Budget a vulnerability assessment cost of £500 to £6,000. Or budget £150 to £600 a month if you choose an ongoing scanning service instead of a one-off engagement. Where you land in that range depends on three things. How big is your network? Are web applications included? Does a human analyst check the scanner’s output before you see it? This guide breaks down each variable so you can budget properly, rather than guessing from a single headline number.

Table of Contents
Start with what you’re actually trying to protect
Before you ask for a price, work out what needs testing. List your public-facing systems: website, VPN, email, remote access. Add your internal network segments and any customer-facing applications. If you’re not sure what a vulnerability assessment actually checks, it’s worth reading up before you ask for quotes. A provider can’t give you an accurate vulnerability assessment cost without this information. A quote given without it is really just a guess dressed up as a number.
Small businesses often underestimate their own footprint. Cloud services, forgotten test servers and old subdomains all count as attack surface. All of them add to the scope a provider needs to price against, so it pays to map this out before you pick up the phone.
The four things that set the price
1. Number and type of targets
Providers price per IP address, host, domain or application, not by the hour. A business with five external systems pays less than one with fifty. A web application with a login area and payment processing costs more to test than a static brochure site. Ask exactly how “one target” is defined before comparing two quotes. A cheap price per target can still add up to more than a slightly pricier all-in figure.
2. Internal, external, or both
External-only assessments check what’s visible from the internet. Internal assessments check what happens if an attacker, or a compromised laptop, is already inside your network. Most UK businesses need both to get a realistic picture. A quote that only covers one should say so plainly, rather than leave you to assume full coverage.
3. Automated versus analyst-reviewed
A pure automated scan is the cheapest option because it needs the least human time. CREST’s own guidance describes vulnerability assessment as largely automated and run on a repeatable schedule. That’s exactly why it costs less than a penetration test. But automated tools generate false positives, and they rank issues by generic severity scores rather than your actual business context. Paying more for an analyst to filter and prioritise the results usually pays for itself the first time it stops your team chasing a non-issue for half a day.
4. How often you need it
The National Cyber Security Centre recommends assessing your whole estate at least monthly. Anything reachable from the internet deserves more frequent checks still. A single annual assessment costs less per engagement, but it leaves months of exposure between checks. A subscription service, like a rolling managed vulnerability scanning service, costs more across the year. It catches new vulnerabilities as they’re disclosed, not months later.
A simple budgeting table
| What you need | Rough budget |
|---|---|
| A handful of external systems, scanned once | £500 – £1,500 |
| Internal and external, small office network | £1,500 – £4,000 |
| Full estate including a customer-facing web app | £2,500 – £6,000+ |
| Monthly or quarterly managed scanning | £150 – £600 per month |
Treat these as planning figures, not quotes. Get your scope defined first. Then ask two or three providers to price against exactly the same brief, so you’re comparing like for like.
A checklist before you accept any quote
- Does the price include analyst review, or is it raw scanner output only?
- Is a written report included, with findings ranked by real business risk?
- Is a retest of fixed issues included, or is that a separate charge?
- Does the provider hold CREST accreditation or an equivalent recognised standard?
- Is the scope defined precisely enough that you could hand it to a different provider and get a comparable quote?
- Does the assessment need to satisfy Cyber Essentials Plus, PCI DSS, ISO 27001 or an insurer, and does the provider know that?
Don’t confuse this with penetration testing cost
A vulnerability assessment and a penetration test solve different problems, and mixing them up in a budget is a common mistake. A vulnerability assessment finds and lists weaknesses, largely through automated scanning. A penetration test has a human actively try to exploit those weaknesses and chain them together into a realistic attack path. That’s why it costs several times more for the same scope. Most businesses budget for both: a scheduled vulnerability assessment through the year, and a deeper penetration test annually or after any major change to the network.
Where the money actually goes
It helps to picture what you’re paying for. Every part of a genuine vulnerability assessment cost maps to one of three things: tooling, analyst time, or accreditation. A chunk of the price covers the scanning tools and licensing themselves, which is a fixed cost regardless of how small the job is. Another chunk covers the analyst’s time: configuring the scan correctly, filtering the results, and writing a report your team can actually act on. The rest reflects the provider’s accreditation and insurance, plus the simple fact that a reputable firm with a track record can charge more than a one-person outfit running a free scanner. None of these costs are wasted if the report drives real fixes. They’re worth understanding, though, so a quote doesn’t feel like a black box.
Frequently asked questions
What is a realistic vulnerability assessment cost for a five-person business?
For a small office with a handful of external systems and no complex web application, expect somewhere around £500 to £1,500 for a one-off external assessment. Add internal testing, and the figure moves toward the middle of that wider £1,500 to £4,000 band.
Is it cheaper to pay monthly than to book one-off assessments?
Usually, if you need repeated testing anyway. A monthly or quarterly scanning subscription tends to work out cheaper across a year than several separate one-off engagements. It also matches the monthly cadence the NCSC recommends.
Does a vulnerability assessment satisfy Cyber Essentials Plus?
Cyber Essentials Plus includes its own external vulnerability scanning as part of the certification audit. Many businesses also run a separate assessment beforehand, though, to catch and fix issues so the certification process goes smoothly on the day.
Can I reduce the cost by only testing part of my network?
You can, but be careful. Narrowing the scope lowers the price, but it also lowers your assurance. If you cut internal testing to save money, you’ll have no visibility into what an attacker could do once inside, which is exactly the scenario behind many real breaches.
How do I stop a vulnerability assessment cost estimate from ballooning mid-project?
Agree the scope in writing before work starts, and ask what happens if new systems turn up during discovery. A reputable provider will flag scope creep and requote rather than silently absorbing it or quietly charging extra later, so put that expectation in the contract up front.
If you’d rather skip the guesswork, Aardwolf Security can scope your network directly and quote against it, including a full penetration test alongside the assessment if you need both. Get in touch for a straight answer on price.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.