Go from signed contract to first vulnerability scan in 48 hours, not 3 weeks. AssessKit collects network topology, existing controls, and compliance scope through a guided client portal — then auto-maps everything to CIS Controls v8 with a gap analysis ready before you touch a scanner.
Works with
Product Preview
Here's what we're building. Join the waitlist to get early access when we launch.
The problem
Nessus, Qualys, Rapid7 — great scanners, but they were built for in-house security teams, not consultants juggling 15 clients. None of them help you manage the pre-assessment discovery that makes or breaks your pen test scope. You're left stitching together Word docs, spreadsheets, and email threads.
Your client doesn't know their CIS Controls maturity level. They can't tell you which of the 18 control families they've implemented. You spend 3 weeks chasing this information over email before you can even scope the vulnerability assessment.
You're a penetration testing professional billing $200/hour, but your client intake process is emailing a Word document and hoping they fill in the network ranges correctly. That gap between your technical skill and your discovery workflow costs you 15 billable hours — $3,000 — per engagement.
How it works
White-labeled with your firm's name. Walks your client through network topology, existing security controls, compliance requirements, and asset inventory — with plain-English explanations for every question. Works even when the client contact is non-technical and doesn't know their subnet ranges.
AssessKit maps client responses to CIS Controls v8 (all 18 control families), identifies gaps, and flags areas needing vulnerability assessment or penetration testing. No manual spreadsheet mapping.
A structured security baseline document with gap analysis, risk prioritization, and pen test scope recommendations lands in your dashboard. Start the vulnerability assessment on day 1, not day 21.
Built for
Every day spent chasing clients for network ranges and control inventories is a day you're not running the pen test. AssessKit collects everything upfront so you can scope the assessment immediately.
AssessKit auto-maps client responses to all 18 CIS control families. You get a gap analysis before you start, so your vulnerability assessment targets the controls that actually need testing.
Early access · Limited spots
We are onboarding a small group of penetration testing and vulnerability assessment consultancies to test AssessKit before full launch. Join the waitlist — you will be the first to know when early access opens.
Free during early access
Your feedback shapes the product
No credit card required
First to know when we launch
We are building this if 50 people sign up. Help us validate the idea.