wow, sorry you have to justify a VA program to anyone these days. is there any sort of compliance card you can throw to help?
hardware you can either go the run the software on your own servers route or most of the big vendors have an appliance you can buy. you'll have to crunch the numbers between the two and see what makes more sense, against how many hosts you need to scan vs timeframe.
Yeah, I know it's ridiculous this day in age to a) not be doing such a thing and b) having to justify it. But, at least I've gotten it to a point where the powers that be are at least willing to listen to reason, but I have to justify this really well. Hoping the feedback from here helps...