Well described. Also pen testing is a litmus test that can be done anytime. The vuln models are for the few companies who have made great progress in squishing bugs and are taking a very proactive approach. Unfortunately that is still a small percentage of companies