Vulnerability assessments and scanning
A vulnerability assessment finds known weaknesses across the systems you put in scope, quickly and repeatably.
- Reply within one business day
- NDA on request
We run authenticated scans, a tester reviews the results, and you get a short, prioritized list your team can act on, with the raw scan data alongside for your own tools. Run it once, or monthly or quarterly between pen tests.
What’s included
- External assessment of internet-facing hosts and services
- Internal assessment of servers and workstations, with credentials
- Discovery of internet-facing assets you may not know about: domains, subdomains, and exposed services
- Web application scanning (DAST)
- Cloud configuration checks against CIS Benchmarks
- Container image scanning
- Tester review of results before they reach your report
- Prioritization by known exploitation (CISA KEV and EPSS) as well as CVSS
Why it matters
-
Verizon 2026 DBIR: “Only 26% of critical vulnerabilities” (CISA KEV-listed) “were fully remediated by organizations in 2025,” and “the median time for full resolution went up to 43 days.”Source: Verizon Business, 2026 Data Breach Investigations Report: Executive Summary (2026) (PDF)
Here ‘critical’ means listed in CISA’s KEV catalog.
-
NIST SP 800-115 says application vulnerability scanners ‘typically have high false positive rates’ and high false negative rates; interpreting results requires ‘a high degree of human involvement.’Source: NIST, SP 800-115: Technical Guide to Information Security Testing and Assessment (2008) (PDF)
How we approach it
Authenticated scans see far more than unauthenticated ones, so we set up credentials wherever possible. A tester reviews the results before anything reaches your report, and anything listed in CISA’s Known Exploited Vulnerabilities catalog goes to the top. A scan finds known weaknesses. It doesn’t chain them or test your business logic, so we’ll tell you when you need a penetration test instead.
Standards and references: CVSS, EPSS, CISA KEV catalog, CIS Benchmarks, CIS Controls v8.1 (Control 7)
See our full methodologyPenetration test vs. vulnerability scan
What you get
- Prioritized findings with affected assets and specific fixes.
- Executive summary, with trends over time for recurring scans.
- Raw scan data for your own tooling.
- Verification scan after remediation.
- Critical findings are reported within 24 hours of confirmation, not held for the report.
- Final report delivered within 5 business days after testing ends.
- One retest of reported findings within 90 days of the final report, included in the price.
Engagement commitments apply to work under a signed HackNow proposal.
When to use it
- Recurring scanning evidence for SOC 2, HIPAA, or ISO 27001
- A baseline before your first pen test
- Teams without dedicated scanning tools or staff
- Catching new exposure between annual pen tests
Can support:
What we’ll need from you
- The IP ranges, hosts, and web applications to scan
- Credentials for authenticated scanning, wherever possible
- Scan windows that suit your operations
- Systems that are fragile or should be excluded
- Who should receive results
Questions about vulnerability assessments
How much does it cost?
A one-time assessment starts at $5,000 for the smallest scope, as a fixed fee set after a free scoping call. Recurring scanning is quoted for an ongoing term. Your price depends on the number of hosts and web apps, internal or external coverage, and how often you scan.
Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.
Is a vulnerability scan enough for an audit?
Sometimes. Some programs and customers ask for recurring scanning, and some ask for a penetration test, which goes further. Your auditor decides what evidence it accepts, and we’ll help you scope what it asks for.
Last reviewed October 2026
Often paired with
- Network penetration testing External perimeter, internal network, Active Directory, and on-site wireless testing.
- Web application penetration testing Authenticated, manual testing of your web apps, from the login page to business logic.
- Cloud penetration testing AWS, Azure, Google Cloud, and Kubernetes tested for misconfiguration and privilege escalation.
Ready to scope a vulnerability assessment?
We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.