VAPT questions, answered
Everything teams ask before booking vulnerability assessment and penetration testing: scope, process, reports, compliance and cost.
VAPT basics
What is VAPT?
VAPT stands for Vulnerability Assessment and Penetration Testing. The vulnerability assessment finds and lists known weaknesses using scanners and manual review. The penetration test then tries to exploit them, as a real attacker would, to prove actual business impact. Together they give a prioritised, evidence-backed view of risk.
What is the difference between VAPT and penetration testing?
Penetration testing is one half of VAPT. VAPT adds a broad vulnerability assessment so coverage is wide as well as deep. In India the term VAPT is commonly used in tenders, audits and regulatory requests, while penetration testing is more common internationally. The work overlaps heavily.
Is a vulnerability scan the same as VAPT?
No. An automated scan alone produces lists of potential issues, often with false positives, and misses business logic and access control flaws. VAPT includes manual testing and validation, which is what auditors and enterprise customers usually expect.
What can be covered by a VAPT?
Typical scopes include web applications, APIs, mobile apps (Android and iOS), cloud configuration on AWS, Azure or GCP, internal and external networks, and source code review. Scope is agreed in writing before testing begins.
Compliance and regulation
Who needs VAPT in India?
Companies commonly commission VAPT because of customer security questionnaires, SOC 2, ISO 27001 or PCI DSS audits, app marketplace reviews and sector expectations from regulators such as RBI, SEBI or IRDAI. Organisations handling personal data must also take reasonable security safeguards under the Digital Personal Data Protection Act, 2023.
Do I need a CERT-In empanelled auditor?
Some government bodies and regulated entities require audits by a CERT-In empanelled organisation. Many private-sector requirements, such as SOC 2 or customer questionnaires, do not. Confirm the exact requirement with your regulator, auditor or customer before choosing a vendor.
Does VAPT help with SOC 2 and ISO 27001?
Yes. Auditors often look for a recent, independent penetration test with tracked findings and evidence that high-risk issues were fixed and retested. A VAPT report can serve as that evidence when its scope covers in-scope systems.
Process, timeline and reports
How long does a VAPT take?
A focused web application or API test commonly takes one to two weeks of testing. Larger scopes with several applications, mobile apps or cloud environments take longer. Scoping happens before testing, and remediation and retesting happen after.
Will VAPT affect my production systems?
Testing is planned to minimise disruption. Many teams test in a staging environment that mirrors production. When production is tested, rules of engagement define safe techniques, timing windows and an escalation contact.
What is in a VAPT report?
An executive summary, scope and dates, methodology, and a detailed finding for each issue with severity (often based on CVSS), affected asset, reproduction steps, evidence, business impact and remediation guidance, plus retest status.
How often should VAPT be done?
Most organisations run VAPT at least once a year and after significant changes such as new features, a new API, authentication changes or a cloud migration. Some regulators and customers specify their own frequency.
Cost and getting started
How much does VAPT cost?
Cost depends on the number of applications, endpoints, user roles and environments, and on the testing depth required. Because scopes vary so widely, we provide a written quote after a short scoping call rather than a fixed public price.
What do you need from us to start?
A list of in-scope assets, test accounts for each user role, any architecture or API documentation, preferred testing windows and a technical point of contact. If you have an audit or launch deadline, share it at the start.
How do I get a VAPT quote from Scantra?
Fill in the short form on our Speak to Sales page and pick a 30-minute slot. We will discuss your scope and requirements and follow up with a written quote.
Read more
Ready to find what attackers will?
Talk to a senior pentester. Get a tailored scope, sample report and timeline within 24 hours.
