New · Release 2026.04, Multi-tenant audit exports & SLA dashboards now live See changelog →
Security & Compliance

What Is VAPT? A Complete Guide

A comprehensive pillar guide covering what VAPT means, how an engagement runs, who needs VAPT services, what a VAPT report contains, which compliance frameworks require it, and what it costs in India — with verified 2025–2026 data.

ShareLinkedInX

VAPT stands for vulnerability assessment and penetration testing. It describes a combined, end-to-end security testing engagement that first identifies weaknesses systematically across your IT environment and then validates how those weaknesses can be exploited under real-world conditions. The result is not just a list of what is broken — it is proof of what a motivated attacker could achieve if those weaknesses were left unaddressed. Gartner forecasts global information security spending will reach USD 244.2 billion in 2026, up 13.3% year-on-year, while IBM's Cost of a Data Breach Report 2025 puts the global average breach at USD 4.44 million, with US organisations absorbing an all-time high of USD 10.22 million per incident.

Definition

What is VAPT, exactly?

VAPT (Vulnerability Assessment and Penetration Testing) is a combined security testing engagement that identifies weaknesses across an IT environment (assessment) and then actively exploits the most critical ones to demonstrate real-world risk (penetration testing). Together they deliver a complete, evidence-backed picture of security posture. If you only need the acronym unpacked, see the full form of VAPT explainer.

Component 1 — Vulnerability assessment is a systematic, broad examination using automated scanning cross-referenced against the CVE catalogue and the NVD. The output is a prioritised findings list scored with CVSS. It answers: what weaknesses exist in our environment right now?

Component 2 — Penetration testing takes the most critical findings and attempts to actively exploit them, chaining vulnerabilities, escalating privileges, and demonstrating business impact. It answers: how bad could it get if those weaknesses were actually exploited?

Process

How does VAPT work?

A VAPT engagement follows the arc defined by recognised methodologies such as PTES and NIST SP 800-115: agree scope and rules of engagement in writing, assess the environment broadly, exploit the highest-risk findings to prove real impact, report with evidence, then fix and retest. The assessment half is wide and largely automated; the penetration half is narrow, manual and attacker-minded. Every phase produces a concrete output — a signed scoping document, a prioritised findings list, proof-of-concept evidence, an audit-ready report, and verified-closed findings after the retest. Our full 8-phase breakdown walks through each phase, its deliverable and its common failure modes.

  • The phases in sequence: pre-engagement scoping → intelligence gathering → threat modelling → vulnerability analysis → exploitation → post-exploitation → reporting → remediation retest

Why VAPT beats either activity alone

Vulnerability assessment alone can generate 300–800 findings in a mid-size environment — many theoretically severe but practically hard to exploit. Penetration testing alone misses the breadth needed to prioritise correctly. VAPT combines both: comprehensive discovery first, then adversarial validation of what matters most. Our side-by-side guide to vulnerability assessment vs penetration testing covers when each activity alone is enough — and when it is not.

Deliverable

What a VAPT report contains

A professional VAPT report is two documents in one: an executive summary that translates findings into business-risk language for leadership, and a technical section that lets your engineers reproduce and fix every finding. If either half is missing, you have paid for half a report.

The executive summary states the overall risk rating, how many Critical and High findings were confirmed exploitable, what an attacker could realistically achieve, and the three to five remediation actions that matter most. It is the only part your board, your enterprise customers and most auditors will read, so it must stand on its own without the technical appendix.

  • Technical findings — each with a description, CVE reference where one exists, CVSS base score, affected assets, step-by-step reproduction instructions, and specific remediation guidance rather than a generic 'apply vendor patches'
  • Proof-of-concept evidence — screenshots or command output for every exploited finding; findings without evidence are opinions, and evidence is what gives the report value as both a risk-management tool and a compliance document
  • Attack narrative — the compromise chain in sequence, showing how individually moderate findings combined into one critical path
  • Scope and methodology statement — what was tested, what was excluded and which standard was followed; this is the section an auditor checks first
  • Retest attestation — a post-remediation confirmation that fixes held and introduced nothing new, which is the evidence that actually closes findings

Audience

Who needs VAPT?

  • Compliance-driven (PCI DSS, ISO 27001, HIPAA, SOC 2, NIS2) — VAPT typically satisfies both the vulnerability-scanning and penetration-testing mandates in a single engagement.
  • SaaS and cloud-first companies — a large attack surface across APIs, cloud configs, and third-party integrations; cloud misconfigurations are a top-three breach cause.
  • MSPs and IT service providers — managing security for multiple clients multiplies the risk surface; per-client isolation and separate reports are essential.
  • Healthcare and financial services — healthcare averages USD 7.42M per incident (most expensive sector 15 years running); financial services averages USD 5.56M.
  • Fast-growing and post-acquisition companies — rapid growth accumulates technical debt; acquired infrastructure carries unknown risk.

VAPT compliance: what frameworks require it

Most first VAPT engagements are commissioned because a specific framework, regulator or enterprise customer demanded one. The practical good news is that a single well-scoped engagement — with a proper scope statement, methodology reference and retest attestation — can serve as evidence across several frameworks at once, provided the report is written to be audit-readable rather than tester-readable.

  • PCI DSS 4.0 — quarterly internal/external scans by an ASV (Req. 11.3) + annual penetration test (Req. 11.4).
  • ISO 27001:2022 — Annex A 8.8 (systematic vulnerability management) + Annex A 8.26 (application security including pen testing).
  • DPDP Act 2023 (India) — data fiduciaries must implement 'reasonable security safeguards' to prevent personal data breaches, and periodic VAPT is the accepted way to evidence them; the Act and its rules are published by MeitY.
  • RBI, SEBI and CERT-In (India) — regulated banks, NBFCs and market intermediaries must run periodic VA/PT under their cyber-security frameworks, and certain filings must be signed off by a CERT-In empanelled auditing organisation.
  • SOC 2 Type II — CC7.1 (risk monitoring) + CC7.2 (vulnerability response, pen testing as evidence).
  • HIPAA — 164.308(a)(8) evaluation standard including technical testing.
  • NIS2 Directive (EU) — Article 21 risk-management measures including security testing.
  • DORA (financial services) — Article 24 regular testing + Article 26 advanced threat-led penetration testing (TLPT).

Budget

What VAPT costs and how long it takes

In India, a focused web application penetration test typically costs ₹1.5–4 lakh (USD 2,000–5,000). A combined network + web application VAPT for a mid-size environment runs ₹5–15 lakh (USD 6,000–18,000), and large multi-scope programmes covering cloud, API and mobile go beyond ₹25 lakh (USD 30,000+). US/EU-market engagements for comparable scope typically price two to three times higher. The final number depends on scope, asset count and whether a remediation retest is included.

On duration: a standard VAPT for a mid-size environment (200–500 assets, 2–3 web applications) takes 2–4 weeks end-to-end, large or multi-cloud environments 6–8 weeks, and the remediation retest 1–3 days. Compare quotes on human tester days and deliverables, not headline price — a fixed-price 'VAPT' delivered in under two days for a complex environment is almost always an automated scan with a cover page.

What to look for in a VAPT provider

Shortlist providers on four things: named testers with credentials such as OSCP or CREST, a methodology mapped to PTES or the OWASP Testing Guide, a redacted sample report with proof-of-concept evidence, and a retest included in the price. Then ask how many human tester days the quote buys — that single question separates genuine testing from rebadged scanning. Our guide to choosing a penetration testing company turns this into a full evaluation checklist, with red flags and the questions to ask before signing.

Infronest

Conclusion

Infronest's Security and VAPT module brings the entire vulnerability assessment and penetration testing workflow into a single tenant-isolated workspace: engagement creation, finding documentation with CVSS scoring, evidence upload, peer review, audit-ready PDF report generation, and remediation tracking — in the same platform where your infrastructure monitoring, IT asset management, helpdesk, and MDM live.

Each client's VAPT data is fully isolated within its own workspace subdomain — no data commingling, full audit trail. Start a 14-day free trial at infronest.com — no credit card required.

Scope, document, report and retest a full VAPT engagement in one workspace. 14-day free trial, no credit card required.

Explore Infronest VAPT services

Sources

Every figure and methodology reference in this article comes from the following published standards and reports. We cite them so you can verify the claims rather than take them on trust.

Frequently Asked Questions

What is the difference between VAPT and a penetration test?
A penetration test is one component of VAPT. VAPT is the full engagement: vulnerability assessment (broad scanning and classification) + penetration testing (active exploitation of the highest-risk findings) + reporting + remediation verification. A standalone penetration test skips the systematic assessment phase and typically focuses on a narrower scope.
How long does a VAPT engagement take?
A standard VAPT engagement for a mid-size environment (200–500 assets, 2–3 web applications) typically takes 2–4 weeks end-to-end. Large or multi-cloud environments may require 6–8 weeks. Retest adds 1–3 days after remediation.
How much does a VAPT cost in India?
In India, a focused web application penetration test typically costs ₹1.5–4 lakh (USD 2,000–5,000). A combined network + web application VAPT for a mid-size environment runs ₹5–15 lakh (USD 6,000–18,000), and large multi-scope programmes covering cloud, API and mobile go beyond ₹25 lakh (USD 30,000+). US/EU-market engagements for comparable scope typically price two to three times higher. The final number depends on scope, asset count and whether a remediation retest is included.
How often should VAPT be done?
Best practice is a full VAPT annually with lighter vulnerability assessments quarterly. Any significant change — a cloud migration, a new public API, a major release or an acquisition — should trigger a targeted engagement regardless of the annual schedule, because each of those resets your attack surface.
Is VAPT mandatory in India?
For regulated entities, effectively yes: RBI, SEBI and CERT-In frameworks require periodic VA/PT, and the DPDP Act 2023 obliges every data fiduciary to maintain 'reasonable security safeguards', which periodic VAPT is the standard way to evidence. Organisations processing card data additionally fall under PCI DSS, which mandates quarterly scans and an annual penetration test.
What does a VAPT report contain?
Two halves: an executive summary in business-risk language (overall rating, exploitable findings, top remediation priorities) and a technical section documenting every finding with its CVSS score, affected assets, reproduction steps, proof-of-concept evidence and specific remediation guidance. A quality report also includes a scope and methodology statement and, after fixes, a retest attestation.
Can VAPT be done on cloud infrastructure?
Yes. Cloud VAPT focuses on identity and entitlement misconfiguration — over-permissive IAM roles, public storage, exposed metadata services and weak tenancy boundaries — rather than missing patches. Note that AWS, Azure and GCP each publish rules on what customer-authorised testing is permitted against their platforms, so check those policies during scoping.

About the Author

Infronest

Infronest Security Research Team

CEH, OSCP, and ISO 27001 Lead Auditor certified, with 10+ years of hands-on VAPT delivery across banking, healthcare, SaaS, and critical infrastructure. Methodology follows PTES, the OWASP Testing Guide v4.2, and NIST SP 800-115.

Written by the Infronest Security Research Team — CEH, OSCP, and ISO 27001 Lead Auditor certified, with 10+ years of hands-on VAPT delivery across banking, healthcare, SaaS, and critical infrastructure. Statistics sourced from Gartner, IBM, and MarketsandMarkets; methodology follows PTES, OWASP Testing Guide v4.2, and NIST SP 800-115.

Ready to see where you are exposed?

Talk through your scope with an Infronest security engineer — targets, timelines and what a report for your environment looks like.