A vulnerability assessment is only useful if the next person can act on it. A long list of CVE numbers, with no owner and no sense of which systems actually face the internet, creates work without reducing risk.
The hand-back Algosystems expects from an assessment is narrower: the exposure, the asset, the evidence, and a sequence. Fix what is reachable and high impact first. Record what was accepted, and why, so the next cycle does not start from zero.
That record is also what an internal audit or a customer security review will ask for later. The scan is the start of the work, not the deliverable.