Can both teams verify the promised coverage?
For Vulnerability Assessment as a Service, the proposed coverage includes servers and workstations, routers and network devices, internet-facing services, websites and web portals, cloud-hosted assets, authenticated systems. The agreement should identify the systems and owners behind each area, the access or telemetry needed, the validation performed during onboarding, and the process for detecting and resolving a silent coverage failure.