← All solutions
Vulnerability Assessment & Penetration Testing

Scope a VAPT engagement

Find the cracks before they do.

VAPT is scoped per engagement, not subscribed. Tell us what you need tested and we’ll come back with a fixed quote and rules of engagement. The more precise the scope, the tighter the price.

HOW WE SCOPE IT

Four dimensions, one fixed quote

Every VAPT engagement is shaped by these choices. Pick where you are today and we’ll size effort and price around it.

1

Test type

  • External web app
  • Internal network
  • Cloud (AWS/Azure/GCP)
  • API / mobile
  • Full-scope engagement
2

Depth

  • Recon
  • Vulnerability Assessment
  • Penetration Test
  • Full (VA + PT)
3

Approx. target count

  • 1–2
  • 3–10
  • 11–25
  • 26+
4

Retest included

  • Yes — 1 round
  • Yes — unlimited until clean
  • No

Why scope before you sign

  • Fixed quote. Scope locks the price — no hourly drift, no surprise invoices.
  • Approved rules of engagement. You sign off before a single test runs.
  • Business-context findings. We report what’s exploitable and what it means, not a CVE dump.
  • Verified to clean. Retest until every critical is closed.
What you walk away with

Scoped rules of engagement, technical findings with proof-of-concept, a prioritized remediation roadmap, and an attestation of test — audit-ready.

Engagement scope

Tell us what you need tested and we’ll return a fixed quote.

Prefer a subscription instead?

OrelLMS, OrelxPhish, and Orel MSOC are billed per learner, per campaign, and per endpoint.

View subscriptions