Two disciplines, priced apart

VAPT, unbundled: continuous assessment + CREST pen testing

Most VAPT services arrive as one opaque quote. The two halves do different jobs on different clocks, so we split them: managed vulnerability assessment from us at a published price, penetration testing scoped and quoted by CyPro's CREST accredited team.

What is VAPT?

Vulnerability assessment and penetration testing, defined

VAPT stands for vulnerability assessment and penetration testing, the combined discipline of finding and proving security weaknesses. The vulnerability assessment casts a wide net: broad scanning of your systems, with every finding triaged and prioritised by an analyst. Penetration testing then goes deep: targeted manual work by an accredited tester to prove which weaknesses an attacker could genuinely exploit.

Here is what the acronym hides: those are two different services. One is broad, recurring and cheap enough to run monthly. The other is deep, manual and expensive enough that it should be scoped deliberately. Most VAPT services are sold as a single line item, which makes it hard to see what each half costs, how often each should run, or whether you are paying testing rates for work a scanning cycle should be doing. Some buyers call the whole discipline vulnerability testing; the same split applies whatever you call it.

So we unbundle it. The assessment leg is ours: managed vulnerability scanning with human triage at a published monthly price, run on the scanner you already licence with our risk analysis on top; the first cycle is the assessment that establishes your baseline. The testing leg belongs to CyPro's CREST accredited penetration testing team, who scope and quote it separately. You see both numbers, and you decide when each half runs.

The two halves

Assessment and penetration testing, side by side

Different jobs, different cadences, different price shapes. Once you see them apart, you can buy each one properly.

Vulnerability assessment Penetration testing
The job Find and prioritise weaknesses across the whole estate: missing patches, misconfigurations, exposed services, weak protocols. Prove what a skilled attacker could do with them: chain weaknesses together, escalate access, reach the data that matters.
Cadence Recurring. Monthly or weekly scans, with new findings triaged as they appear. Point in time. Typically annual, and after significant change to systems or applications.
Output A prioritised fix list with severity, exploit context and remediation guidance, refreshed every cycle. A report of the paths actually exploited, evidence of impact, remediation advice and a retest.
Price shape A published monthly fee that scales with your scanner count. A scoped quote agreed before any work starts.
Delivered by Us: the managed vulnerability process run on your own scanner, with an analyst triaging every finding. CyPro's CREST accredited testing team, quoted separately.

The left column is what this site sells, priced on the pricing page. The right column is CREST penetration testing delivered by CyPro, scoped as its own engagement with its own quote.

Three questions for any VAPT quote

Whoever you buy from, put these to anyone selling VAPT testing as a single figure:

  • How much of the fee is assessment and how much is testing? If the split is not on the quote, you cannot judge either half, or drop the half you do not need this year.
  • What happens between tests? A test report dated last spring says nothing about the weakness disclosed this morning; the recurring assessment cycle is what covers that gap.
  • Who performs the manual testing, and under which accreditation scheme? A named, accredited testing team is a different purchase from an anonymous bench.

Our answers are the point of this page: the split is two price lines, the gap is covered by a monthly cycle run on your own scanner with analyst triage, and the testing is CREST work carried out by CyPro.

When you need which

What the compliance regimes actually ask for

Most VAPT purchases are triggered by an auditor, an acquirer or an insurer. None of them asks for a bundle; each asks for specific evidence.

PCI DSS

The one regime that plainly wants both halves: recurring internal and external vulnerability scans, with the quarterly external scans run by a PCI-SSC Approved Scanning Vendor, plus penetration testing. We run the scanning programme, with ASV scans arranged through an Approved Scanning Vendor partner and managed by us, and CyPro scopes the testing.

Cyber Essentials Plus

The scheme never uses the word VAPT, but your assessor will scan in-scope systems during the audit. A monthly assessment cycle means those scans confirm what you already know, instead of surfacing surprises inside the certification window.

ISO 27001

Control A.8.8 of the 2022 Annex expects technical vulnerabilities to be managed: a defined cadence, triage decisions and treatment evidence. A recurring assessment produces exactly that record. A penetration test strengthens the evidence file, but the control is satisfied by management, not by a single test.

Cyber insurance

Proposal forms increasingly ask how often you scan, how findings are treated and when you were last penetration tested. Running the two halves on their proper cadences gives every one of those questions a specific, dated answer.

Reviewed July 2026.

Our VAPT service

One scope, two price lines

You get a VAPT programme with each half on its own line, so the recurring cost and the engagement cost never blur into one number.

Step 1

Choose the assessment leg

The managed service from £1,890 a month runs the cycle on your own scanner, with every finding put through our proprietary risk analysis and a report each cycle. The first cycle doubles as the assessment: a full prioritised findings list and remediation plan, with fixes retested as they land. Every figure sits on the pricing page.

Step 2

Scope the testing leg with CyPro

When a penetration test is due, we hand the scoping conversation to CyPro's CREST accredited penetration testers, who quote it as a separate engagement. You approve that spend knowing exactly what it is for, and it never inflates your monthly fee.

Step 3

Run each half on its own clock

The scanning cycle keeps running between tests, so test findings get retested and new weaknesses surface within days rather than at the next annual engagement. How the cycle runs, from scan to triage to fix list.

Judging the paperwork

What a VAPT report should contain

If a VAPT service hands you one undifferentiated PDF, that is the bundle problem on paper. You should receive two documents doing two jobs.

The assessment report, every cycle

  • Findings prioritised by real-world exploitability, not raw severity scores alone
  • Plain remediation guidance per finding: what to change, where, and in what order
  • Movement against the last cycle: what was fixed, what is new, what is still open
  • A summary written for whoever owns the risk, not just the engineers

The penetration test report, per engagement

  • The agreed scope and the paths the tester actually attempted
  • Evidence of each successful exploit and the business impact it demonstrates
  • Remediation advice and a retest window to confirm fixes hold
  • This document comes from the testing engagement, which for our clients means CyPro's CREST penetration testing practice

VAPT questions

Asked before buying

What is VAPT?

VAPT stands for vulnerability assessment and penetration testing, two disciplines usually sold together. The assessment is broad and recurring: scan the estate, triage what comes back, fix in priority order. The penetration test is deep and point in time: a skilled tester proves what an attacker could actually achieve.

They complement each other, which is why they get bundled. They are not the same work, which is why we price them separately.

How often should VAPT be carried out?

Each half has its own clock. Vulnerability assessment should be recurring, monthly at minimum and weekly for larger or faster-changing estates, because new weaknesses are disclosed daily. Penetration testing is typically annual, plus after significant change such as a new application, a migration or a major infrastructure change.

Compliance can set the floor: PCI DSS expects quarterly external scans and defined testing intervals, and ISO 27001 auditors want to see a cadence you actually keep to.

How the scanning cycle runs

Is VAPT required for ISO 27001, PCI DSS or Cyber Essentials Plus?

No framework mandates a product called VAPT, but most expect its ingredients. PCI DSS requires both recurring vulnerability scans and penetration testing. ISO 27001 control A.8.8 expects vulnerabilities to be identified and treated on a managed cadence. Cyber Essentials Plus involves your assessor scanning in-scope systems during the audit. Cyber insurers ask about scanning cadence and testing dates on proposal forms.

Can we buy just one half?

Yes, and most organisations should start that way. The assessment leg is available on its own as the managed monthly service, at published prices, with the first cycle establishing your baseline. When a penetration test is due, CyPro's CREST accredited team scopes and quotes it as its own engagement, so you approve that spend on its own merits.

Penetration testing by CyPro

Rocket above the Managed Vulnerability Scanning call to action

Scope both halves in one call

Get a VAPT scope with each half priced on its own line

Forty-five free minutes with a consultant establish what your assessment cycle should cover and at what cadence, and whether a penetration test is actually due yet. You leave with our published band and, where testing is needed, a separate CyPro quote to approve or decline.