Request quotes and ASM, vulnerability assessment, and penetration testing arrive side by side under the heading of "security testing". The pricing basis differs, the ranges differ, and so do the reports.
They are not competing with each other; each confirms something different. Settling which one is being bought is what makes the numbers comparable.
01 / Depth and cadence separate the three, not breadth
In the shapes these are usually sold in, ASM watches the externally visible surface continuously, a vulnerability assessment works a fixed scope systematically inside a time-boxed engagement, and a penetration test presses through to whether exploitation actually succeeds. The word on the quote is the same; the stopping point is not.

Figure 1: Depth and cadence, compared across the usual operating models
02 / Only ASM starts by building the inventory
Assessments and penetration tests both begin with "test this", while ASM takes the seed domains you register and expands outward through externally visible relationships. A subdomain a team stood up on its own, a staging server still reachable, a domain inherited through an acquisition — whatever is missing from the register is exactly what this step picks up.

Figure 2: Setting the scope — receive a fixed range, or expand from seeds into an inventory
Deep dive: what ASM does not see
The seeds themselves still have to be supplied, and a separate domain with no externally visible relationship to them will not be discovered automatically, so it has to be added by hand.
It trades depth on any single target for breadth and continuity across the external surface. Up to the login wall, within non-destructive actions, and in exchange it runs every day. The number and state of entry points shift daily, which is what continuous observation is good at.
More detail in ASM (Attack Surface Management) — A Beginner's Guide.
03 / What an assessment delivers is the findings and the coverage behind them
Being able to show "this scope was examined against these criteria" is the deliverable itself, which is what a customer's security questionnaire or an audit actually needs. Because the work is time-boxed, it cannot prove that no vulnerabilities exist.
Table 1: What an assessment report carries
| What the report carries |
Contents |
| The scope examined |
Which assets were looked at, against which criteria |
| What was found |
The defects, and the grounds for calling them that |
| What could not be confirmed |
Ground the time box or the granted access did not reach |
Deep dive: why the same word carries a tenfold price difference
Depth varies with how the work is commissioned — anonymous surface only, or test accounts and the authenticated screens; a person probing business-specific rules, or tool output organised into a report.
Line up the numbers before those choices are settled and the range looks inexplicable, so scope and criteria come first (what a vulnerability assessment costs).
The report states the coverage achieved, what was found, and the conditions that could not be exercised.
04 / A penetration test shows the path that chains the weaknesses
Settings that look harmless one at a time combine into a route to the objective. Establishing that, and reporting the path taken, is what a penetration test is for.

Figure 3: Individually minor weaknesses chaining into a reachable objective
Deep dive: what "no intrusion achieved" does not mean
Comprehensiveness is not the goal, so the result reads as no route to the objective having been found within that window and under those conditions. It does not mean no flaws exist.
When the objective is not reached, what was attempted and how far it got are still reported. An assessment returns coverage and a list of findings; a penetration test returns where entry happened, what it passed through, and what it reached.
05 / Sequence the three instead of choosing between them
When the target is already clear, an assessment or a penetration test can be commissioned directly, and ASM earns its place in the other case — when the intent is to cover everything the organisation exposes and no such inventory exists. With the inventory in hand and the important surfaces identified, an assessment can be aimed at them, and a penetration test answers the remaining question of whether an attacker really reaches what matters.

Figure 4: The inventory decides the entry point; the order after it is the same
06 / PentaTrail covers discovery and non-destructive reproduction
Discovery expands outward from registered seeds, the result is monitored daily, and changes and vulnerability candidates are reported. On the CTEM plan, candidates that qualify are reproduced remotely and non-destructively, and "not reproduced" does not mean "safe".

Figure 5: Where PentaTrail stops, and who covers what lies beyond
It does not go past a login, and never takes routes that would write data. No specification is handed over, so operations forbidden only by a particular business cannot be judged either. Confirming what sits behind authentication calls for an assessment; demonstrating reachability to a target calls for a penetration test.
Appendix: the six-dimension comparison, and red teaming
Table 2: ASM, vulnerability assessment, and penetration testing compared
| Dimension |
ASM |
Vulnerability assessment |
Penetration testing |
| How scope is set |
Seeds supplied, expanded automatically |
Supplied by the customer |
A supplied range, or a target to reach |
| Common operating model |
Ongoing observation (e.g. daily) |
Time-boxed engagement |
Time-boxed engagement |
| Depth |
What is visible externally |
Systematic across scope, by agreed criteria |
Presses through to actual exploitation |
| Deliverable |
Asset inventory and changes |
Coverage achieved and findings |
What was exploited, and the path taken |
| Coverage |
Broad across assets |
High within the agreed criteria |
Comprehensiveness is not the goal |
| Common pricing basis |
Monthly |
Per engagement |
Per engagement |
The table lists common shapes, not definitions. Assessments are often contracted as recurring runs, and penetration testing is sold on retainers and subscriptions too.
Red teaming and TLPT
Red team exercises attack too, but their character differs. Threat intelligence shapes a realistic adversary scenario, the work stays deliberately quiet, the scope includes people and processes across the organisation, and the defenders' detection and response are exercised.
Threat-led penetration testing (TLPT) belongs to that red team family. Frameworks such as TIBER-EU in Europe define how threat intelligence drives an engagement that tests prevention, detection, and response; the practice spread from heavily regulated sectors and is now used across industries. What separates a scoped penetration test from red teaming is the use of threat intelligence, the demand for stealth, the inclusion of people and process, and whether the defending side is exercised.