Vulnerability Assessment vs Penetration Testing: Which Does Your Business Need?
These two get sold interchangeably and they are not the same thing. Here is the actual difference, what each one costs you in time and money, and which one to buy first if you have never had either.
What is the difference between a vulnerability assessment and a penetration test?
A vulnerability assessment identifies and prioritises known weaknesses across everything in scope, giving broad coverage without exploitation. A penetration test goes deep on a narrower target, with a tester actively exploiting weaknesses to prove real-world impact. Most small businesses should run an assessment first.
Ask three security companies for a quote and you will get three different documents,
two of which use the words "vulnerability assessment" and "penetration test" as though they mean the
same thing. They do not, and buying the wrong one first is a genuinely expensive mistake.
The short version
A vulnerability assessment asks "what is weak here?" A penetration test asks "what can somebody
actually do with it?"
An assessment is broad, systematic and non-destructive. It enumerates every known weakness across
everything in scope, verifies which ones are real, and ranks them so you know what to fix first. It
covers your whole estate.
A penetration test is narrow, adversarial and creative. A tester takes a defined target and actively
exploits weaknesses, chaining small issues together to reach something that matters, then documents
exactly how they did it. It covers less ground in far more depth.
Why the distinction matters commercially
The two produce different documents for different audiences. An assessment report is an operational
work list: here are 140 findings, here are the eleven that matter this month, here is how to close
them. A penetration test report is an argument: here is how we got from an anonymous internet
connection to your customer database, in six steps, with screenshots.
If a customer or an insurer has asked you for evidence, you usually need the second. If you have
never had either and want to reduce your actual risk, you almost certainly need the first.
Why we tell most SMEs to assess first
There is very little value in paying an experienced tester to be creative about breaking into a
network that still has an unpatched internet-facing service and no multi-factor authentication on
email. You already know how that ends. You are paying a premium day rate to be told something a
scan would have found in an afternoon.
- An assessment covers everything; a test covers what was scoped
- An assessment is typically repeated quarterly; a test annually
- An assessment costs materially less and turns round faster
- An assessment gives you a work list; a test gives you proof
Fix the known weaknesses first. Then commission a penetration test to find out whether a
determined attacker can still get through — which is a much more interesting question once the
obvious answers have been removed.
When to go straight to a penetration test
There are legitimate cases for skipping ahead. If you have built a web application of your own — a
customer portal, a booking system, an online shop with custom code — automated scanning will not
find the business logic flaws that matter most. Being able to change a price, view another
customer's order, or skip a payment step by manipulating a request is invisible to a scanner and
obvious to a tester.
Likewise if a contract explicitly requires an annual penetration test, or if you are already running
regular assessments and want to validate that your defences hold.
What "included" should mean in both
Whichever you buy, insist on the same three things:
- Manual verification, so you are not handed raw scanner output full of false positives
- Risk ranking that accounts for your environment, not just a CVSS number
- A free retest of remediated findings, because an unactioned report has achieved nothing
If a quote does not include a retest, ask why. Fixing things is the entire point of the exercise,
and a supplier who charges separately to check whether the fixes worked has an incentive misaligned
with yours.
A sensible sequence for a business starting from nothing
- Vulnerability assessment to establish where you actually stand
- Remediate the critical and high findings — usually a fortnight of work
- Cyber Essentials to evidence the baseline to customers and insurers
- Ongoing assessment or managed support so it does not drift back
- Penetration testing once the foundations are genuinely in place
That order delivers the most risk reduction per pound, and it means that when you do commission a
penetration test, the report is worth reading rather than a list of things you could have fixed
yourself.