AnySec
Vulnerability Assessment Services: What the Quote Must Say
← InsightsPenetration Testing · 7 min read

Vulnerability Assessment Services: What the Quote Must Say

Comparing vulnerability assessment services? Check five things in every quote: what counts as an asset, authenticated or not, validation, the report, and the rescan.

By AnySec EngineeringAnySec engineering

The short answer

A vulnerability assessment quote is comparable only if it states five things: the unit it counts as one asset, how the target list is defined or discovered, whether scans are authenticated, who validates findings by hand, and whether a rescan is included. Providers can quote the same estate at very different prices because they are counting different things and delivering different artefacts. Get those five in writing before comparing price, and treat a quote that names a scanner brand but none of them as a scan, not an assessment.

Who this is for

This is for the security lead, head of infrastructure or procurement owner at a casino, crypto exchange or fintech who has two or three vulnerability assessment proposals on the desk and cannot tell why they differ. It is about reading the quote. For what an external scan covers on a casino perimeter, see scoping an external vulnerability assessment for a casino; for what to do with the results, see turning a scanner's critical list into a fix queue.

The five lines to look for

Quote lineWhat to askWhy it changes the price and the result
Unit of countIs an asset an IP address, a hostname, an application, or a cloud account?The same estate is a different number under each unit. Load balancers, shared hosting and short-lived cloud instances are where counts diverge.
Target listWho supplies it, and is discovery included?A list you wrote misses what you forgot. Discovery finds forgotten assets but needs agreed boundaries.
AuthenticationWhich targets are scanned with credentials, which without?Authenticated checks read configuration directly. Unauthenticated ones infer from what a stranger sees.
ValidationDoes a person confirm findings before they reach the report?Without it, version-guess false positives and unreachable findings go straight into your queue.
RescanIncluded, optional, or absent? How long after delivery?Without a rescan you learn whether fixes worked only at the next cycle.

Line 1: what counts as one asset

Providers price by a unit, and the unit is rarely the one you think in. An engineering team counts services; a quote may count IP addresses. A cloud estate with autoscaling groups can produce many addresses over a month from a handful of services. Ask for the unit in writing, and ask what happens when the estate changes during the engagement: is a new instance in scope, out of scope, or a change order?

Line 2: the target list

An assessment of a list you supplied tests that list. It says nothing about the staging host someone left open or the old subdomain still pointing at a live service. Ask whether discovery is part of the quote, and if it is, what the provider will do with an asset that turns out not to be yours. Hosts run by a third party need that party's permission before anyone scans them; the quote should say who obtains it.

Line 3: authenticated or not

An unauthenticated scan sees open services, banners and responses. An authenticated one logs in and reads packages and configuration, which finds more and guesses less, but needs credentials and rules about what the scanner may touch. A sound quote splits the two: credentials for the systems where the answer matters most, anonymous scanning for the outside view, and a sentence on which is which.

Line 4: who validates

This is the line that separates an assessment from a scan. Scanners infer vulnerabilities from version strings, and a vendor that backported a fix without changing the version produces a finding that is not real. Others are real but unreachable. A quote should say that a named person reviews the findings, removes the noise and records what they could not confirm. Ask whether manual validation covers every finding or a sample, because the answer determines how much triage lands on your team.

Line 5: the report and the rescan

The deliverable should be a de-duplicated, prioritised list grouped by affected asset, with evidence for each finding, a concrete fix, and a statement of what was not scanned. Ask for a redacted sample report before you sign. Then ask about the rescan: whether it is included, the window in which you can request it, and which findings it covers. A rescan confirms that a signature is gone; for anything found by hand, the narrower retest described in what counts as fixed after a pentest applies.

Red flags in a quote

  • The deliverable is described as "scan output" or "scanner export".
  • No unit of count, or a unit that changes between pages.
  • "Unlimited scans" with no statement of who reviews the results.
  • No sentence on what was out of scope.
  • A compliance badge promised without naming the standard or the scope it applies to.

Limitations

This is a reading guide, not a price list or a recommendation of any scanner. It states no market prices, no turnaround times and no AnySec-original figures. Compliance scans such as those required for card-payment environments have their own rules; read the current text of the programme that applies to you.

What to do next

Put your proposals side by side against the table above and send the gaps back as questions. If you would like a quote that answers all five lines up front, request a fixed quote for a vulnerability assessment and tell us the asset types and whether you need external, internal or both. The Vulnerability Assessment page describes how an engagement runs. If the assessment is the first step toward fixing what it finds, the Security Hardening page covers the follow-on.

Frequently asked questions

What should a vulnerability assessment quote include? The asset unit, the target list or discovery method, authentication, manual validation, the report contents, and the rescan.

Is a vulnerability assessment priced per IP address? Often, but some count hostnames, applications or cloud accounts. Ask for the unit in writing.

What is the difference between a scan and a vulnerability assessment? A scan is a tool run. An assessment adds scoping, validation, prioritisation and a report.

Should a vulnerability assessment be authenticated? For the systems that matter most, where credentials and boundaries can be agreed. The quote should say which.

Does a vulnerability assessment include a rescan? Only if the quote says so. Ask about the window and the findings covered.

Sources and review

This article describes procurement practice in general terms and cites no statistics, prices or AnySec-original numbers, case results or SLA figures. Author: AnySec Engineering. Published 2026-10-08; last reviewed 2026-10-08.


Related reading

Rather not learn this in production.

Talk to the engineers behind these write-ups — no sales script, a straight read on where you stand.

Get a fixed quote