Vulnerability assessments and scanning

A vulnerability assessment finds known weaknesses across the systems you put in scope, quickly and repeatably.

We run authenticated scans, a tester reviews the results, and you get a short, prioritized list your team can act on, with the raw scan data alongside for your own tools. Run it once, or monthly or quarterly between pen tests.

What’s included

  • External assessment of internet-facing hosts and services
  • Internal assessment of servers and workstations, with credentials
  • Discovery of internet-facing assets you may not know about: domains, subdomains, and exposed services
  • Web application scanning (DAST)
  • Cloud configuration checks against CIS Benchmarks
  • Container image scanning
  • Tester review of results before they reach your report
  • Prioritization by known exploitation (CISA KEV and EPSS) as well as CVSS

Why it matters

How we approach it

Authenticated scans see far more than unauthenticated ones, so we set up credentials wherever possible. A tester reviews the results before anything reaches your report, and anything listed in CISA’s Known Exploited Vulnerabilities catalog goes to the top. A scan finds known weaknesses. It doesn’t chain them or test your business logic, so we’ll tell you when you need a penetration test instead.

Standards and references: CVSS, EPSS, CISA KEV catalog, CIS Benchmarks, CIS Controls v8.1 (Control 7)

What you get

  • Prioritized findings with affected assets and specific fixes.
  • Executive summary, with trends over time for recurring scans.
  • Raw scan data for your own tooling.
  • Verification scan after remediation.
  • Critical findings are reported within 24 hours of confirmation, not held for the report.
  • Final report delivered within 5 business days after testing ends.
  • One retest of reported findings within 90 days of the final report, included in the price.

Engagement commitments apply to work under a signed HackNow proposal.

When to use it

  • Recurring scanning evidence for SOC 2, HIPAA, or ISO 27001
  • A baseline before your first pen test
  • Teams without dedicated scanning tools or staff
  • Catching new exposure between annual pen tests

What we’ll need from you

  • The IP ranges, hosts, and web applications to scan
  • Credentials for authenticated scanning, wherever possible
  • Scan windows that suit your operations
  • Systems that are fragile or should be excluded
  • Who should receive results

See the full scoping checklist

Questions about vulnerability assessments

How much does it cost?

A one-time assessment starts at $5,000 for the smallest scope, as a fixed fee set after a free scoping call. Recurring scanning is quoted for an ongoing term. Your price depends on the number of hosts and web apps, internal or external coverage, and how often you scan.

Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.

Is a vulnerability scan enough for an audit?

Sometimes. Some programs and customers ask for recurring scanning, and some ask for a penetration test, which goes further. Your auditor decides what evidence it accepts, and we’ll help you scope what it asks for.

Last reviewed October 2026

Ready to scope a vulnerability assessment?

We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.