Get a vulnerability scan

Basic Scan by OSCP-certified ethical hackers

Get a Basic Scan

The Basic Scan is our semi-automated vulnerability scan for organizations that want quick insight into common vulnerabilities. Ideal as a first security check, during development phases or as a periodic supplement to an annual pentest. From €1,480 excl. VAT, performed by OSCP-certified ethical hackers.

The scan detects vulnerabilities based on the OWASP Top 10. The scanning tools are manually configured to match the behavior of your application and the results are evaluated by a pentester. You receive a concise report via our self-developed Security Reporter platform, directly usable for internal compliance reporting.

 

Fast request

Request via our contact form. Response within one business day with concrete planning.

 

Practical insight

Results with concrete security status per identified vulnerability, mapped to OWASP Top 10.

 

Fixed price

Clear rate of €1,480 excl. VAT. No surprises, no hidden costs.

 

Tailored setup

Scans manually configured by an OSCP-certified ethical hacker.

Basic Scan in four steps

How the Basic Scan works

Four simple steps from request to report.

  1. Request and intake

    You request a Basic Scan via our contact form. Within one business day you receive a brief intake to confirm your scope and planning.

  2. Semi-automated scan

    Our OSCP-certified ethical hackers configure the scanning tools to your application and perform the scan. Additional manual verification to filter out false positives.

  3. Reporting via Security Reporter

    You receive a concise report with findings mapped to the OWASP Top 10, with impact assessment and concrete remediation advice per vulnerability.

  4. Questions and optional retest

    Direct contact with the pentester via the Security Reporter portal for follow-up questions. Optional retest after remediation on time and materials.

Duration: from request to final report typically within 2 weeks.

Who is the Basic Scan suitable for?

The Basic Scan delivers maximum value in three situations:

  • First security check. Organizations that want quick insight into the current security status of a web application or API, without immediately investing in a full pentest.
  • During development. As an interim check during a development engagement to detect common vulnerabilities early, before an application goes live.
  • Periodic supplement to a pentest. For continuous monitoring between annual pentests. Quarterly scans keep the security status sharp.

The Basic Scan is less suitable for: complex multi-tenant SaaS platforms, applications with critical business logic flows, or compliance engagements that require formal pentest reporting (DigiD, NIS2 essential entity, DORA). For these situations we recommend a full pentest.

Who the Basic Scan is suitable for
separator
Difference between Basic Scan and pentest

Difference between Basic Scan and pentest

Both deliver valuable insights, but cover different risks:

  • Basic Scan. Semi-automated scan with manual configuration and result verification. Detects common vulnerabilities such as SQL injection, cross-site scripting (XSS) and outdated components. Reporting per OWASP Top 10.
  • Pentest. Predominantly manual investigation by OSCP-certified ethical hackers. Discovers vulnerabilities that scanners systematically miss: business logic flaws, IDOR patterns, race conditions, multi-tenant leakage and creative exploit chains. Reporting per NCSC guidelines and compliance frameworks.

In short: a Basic Scan finds the "known unknowns", a pentest discovers the "unknown unknowns". For complete security validation both are valuable.

Compliance context of the Basic Scan

Vulnerability scans cover specific compliance requirements, particularly for continuous monitoring:

NIS2 and Dutch Cybersecurity Act

Article 21(2)(g) Dutch Cybersecurity Act requires "basic cyber hygiene", including patch management and vulnerability detection. Periodic vulnerability scans demonstrably contribute to this obligation.

ISO 27001

Annex A.8.8 "Management of technical vulnerabilities" requires active identification of vulnerabilities. Vulnerability scans are the most concrete implementation between pentests.

PCI DSS

Requirement 11.3 mandates periodic internal and external vulnerability scans for organizations that process payment data. Our scans meet this requirement.

For formal audit reporting, DigiD assessments or NIS2 essential entities we recommend a full pentest. The Basic Scan is then a supplement for interim monitoring, not a replacement.

What does a Basic Scan cost?

The Basic Scan has a fixed rate. No scoping conversation needed for standard scans on web applications.

  • Basic Scan, €1,480 excl. VAT
  • Semi-automated scan on OWASP Top 10
  • Manual configuration of scanning tools
  • Four-eyes principle (peer review on findings)
  • Concise reporting via Security Reporter platform
  • Direct contact with pentester via the portal

For more extensive engagements we recommend a Quick, Expert or Extensive Pentest. View all packages.

Recurring scans?

For organizations wanting to set up quarterly or monthly scans, we offer agreed rates on multi-year commitments. Contact us for a tailored quotation.

Frequently asked questions about the Basic Scan

Below are the most frequently asked questions about vulnerability scans. For a complete overview please visit our FAQ page.

Is a Basic Scan the same as a pentest?

No. The Basic Scan is a semi-automated vulnerability scan with manual configuration and result verification. A pentest is predominantly manual investigation and finds vulnerabilities that scanners systematically miss. For compliance purposes (audits, DigiD, NIS2 essential entity) a pentest is typically required.

What is tested during a Basic Scan?

The scan detects common vulnerabilities mapped to the OWASP Top 10: SQL injection, cross-site scripting (XSS), CSRF, broken authentication, security misconfigurations, XML external entities (XXE), broken access control, insecure deserialization, outdated components and insufficient logging. The scanning tools are manually configured to your specific application.

How long does a Basic Scan take?

Active testing time 2 to 4 hours for a standard web application. Total duration from request to final report is typically 1 to 2 weeks, depending on planning and available access.

What do I provide as input?

The URL of your web application or API. For authenticated scans we would appreciate a test account with regular user rights. For complex applications with multiple user roles we recommend a pentest instead of a Basic Scan.

Is a Basic Scan suitable for DigiD or NIS2 compliance?

For formal DigiD assessments and NIS2 essential entities we recommend a full DigiD pentest or NIS2 pentest. The Basic Scan can serve as interim monitoring between these annual audits, contributing to article 21(2)(g) Dutch Cybersecurity Act (basic cyber hygiene).

Can you perform recurring scans?

Yes. For organizations wanting to set up quarterly or monthly scans, we offer agreed rates on multi-year commitments. This is a valuable supplement to an annual pentest, especially for SaaS platforms with frequent releases.

What is the difference between a Basic Scan and a free online scanner?

Free online scanners perform generic scans without configuration or context. The Basic Scan is manually configured by an OSCP-certified ethical hacker, results are checked for false positives and you receive understandable remediation advice per finding. Four-eyes principle also applies: peer review on every finding.

Is a retest included?

Retest of resolved vulnerabilities is performed on time and materials. This is discussed during intake. For most Basic Scans, a retest of 2 to 4 hours is sufficient. More information on our retest page.

Ready for your first Basic Scan?

Want quick insight into the security status of your web application? Looking for a periodic supplement to your annual pentest? Request a Basic Scan directly or contact us for advice on the right approach. Fixed rate of €1,480 excl. VAT. Response within one business day.