
Vulnerability Assessment Services: What the Quote Must Say
Comparing vulnerability assessment services? Check five things in every quote: what counts as an asset, authenticated or not, validation, the report, and the rescan.
The short answer
A vulnerability assessment quote is comparable only if it states five things: the unit it counts as one asset, how the target list is defined or discovered, whether scans are authenticated, who validates findings by hand, and whether a rescan is included. Providers can quote the same estate at very different prices because they are counting different things and delivering different artefacts. Get those five in writing before comparing price, and treat a quote that names a scanner brand but none of them as a scan, not an assessment.
Who this is for
This is for the security lead, head of infrastructure or procurement owner at a casino, crypto exchange or fintech who has two or three vulnerability assessment proposals on the desk and cannot tell why they differ. It is about reading the quote. For what an external scan covers on a casino perimeter, see scoping an external vulnerability assessment for a casino; for what to do with the results, see turning a scanner's critical list into a fix queue.
The five lines to look for
| Quote line | What to ask | Why it changes the price and the result |
|---|---|---|
| Unit of count | Is an asset an IP address, a hostname, an application, or a cloud account? | The same estate is a different number under each unit. Load balancers, shared hosting and short-lived cloud instances are where counts diverge. |
| Target list | Who supplies it, and is discovery included? | A list you wrote misses what you forgot. Discovery finds forgotten assets but needs agreed boundaries. |
| Authentication | Which targets are scanned with credentials, which without? | Authenticated checks read configuration directly. Unauthenticated ones infer from what a stranger sees. |
| Validation | Does a person confirm findings before they reach the report? | Without it, version-guess false positives and unreachable findings go straight into your queue. |
| Rescan | Included, optional, or absent? How long after delivery? | Without a rescan you learn whether fixes worked only at the next cycle. |
Line 1: what counts as one asset
Providers price by a unit, and the unit is rarely the one you think in. An engineering team counts services; a quote may count IP addresses. A cloud estate with autoscaling groups can produce many addresses over a month from a handful of services. Ask for the unit in writing, and ask what happens when the estate changes during the engagement: is a new instance in scope, out of scope, or a change order?
Line 2: the target list
An assessment of a list you supplied tests that list. It says nothing about the staging host someone left open or the old subdomain still pointing at a live service. Ask whether discovery is part of the quote, and if it is, what the provider will do with an asset that turns out not to be yours. Hosts run by a third party need that party's permission before anyone scans them; the quote should say who obtains it.
Line 3: authenticated or not
An unauthenticated scan sees open services, banners and responses. An authenticated one logs in and reads packages and configuration, which finds more and guesses less, but needs credentials and rules about what the scanner may touch. A sound quote splits the two: credentials for the systems where the answer matters most, anonymous scanning for the outside view, and a sentence on which is which.
Line 4: who validates
This is the line that separates an assessment from a scan. Scanners infer vulnerabilities from version strings, and a vendor that backported a fix without changing the version produces a finding that is not real. Others are real but unreachable. A quote should say that a named person reviews the findings, removes the noise and records what they could not confirm. Ask whether manual validation covers every finding or a sample, because the answer determines how much triage lands on your team.
Line 5: the report and the rescan
The deliverable should be a de-duplicated, prioritised list grouped by affected asset, with evidence for each finding, a concrete fix, and a statement of what was not scanned. Ask for a redacted sample report before you sign. Then ask about the rescan: whether it is included, the window in which you can request it, and which findings it covers. A rescan confirms that a signature is gone; for anything found by hand, the narrower retest described in what counts as fixed after a pentest applies.
Red flags in a quote
- The deliverable is described as "scan output" or "scanner export".
- No unit of count, or a unit that changes between pages.
- "Unlimited scans" with no statement of who reviews the results.
- No sentence on what was out of scope.
- A compliance badge promised without naming the standard or the scope it applies to.
Limitations
This is a reading guide, not a price list or a recommendation of any scanner. It states no market prices, no turnaround times and no AnySec-original figures. Compliance scans such as those required for card-payment environments have their own rules; read the current text of the programme that applies to you.
What to do next
Put your proposals side by side against the table above and send the gaps back as questions. If you would like a quote that answers all five lines up front, request a fixed quote for a vulnerability assessment and tell us the asset types and whether you need external, internal or both. The Vulnerability Assessment page describes how an engagement runs. If the assessment is the first step toward fixing what it finds, the Security Hardening page covers the follow-on.
Frequently asked questions
What should a vulnerability assessment quote include? The asset unit, the target list or discovery method, authentication, manual validation, the report contents, and the rescan.
Is a vulnerability assessment priced per IP address? Often, but some count hostnames, applications or cloud accounts. Ask for the unit in writing.
What is the difference between a scan and a vulnerability assessment? A scan is a tool run. An assessment adds scoping, validation, prioritisation and a report.
Should a vulnerability assessment be authenticated? For the systems that matter most, where credentials and boundaries can be agreed. The quote should say which.
Does a vulnerability assessment include a rescan? Only if the quote says so. Ask about the window and the findings covered.
Sources and review
This article describes procurement practice in general terms and cites no statistics, prices or AnySec-original numbers, case results or SLA figures. Author: AnySec Engineering. Published 2026-10-08; last reviewed 2026-10-08.
Related reading
- Vulnerability scan results: turning a scanner's critical list into a fix queue — what to do once the report arrives.
- Scoping an external vulnerability assessment for a casino — what the perimeter scan covers and cannot prove.
- Vulnerability assessment vs penetration testing for iGaming — when the quote should be a pentest instead.
- Server hardening services: scan, script, or engagement? — the same quote-reading approach for hardening.
Keep reading
All insights →Rather not learn this in production.
Talk to the engineers behind these write-ups — no sales script, a straight read on where you stand.
Get a fixed quote
