Skip to content

Cost guide

Vulnerability Scanning Cost

Vulnerability scanning is a flat $1,500 per scan for a defined scope, with recurring plans available for ongoing coverage. Each scan is run and tuned by our team, validated by an analyst who removes false positives, and delivered as a prioritized, deduplicated report you can act on.

Vulnerability ScanningFixed price

Per scan

One validated scan of a defined scope, internal or external, authenticated or unauthenticated, with false positives removed and findings ranked by risk.

$1,500
Free retest includedFrom $1,500

What moves the number

What drives the cost of vulnerability scanning

01

Internal or external scope

A scan is a flat $1,500 for a defined scope. Whether you need the internet-facing perimeter, the internal estate, or both determines how many scans a full picture takes, rather than the per-scan rate.

02

Authenticated versus unauthenticated

Authenticated scans, run with credentials on the host or application, find several times more than an unauthenticated pass and are the more useful of the two. Both fit the flat per-scan rate for a defined scope.

03

Size of the estate

A defined scope sets the scan. A very large or fast-changing estate may be split into more than one scan or scoped as a program, so the per-scan rate stays predictable rather than ballooning with host count.

04

Frequency and recurring plans

One baseline scan is $1,500 flat. Quarterly or monthly programs, which PCI DSS and most auditors expect, are priced as a recurring plan and more favorably than a series of one-off scans.

05

Where it fits with testing

Scanning is not a penetration test. Folding recurring validated scans and manual test windows into one program keeps ongoing coverage and audit evidence on a single fixed annual price rather than separate purchases.

In the price

What every vulnerability scanning price includes

  • A validated scan of a defined scope, internal or external, authenticated or unauthenticated
  • Analyst validation with false positives removed and findings ranked by risk
  • A prioritized, deduplicated report, with recurring plans available for ongoing coverage
  • A fixed price agreed in writing before work begins, with no hourly billing
  • An executive summary for leadership and a full technical report
  • A free re-scan to verify remediated findings, with the report updated to show them closed
  • An attestation of the scanning performed and findings platform access at no extra cost
  • Senior in-house analysts and testers, OSCP and OSCE3 certified

Keep it tight

How to keep the price down

  1. 01Provide credentials for authenticated scanning. It finds several times more than an unauthenticated pass, so the same flat scan fee returns far more value on the systems that matter.
  2. 02Confirm the scope of hosts and applications before the scan. A defined target keeps the flat per-scan rate predictable and avoids paying to scan assets that are out of scope.
  3. 03Move to a quarterly or monthly recurring plan if you scan regularly. Ongoing coverage is priced more favorably than a series of one-off scans, and it matches what auditors expect.
  4. 04Fold scanning and manual testing into one program. A single fixed annual price for scans plus test windows costs less to run than buying each piece separately through the year.

Timeline

Onboarding begins within 24 hours of a signed proposal, and a scan usually starts within a week of scoping, sooner once scope and credentials are confirmed. A single validated scan is quick to run; the analyst validation and prioritized report follow within days. Recurring plans run on the cadence you set, whether monthly or quarterly.

FAQ

Questions about vulnerability scanning cost

01How much does a vulnerability scan cost?

A validated scan is a flat $1,500 per scan for a defined scope, with recurring plans available for ongoing coverage and priced more favorably than a series of one-off scans. Starting prices for every service are on the pricing page.

02Why does a scan cost more than free or automated tools?

Because the scan is not the product. The flat fee covers running and tuning the scanner, an analyst validating the results, removing false positives, and ranking findings by real risk, so your team fixes genuine issues rather than wading through raw scanner noise.

03What changes the cost across a scanning program?

The flat per-scan rate is fixed for a defined scope. What varies is how many scans a full picture needs: internal and external, authenticated and unauthenticated, and how often you run them. Quarterly or monthly programs are priced as a recurring plan.

04Is a scan the same as a penetration test?

No. A scan finds known weaknesses across many systems quickly; a penetration test manually exploits and chains issues to prove real impact. Most programs use scanning continuously and testing periodically. Our testing program combines both on one fixed annual price.

05How can we get the most from the flat scan fee?

Provide credentials for authenticated scanning, which finds several times more than an unauthenticated pass, confirm the scope of hosts and applications up front, and move to a recurring plan if you scan regularly, which matches what PCI DSS and most auditors expect.

Get the exact number for your scope

Tell us what needs testing. You get a written fixed price within one business day, and the number does not move once testing starts.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.