The Greenbone MSSP Program: vulnerability management, licensed for the way you sell it

As of now, the Greenbone MSSP Program is open to service providers in Europe and beyond. It puts OPENVAS, the world’s most widely used open-source vulnerability management solution, in the hands of providers who deliver it as a service, on commercial terms built around how managed services actually make money: one platform for every customer you serve, one agreement covering all of them, and costs that follow the assets you manage.
Learn More About the Greenbone MSSP Program
Find full program details, terms, and how to apply at greenbone.net/en/mssp.
Many customers, one platform, one team
You run all of your customer environments from one central platform, with strict separation between them. Each customer sees only their own environment and their own results. Your team keeps a single point of control, and access is granted per team member for the accounts they are responsible for. Adding a customer becomes an operational step rather than a project, which is the whole point: your delivery effort should not grow one to one with your customer base.
Starting is deliberately small. You begin with a working setup and grow it as your customer base does, instead of committing to a rollout that has to be finished before it earns anything. How involved it gets from there depends on your customers’ networks rather than on our software, and our Professional Services team is there for the architecture questions that come with segmented networks, authenticated scanning, and air-gapped environments.
Evidence your customers and their auditors accept
Managed vulnerability management either stays profitable or quietly bleeds hours, and the difference usually sits in how much you assemble by hand. Findings, risk context, priorities and remediation guidance can be produced per customer, in the shape that each service agreement calls for. You are not rebuilding the same output for every account, every month, and every audit.
Behind the scanner sits a security research team maintaining one of the world’s leading vulnerability test feeds, updated daily. Coverage and freshness are what your customers rely on the day a critical vulnerability becomes public, and they are not something a service can be built on top of by chance.
European, open, and yours to deploy
Where a security solution comes from has become a deciding factor in buying decisions, and your customers are the ones asking. Greenbone is a European vendor. We have developed vulnerability management as open-source software since 2008, our technology is built and hosted in the EU, and it is developed with GDPR requirements in mind.
The solution runs in your own environment, so the deployment and data-residency options your customers ask for are yours to offer. For the customers wary of US-based providers within the reach of regulations like the Cloud Act, or working under strict data-protection rules, that is a requirement you can meet without a workaround, and an argument you can carry into your own sales conversations.
Nothing you have to buy twice
Partners tell us the same two things about the platforms they have worked with. The scope they bought keeps growing into modules that arrive later as separate line items. And the interface they automated against keeps moving, or closes.
We do neither, and that is a position rather than a phase. Vulnerability management is our product, not the entry ticket to a suite. Our scanning technology is open-source at its core, it integrates into heterogeneous environments, and the interface you build against belongs to the product rather than serving as a commercial lever. The automation your team writes around it stays worth something.
For you that counts twice over, because your delivery platform is your product too. Every hour spent re-engineering around someone else’s roadmap is an hour you cannot bill, and every function that migrates behind a new licence is a margin decision somebody made on your behalf. We would rather be the best vulnerability management engine in your stack than a suite that treats vulnerability management as one feature among many.
A commercial model that rewards growth
Licensing follows the assets you manage, not fixed seats. It is settled at partner level, across your entire customer base, and that is the part that matters most for your economics. Every customer you onboard counts towards the same volume, so your fortieth customer improves your position instead of opening a new negotiation. There is a minimum commitment, and it sits with you as a partner rather than with any individual customer, so a mix of large and small accounts costs you nothing. Commit to a volume for a year and your terms improve further.
Growth sits on your side of the table, which is where it belongs.
Partners are already delivering this as a service
CYBER FOX AG has integrated OPENVAS deeply into its managed security services. Continuous vulnerability analysis forms the basis for context-based risk assessment, risk-driven prioritisation, and concrete remediation guidance, delivered around the clock by the CYBER FOX® Security Operations Center as a fully managed service. Operations and data storage for both companies run entirely in Europe, in line with GDPR.
“Greenbone delivers exactly the technological depth and transparency we need for vulnerability management as a managed service. The MSSP model lets us scale that service efficiently and deliver measurable value to our customers,” says Patrick Antoun, Executive Board Member at CYBER FOX AG.
Learn More About the Greenbone MSSP Program
Find full program details, terms, and how to apply at greenbone.net/en/mssp.
Talk to us
If you are choosing a vulnerability management partner, or reconsidering the one you have, start where it counts: most partners begin with a short technical walkthrough and a guided proof of concept, so you can test the platform against your own environment and your own customer mix before committing to anything.



