A clear, plain-language answer for anyone scoping their first assessment, briefing a non-technical stakeholder, or just trying to understand what they're actually paying for.
A vulnerability assessment identifies your assets, scans and reviews them for known weaknesses, and produces a risk-rated report so you know what to fix first. It's a structured way of answering the question every business eventually has to ask: where are we actually exposed?
The output isn't just a list of problems — a good assessment tells you which problems matter most, given your specific environment and what an attacker could realistically do with each weakness.
Assessments typically surface a mix of technical and configuration issues. Some are obvious once flagged — unpatched software with a known vulnerability — while others are subtler, like an access control that's technically working as configured but was configured too permissively in the first place.
It doesn't actively exploit those weaknesses to prove they're dangerous — that's the job of a penetration test. An assessment tells you what could go wrong; a pentest shows you what actually would go wrong, and how far an attacker could get once they were in.
It also isn't a substitute for ongoing monitoring. An assessment is a snapshot in time; your environment keeps changing after the report is delivered, which is why a recurring cadence matters more than a single one-off engagement.
Quarterly or annually is common for most businesses, with additional assessments after major infrastructure changes, new product launches, or significant staff turnover in IT.
No. See our comparison page for the difference — they're complementary, not interchangeable, and most mature security programs use both.
Yes. Smaller businesses are often targeted precisely because attackers assume less mature defenses — an assessment scoped to your actual size and budget is still valuable, even if the scope is smaller than an enterprise engagement.