ISO 27001 · A.8.8CERT-In · Clause 4NIST CSF · ID.RA-1

Vulnerability Scanning & Assessment

Continuous scanning across your network, cloud, and endpoints — every finding CVSS-scored and tagged to ISO 27001 A.8.8, CERT-In, or NIST CSF. Close vulnerabilities before attackers find them, and before your next compliance audit.

Methodology

Four Phases of Every Scan Engagement

Each phase builds on the last. Together they turn raw scan output into an actionable remediation plan.

01

Asset Discovery

Full enumeration of live hosts, open ports, running services, and version fingerprints. Nothing can be secured if it isn't known.

02

Vulnerability Detection

CVE database matching, configuration auditing, and patch gap analysis across every identified asset using authenticated and unauthenticated scans.

03

Risk Scoring

Every finding scored with CVSS 3.1, weighted by exploitability, asset criticality, and business impact — so you know exactly where to start.

04

Remediation Guidance

A prioritised fix plan with specific patch references, configuration hardening steps, and timeline targets. Not just a list of problems.

Coverage

What We Scan

Network Devices & Firewalls

Routers, switches, and firewalls checked for outdated firmware, weak ACLs, and exposed management interfaces.

Web Applications

OWASP Top 10 surface coverage on public-facing apps — injection, auth flaws, misconfigurations, and more.

Operating Systems

Missing patches, end-of-life OS versions, insecure default configurations, and unnecessary running services.

Cloud Infrastructure

AWS, Azure, and GCP misconfigurations — open storage buckets, over-privileged IAM roles, and exposed APIs.

Databases

Default credentials, unpatched engine versions, and excessive access permissions across SQL and NoSQL stores.

Endpoints & Workstations

Unpatched software, legacy clients, disabled AV, and insecure local policies across the endpoint fleet.

Control Mapping

Which Controls Does Vulnerability Scanning Satisfy?

Every finding in our report is tagged to the specific compliance control it addresses.

ISO 27001
  • A.8.8

    Management of technical vulnerabilities

  • A.8.9

    Configuration management — hardened baselines

  • A.8.20

    Networks security — segmentation and monitoring

CERT-In (2022 Directions)
  • Clause 4(i)

    Periodic vulnerability scanning of IT infrastructure

  • Clause 4(ii)

    Remediation within defined SLA based on severity

  • Clause 6(1)(a)

    Mandatory reporting of incidents within 6 hours

NIST CSF 2.0
  • ID.RA-1

    Asset vulnerabilities identified and documented

  • ID.RA-2

    Threat intelligence feeds inform vulnerability prioritisation

  • RS.MI-3

    Newly identified vulnerabilities mitigated or documented

What You Get

Deliverables

  • Full asset inventory with open ports, services, and version fingerprints
  • CVSS 3.1-scored findings: Critical → High → Medium → Low → Informational
  • ISO 27001 A.8.8, CERT-In, and NIST CSF control tags on every finding
  • Remediation playbook with patch links, config guides, and timeline targets
  • Attestation letter confirming scan completion — accepted by ISO auditors
  • Free rescan after remediation to confirm all Critical and High findings are closed

Audit-Ready Evidence

Satisfies ISO 27001 A.8.8 and CERT-In requirements

ISO 27001:2022 Annex A 8.8 requires documented evidence that technical vulnerabilities are identified, assessed, and remediated on a defined schedule. Our scan report and attestation letter provide exactly that evidence for your certification audit.

CERT-In Directions (2022) require periodic vulnerability scanning of IT infrastructure. We provide the scan records, findings log, and remediation timeline your team needs to demonstrate compliance.

Book a Scoping Call

Frequently Asked Questions

ISO 27001 A.8.8 and CERT-In both require periodic scanning — most organisations run external scans monthly and internal network scans quarterly at minimum. After any significant infrastructure change, an out-of-cycle scan is strongly recommended.

Vulnerability scanning is automated and broad — it identifies known weaknesses across your entire estate. Penetration testing is manual and targeted — an engineer actively attempts to exploit specific weaknesses to demonstrate real business impact. Both are required for ISO 27001 and a complete security programme.

Authenticated scans are designed to be non-destructive. For sensitive production environments, we schedule scans during low-traffic windows and use read-only credentials. We confirm scope and any exclusions in writing before scanning begins.

ISO 27001:2022 Annex A 8.8 (management of technical vulnerabilities) requires evidence that vulnerabilities are identified, assessed, and remediated on a defined schedule. Our scan report and attestation letter satisfy that requirement directly.

Yes. We scan AWS, Azure, and GCP environments alongside traditional on-premise infrastructure. Cloud scans cover IAM misconfigurations, open storage buckets, unpatched compute instances, and exposed API endpoints.

Find Your Vulnerabilities Before Attackers Do.

Close security gaps with a CVSS-scored, compliance-mapped scan report — and a free rescan once you've remediated.

Request a Vulnerability Scan