Vulnerability Assessment and Penetration Testing · United Kingdom
Vulnerability assessment and penetration testing. Both halves.
A vulnerability assessment tells you what is known to be weak. A penetration test tells you which of those a person can actually use, and what it reaches once they do. Buy one without the other and you are guessing at your own risk register.
CREST-certified operators · authenticated scanning plus manual exploitation · every finding proven · free retest at 60 days
Get a fixed quote in 48 hours.
Three fields. An itemised price in writing, no call needed to get it.







What is VAPT?
VAPT is one engagement with two halves. The vulnerability assessment enumerates what is known-vulnerable across your estate: missing patches, weak configuration, exposed services, components with published exploits. The penetration test then takes those findings and proves which of them a person can chain into real access.
The order matters. An assessment on its own hands you a list ranked by a generic severity score, with no sense of which entries an attacker could actually use against you. A test on its own goes deep on a narrow path and may walk straight past a patch gap sitting elsewhere in the estate.
Run together, they answer the two questions a board actually asks. What is wrong, and what happens if someone uses it.
What is covered
What a UK VAPT engagement includes
| Half | What we do |
|---|---|
| Assessment: external estate | Every internet-facing host, service and certificate in the agreed scope, authenticated where credentials exist. Missing patches, end-of-life components, exposed management interfaces and misconfiguration. |
| Assessment: internal estate | Servers, workstations, identity and the network fabric between them, scanned with credentials so the result reflects what is installed rather than what responds to a probe. |
| Test: exploitation | A CREST-certified operator takes the assessment findings and proves which are reachable and usable, chaining them the way an attacker would rather than reporting them in isolation. |
| Test: privilege and lateral movement | What one working credential reaches. Where it escalates. Which systems trust it that should not. |
| Test: business logic | The class no scanner reports, because the application is doing exactly what it was built to do in a situation nobody considered. |
| Evidence and remediation | Every finding reproduced with the request or command that worked, ranked by what it reaches, with the fix written for the team that owns that layer. |
What of yours is already exposed?
We search the breach corpus and the criminal markets for your domain, your staff addresses and the credentials attached to them. You get the list back, whether or not we ever speak.
How it runs
Four stages, two to three weeks
- 01
Scope and rules of engagement
We agree what is in scope, what is explicitly out, the testing window and who to call if something looks live. Signed before anything is touched.
- 02
Assessment
Authenticated and unauthenticated scanning across the agreed estate. The output is the input to the next stage, not a deliverable we hand you and invoice for.
- 03
Manual testing and exploitation
An operator works the findings by hand, proves what is usable, and chains what chains. Anything that cannot be reproduced does not reach the report.
- 04
Report, walkthrough and retest
A written report plus a session with the people who have to fix it. Every fixed finding is retested free at 60 days, so you can close it properly.
The difference
Two halves, two questions
If a supplier quotes you VAPT and the deliverable is a tool export, you are buying half of it at the price of both.
| Vulnerability assessment | Penetration test | |
|---|---|---|
| Question answered | What is known to be weak? | What can someone actually do with it? |
| Method | Authenticated and unauthenticated scanning across the agreed estate | A CREST-certified operator working by hand, chaining findings into access |
| Coverage | Broad. Every host, every service in scope | Deep. The paths that lead somewhere |
| Finds logic flaws | No. A tool cannot know your approval workflow is skippable | Yes. That is the half a person is for |
| False positives | Common, and yours to triage | None reaches you. Every finding is reproduced before it is written up |
| Output | A ranked list of known weaknesses | The route in, what it reached, and the fix at the layer it belongs |
| On its own it tells you | Your patch and configuration position | Your exposure on the paths tested |
What you get
A report your auditor accepts and your engineers can act on
- An executive summary written for a board, not a scoring rubric
- Every finding reproduced: the request or command, the result, and the steps to repeat it
- Findings ranked by what they reach, not by a generic severity number
- The remediation written for the team that owns that layer
- A named CREST-certified operator behind the work, and a signed scope
- A free retest of every fixed finding at 60 days
- Under your own brand if you are reselling, with your logo on every page
Before you ask
VAPT, answered
What does VAPT stand for?
Vulnerability Assessment and Penetration Testing. It describes a single engagement with two halves: a broad assessment that enumerates what is known-vulnerable across the agreed estate, then a penetration test in which a person proves which of those weaknesses can actually be used and what they reach. The term is used most often in procurement and in supplier questionnaires, which is why it tends to appear in a scope document rather than in a tester’s own vocabulary.
Is VAPT the same as a penetration test?
No. A penetration test is one half of it. The assessment half gives you breadth across the whole estate, which a test on its own does not, because a test follows the paths that lead somewhere and will walk past a patch gap sitting in a corner nobody attacked. The test half gives you proof, which an assessment on its own cannot, because a scanner reports what is known-vulnerable and has no way of knowing which entries a person could chain into access.
Does VAPT satisfy Cyber Essentials Plus or PCI DSS?
They ask for different things and it is worth being precise. Cyber Essentials Plus requires an independent technical verification against a defined set of controls, carried out by a certified assessor, and is narrower than a VAPT engagement. PCI DSS requires both quarterly vulnerability scanning and annual penetration testing, which maps closely onto the two halves. A VAPT engagement will usually produce the evidence both frameworks want, but the scope has to be written against the framework rather than assumed to cover it.
How much does VAPT cost in the UK?
Price follows scope: the number of live hosts, the number of applications and user roles, whether internal testing is included, and whether it is a first engagement or a repeat. A small estate with one application typically runs two weeks. We quote a fixed price against a written scope rather than a day rate, so the number does not move once testing starts, and the retest at 60 days is included rather than billed as a second engagement.
How often should VAPT be repeated?
Annually as a floor, and after any material change: a new application, a migration, a merger, a significant change to who can reach what. The gap between annual tests is where most exposure accumulates, which is why the assessment half is worth running more frequently than the test half. Continuous testing covers that gap if the estate changes often.
Rather talk it through?
Book a 30-minute scoping call with an operator. You leave with a scope and a fixed price.