What Does a Vulnerability Assessment Cost in New Zealand?

Engineer scoping a vulnerability assessment for a Christchurch business
A vulnerability assessment with OxygenIT is priced at roughly $1,500 per 10 staff on the network. A 30-user business lands at about $4,500. Scope is agreed in writing before any technical work starts, and there is no call-out fee.
ISO 27001 and ISO 42001 certifiedNZ based engineers onlyOperating since 2005100+ NZ businesses supported

All OxygenIT prices in one place. This page covers one service. Every price we publish, and what is never included in any of them, is on our pricing page.

The Real Price Range for a Vulnerability Assessment

Quick Summary: A Vulnerability Assessment costs roughly $1500 per 10 staff, so a 30-person business typically pays around $4500 for the full technology and cyber risk assessment. Staff count and how much regulation your industry carries are what push that number up or down. There’s no call-out fee and no financing option, so the quote you get is the number you pay.

We price Vulnerability Assessments at roughly $1500 per 10 staff on the network. A 30-user business, which is a size we see often, lands at that $4500 mark for the full technology and cyber risk assessment. That figure covers the work of actually finding the gaps in your systems, not a quick scan of one server or a single laptop.

Two things move that price. The first is staff count, since more people usually means more devices, more logins, and more entry points to check. The second is regulation. A business that has to meet specific compliance requirements, or one working towards SMB1001 certification, needs a deeper look than a business with no external obligations. We factor both into the proposal before we start, not after.

That’s the scope included in the price. We don’t charge a call-out fee on top, and we don’t offer financing on this service. It’s a fixed piece of work with a fixed cost, so the number in your proposal is the number you’ll see on the invoice.

The proposal you get isn’t pulled from a template. It comes out of a Cyber Risk Assessment we run after two calls, a 15-minute founder call and a 45-minute discovery call, so the scope actually matches what your business has running. If you want to see how this fits with wider security work, our Vulnerability Assessments page sets out where it sits alongside the rest of what we do.

Call now

What Drives Your Price Up or Down

Two things move the number on your quote. The first is staff count. We price at roughly $1500 per 10 staff, so a 30-user business lands at $4500 for the full assessment. Add more people or more endpoints and the price climbs in that same step, simply because there’s more ground to cover: more devices to scan, more accounts to check for exposed passwords or weak access controls.

The second is regulation. A business that has to prove compliance, whether that’s for cyber insurance, a client contract, or a framework like SMB1001, needs a deeper look at policy and process on top of the technical scan. That takes more of our time, so it costs more than a business that just wants a baseline read on their exposure.

What doesn’t move the price is scope creep on our end. Every assessment, no matter the size, includes the same three components: a vulnerability scan across your network and endpoints, penetration testing to see how far a real attack could get, and an IT review that looks at how your systems are set up day to day. We don’t sell a stripped-down version and then charge extra to fill in the gaps later.

There’s no call-out fee and we don’t offer financing on this work. It’s a fixed-scope job, quoted after the discovery call rather than run as an open-ended hourly arrangement. If your business has fewer than 5 staff, this usually isn’t the right fit financially. The 30-user version gives you a working example, but every quote is built from your actual staff count and setup, which you can talk through on our Vulnerability Assessments page before you commit to anything.

We won’t inflate a scope just to hit a bigger number. If a 20-person business doesn’t need the same depth as a 100-person one facing insurance renewal, we’ll say so on the call. That’s part of why the 45-minute discovery session happens before any proposal goes out, so the price ends up matching the actual work, not a standard package that doesn’t fit your business.

Call now

What’s Included in Our Vulnerability Assessment Pricing

Our vulnerability assessment pricing runs at roughly $1500 per 10 staff. A 30-user business sits at $4500 for the technology and cyber risk assessment that finds where the gaps are. That number covers three things done together: a vulnerability scan across your network and endpoints, a penetration test component to check how far a real attack could get, and an IT review that looks at how your systems are set up day to day.

The two things that move the price are staff numbers and regulatory load. More staff means more endpoints, more logins, and more devices to check, so the cost climbs with headcount. Businesses working towards SMB1001 certification or preparing for a cyber insurance renewal usually need a wider check, because the assessor or insurer wants specific gaps documented, not just a general health check.

There’s no call-out fee added on top and we don’t offer financing on this. It’s a fixed quote based on staff numbers once we’ve scoped the business. What’s not in the base price is remediation work itself. The assessment tells you what’s wrong and what order to fix it in; actually doing the fixing, patching, or system changes is a separate piece of work we’d quote once we know what the assessment turns up. Some businesses just want us to hand over the findings so their own IT person can action them, and that’s fine. Others ask us to run the fixes too. Either way the assessment price stays the same, because it’s the scanning and reporting work that’s priced, not what happens after.

If you’re weighing this up against a broader security programme, it’s worth reading through our vulnerability assessments page for how this fits alongside penetration testing and ongoing managed security work. Some businesses start with the assessment and build from there rather than doing everything at once.

If your business has fewer than 5 staff, this level of assessment is usually more than you need. We’d rather say that upfront than quote a job that doesn’t fit your risk profile.

Call now

Thinking about Vulnerability Assessments? Let’s talk.

0800 242 206

Get a free 15-minute IT health check. OxygenIT is ready to help.

The Most Common Engagement and What It Runs

Most businesses that come to us for a vulnerability assessment land around $1500 per 10 staff. A job we run often, a full technology and cyber risk assessment for a 30-user business, sits at $4500. That figure covers the scan, the analysis, and a written report we walk through with you. It’s not a placeholder number. It’s what we’ve charged repeatedly for this exact size of business.

Two things move that price. The first is headcount. More staff means more endpoints, more logins, more places for a gap to hide, so the scope of the assessment grows with the business. The second is regulatory load. A business chasing SMB1001 certification or working towards cyber insurance readiness needs a deeper look at policy and process, not just the network. That takes more of our time, and it shows up in the quote.

What’s included in that price is the vulnerability scan itself, a penetration test component, and an IT review that looks at how your systems are set up day to day. We don’t scope a job down to just the scan and call it done. If we find something during the assessment, it goes in the report along with a plain-English explanation of what it means for your business.

There’s no call-out fee to get this started. We don’t add a truck fee or a site visit charge on top of the quoted price. We also don’t offer financing on this work; it’s billed as one project fee, not spread across instalments. If you’re weighing this up against other IT spend for the year, that’s worth knowing upfront rather than finding out partway through a quote conversation.

What we won’t do is quote you a number before we know your staff count and whether you’re chasing a specific compliance outcome. A 12-person business with no regulatory pressure and a 60-person business preparing for cyber insurance are not the same job, even though both might call it a vulnerability assessment. We’d rather ask two questions upfront and give you a real figure than throw out a range that doesn’t hold up once we’re in your systems.

This pricing sits inside the wider work we do under our Vulnerability Assessments service, alongside penetration testing and security audits for businesses that want the full picture rather than a single scan.

Call now

How We Confirm Your Final Price

The $1500 per 10 staff figure and the $4500 example at 30 users are starting points, not quotes. We don’t hand over a fixed number until we’ve actually looked at your business. Here’s the order we work through it in.

Staff count moves the price the most, since it drives how many endpoints and accounts we’re checking. Regulatory pressure is the other big driver. A business chasing SMB1001 Gold or preparing for a compliance audit needs a wider assessment than one doing this as a general check, and that shows up in the proposal, not the headline range.

There’s no call-out fee at any stage of this process and no financing option attached to the pricing. What you’re quoted is what you pay for the scope agreed. If your business doesn’t need the full assessment, we’ll say so in the discovery call rather than scoping you into a bigger job than you need.

If you want to see where a Vulnerability Assessment sits against our other Vulnerability Assessments and security work before you book a call, that page has the wider detail.

Call now

Vulnerability Assessment: Frequently Asked Questions

What’s included in the price, and what isn’t?

The price covers a vulnerability scan, a penetration test, and a full IT review. Those three parts make up every assessment we run, no matter the business size. What’s not included is the actual fix-up work. Once the assessment shows where the gaps are, patching them or changing systems is a separate piece of work. We’d quote that once we know what needs doing, after we see the results together.

Is there a call-out fee to get a quote?

No. We don’t charge a call-out fee on this service. The price you’re quoted is based on your staff count, and that’s the number that shows up on the invoice. There’s nothing added on top for us to come out, run the scoping calls, or put the proposal together.

Do you offer financing for a Vulnerability Assessment?

No, we don’t offer financing on this service. It’s a fixed-scope job with a fixed cost, paid as a single invoice rather than spread out. If budgeting matters to your decision, staff count is the main thing that sets the price, so a smaller team means a smaller number to plan for.

Why do quotes for this vary so much between businesses?

Two things move the number: staff count and regulation. More staff means more devices, logins, and endpoints for us to check, so the price climbs in steps from there. Regulation adds to that. A business working towards SMB1001, or one facing a cyber insurance renewal, needs a deeper look at policy and documentation, not just a technical scan. Both get factored into the proposal before any work starts.

Is a Vulnerability Assessment worth it for a very small business?

If your business has fewer than 5 staff, this usually isn’t the right fit financially. The scope and depth of the assessment, the scan, the penetration test, and the IT review, are built for businesses with enough staff and systems to make that depth worthwhile. We’ll say so on the discovery call if your setup doesn’t need the full scope priced here.

This is not the same as a cyber security audit. A vulnerability assessment is the technical testing: the scan across your network and endpoints, the penetration test component, and the IT review. It is not the advisory review. If you want your gaps mapped against a framework with a remediation proposal, that is a cyber security audit, priced from $4,500. A 30-user business also lands at $4,500 here, so the two meet at the same number. They are different services with different outcomes, not two names for one thing.