Get a Basic Scan
The Basic Scan is our semi-automated vulnerability scan for web applications, APIs and networks. For €1,480 excluding VAT, it identifies common vulnerabilities within the agreed scope. A pentester configures the tools and reviews the results; the scan does not replace a manual pentest.

We tailor the scanning tools to the systems you want assessed. For web applications, we use the OWASP Top 10 as a reference for relevant findings. For networks, we look for known vulnerabilities in reachable services, outdated software and insecure settings. A pentester configures the tools and reviews the results. You receive a concise report via our self-developed Security Reporter platform, directly usable for internal compliance reporting.
Fast request
Request via our contact form. Response within one business day with concrete planning.
Practical insight
An overview of identified vulnerabilities, their potential impact and practical remediation advice.
Fixed price
Clear rate of €1,480 excl. VAT. No surprises, no hidden costs.
Tailored setup
Scans manually configured by an OSCP-certified ethical hacker.
How the Basic Scan works
Four simple steps from request to report.
Request and intake
You request a Basic Scan via our contact form. Within one business day you receive a brief intake to confirm your scope and planning.
Semi-automated scan
Our OSCP-certified ethical hackers tailor the scanning tools to your web application, API or network and perform the scan within the agreed scope. They manually check the results to filter out false positives.
Reporting via Security Reporter
You receive a concise report with identified vulnerabilities, an assessment of their impact and practical remediation advice. For web applications, we map relevant findings to the OWASP Top 10.
Questions and optional retest
Direct contact with the pentester via the Security Reporter portal for follow-up questions. Optional retest after remediation on time and materials.
Duration: from request to final report typically within 2 weeks.
Who is the Basic Scan suitable for?
The Basic Scan delivers maximum value in three situations:
- First security check. Organizations that want quick insight into the current security status of a web application, API or network, without immediately investing in a full pentest.
- During development. As an interim check during a development engagement to detect common vulnerabilities early, before an application goes live.
- Periodic supplement to a pentest. To check again for known vulnerabilities between annual pentests, for example with a quarterly scan.
The Basic Scan is less suitable for: complex multi-tenant SaaS platforms, applications with critical business logic flows, or compliance engagements that require formal pentest reporting (DigiD, NIS2 essential entity, DORA). For these situations we recommend a full pentest.

Difference between Basic Scan and pentest
Both deliver valuable insights, but cover different risks:
- Basic Scan. Semi-automated assessment of web applications, APIs or networks, with manual configuration and verification of results. Focused on known vulnerabilities, such as outdated software, insecure settings and common web vulnerabilities. Coverage depends on the agreed scope and available access.
- Pentest. Predominantly manual investigation by OSCP-certified ethical hackers. Discovers vulnerabilities that scanners systematically miss: business logic flaws, IDOR patterns, race conditions, multi-tenant leakage and creative exploit chains. Reporting per NCSC guidelines and compliance frameworks.
In short: a Basic Scan finds the "known unknowns", a pentest discovers the "unknown unknowns". For complete security validation both are valuable.
Also read: the full difference between a vulnerability scan and a penetration test and whether a scan alone is sufficient security.
Compliance context of the Basic Scan
Vulnerability scans cover specific compliance requirements, particularly for continuous monitoring:
NIS2 and Dutch Cybersecurity Act
Article 21(2)(g) Dutch Cybersecurity Act requires "basic cyber hygiene", including patch management and vulnerability detection. Periodic vulnerability scans demonstrably contribute to this obligation.
ISO 27001
Annex A.8.8 "Management of technical vulnerabilities" requires active identification of vulnerabilities. Vulnerability scans are the most concrete implementation between pentests.
PCI DSS
Requirement 11.3 mandates periodic internal and external vulnerability scans for organizations that process payment data. Our scans meet this requirement.
For formal audit reporting, DigiD assessments or NIS2 essential entities we recommend a full pentest. The Basic Scan is then a supplement for interim monitoring, not a replacement.
What does a Basic Scan cost?
The Basic Scan has a fixed rate. During the brief intake, we confirm which web application, API or network components the scan will cover and what access is needed. This makes clear in advance what we will assess.
- Basic Scan, €1,480 excl. VAT
- Semi-automated scan of the agreed systems
- Manual configuration of scanning tools
- Four-eyes principle (peer review on findings)
- Concise reporting via Security Reporter platform
- Direct contact with pentester via the portal
For more extensive engagements we recommend a Quick, Expert or Extensive Pentest. View all packages.
Recurring scans?
For organizations wanting to set up quarterly or monthly scans, we offer agreed rates on multi-year commitments. Contact us for a tailored quotation.
Frequently asked questions about the Basic Scan
Below are the most frequently asked questions about vulnerability scans. For a complete overview please visit our FAQ page.
Is a Basic Scan the same as a pentest?
No. The Basic Scan is a largely automated assessment with manual configuration and verification of results. A pentest also includes manual investigation of areas such as authorization, business logic and combined attack paths. The appropriate test depends on your risks and any audit or contractual requirements; a scan does not replace a pentest where one is explicitly required.
What is tested during a Basic Scan?
This depends on the agreed scope. For web applications and APIs, we look for common vulnerabilities such as injection flaws, insecure settings and outdated components. For networks, we scan the agreed IP addresses, IP ranges or domain names for known vulnerabilities in reachable services and software. The Basic Scan does not include a full manual assessment of all functionality or possible attack paths; for that, we recommend a pentest.
How long does a Basic Scan take?
For a standard web application, active testing typically takes 2 to 4 hours. For a network scan, the time required depends in part on the number of systems and reachable services. We confirm the schedule during intake. From request to final report, the process typically takes 1 to 2 weeks, depending on scheduling and available access.
What do I need to provide for a Basic Scan?
For a web application or API, provide the URL. For a network scan, you can provide IP addresses, IP ranges or domain names. Together, we agree which systems we are authorized to scan and what access is needed. If we also scan areas of your application that require a login, please provide a test account with regular user permissions.
Is a Basic Scan suitable for DigiD or NIS2 compliance?
A Basic Scan does not replace the pentest required within a DigiD assessment. For NIS2, appropriate testing depends on your risk assessment and the applicable requirements; the same pentest obligation does not automatically apply to every organization. Scanning can contribute to vulnerability management but does not establish full compliance on its own. Discuss your audit requirements in advance so we can determine the scope and depth needed.
Can you perform recurring scans?
Yes. For organizations wanting to set up quarterly or monthly scans, we offer agreed rates on multi-year commitments. This is a valuable supplement to an annual pentest, especially for SaaS platforms with frequent releases.
What is the difference between a Basic Scan and a free online scanner?
Free online scanners perform generic scans without configuration or context. The Basic Scan is manually configured by an OSCP-certified ethical hacker, results are checked for false positives and you receive understandable remediation advice per finding. Four-eyes principle also applies: peer review on every finding.
Is a retest included?
Retest of resolved vulnerabilities is performed on time and materials. This is discussed during intake. For most Basic Scans, a retest of 2 to 4 hours is sufficient. More information on our retest page.
Ready for your first Basic Scan?
Want quick insight into the security status of your web application, API or network? Looking for a periodic supplement to your annual pentest? Request a Basic Scan directly or contact us for advice on the right approach. Fixed rate of €1,480 excl. VAT. Response within one business day.
Nederlands