What a VAPT Actually Is, and What You Receive
Somebody has asked you for a VAPT. What the two halves are, what happens during one, what you get at the end, and the four things it is not.
Somebody has asked you for a VAPT. It could be a customer, an investor, an auditor, or a platform you want to sell through. This is what they are asking for.
Two activities, usually sold together
Vulnerability assessment is breadth. Tooling does most of the work, checking systems against known classes of weakness to produce an inventory of what is wrong. It covers ground quickly and says nothing about consequence. A list of two hundred issues does not tell you which one ends your week.
Penetration testing is depth. A person attempts to use what is wrong, in sequence, the way somebody hostile would. That means chaining a weak setting to an exposed endpoint to reach data that was supposed to be unreachable. It shows consequence over far less ground.
Sold together as VAPT, they answer both questions: what is wrong, and what could someone actually do. An engagement that is all assessment and no testing is a scan with a covering letter.
What actually happens
- Scoping. What is being tested, from what perspective, in which environment, and what is excluded.
- Reconnaissance. Mapping what exists, including the parts you had forgotten. Those are usually where the findings start.
- Testing. Automated coverage plus manual work on the things tooling cannot reason about: authorisation between users, business logic, sequences of legitimate actions with an illegitimate result.
- Verification. Confirming a finding is real and reachable in the running system. A scanner export skips this step.
- Reporting. Findings with evidence, severity, reproduction steps and remediation guidance.
- Retest. Confirming the fixes worked, ideally as its own dated document.
Two to four weeks is typical for a single application, most of it in steps three and five.
What you receive
A report. If the engagement exists to satisfy someone else, you usually get a certificate or attestation letter as well, stating what was tested and when.
You forward the certificate. The report is the part that improves your systems, and reports vary far more in quality than quotes do in price.
What it is not
- Not a guarantee. It describes what was found in an agreed scope during a fixed window. It does not certify that nothing else exists.
- Not continuous. It is a point in time, and the system changes the following week. Regulators impose repeat testing cadences on regulated entities for that reason.
- Not a substitute for fixing things. An unremediated report is documentation that you knew.
- Not an audit. An audit assesses controls and process against a standard. A penetration test attacks a system. Indian procurement documents routinely confuse the two, so check which one a requirement means before you respond to it.
How often
Annually is the common baseline, with a test after significant change: a new authentication system, a major release, a migration, a new integration handling sensitive data. Several Indian regulators set explicit cadences for the entities they supervise, and those override any general rule.
If you are buying one for the first time
Three things decide whether the engagement is worth what you pay: a scope written down properly, exclusions included; enough of the work done by hand instead of by tooling; and a retest, so the findings actually close.
None of them show up in a price. All three are negotiable before you sign.
About the author
Abhinav A
Lead — VAPT & Security Assessments
Leads Security Brigade's VAPT delivery team, having progressed from Security Consultant to Team Lead. Has executed advanced penetration tests across BFSI, fintech, QSR and telecom.
Continue reading
All articles →VAPT When No Regulator Requires It
Unregulated companies still end up buying penetration tests. The requirement arrives through customers, contracts, insurers and investors, and each of them wants something slightly different.
Which Indian Regulators Require Security Testing
Which regulator binds you, what instrument sets the requirement, and where to read the detail that applies to your entity type.
Writing a VAPT RFP That Gets Comparable Quotes
Most VAPT tenders return responses that cannot be compared. Four ways an RFP causes that, and what to specify instead so three proposals answer the same question.