🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Vulnerability Assessment
✓ EU Compliant

Web Application Vulnerability Assessment

Independent assessment combining automated discovery with manual validation of high-severity findings. OWASP Top 10:2025. Signed Attestation Letter included.

€539
9–10 business days

Quick Answer

Independent vulnerability assessment of one web application. Combines automated discovery (Burp Suite Professional, Nuclei, OWASP ZAP) with manual validation of high-severity findings. Delivers structured VA report mapped to OWASP Top 10:2025 with CVSS v3.1 vectors and CWE classification. Includes signed Attestation Letter identifying the engagement as Vulnerability Assessment. Suitable evidence for ISO 27001 Annex A.8.8, GDPR Article 32 risk assessment, and many vendor security questionnaires.

PayPal · SSL Senior only 14-day warranty SEC-PENT-01

Vulnerability Assessment vs. Penetration Test

Not sure which one you need? Here's the honest comparison.

DimensionVulnerability AssessmentPenetration Test
GoalIdentify and validate known weaknessesProve exploitability and attack-chain impact
MethodAutomated scanning plus manual validation of high-severity findingsManual exploitation attempted on every finding, business logic tested
ExploitationNoYes, within Rules of Engagement
ScopePublic, unauthenticated attack surface of one applicationAuthenticated and unauthenticated, multiple roles
Delivery9–10 business days1.5–2 weeks (Focused tier)
Price€539 fixedFrom €1,800
SatisfiesISO 27001 A.8.8, GDPR Art. 32, many vendor questionnairesISO 27001 A.8.29, PCI DSS 11.4, cyber insurance, most enterprise reviews
Attestation LetterStates explicitly: Vulnerability AssessmentStates explicitly: Penetration Test

Need real exploitation and business-logic testing? See our Focused Web Application Penetration Test.

Why You Need This

Most compliance scenarios require evidence of regular security testing, but not all of them specifically demand a full penetration test. Vulnerability Assessment is the legitimate, audit-recognised baseline — and it's the right fit when your auditor accepts "regular vulnerability testing" rather than "penetration testing specifically", your enterprise prospect's vendor security questionnaire asks generally about "security testing", you need baseline security validation before investing in a full penetration test, or your budget doesn't yet support full pentest engagement (€1,800+).

What VA is not: it is not a substitute for a penetration test where regulation specifically demands one. ISO 27001 Annex A.8.29 requires "security testing" which most auditors interpret as penetration testing. Where the requirement specifically names "penetration test", choose our Focused Pentest (€1,800+) instead.

Who Requires This From You

  • ISO/IEC 27001:2022 Annex A.8.8 — Management of technical vulnerabilities
  • SOC 2 Trust Services Criteria CC7.1 — Detection of vulnerabilities
  • GDPR Article 32 — Regular testing of effectiveness of security measures
  • NIS2 Article 21 — Cybersecurity risk-management measures
  • Some vendor security questionnaires — those asking about "regular security testing" without specifying penetration test
  • Internal security baselines — for SaaS in pre-Series-A stage

What You Get

Automated discovery and scanning

  • Burp Suite Professional (current licensed version)
  • Nuclei with curated, regularly-updated templates
  • OWASP ZAP automated baseline scan
  • Subfinder + httpx for asset inventory

Manual validation of all high-severity findings

  • Critical and High findings manually validated to eliminate false positives
  • CVSS v3.1 vectors for each finding
  • CWE classification per finding
  • OWASP Top 10:2025 mapping

Deliverables

  • Structured Vulnerability Assessment Report (executive summary, methodology, findings)
  • Remediation guidance per finding
  • Signed Attestation Letter explicitly identifying the engagement as Vulnerability Assessment
  • One round of clarification questions within 14 days of delivery

What Happens If You Don't

ISO 27001 auditor flags A.8.8 control as having insufficient evidence
GDPR Article 32 risk assessment is incomplete
Vendor security questionnaire returned with "no recent independent testing" — application stalled

Our Process

1
Order placement
Confirm target application URL, contact email, preferred delivery date.
2
Mutual NDA signature (Day 1)
Sent within 1 business hour of order.
3
Brief intake form (Day 1)
Basic scope information, no test accounts needed for unauthenticated scope.
4
Active assessment (Days 2–4)
Automated discovery + manual validation of high-severity findings. Critical findings escalated within 4 hours, without waiting for the report.
5
Report preparation (Days 5–9)
Findings written up, CVSS v3.1 vectors assigned, CWE classified, OWASP Top 10:2025 mapping completed.
6
Report delivery (Day 9)
VA report + Attestation Letter as encrypted archive, password via separate channel.

Is This the Right Assessment for You?

You should choose this tier if…

  • You need cheap security testing for baseline compliance evidence
  • Your ISO 27001 auditor needs Annex A.8.8 (Management of technical vulnerabilities) evidence
  • You're doing vulnerability scanning for GDPR Article 32 risk assessment
  • You need a web application security scan with expert validation
  • You're an early-stage SaaS on tight budget seeking first security evidence
  • Your enterprise customer asked 'when was your last vulnerability scan?'

Common scenarios

Pre-Series-A SaaS founder

"We need something on our security page to close enterprise deals, but we can't afford £5,000 pen tests yet."

Compliance manager preparing ISO 27001

"The auditor wants evidence of regular vulnerability testing (A.8.8). This is the cheapest defensible option."

CTO handling GDPR requests

"We need to show the DPA authority we're doing 'regular vulnerability assessment' per Article 32."

Growing startup between pen tests

"We had a full pen test last year, but need something between annual tests to catch new vulnerabilities."

What buyers search for that leads here

Most buyers who choose our €539 Vulnerability Assessment first search for "cheap vulnerability assessment", "web app vulnerability scan cost", "OWASP Top 10 scan services", or "GDPR Article 32 vulnerability testing".

A Vulnerability Assessment is fundamentally different from a Penetration Test. VA is breadth-first — we scan for all known vulnerabilities using automated tools (Burp Suite Professional, Nuclei, OWASP ZAP), then manually validate high-severity findings to remove false positives. We produce a structured report with CVSS v3.1 scoring.

We do NOT exploit vulnerabilities to prove impact, test business logic flaws, or attempt to chain multiple weaknesses. If you need that depth, choose our Focused Web Application Penetration Test (€1,800) instead.

Real-world cost comparison: UK CREST-accredited providers charge £1,500–£3,000 for equivalent vulnerability assessments. Our €539 (~£465) delivers the same quality of finding identification with signed Attestation Letter — 60–70% cost saving.

When to choose a different tier instead

SignalRecommended service
Enterprise customer asked for 'recent penetration test' specificallyFocused Pentest (€1,800)
ISO 27001 Annex A.8.29 evidence requiredFocused Pentest (€1,800)
Cyber insurance underwriter requires pentestFocused Pentest (€1,800)
Multi-tenant SaaS with REST APIStandard Pentest (€4,500)
SOC 2 Type II preparationStandard Pentest (€4,500)

Frequently asked questions about this tier

What's the difference between a vulnerability assessment and a penetration test?

A VA identifies known weaknesses using automated scanning with manual validation. A pentest actively exploits those weaknesses to prove impact. VA is breadth-first, pentest is depth-first. VA is typically 60–70% cheaper.

How is €539 possible when UK providers charge £1,500–3,000?

Our Chișinău cost base (Moldova IT Park) is lower than London or Manchester. Same tooling (Burp Suite Professional, Nuclei, OWASP ZAP), same OWASP Top 10:2025 mapping, same CVSS v3.1 scoring, same signed Attestation Letter. Different geography = different price.

What tools do you use?

Burp Suite Professional, Nuclei with all recent templates, OWASP ZAP, plus custom checks. All findings manually validated by our senior pentester before inclusion in the report.

Do you test authenticated users?

No — the €539 tier covers the public, unauthenticated attack surface of one web application, and no test accounts are required. If you need testing behind the login, choose our Focused Pentest (from €1,800), which includes authenticated testing across multiple roles.

Do I get a Rules of Engagement document?

Yes. Standard Rules of Engagement, mutual NDA, and DPA templates are signed before testing starts.

How long does the report take?

5 business days from completion of testing. Overall this is 9–10 business days from order: NDA and intake on day 1, active assessment on days 2–4, report and Attestation Letter delivered on day 9.

Can I get a sample report?

Yes, under NDA. Email info@optimum-web.com with your company name and we'll send a mutual NDA the same business day, followed by an anonymised sample report.

Pricing & Delivery

€539
9–10 business days

€539 fixed price — one web application, public attack surface. Add-ons: Authenticated testing → upgrade to Focused Pentest (€1,800+). REST API depth → upgrade to Standard Pentest (€4,500+). Remediation retest → +€200.

Last reviewed: 24 August 2026

PayPal · SSL Senior only 14-day warranty SEC-PENT-01

Frequently Asked Questions

Is this a penetration test?

No. This is a Vulnerability Assessment (VA). The Attestation Letter explicitly identifies it as VA. We use this honest labelling because the difference matters in audit and procurement contexts. If your requirement specifically names "penetration test", choose our Focused Pentest (€1,800+) instead.

Will my auditor accept this?

It depends on your specific control requirement. For ISO 27001 Annex A.8.8 (Management of Technical Vulnerabilities) — typically yes. For Annex A.8.29 (Security testing in development and acceptance) — auditor-dependent; most accept it but some specifically require pen testing. We recommend confirming with your auditor before purchase.

How is this different from a subscription vulnerability scanner (Intruder, Detectify, Qualys)?

Subscription scanners are excellent for continuous, automated coverage between periodic tests — they run on a schedule and flag known CVEs and misconfigurations as they appear. What they don't do is validate their own output: every finding is raw scanner data, false positives included, with no signed deliverable an auditor recognises. Here, every high-severity finding is manually validated by a certified engineer before it reaches you, and delivery includes a structured report plus a signed Attestation Letter. Think of a subscription scanner as continuous monitoring and this as the periodic, audit-grade checkpoint — most compliance programmes use both, not one instead of the other.

What if you find Critical vulnerabilities?

Critical-severity findings are communicated to your nominated contact within 4 hours of validation via secure channel, with clear reproduction steps and immediate remediation guidance. We don't wait for the report delivery date.

Can I order this anonymously?

You need to be the legitimate owner or authorised representative of the target application — we will verify this during NDA signature. Beyond that, your engagement is held under strict confidentiality.

What if you don't find anything?

You still receive the full report and a signed Attestation Letter — a clean result is a legitimate, valid outcome, not a lesser one. For an auditor or insurer, evidence that testing was performed and found no critical exposure is exactly what the control asks for; it does not need to surface findings to be useful.

Who signs the Attestation Letter, and what if my auditor doesn't accept it?

The letter is signed by the senior engineer named as accountable for this service line (see "Reviewed by" above), stating the scope tested, dates, methodology and remediation status. If a specific auditor or insurer rejects it, tell us before the engagement starts — most rejections come from a mismatch between the control being tested (ISO 27001 Annex A.8.8, satisfied by this VA tier) and a different control that specifically requires full penetration testing (Annex A.8.29), not from a problem with the letter itself. We'll confirm fit with your control requirement in advance rather than after delivery.

What happens if testing affects our production environment?

Scope and Rules of Engagement are agreed and signed before testing starts, including which environment is in scope, testing windows, and an emergency contact for immediate pause if anything unexpected occurs. Automated scanning is throttled to avoid denial-of-service side effects, and any exploitation step capable of altering data or state requires your explicit sign-off first. In practice, testing against a staging environment is strongly preferred where one exists and is representative of production.

Are you CREST-accredited?

No — we are not CREST-accredited; Moldova has no CREST accreditation pathway, so this reflects jurisdiction rather than capability. Even though we are not CREST-accredited, our Vulnerability Assessment methodology matches what CREST-accredited firms use — OWASP WSTG v4.2 test coverage, CVSS v3.1 scoring with CWE classification, and a signed Attestation Letter accepted for ISO 27001, SOC 2 and cyber insurance evidence. Because we are not CREST-accredited, if your procurement policy specifically requires CREST membership — most commonly UK public sector — tell us at the first call and we'll refer a partner firm rather than start a scoping exercise that can't end in a contract.