🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Vulnerability Assessment
✓ EU Compliant

Web Application Vulnerability Assessment

Independent assessment combining automated discovery with manual validation of high-severity findings. OWASP Top 10:2025. Signed Attestation Letter included.

€539
5 business days

Quick Answer

Independent vulnerability assessment of one web application. Combines automated discovery (Burp Suite Professional, Nuclei, OWASP ZAP) with manual validation of high-severity findings. Delivers structured VA report mapped to OWASP Top 10:2025 with CVSS v3.1 vectors and CWE classification. Includes signed Attestation Letter identifying the engagement as Vulnerability Assessment. Suitable evidence for ISO 27001 Annex A.8.8, GDPR Article 32 risk assessment, and many vendor security questionnaires.

PayPal · SSL Senior only 14-day warranty SEC-PENT-01

Why You Need This

Most compliance scenarios require evidence of regular security testing, but not all of them specifically demand a full penetration test. Vulnerability Assessment is the legitimate, audit-recognised baseline — and it's the right fit when your auditor accepts "regular vulnerability testing" rather than "penetration testing specifically", your enterprise prospect's vendor security questionnaire asks generally about "security testing", you need baseline security validation before investing in a full penetration test, or your budget doesn't yet support full pentest engagement (€1,800+).

What VA is not: it is not a substitute for a penetration test where regulation specifically demands one. ISO 27001 Annex A.8.29 requires "security testing" which most auditors interpret as penetration testing. Where the requirement specifically names "penetration test", choose our Focused Pentest (€1,800+) instead.

Who Requires This From You

  • ISO/IEC 27001:2022 Annex A.8.8 — Management of technical vulnerabilities
  • GDPR Article 32 — Regular testing of effectiveness of security measures
  • Some vendor security questionnaires — those asking about "regular security testing" without specifying penetration test
  • Internal security baselines — for SaaS in pre-Series-A stage

What You Get

Automated discovery and scanning

  • Burp Suite Professional (current licensed version)
  • Nuclei with curated, regularly-updated templates
  • OWASP ZAP automated baseline scan
  • Subfinder + httpx for asset inventory

Manual validation of all high-severity findings

  • Critical and High findings manually validated to eliminate false positives
  • CVSS v3.1 vectors for each finding
  • CWE classification per finding
  • OWASP Top 10:2025 mapping

Deliverables

  • Structured Vulnerability Assessment Report (executive summary, methodology, findings)
  • Remediation guidance per finding
  • Signed Attestation Letter explicitly identifying the engagement as Vulnerability Assessment
  • One round of clarification questions within 14 days of delivery

What Happens If You Don't

ISO 27001 auditor flags A.8.8 control as having insufficient evidence
GDPR Article 32 risk assessment is incomplete
Vendor security questionnaire returned with "no recent independent testing" — application stalled

Our Process

1
Order placement
Confirm target application URL, contact email, preferred delivery date.
2
Mutual NDA signature (Day 1)
Sent within 1 business hour of order.
3
Brief intake form (Day 1)
Basic scope information, no test accounts needed for unauthenticated scope.
4
Active assessment (Days 2–4)
Automated discovery + manual validation of high-severity findings.
5
Report delivery (Day 5)
VA report + Attestation Letter as encrypted archive, password via separate channel.

Is This the Right Penetration Test for You?

You should choose this tier if…

  • You need cheap security testing for baseline compliance evidence
  • Your ISO 27001 auditor needs Annex A.8.8 (Management of technical vulnerabilities) evidence
  • You're doing vulnerability scanning for GDPR Article 32 risk assessment
  • You need a web application security scan with expert validation
  • You're an early-stage SaaS on tight budget seeking first security evidence
  • Your enterprise customer asked 'when was your last vulnerability scan?'

Common scenarios

Pre-Series-A SaaS founder

"We need something on our security page to close enterprise deals, but we can't afford £5,000 pen tests yet."

Compliance manager preparing ISO 27001

"The auditor wants evidence of regular vulnerability testing (A.8.8). This is the cheapest defensible option."

CTO handling GDPR requests

"We need to show the DPA authority we're doing 'regular vulnerability assessment' per Article 32."

Growing startup between pen tests

"We had a full pen test last year, but need something between annual tests to catch new vulnerabilities."

What buyers search for that leads here

Most buyers who choose our €539 Vulnerability Assessment first search for "cheap vulnerability assessment", "web app vulnerability scan cost", "OWASP Top 10 scan services", or "GDPR Article 32 vulnerability testing".

A Vulnerability Assessment is fundamentally different from a Penetration Test. VA is breadth-first — we scan for all known vulnerabilities using automated tools (Burp Suite Professional, Nuclei, OWASP ZAP), then manually validate high-severity findings to remove false positives. We produce a structured report with CVSS v3.1 scoring.

We do NOT exploit vulnerabilities to prove impact, test business logic flaws, or attempt to chain multiple weaknesses. If you need that depth, choose our Focused Web Application Penetration Test (€1,800) instead.

Real-world cost comparison: UK CREST-accredited providers charge £1,500–£3,000 for equivalent vulnerability assessments. Our €539 (~£465) delivers the same quality of finding identification with signed Attestation Letter — 60–70% cost saving.

When to choose a different tier instead

SignalRecommended service
Enterprise customer asked for 'recent penetration test' specificallyFocused Pentest (€1,800)
ISO 27001 Annex A.8.29 evidence requiredFocused Pentest (€1,800)
Cyber insurance underwriter requires pentestFocused Pentest (€1,800)
Multi-tenant SaaS with REST APIStandard Pentest (€4,500)
SOC 2 Type II preparationStandard Pentest (€4,500)

Frequently asked questions about this tier

What's the difference between a vulnerability assessment and a penetration test?

A VA identifies known weaknesses using automated scanning with manual validation. A pentest actively exploits those weaknesses to prove impact. VA is breadth-first, pentest is depth-first. VA is typically 60–70% cheaper.

Will my ISO 27001 auditor accept this?

For Annex A.8.8 (Management of technical vulnerabilities), typically yes. Our Attestation Letter is explicit that this is a Vulnerability Assessment. For Annex A.8.29 (Security testing in development), most auditors require a full pentest — consider our Focused Pentest tier.

How is €539 possible when UK providers charge £1,500–3,000?

Our Chișinău cost base (Moldova IT Park) is lower than London or Manchester. Same OWASP methodology (WSTG v4.2), same CVSS v3.1 scoring, same signed Attestation Letter. Different geography = different price.

What tools do you use?

Burp Suite Professional, Nuclei with all recent templates, OWASP ZAP, plus custom checks. All findings manually validated by our senior pentester before inclusion in the report.

Do you test authenticated users?

The €539 tier includes unauthenticated scanning plus basic authenticated scanning (single role). If you need full authenticated multi-role testing, upgrade to our Focused Pentest (from €1,800).

Do I get a Rules of Engagement document?

Yes. Standard Rules of Engagement, mutual NDA, and DPA templates are signed before testing starts.

How long does the report take?

5 business days from testing completion. Rush delivery (3 days) can be accommodated when available.

Can I get a sample report?

Yes, under NDA. Contact us to request the sample.

Pricing & Delivery

€539
5 business days

€539 fixed price — one web application, public attack surface. Add-ons: Authenticated testing → upgrade to Focused Pentest (€1,800+). REST API depth → upgrade to Standard Pentest (€4,500+). Remediation retest → +€200.

PayPal · SSL Senior only 14-day warranty SEC-PENT-01

Frequently Asked Questions

Is this a penetration test?

No. This is a Vulnerability Assessment (VA). The Attestation Letter explicitly identifies it as VA. We use this honest labelling because the difference matters in audit and procurement contexts. If your requirement specifically names "penetration test", choose our Focused Pentest (€1,800+) instead.

Will my auditor accept this?

It depends on your specific control requirement. For ISO 27001 Annex A.8.8 (Management of Technical Vulnerabilities) — typically yes. For Annex A.8.29 (Security testing in development and acceptance) — auditor-dependent; most accept it but some specifically require pen testing. We recommend confirming with your auditor before purchase.

How is this different from a free online scanner?

Three things: (1) we use Burp Suite Professional, Nuclei, and OWASP ZAP — professional commercial-grade tools, not free SaaS scanners; (2) every high-severity finding is manually validated by a certified engineer to eliminate false positives; (3) we deliver a structured report and signed Attestation Letter recognised in audit contexts. Free scanners deliver raw output with no validation and no formal report.

What if you find Critical vulnerabilities?

Critical-severity findings are communicated to your nominated contact within 4 hours of validation via secure channel, with clear reproduction steps and immediate remediation guidance. We don't wait for the report delivery date.

Can I order this anonymously?

You need to be the legitimate owner or authorised representative of the target application — we will verify this during NDA signature. Beyond that, your engagement is held under strict confidentiality.