Two terms you'll keep meeting in security proposals: vulnerability assessment and penetration test. They sound similar, the vendors will happily sell you either, and choosing wrong means either spending too much for what you asked — or believing you're safer than you actually are. Here's the practical difference, and how to pick.
What a vulnerability assessment actually is
A vulnerability assessment is the broader sweep. It typically combines automated scanning with manual review to identify, classify, and prioritise weaknesses across your systems — known vulnerabilities, misconfigurations, missing patches, weak credentials. The output is a catalogue of issues with severity ratings.
Think of it as the full check-up: it tells you what's wrong, but it doesn't prove which findings are actually exploitable in your specific setup. That's fine and genuinely useful — it's often the right first step.
What a penetration test actually is
A penetration test goes a step further. It uses targeted manual and structured testing within an agreed scope — and attempts to actually exploit findings to prove real impact. It answers the question that a scan can't: "if an attacker really tried, which of these would get them in?"
The value isn't the exploit itself; it's what follows. Findings come ranked by business risk, each with reproduction steps and proof-of-concept evidence, and practical remediation guidance your team can action. In a proper engagement, a retest is included to confirm your fixes work.
The difference in one table
| Vulnerability Assessment | Penetration Test | |
|---|---|---|
| Question it answers | What's wrong? | What can an attacker actually reach and abuse? |
| Method | Scanning + manual review | Targeted manual testing, exploitation attempts within scope |
| Output | Prioritised list of weaknesses | Findings ranked by business risk + evidence + remediation + retest |
| Starting price* | From SAR 3,500 | From SAR 7,500 (web apps); SAR 9,500 (network); SAR 8,000 (cloud) |
*Starting estimates; the exact quote is confirmed after a free scoping call.
How to choose — a simple rule of thumb
First check, or you're unsure where you stand? → Vulnerability assessment.
Production systems, and you need proof of real impact? → Penetration test.
You need compliance evidence (e.g. SAMA CSF, NCA ECC, ISO 27001)? → Penetration test, with the report mapped to the framework.
Many clients run a vulnerability assessment once, clean up the easy wins, then commission a penetration test on what matters most. That's a sensible, budget-friendly path.
Timeline and process
Most assessments complete in 4–10 working days depending on scope, always behind a signed NDA and a rules-of-engagement document that defines exactly what's in and out of bounds. You get a confirmed timeline before anything starts — never a silent black box.
And before you pick: every engagement begins with a free scoping call, where I confirm the scope and give you a fixed quote and timeline. If you're on the fence between VA and pentest, that call is exactly the right place to resolve it.