as the surface grows.
Check that the scan actually ran
External attack surface monitoring depends on knowing what was checked and when. A schedule entry tells you what was intended to run; a completed scan tells you what actually ran. Check status before treating the assessment as current evidence.
If a run fails or cannot reach an expected service, inspect the scope and failure information. Confirm whether a firewall, service change or availability issue explains the result. Rerun when appropriate and retain the distinction between the failed attempt and the successful assessment. “No findings” is useful only when you understand what was checked.
Keep reports connected to the work
PDF reports and scan history help an engineer, customer or reviewer understand what was assessed and when. Keep them alongside the remediation decisions that explain what happened next.
For SOC 2 preparation, recurring scanning can support the evidence trail around vulnerability detection and follow-up. Your scope, controls and reviewer determine what is appropriate. Read our SOC 2 vulnerability scanning guide for the wider process.
Still choosing a tool? The small-business scanner buyer guide compares external scanning with application testing and broader network toolkits. For the mechanics of discovery, start with why full TCP-port scanning matters.
Questions about recurring scanning
Does continuous mean real-time?
On standard plans it means scheduled recurring scanning: weekly on Starter and Growth, daily on Business and Scale. Findings become available through scan execution and review; this is not a real-time intrusion-detection service.
Can I scan after a deployment?
Yes. Start a manual scan of the relevant assets. Each selected asset uses a manual credit. Check your remaining allowance or additional scan packs before running a larger scope.
Does a recurring scan fix vulnerabilities?
No. Scanning helps find and reassess exposures. Your team applies the configuration changes, patches or other remediation, then checks the result.
