Skip to content

Assessment

Vulnerability
Assessment Services

$1,500 per assessment, fixed scope, free retest included. See all pricing →

Get a Fixed Quote

Three fields. A senior tester reads it and replies within one business day.

Prefer the full scoping questionnaire? 
OSCP & OSCE3 certified testers150+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When you need a vulnerability assessment

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • You have never had an outside view of the estate and want a validated baseline before committing to a full penetration test.
  • A scanner is already running and the output is hundreds of findings nobody has time to verify or rank.
  • PCI DSS, SOC 2, NYDFS 500.5, or CMMC expects evidence of an ongoing vulnerability management process, not one annual test.
  • A cyber-insurance application asks how often you assess and how quickly critical findings are fixed.
  • You want coverage between annual penetration tests, after a patch cycle, a migration, or a merger.

Definitions

Vulnerability assessment vs penetration test vs scan

Three products that get sold under each other’s names. Paying for the wrong one is the most common mistake we see, so here is the honest comparison.

Vulnerability scan

Who does the work
Software
What you get
A raw list of possible issues
Finds business-logic flaws
No
Cadence
Continuous or monthly
Price
$1,500 per validated scan
Best for
Catching new exposures fast

Vulnerability assessment

Who does the work
Software plus an analyst who validates, deduplicates, and ranks
What you get
A verified, prioritized list of real issues with remediation order
Finds business-logic flaws
No
Cadence
Quarterly, or before each retest
Price
$1,500 per assessment
Best for
A validated baseline, compliance evidence, and coverage between tests

Penetration test

Who does the work
Senior testers who exploit and chain findings by hand
What you get
Proof of what an attacker can actually reach, and how
Finds business-logic flaws
Yes
Cadence
Annually and after significant change
Price
From $4,000 depending on the target
Best for
Depth, business logic, and audit-grade assurance

A vulnerability assessment does not replace a penetration test for PCI DSS Requirement 11.4, NYDFS 500.5, or a SOC 2 auditor who asked for a pentest. It is the evidence for the vulnerability management process those same frameworks also require. Our guide to penetration testing vs vulnerability scanning goes deeper.

What we look for

What a vulnerability assessment finds and validates

The scanner produces candidates. The analyst turns them into an assessment: confirmed, deduplicated, ranked, and explained, so your team fixes real risk in the right order.

Missing patches and known CVEs

The vulnerabilities in software and systems that attackers exploit first, and the ones that scanners are best at surfacing.

We test for

  • Known-CVE detection across hosts and services
  • Outdated software, frameworks, and operating systems
  • End-of-life components still in service
  • Patch verification after remediation

Misconfiguration

Insecure settings across hosts, services, and cloud resources that widen exposure without any missing patch.

We test for

  • Insecure service and protocol configuration
  • Weak TLS and SSL settings
  • Default and sample content
  • Exposed management interfaces

Weak credentials and access

Default or guessable access sitting on reachable services.

We test for

  • Default credentials
  • Weak password policy
  • Unnecessary services and open ports
  • Excessive access on shared resources

Cloud configuration

The storage, identity, and network settings in AWS, Azure, or GCP that a scanner reads from the control plane.

We test for

  • Public storage and snapshots
  • Over-permissive identities and roles
  • Open security groups and network rules
  • Logging and monitoring gaps

Web application weaknesses

The known-pattern issues in a web application that automated testing can reach, validated by hand.

We test for

  • Outdated components and libraries
  • Missing security headers and cookie flags
  • Injection and cross-site scripting candidates
  • Information disclosure in errors and metadata

Validation and ranking

The analyst work that turns raw output into an assessment.

We test for

  • False-positive removal
  • Exploitability confirmation
  • Deduplication across hosts and scans
  • Risk ranking with business context

Cadence

How often to run a vulnerability assessment

Once, as a baseline

A single assessment of a defined scope before a first penetration test, an audit, or a cyber-insurance application. You learn what the estate looks like from outside before anyone decides what to test by hand.

Quarterly

The cadence PCI DSS and most auditors expect. Each assessment is benchmarked against the last, with trend reporting that shows remediation velocity improving.

Before each retest

After a patch cycle, a migration, or a merger, an assessment confirms the fixes landed and nothing new arrived, ahead of the free retest that closes a penetration test.

Recurring assessments are priced as a fixed annual figure and combine with manual testing windows in a penetration testing as a service program.

The report

What the assessment report contains

  • An executive summary with the counts an auditor, an examiner, or an underwriter asks for: findings by severity, by asset, and by age.
  • Every validated finding with the affected asset, the evidence, the exploitability note, and the fix, deduplicated across hosts.
  • The false positives removed, listed, so you can see what the scanner claimed and why it was wrong.
  • A remediation plan in priority order, with the quick wins separated from the projects.
  • On a cadence, the trend against the previous assessment: what closed, what is new, and what has been open too long.

Coverage

Network, cloud, and application assessments

External network

The internet-facing perimeter: exposed services, outdated appliances, TLS weaknesses, and forgotten hosts. Pair it with an external penetration test when you need proof of exploitation.

Internal network

Servers, workstations, and network devices behind the firewall, scanned with credentials so the missing patches and local misconfigurations are visible. The baseline before an internal penetration test.

Cloud

AWS, Azure, or GCP configuration read from the control plane: storage, identities, network rules, and logging, benchmarked against the CIS foundations.

Web application

Authenticated application scanning validated by an analyst, for the known-pattern issues a web application penetration test then goes beyond.

Methodology

How we test

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your vulnerability assessment runs through.

  1. 01

    Scope & credentials

    Ranges, hosts, and authenticated versus unauthenticated coverage agreed.

  2. 02

    Scan

    Tuned scans run internally and externally on the agreed cadence.

  3. 03

    Validate

    Analysts confirm findings and remove false positives before anything reaches you.

  4. 04

    Prioritize

    Findings ranked by exploitability and exposure, not by raw scanner score.

  5. 05

    Report & trend

    Prioritized list, ticketing integration, and trend reporting over time.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Define the scope

    External perimeter, internal network, cloud account, or application. One assessment covers one defined scope at a flat $1,500.

  2. 02

    Scan, tuned

    Authenticated and unauthenticated scanning with engines chosen for the target and tuned so the results mean something for your environment.

  3. 03

    Validate by hand

    An analyst confirms every finding that matters, removes the false positives, and deduplicates across hosts.

  4. 04

    Rank and explain

    Findings are ranked by real risk, with exploitability notes and the business context that decides the order of fixes.

  5. 05

    Report and verify

    A prioritized report with remediation guidance, then a verification scan of the fixes and, on a cadence, trend reporting across assessments.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type. The findings and outcomes are real.

All case studies →

Free

Retest on every penetration test

150+

Years combined experience

13

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Post-Incident Web App Assessment

Medium risk

Excessive data exposure: API responses leaked transaction metadata, including precise geolocation, enabling real-world tracking of users.

Outcome. Surfaced the exposure and hardening gaps, prioritized by how readily an attacker could chain them, and delivered fixes plus a retest to confirm closure.

8

Findings

3

Medium

Post-incident

Engagement

Read the case study

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before scoping vulnerability assessment services.

Still have questions? 
01What is a vulnerability assessment?

A systematic review of a defined scope, such as your external perimeter, internal network, cloud account, or web application, that identifies known vulnerabilities and misconfigurations, validates them, and ranks them by real risk. The scanning is automated; the validation, deduplication, and ranking are done by an analyst, which is what separates an assessment from a raw scan. It is the standard evidence for the vulnerability management process most compliance frameworks require.

02What is the difference between a vulnerability assessment and a penetration test?

An assessment finds and ranks known weaknesses across a scope; a penetration test proves what an attacker can do with them, by exploiting and chaining them by hand and by finding the business-logic flaws no scanner can see. Assessments are broad, repeatable, and priced at $1,500 per scope. Penetration tests are deep, periodic, and priced from $4,000 by target. Most organizations need both: assessments on a cadence, a penetration test annually and after significant change.

03What is the difference between a vulnerability assessment and a vulnerability scan?

The analyst. A scan is the raw output of the tool: every candidate finding, including the false positives and the duplicates across hosts. An assessment is that output validated, deduplicated, ranked by risk with business context, and explained, so your team spends remediation time on what is real. We sell both, at the same flat price, because the scan is where the assessment starts.

04How much does a vulnerability assessment cost?

A vulnerability assessment is $1,500 flat for a defined scope, internal or external, authenticated or unauthenticated, with false positives removed and findings ranked by risk. Recurring quarterly or monthly programs are priced as a fixed annual figure. Starting prices for every service are on our pricing page.

05How often should we run one?

Quarterly is the cadence PCI DSS requires for scans and most SOC 2 and ISO 27001 auditors expect for vulnerability management evidence. Environments that change constantly run monthly. Everyone should run one after a major patch cycle, a migration, or a merger, and before the retest that closes a penetration test.

06Does this satisfy PCI DSS, SOC 2, or NYDFS?

It satisfies the vulnerability management half of each: PCI DSS Requirement 11.3.1 internal scans, the SOC 2 CC7.1 expectation of ongoing vulnerability identification, and the NYDFS 500.5(a)(2) automated scans and manual review. It does not replace the penetration test those frameworks also require, and PCI DSS external scans under 11.3.2 must be run by an Approved Scanning Vendor, which we are not; we run the pre-ASV assessment that gets you a clean ASV result the first time.

07Do you offer vulnerability assessment services in New York?

Yes. Invadel is headquartered in Manhattan and runs assessments for New York financial firms under NYDFS 23 NYCRR 500, healthcare organizations under HIPAA, and SaaS companies preparing for SOC 2, as well as clients nationwide. Assessments are delivered remotely, so location changes nothing about the price.

08What do we need to provide?

The scope: IP ranges or hostnames for a network assessment, read-only credentials for an authenticated host or cloud assessment, and a test account for an application assessment. We confirm the scope and the flat price in writing from those details before anything runs, no sales call required.

Ready to test your defenses?

Talk to our team about scoping vulnerability assessment services.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.