Vulnerability assessment vs penetration test
These are different products with different prices and different buyers, and a large share of what is sold in Canada as a penetration test is the cheaper one with the more expensive name on the invoice.
A vulnerability assessment enumerates known weaknesses using automated tools and reports them by severity. A penetration test hires a person to attempt to exploit weaknesses, chain them together, and reach something that matters. The first is broad, repeatable, cheap and largely machine-driven. The second is narrow, expensive, and produces findings that only exist because somebody understood what your system was supposed to do. Both are worth buying. Neither substitutes for the other. Most Canadian buyers are sold the first and invoiced for the second.
The two products side by side
| Vulnerability assessment | Penetration test | |
|---|---|---|
| Question answered | What known weaknesses exist across everything | What can an attacker actually do |
| Method | Automated scanning against a signature database, with review | A tester working manually, using tools as one input |
| Coverage | Wide. Every host, every service | Narrow and deep. An agreed scope |
| Finds business logic flaws | No | Yes, and this is the main reason to buy one |
| Finds authorization flaws | No, because it cannot know whose data is whose | Yes |
| Finds missing patches | Yes, better than a person would | Yes, incidentally |
| False positives | Common, and triage is part of the work | Rare, because findings are demonstrated |
| Frequency | Continuous or monthly | Annually, or after a significant change |
| Typical Canadian cost | $1,500 to $8,000 CAD a year | $8,000 to $40,000 CAD per engagement |
| Deliverable | A ranked list, ideally with your context applied | A narrative with reproduction steps, evidence and a retest |
The hard part, said plainly
A scanner cannot find the flaws that cost companies money. It has no model of your business, so it has no idea that invoice 4192 belongs to a different customer than invoice 4191. Every serious finding of the last decade in a SaaS product has the same shape: an authenticated user reached data or an action that belonged to someone else. There is no signature for that. There is a person with two accounts and the patience to compare.
So when an engagement is priced at $2,500 CAD, divide it by a Canadian tester day, roughly $1,500 to $2,800. No version of that engagement includes a person mapping your authorization model. You are buying a scan, a triage pass and a document. That may be what you need. It should be named as what it is.
How to tell from the report
Read the findings. If every one of them cites a CVE identifier, a version number, a missing HTTP header or a TLS configuration item, a tool produced them. A penetration test report contains at least one finding that could not exist anywhere but in your system, described in your own vocabulary: your roles, your objects, your workflow. If nothing in the report names a concept from your own product, nobody tested your product.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
What a scan buys you, and what a test buys you
Both are worth money, for different reasons. The mistake that costs the most is buying one while believing you bought the other.
What a scan buys you
- Coverage of everything, cheaply and repeatedly. A scanner will look at ten thousand hosts as happily as at ten.
- Known vulnerabilities with public identifiers: unpatched software, expired certificates, weak TLS configuration, default credentials, exposed admin interfaces.
- A defensible answer to "do you scan for vulnerabilities", which is a real line in most questionnaires and in ISO 27001 Annex A.
- Trend data. Run monthly, the count going down is evidence your patching process operates, which is what an auditor wants to see.
- A cheap way to clear the easy findings before you pay a senior tester day rate to rediscover them.
What a test buys you
- Findings that could only exist in your product: one tenant reading another's records, a role check enforced in the interface and not in the API, an approval step that can be skipped by changing a value.
- Proof rather than possibility. A tester chains three medium issues into a real compromise and shows you the path, which a scanner reporting the same three issues separately never does.
- Verified findings. Somebody reproduced each one before writing it down, so your engineers are not spending a week chasing false positives.
- Independence a customer or an auditor will accept, from a named person who can be asked follow-up questions about the scope they covered.
- An artifact you can hand over: a report, and the attestation letter you send instead of it.
Neither list contains the other. For most companies the answer is both: scan continuously, test annually, and never let a supplier sell you the first while naming it the second. What happens after the test is the part buyers forget to purchase, covered on retest and remediation verification.
When a scan is the right purchase and a test is not
For some companies authenticated vulnerability scanning is the correct purchase this year and a penetration test is not. Telling them to spend $15,000 CAD anyway serves testing firms rather than buyers. If most of the following describe you, buy the scanner and put the difference into fixing what it finds.
- You have no product of your own. You resell or implement other people's software, and the only things with your name on them are a marketing site and a Microsoft 365 tenant. There is no authorization model to test because you did not write one.
- Nobody has asked. No customer contract, no auditor, no insurer names a test. Buying one speculatively is buying an artifact no one will read.
- You already know the answer. If you have never patched, never inventoried your external surface and have three servers whose owner left in 2023, a tester will spend day one telling you what a $200 CAD a month scanner tells you in an hour, and you will pay senior rates for it.
- Your last test's findings are still open. A second test before you have fixed the first one buys you the same report with a newer date on it.
The threshold that flips it is not headcount or revenue. It is the moment you hold data on behalf of somebody else in a system you built. From there a scanner cannot answer the question that matters, which is whether one customer can reach another customer's records. No scanning frequency substitutes. It is also the point at which customers start sending you security questionnaires that ask for a test by name.
What VAPT means, and why the word is a problem
VAPT stands for vulnerability assessment and penetration testing. As a phrase describing a program that includes both, it is the right shape for most companies. As the name of a single product on a price list, it is where the cheaper one absorbs the expensive one's name.
If a proposal is titled VAPT, ask for the split: how many tester days go to the manual testing portion, separately from the scanning. A firm doing both will answer immediately, because they costed it that way. A firm selling a scan answers in tools and coverage rather than days, which is the answer you were looking for.
Which one your requirement is actually asking for
| Driver | What satisfies it |
|---|---|
| SOC 2 | Evidence of vulnerability identification and remediation. Auditors have settled on an annual independent test plus continuous scanning. Scanning alone is increasingly questioned |
| ISO 27001 | Technical vulnerability management under Annex A. Certification auditors accept a scanning program with evidence of action, and expect testing where the Statement of Applicability implies it |
| PCI DSS | Both, explicitly and separately. Quarterly scanning under 11.3 and annual penetration testing under 11.4. Neither substitutes for the other |
| A customer security schedule | Read the clause. It usually says penetration test and means an independent report with a date on it |
| Cyber insurance | Usually attested rather than inspected. Scanning with evidence of remediation generally answers the question |
How to buy both without wasting money
The arrangement that works for a company between twenty and two hundred people is scanning owned internally and running continuously, in the build pipeline and against production infrastructure, plus one scoped independent test a year against the product and whichever environment holds customer data.
Paying a consultancy to run monthly scanning is poor value. You are paying professional day rates for tool operation and a report you could generate. Outside help pays for itself in the first configuration, in tuning out the noise and in deciding which findings matter in your context. That is a few days of work once, not a retainer.
Spend the external budget on the independent manual test, which is the thing you cannot do yourself. What that engagement should contain is on penetration testing services. If the requirement is continuous coverage rather than an annual snapshot, pentest as a service is the model that tries to bridge the two.
If the term you were sold was VAPT, or another word used loosely in this market, the penetration testing glossary defines them the way a practitioner uses them.
Get quoted for the right one
Tell us what triggered the requirement and we will tell you which of the two it is asking for before you collect prices.
Get matchedCommon questions
Is a vulnerability assessment enough for SOC 2?
It is enough to demonstrate that you identify vulnerabilities, which is what the criteria actually ask for. It is increasingly not enough to satisfy an auditor who has seen every other client in your category produce an annual independent test, and it will not satisfy a customer whose security schedule uses the words penetration test. Scanning plus one annual test is the arrangement that closes both questions.
What is the difference between a penetration test and a red team?
A penetration test measures how many exploitable weaknesses exist in an agreed scope. A red team measures whether your defenders would notice someone using them, and it is scoped by objective rather than by asset. A red team is the wrong purchase for a company without monitoring and a response function, and the reasoning is on penetration testing types.
Why is a penetration test so much more expensive?
Because it is a person's time rather than a subscription. A qualified tester in Canada costs $1,500 to $2,800 CAD a day once salary, tooling and overhead are counted, and a real engagement is five to fifteen of those days plus reporting. Scanning has almost no marginal cost per target, which is why one is priced per year and the other per engagement.
Can a scanner find business logic flaws?
No, and this is definitional rather than a limitation to be engineered away. A business logic flaw is behaviour your application was built to allow, used in a sequence you did not intend. Recognizing it requires knowing what was intended, which is information that exists only in your team and in your product. A tool with no model of your intent cannot judge a departure from it.
How do we tell what a quote is offering before we buy?
Ask three questions. How many tester days are in the engagement, and how many of those are manual. Which published methodology is followed. Can you see a redacted sample report from a similar engagement. The first answer tells you whether a person is involved, the second tells you whether the work is structured against a published penetration testing methodology, and the third tells you what you will receive. Any firm doing this work seriously answers all three in a day.