On paper Nessus and OpenVAS cover the same ground: authenticated and unauthenticated vulnerability scanning across a network. In practice the choice comes down to budget, plugin freshness, and how much noise you are willing to triage.
Neither is simply better. They are built for different constraints.
Coverage and plugin freshness
Nessus, from Tenable, ships a large and fast-moving plugin feed; checks for a newly disclosed CVE tend to appear quickly. OpenVAS, now Greenbone, has a solid and free feed that has historically lagged a little on the very newest vulnerabilities.
For time-sensitive engagements, that lag is the difference between catching the thing everyone is talking about this week and missing it.
False positives and triage
Both scanners produce false positives; the difference is volume and how much the plugin write-ups help you triage. Nessus output tends to be cleaner and more actionable. OpenVAS can be noisier, and noise costs you the most expensive thing you have, time.
Whichever you run, authenticated scans cut false positives dramatically because the scanner reads real versions instead of guessing from banners.
Licensing and cost
Nessus Professional is a per-seat annual licence. OpenVAS Community is free, and Greenbone sells appliances on top. For a solo consultant, free is genuinely compelling.
For a firm running many engagements a month, the hours Nessus saves in triage and reporting often pay for the licence several times over. Do that maths honestly rather than by reflex.
It is rarely either/or
Plenty of consultants run both: Nessus as the primary pass, OpenVAS as a cross-check or for clients who require open-source tooling. Disagreements between the two are often the most interesting findings.
Whatever you scan with, the export is a starting point, not the deliverable. The report is where the judgement happens.