All articlesVAPT guide

What Is a VAPT Audit? Process, Scope and Timeline

2026-10-04 9 min read

A practical guide to VAPT audits in India: what vulnerability assessment and penetration testing cover, how the process runs step by step, how long it takes and how to prepare your team.

What VAPT means

VAPT stands for Vulnerability Assessment and Penetration Testing. It combines two activities. A vulnerability assessment uses automated scanners and manual review to list known weaknesses across your applications, APIs, servers and cloud accounts. Penetration testing goes further: a tester tries to exploit those weaknesses, chain them together and prove what an attacker could actually reach, such as customer data, admin functions or payment flows.

The assessment gives breadth and the penetration test gives depth. A scan alone produces long lists with many false positives and misses business logic flaws. A manual test alone may not cover every host. Together they give a prioritised, evidence-backed view of real risk, which is why customers, auditors and regulators usually ask for VAPT rather than a scan report.

Why companies in India commission a VAPT audit

The most common triggers are customer security questionnaires, enterprise procurement, SOC 2 and ISO 27001 audits, PCI DSS, app marketplace reviews and sector rules. Regulated entities may also face expectations from regulators such as RBI, SEBI or IRDAI, and organisations handling personal data have obligations under the Digital Personal Data Protection Act, 2023 to take reasonable security safeguards.

Beyond compliance, VAPT is the cheapest moment to find a serious flaw. Fixing a broken access control issue before launch costs a few developer hours; discovering it after a breach costs incident response, notifications and customer trust.

Scoping the engagement

Scope defines exactly what will be tested: domains and URLs, API endpoints, mobile app builds, IP ranges, cloud accounts and user roles. Good scoping also records what is out of scope, testing windows, whether production may be tested and who to call if something critical is found.

Effort is driven by the number of unique pages and endpoints, user roles, integrations and how complex the business logic is. A small marketing site and a multi-tenant SaaS platform both have a URL, but the effort to test them properly is very different. Share architecture notes and test credentials for each role so testers spend time testing, not waiting.

The VAPT process step by step

1. Kick-off and rules of engagement: confirm scope, contacts, timing and data handling. 2. Reconnaissance: map the attack surface, technologies, subdomains and exposed services. 3. Vulnerability assessment: run authenticated and unauthenticated scans and review configuration. 4. Manual penetration testing: test authentication, session handling, authorisation between roles and tenants, input handling, file uploads, business logic and API behaviour, guided by references such as the OWASP Top 10 and OWASP ASVS. 5. Exploitation and validation: confirm findings safely and remove false positives. 6. Reporting: document each finding with severity, evidence, impact and remediation. 7. Remediation support and retesting: your team fixes issues and the tester verifies the fixes.

Critical findings should be shared as soon as they are confirmed rather than held until the final report.

How long a VAPT audit takes

Timelines depend on scope. A focused web application or API test commonly takes one to two weeks of testing, while larger estates with several applications, mobile apps and cloud environments take longer. Add time for scoping before testing and for remediation and retesting afterwards. If you have a hard audit or launch date, mention it during scoping so the plan works backwards from it.

How to prepare your team

Create dedicated test accounts for every role, ideally in a staging environment that mirrors production. Whitelist tester IPs on your WAF if you want the application itself tested rather than the firewall. Freeze major releases during the test window where possible, nominate a technical point of contact and tell your monitoring team so alerts are not escalated as a real attack.

After the audit

Prioritise fixes by severity and exploitability, not just by count. Fix critical and high issues first, request a retest and keep the final report and remediation evidence for auditors and customers. Most organisations repeat VAPT at least annually and after major changes such as new features, infrastructure migrations or acquisitions.

Get started

Ready to find what attackers will?

Talk to a senior pentester. Get a tailored scope, sample report and timeline within 24 hours.