A fixed-fee CyPro product
Vulnerability assessment services, productised and priced
The assessment that starts every engagement, with the fee published before you ever speak to us: a scoped scan, findings ranked by how exploitable they really are, a remediation plan your team can act on, and a retest to prove the fixes worked.
What is a vulnerability assessment?
A vulnerability assessment service is a structured engagement in which security consultants sweep your systems for known weaknesses, verify and prioritise what they find, and deliver a remediation plan ranked by real-world risk. Where you already run a scanner such as Nessus, Tenable or Qualys, we deliver the assessment through your own tooling; where you do not, we run tooling for the duration of the engagement. Either way, the value sits in what surrounds the scan: the analysis, the prioritisation, the remediation plan and the retest. Unlike raw scan output, an assessment adds human judgement, so you know which findings matter and in what order to fix them.
That last part is where most of the market falls down. Established UK consultancies typically charge in excess of £1,000 a day for traditional assessments, and almost all of them price by quotation only: you fill in a form, wait for a call, and negotiate a statement of work before you learn a number. We deliver the assessment as the first cycle of the managed service: your scanners connected, the full backlog ingested, our proprietary risk analysis run across everything, and the baseline report with a prioritised remediation plan, at the monthly band price printed on the pricing page and confirmed in writing before work starts. Fixes are retested as they land in the cycles that follow, because an assessment that ends at the findings list is only half finished.
Every assessment is a cyber security vulnerability assessment in the full sense: an IT vulnerability assessment of your infrastructure, delivered by a UK consultant employed by CyPro Ltd, the security consultancy behind this service. No offshore triage queue, no report generated straight from a scanner and posted on. A person who understands your environment reads every finding before you do.
Scope
What the assessment covers
Scope is agreed on the free call, in plain terms: which parts of your estate, from which vantage points, in which window. Three layers are on the table.
External infrastructure
Everything an attacker can reach from the internet: web servers, applications, remote access services, mail and DNS. We map what you actually have exposed, then test it for known weaknesses, weak configuration and services that should never have been public.
Internal network
What an attacker, or a compromised laptop, could reach once inside your network: unpatched servers and endpoints, legacy protocols still switched on, weak service configuration and the flat-network paths that turn one foothold into many.
Cloud configuration review
Your cloud estate reviewed for the mistakes that cause real breaches: storage open to the world, management interfaces exposed to the internet, over-permissive identities and missing hardening on the services your business runs on.
Ranked by exploitability, not just a score
Two findings can carry the same CVSS score and pose entirely different levels of danger. Our proprietary risk analysis weighs each one against what actually matters: whether a working exploit is circulating, whether the affected system is reachable, and the business value of what an attacker would gain by landing on it. The plan you receive is ordered by actual exposure, so the first items on the list are the ones that genuinely reduce your risk, not the ones a scoring formula happened to rate highest.
First cycle, then the rhythm
How an assessment differs from managed scanning
The first assessment cycle
Answers the question "where do we stand today?". Your scanners connected, the historical backlog ingested and deduplicated, every finding risk-analysed, and a baseline report with a prioritised remediation plan. That is this page's service, and it is how every engagement starts.
The managed scanning service
Answers the harder question: "are we staying on top of it?". New weaknesses are published daily, and estates drift. Our managed vulnerability scanning service keeps the cycle running on your own scanner, with a consultant triaging every cycle, at a published monthly price you can check on the pricing page right now.
The two are the same service at different moments. The first cycle produces the baseline, clears the backlog of historical findings and makes the case visible; the cycles that follow keep the estate honest month after month, so the same drift is never rediscovered a year later. There is no separate assessment product to buy and outgrow: you start the service, and the assessment is how it starts.
Timing
When an assessment is the moment to start
Four situations bring most UK businesses to this page. Reviewed July 2026.
Before an audit or certification
Your Cyber Essentials Plus assessor will scan in-scope systems, and an ISO 27001 auditor will ask for vulnerability management evidence under control A.8.8. An assessment finds what they would find, weeks before they do, with time to fix it.
After an incident or near miss
Once the immediate response is over, the obvious question is what else is exposed. A scoped assessment answers it with evidence rather than reassurance, and the retest proves the gaps were actually closed.
Acquisition due diligence
Buying a company means buying its unpatched servers. An assessment of the target's estate puts a factual finding list on the deal table, priced as a fixed fee you can put in the diligence budget from day one.
An insurer or client is asking
Cyber insurance proposal forms and enterprise client questionnaires increasingly ask when you last had your estate assessed. The report and closure statement are written to be handed over as the answer.
What you receive
Deliverables, end to end
Everything is written to be used: by the engineer fixing the finding, the manager sequencing the work and the director answering for it.
Findings report
Every verified weakness with the evidence behind it, the assets affected and its severity judged in your context, not copied from a generic score.
Prioritised remediation plan
Findings ordered by real exploitability and business impact, with quick wins separated from project work, so your team knows what to fix first and why.
Executive summary
A plain-English account of your position for the board, an insurer or a client, written to be read by people who will never open the technical annex.
Retest and closure statement
Once you have remediated, we test the fixed items again and record what closed. The retest is part of the fixed fee, not an extra line on a second invoice.
Our remediation guidance tells your team exactly what to change and how to verify it; the fixing itself stays in your hands or your IT provider's. If a finding calls for deeper offensive testing, that is penetration testing, delivered by CyPro's CREST-accredited team under its own scope. The how it works page walks through the whole sequence, from scoping call to closure statement.
Assessment plus pen testing
Need both halves of VAPT? How the assessment leg pairs with CREST penetration testing.
VAPT explainedTaking card payments?
PCI DSS requires quarterly external ASV scans. We manage the whole cycle for you.
PCI ASV scanningThe process in detail
Scan, human triage, prioritised fix list, retest: each step of the engagement explained.
How it worksBefore you book
Assessment questions, answered
How long does a vulnerability assessment take?
The scanning window itself is short, typically a matter of days depending on the size of the estate, and is agreed with you at scoping so it lands when your team can accommodate it.
The full engagement runs from scoping call to retest: scan, human triage of the results, delivery of the report and remediation plan, then the retest once your fixes are in. The timetable is set out in writing before work starts.
Will the assessment disrupt our systems?
Assessment scanning is designed to observe, not to break. We agree the scope, the scanning window and any fragile systems with you in advance, and anything sensitive can be scheduled out of hours.
Disruptive techniques such as active exploitation belong to penetration testing, which is a separate, deliberately scoped exercise. An assessment does not attempt them.
What is the difference between a vulnerability assessment and a penetration test?
An assessment identifies and prioritises known weaknesses across your estate in breadth. A penetration test goes narrow and deep: a human tester actively attempts to exploit weaknesses and chain them together, the way a real attacker would.
Many organisations need both, in that order. Our VAPT page explains how a productised assessment pairs with penetration testing delivered by CyPro's CREST-accredited team.
How much does a vulnerability assessment cost?
The assessment is delivered as the first cycle of the managed service, so it costs the first month of your band: £1,890 for one scanner, £2,870 for up to five, from £3,450 for larger estates, each ex VAT and confirmed in writing before any work begins. Retesting of fixes is part of the ongoing cycle.
Established UK consultancies typically charge in excess of £1,000 a day for standalone assessments, almost always by quotation only. Our fees are printed on the pricing page instead.
Fixed fee, known finish line
Get your assessment scoped this week
Forty-five minutes with a consultant, free and without obligation, covers what you have exposed, what the assessment would include for your estate, and the exact fixed fee, confirmed in writing before you commit to anything.