Web Application Vulnerability Assessment
Independent assessment combining automated discovery with manual validation of high-severity findings. OWASP Top 10:2025. Signed Attestation Letter included.
Quick Answer
Independent vulnerability assessment of one web application. Combines automated discovery (Burp Suite Professional, Nuclei, OWASP ZAP) with manual validation of high-severity findings. Delivers structured VA report mapped to OWASP Top 10:2025 with CVSS v3.1 vectors and CWE classification. Includes signed Attestation Letter identifying the engagement as Vulnerability Assessment. Suitable evidence for ISO 27001 Annex A.8.8, GDPR Article 32 risk assessment, and many vendor security questionnaires.
Why You Need This
Most compliance scenarios require evidence of regular security testing, but not all of them specifically demand a full penetration test. Vulnerability Assessment is the legitimate, audit-recognised baseline — and it's the right fit when your auditor accepts "regular vulnerability testing" rather than "penetration testing specifically", your enterprise prospect's vendor security questionnaire asks generally about "security testing", you need baseline security validation before investing in a full penetration test, or your budget doesn't yet support full pentest engagement (€1,800+).
What VA is not: it is not a substitute for a penetration test where regulation specifically demands one. ISO 27001 Annex A.8.29 requires "security testing" which most auditors interpret as penetration testing. Where the requirement specifically names "penetration test", choose our Focused Pentest (€1,800+) instead.
Who Requires This From You
- ISO/IEC 27001:2022 Annex A.8.8 — Management of technical vulnerabilities
- GDPR Article 32 — Regular testing of effectiveness of security measures
- Some vendor security questionnaires — those asking about "regular security testing" without specifying penetration test
- Internal security baselines — for SaaS in pre-Series-A stage
What You Get
Automated discovery and scanning
- Burp Suite Professional (current licensed version)
- Nuclei with curated, regularly-updated templates
- OWASP ZAP automated baseline scan
- Subfinder + httpx for asset inventory
Manual validation of all high-severity findings
- Critical and High findings manually validated to eliminate false positives
- CVSS v3.1 vectors for each finding
- CWE classification per finding
- OWASP Top 10:2025 mapping
Deliverables
- Structured Vulnerability Assessment Report (executive summary, methodology, findings)
- Remediation guidance per finding
- Signed Attestation Letter explicitly identifying the engagement as Vulnerability Assessment
- One round of clarification questions within 14 days of delivery
What Happens If You Don't
Our Process
Is This the Right Penetration Test for You?
You should choose this tier if…
- You need cheap security testing for baseline compliance evidence
- Your ISO 27001 auditor needs Annex A.8.8 (Management of technical vulnerabilities) evidence
- You're doing vulnerability scanning for GDPR Article 32 risk assessment
- You need a web application security scan with expert validation
- You're an early-stage SaaS on tight budget seeking first security evidence
- Your enterprise customer asked 'when was your last vulnerability scan?'
Common scenarios
"We need something on our security page to close enterprise deals, but we can't afford £5,000 pen tests yet."
"The auditor wants evidence of regular vulnerability testing (A.8.8). This is the cheapest defensible option."
"We need to show the DPA authority we're doing 'regular vulnerability assessment' per Article 32."
"We had a full pen test last year, but need something between annual tests to catch new vulnerabilities."
What buyers search for that leads here
Most buyers who choose our €539 Vulnerability Assessment first search for "cheap vulnerability assessment", "web app vulnerability scan cost", "OWASP Top 10 scan services", or "GDPR Article 32 vulnerability testing".
A Vulnerability Assessment is fundamentally different from a Penetration Test. VA is breadth-first — we scan for all known vulnerabilities using automated tools (Burp Suite Professional, Nuclei, OWASP ZAP), then manually validate high-severity findings to remove false positives. We produce a structured report with CVSS v3.1 scoring.
We do NOT exploit vulnerabilities to prove impact, test business logic flaws, or attempt to chain multiple weaknesses. If you need that depth, choose our Focused Web Application Penetration Test (€1,800) instead.
Real-world cost comparison: UK CREST-accredited providers charge £1,500–£3,000 for equivalent vulnerability assessments. Our €539 (~£465) delivers the same quality of finding identification with signed Attestation Letter — 60–70% cost saving.
When to choose a different tier instead
| Signal | Recommended service |
|---|---|
| Enterprise customer asked for 'recent penetration test' specifically | Focused Pentest (€1,800) |
| ISO 27001 Annex A.8.29 evidence required | Focused Pentest (€1,800) |
| Cyber insurance underwriter requires pentest | Focused Pentest (€1,800) |
| Multi-tenant SaaS with REST API | Standard Pentest (€4,500) |
| SOC 2 Type II preparation | Standard Pentest (€4,500) |
Frequently asked questions about this tier
What's the difference between a vulnerability assessment and a penetration test?
A VA identifies known weaknesses using automated scanning with manual validation. A pentest actively exploits those weaknesses to prove impact. VA is breadth-first, pentest is depth-first. VA is typically 60–70% cheaper.
Will my ISO 27001 auditor accept this?
For Annex A.8.8 (Management of technical vulnerabilities), typically yes. Our Attestation Letter is explicit that this is a Vulnerability Assessment. For Annex A.8.29 (Security testing in development), most auditors require a full pentest — consider our Focused Pentest tier.
How is €539 possible when UK providers charge £1,500–3,000?
Our Chișinău cost base (Moldova IT Park) is lower than London or Manchester. Same OWASP methodology (WSTG v4.2), same CVSS v3.1 scoring, same signed Attestation Letter. Different geography = different price.
What tools do you use?
Burp Suite Professional, Nuclei with all recent templates, OWASP ZAP, plus custom checks. All findings manually validated by our senior pentester before inclusion in the report.
Do you test authenticated users?
The €539 tier includes unauthenticated scanning plus basic authenticated scanning (single role). If you need full authenticated multi-role testing, upgrade to our Focused Pentest (from €1,800).
Do I get a Rules of Engagement document?
Yes. Standard Rules of Engagement, mutual NDA, and DPA templates are signed before testing starts.
How long does the report take?
5 business days from testing completion. Rush delivery (3 days) can be accommodated when available.
Can I get a sample report?
Yes, under NDA. Contact us to request the sample.
Pricing & Delivery
€539 fixed price — one web application, public attack surface. Add-ons: Authenticated testing → upgrade to Focused Pentest (€1,800+). REST API depth → upgrade to Standard Pentest (€4,500+). Remediation retest → +€200.
Frequently Asked Questions
Is this a penetration test?
No. This is a Vulnerability Assessment (VA). The Attestation Letter explicitly identifies it as VA. We use this honest labelling because the difference matters in audit and procurement contexts. If your requirement specifically names "penetration test", choose our Focused Pentest (€1,800+) instead.
Will my auditor accept this?
It depends on your specific control requirement. For ISO 27001 Annex A.8.8 (Management of Technical Vulnerabilities) — typically yes. For Annex A.8.29 (Security testing in development and acceptance) — auditor-dependent; most accept it but some specifically require pen testing. We recommend confirming with your auditor before purchase.
How is this different from a free online scanner?
Three things: (1) we use Burp Suite Professional, Nuclei, and OWASP ZAP — professional commercial-grade tools, not free SaaS scanners; (2) every high-severity finding is manually validated by a certified engineer to eliminate false positives; (3) we deliver a structured report and signed Attestation Letter recognised in audit contexts. Free scanners deliver raw output with no validation and no formal report.
What if you find Critical vulnerabilities?
Critical-severity findings are communicated to your nominated contact within 4 hours of validation via secure channel, with clear reproduction steps and immediate remediation guidance. We don't wait for the report delivery date.
Can I order this anonymously?
You need to be the legitimate owner or authorised representative of the target application — we will verify this during NDA signature. Beyond that, your engagement is held under strict confidentiality.
