Infrastructure and network scanning
Authenticated and unauthenticated assessment across servers, network devices, and the perimeter. Authenticated scanning finds substantially more and produces far fewer false positives, which is why it is worth the effort of arranging credentials.
Endpoint and patch posture
Assessment of what is actually installed and actually patched across your fleet, against what your management tooling reports. The gap between the two is a normal finding rather than an unusual one, and it is the gap an assessor will find if you do not.
Cloud configuration assessment
Posture checks across cloud accounts and subscriptions: public exposure, over-broad identity, unencrypted storage, and logging that was never turned on. Distinct from adversarial cloud testing, which asks what someone could do with what is exposed.
See also: Cloud Architecture Assessment
Triage and prioritization
The part that makes the rest useful. Findings are assessed against your environment: whether the affected service is reachable, whether a compensating control already covers it, and what it would actually cost an attacker. A prioritized list of twelve is actionable in a way a list of four thousand is not.
Remediation tracking
Following findings through to closed rather than reporting them and moving on, including verification that a fix worked. Recurring assessment produces trend data, which is usually the first evidence a board sees that the programme is working.
Compliance evidence
Most frameworks require vulnerability management as an operating process rather than an annual event, and require you to show it running. The output is produced in a form an assessor accepts.
See also: Compliance Readiness