patch&proof.
← Field manual

Testing / Field guide

Vulnerability scan or penetration test? The difference is what you're paying for

A scan finds possible problems. A penetration test proves real ones. Here's how to tell them apart, what each costs, and how to spot a scan sold as a test.

From the supplied September 2026 research package. Historical figures and evolving policy require source review; see the correction record.

A vulnerability scan finds things that might be problems. A penetration test proves which ones actually are, and what an attacker could do with them.

Conflating the two is the most commonly abused sales tactic in this market, and it costs buyers real money — usually in the form of a scan report with a penetration test's price tag and a false sense of assurance.

The difference in one table

Vulnerability assessment Penetration test
Method Mostly automated scanning, then triage. Breadth. Human-led, hypothesis-driven, chains weaknesses together. Depth.
Output A prioritised list of potential issues, including false positives Verified findings with demonstrated business impact and attack narratives
Cadence Continuous, monthly or quarterly Point-in-time, or continuous through a testing-as-a-service platform
Cost $1,000–$5,000, or bundled into a scanner subscription $5,000–$50,000+ depending on scope
Use it for Hygiene, patch validation, asset discovery, compliance scanning Before launches, for compliance, after architecture changes, to test whether your detection actually works

The plain-language version: a scan tells you the window might be unlocked. A test tells you someone got in through it, and what they could reach once inside.

What things cost in 2026

Prices vary by scope, tester seniority, compliance driver and geography, but these ranges hold across multiple current buyer's guides.

  • Web application: $5,000–$50,000
  • API: $5,000–$30,000
  • Mobile application: $5,000–$40,000
  • Cloud environment: $5,000–$50,000
  • External network: $150–$1,000 per device; typically $5,000–$20,000
  • Internal network: $10,000–$40,000
  • Wireless: low thousands to $15,000 per site
  • Social engineering: $4,000–$20,000 per campaign
  • Red team: $10,000–$100,000+

A credible small-scope test from a reputable firm rarely comes in under $10,000–$20,000. If someone quotes you $500 for a web application penetration test, you are buying a scan with a report template.

Green flags when buying

Named, credentialed testers you can vet. Ask who will actually do the work — not who's on the website. Relevant certifications include OSCP or OSCP+, CPTS, CREST's CRT and CCT, and GIAC's GPEN and GWAPT.

Firm-level accreditation, particularly CREST membership, which is internationally recognised and mandatory for some UK and Australian government and financial work.

A real scoping call, not an instant quote. Anyone who can price your environment without asking about it isn't testing your environment.

A methodology mapped to a standard — OWASP's Web Security Testing Guide, PTES, or NIST SP 800-115.

A sanitised sample report before you buy. This is the single most revealing thing you can ask for, and good firms hand it over readily.

Manual testing hours quoted explicitly, findings with reproduction evidence, and retesting either included or clearly priced.

Red flags

A price far below market. The discount is the warning.

A 24–48 hour turnaround on a complex scope.

A report that's clearly raw scanner output — unverified false positives, generic remediation text, no narrative.

"Unlimited penetration testing" with no defined human hours.

No paperwork discipline. If a provider is casual about written authorization and rules of engagement, they'll be casual about your production systems too. This one is disqualifying on its own.

What good testing requires from you

Testing is legal because it's authorized, and that authorization has to be real.

A written authorization letter — sometimes called a get-out-of-jail letter — naming the testers, signed by someone with actual authority over the systems, specifying exact scope, dates, permitted techniques and emergency contacts. Physical testers carry it on them.

Third-party consent where relevant. If your systems are hosted or managed by someone else, their authorization matters too. Major cloud providers permit most testing of your own resources without pre-approval, but all of them prohibit denial-of-service testing.

Rules of engagement covering test windows, safety limits, stop conditions, what happens if the testers find an actual live intrusion — which does happen, and turns the engagement into an incident — and what data they may access.

A remediation and retest window, typically 30 to 90 days, with an attestation letter confirming the fixes. Ask whether this is included, because it's often billed separately and it's the part that makes the test useful for compliance evidence.

Which one do you need?

If you don't yet have multi-factor authentication everywhere and tested backups, you need neither. You need minimum viable security. A penetration test at that stage will produce a report telling you things you already know, for several thousand pounds.

If you have the basics and want to know what's exposed, start with vulnerability scanning — including CISA's free external scanning service if you're a US organization that qualifies for it.

If you're launching something significant, a customer or regulator requires it, or you want to know whether your detection actually works, that's a penetration test.

If you have a functioning security operations team and want to test people and process rather than find bugs, that's a red team — and honestly, most organizations that ask for one would get more value from a purple team, where attackers and defenders work together and tune detections in real time.

A note on how this section is written

Everything on this site about offensive security describes authorized, legal work only. We name tools with their purpose and licensing, never with usage walkthroughs against real targets, and we route all practice to lawful environments — PortSwigger's free Web Security Academy, TryHackMe, Hack The Box, OverTheWire and in-scope bug bounty programmes.

Testing systems you don't own, without written authorization from someone with authority over them, is a criminal offence in most jurisdictions regardless of intent. Even well-intentioned testers have been arrested: in 2019 two contractors were held overnight in Iowa over a scope dispute while holding a contract. Without one, the position is considerably worse.


What to do next: Before you request quotes, write down what decision the test results will inform. "We need a pentest" usually means "a customer asked," and knowing which report they need will narrow the scope — and the price — substantially.

Related: How to buy a penetration test · Labs and training directory · Minimum viable security · Responsible disclosure

Sources: NIST SP 800-115, Technical Guide to Information Security Testing and Assessment. OWASP Web Security Testing Guide and ASVS 5.0. CREST — provider and individual accreditation. CISA, NSA and international partners — joint guidance on coordinated vulnerability disclosure programs (Jul 2026). 2026 penetration-testing buyer's guides from Astra, Blaze Infosec and Bright Defense — price ranges. Reporting on the 2019 Coalfire arrests in Iowa.

Evidence & dates

Follow the source.

Source published
See individual source / original research
Event date
No single confirmed day assigned
Site publication
Unpublished · local review
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval