VAPT means Vulnerability Assessment and Penetration Testing: a broad scan for known weaknesses plus manual testing that proves which can be exploited. A penetration test on its own is the second half of that pair. The acronym is used mostly in India and across South and Southeast Asia, and Indian regulators including RBI, SEBI and CERT-In refer to it in their directions and guidelines. This guide explains what each activity involves, what you receive at the end, how often regulators expect it, and how to decide which one you need.
01What is VAPT and what does it stand for?
VAPT stands for Vulnerability Assessment and Penetration Testing. It describes one engagement that combines two activities: an assessment that finds and ranks known weaknesses across a set of systems, and a penetration test that tries to exploit those weaknesses to show real impact. The acronym is most widely used in India and across South and Southeast Asia. In the US and Europe, buyers tend to order a vulnerability scan and a penetration test as separate line items, and the word VAPT rarely appears in contracts. In India the term carries regulatory weight. RBI's IT governance directions refer to VA/PT, SEBI's cybersecurity framework uses VAPT throughout, and CERT-In's audit guidelines list VAPT as one of the audit types an engagement scope must name. That is why procurement teams, auditors and enterprise customers ask for a 'VAPT report' by name. When someone asks you for one, confirm what they expect inside it. Some mean a scanner export with a cover page. Others mean a full manual test with exploitation evidence. Those are very different pieces of work.
02What is the difference between VAPT and penetration testing?
A penetration test is one half of VAPT. VAPT puts a broad vulnerability assessment in front of it, so the engagement covers breadth, with every in-scope asset checked for known issues, and depth, with selected weaknesses exploited to prove impact. In practice the line blurs. A good penetration test includes its own discovery and scanning phase, and a good VAPT spends most of its effort on manual testing. The meaningful differences are emphasis and deliverable. A VAPT report usually lists every confirmed vulnerability across the scope, including low-severity hygiene issues, and marks which ones were exploited. A penetration test report usually centers on attack paths: how the tester moved from an initial foothold to an outcome that matters, such as access to sensitive data or administrative control. This matters when you buy. If a regulator or customer asks for VAPT, a penetration test report that omits the broad vulnerability inventory may not satisfy them. If your goal is to understand how a real attacker would get in, a VAPT that is mostly automated scanning will not tell you.
03How does a vulnerability assessment differ from a penetration test?
A vulnerability assessment identifies and ranks weaknesses, mostly with automated tools. A penetration test attempts to exploit them, mostly by hand, to show what an attacker could achieve. CERT-In's Comprehensive Cyber Security Audit Policy Guidelines draw the same line. They define a vulnerability assessment as an examination of a system to determine the adequacy of its security measures and identify deficiencies. They define penetration testing as actively testing components to identify and exploit vulnerabilities, with the objective of determining whether those vulnerabilities can be used to compromise the application, access sensitive data or affect the underlying infrastructure. Method. An assessment runs authenticated and unauthenticated scans, checks configurations against hardening benchmarks, and matches software versions against known vulnerabilities, after which an analyst reviews the output. A penetration test starts with reconnaissance, then moves to manual exploitation, privilege escalation and, where the scope allows, movement between systems. It needs written rules of engagement, and CERT-In's guidelines require written approval before any penetration test is conducted. False positives. Scanners often infer a vulnerability from a version string or banner, so a server running a backported security fix can still report an old version and get flagged. Assessments also miss whole classes of issues that no signature can detect: broken access control between users, flawed business logic, and weaknesses that only become serious when chained together. A penetration test removes most false positives by attempting the exploit, and it finds logic flaws because a person is reasoning about how the application is supposed to behave. Output. An assessment delivers a prioritized list of findings with severity ratings and remediation steps. A penetration test delivers evidence: request and response pairs, screenshots, the exact path from entry to impact, and a plain statement of business risk. CERT-In's guidelines require empanelled auditors to rate findings with CVSS for severity and to add EPSS to show the likelihood of real-world exploitation.
- 01Goal: an assessment finds and ranks known weaknesses; a penetration test proves what can be exploited
- 02Method: an assessment is mostly automated scanning plus analyst review; a penetration test is mostly manual attack work
- 03Coverage: an assessment is broad across many assets; a penetration test goes deep on a defined scope
- 04False positives: common in assessments; rare in penetration tests because each finding is demonstrated
- 05Logic and access-control flaws: usually missed by scanners; a core target of manual testing
- 06Output: an assessment gives a ranked findings list; a penetration test gives attack narratives with proof of impact
- 07Frequency: assessments can run on a schedule or on every change; penetration tests run periodically and after major change
- 08VAPT: both in one engagement, with the assessment feeding the test
04How often should you run a vulnerability assessment and a penetration test?
Run vulnerability assessments on a regular schedule and after significant changes, and run penetration tests at least annually and after major changes. Regulated entities in India have specific minimums, covered in the next section. The two activities have different economics. Scanning is largely automated, so it can run on a schedule or be wired into the release pipeline, and it catches newly disclosed vulnerabilities in software you already run. A penetration test needs skilled people for a fixed window, so it runs periodically and is timed around the changes that matter. CERT-In's audit guidelines give a sensible baseline for any organization. They treat a comprehensive cyber security audit at least once a year as the minimum, require an audit after major changes such as system overhauls, technology migrations or configuration changes that affect sensitive data or critical infrastructure, and call for periodic audits even when nothing has changed, because new vulnerabilities keep being disclosed. The same guidelines allow sectoral regulators to raise the frequency based on the size of the organization, the criticality of its assets and the complexity of its digital infrastructure. Events worth treating as a reason to retest include a new internet-facing application or API, a major release, a cloud migration, an acquisition and a significant security incident.
05When do Indian regulators require VAPT?
Banks, larger NBFCs and SEBI-regulated entities have explicit VAPT requirements, and CERT-In's audit guidelines set expectations for audits carried out by CERT-In empanelled auditors. The details below come from the primary documents. RBI. The Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (RBI/2023-24/107, dated November 7, 2023) applies to scheduled commercial banks other than regional rural banks, small finance banks, payments banks, NBFCs in the top, upper and middle layers, credit information companies and the all India financial institutions. Paragraph 26 sets minimum VA and PT frequencies for critical information systems and for systems in the DMZ with a customer interface. It also requires VA/PT across the system lifecycle, including before and after implementation and after major changes, a risk-based approach for non-critical systems, testing by trained and independent experts, and time-bound remediation. SEBI. The Cybersecurity and Cyber Resilience Framework (CSCRF), issued by circular dated August 20, 2024, sets VAPT periodicity by entity type and fixes timelines for reporting, closure and revalidation. Unless otherwise specified, CSCRF audits must be conducted by a CERT-In empanelled auditing organization, and VAPT is required before new systems are commissioned, especially critical ones. SEBI's CSCRF FAQs add that qualified stock brokers must run VAPT half-yearly regardless of their CSCRF category. CERT-In. The Comprehensive Cyber Security Audit Policy Guidelines, version 1.0 dated July 25, 2025, are binding on CERT-In empanelled auditing organizations and on the auditee entities covered under the relevant provisions. They also require the audit scope to state the type of audit being conducted, with VAPT named as one of those types. Outside these sectors, the most common source of a VAPT request is an enterprise customer's vendor security review. Always work from the current version of the circular that applies to you, because regulators revise these documents.
- 01RBI: vulnerability assessment at least once every six months and penetration test at least once in 12 months for critical systems and customer-facing DMZ systems
- 02SEBI CSCRF, entities identified as protected systems or CII by NCIIPC: VAPT at least twice a year, one in each half of the financial year
- 03SEBI CSCRF, all other regulated entities: VAPT at least once a year, starting in the first quarter of the financial year
- 04SEBI CSCRF timelines: report within 1 month of completing VAPT, findings closed within 3 months of the report, revalidation within 5 months of completing VAPT
- 05CERT-In audit guidelines: a comprehensive cyber security audit at least once a year as the minimum, plus audits after major changes
06How do you choose between a vulnerability assessment, a penetration test and VAPT?
Start from the question you need answered and who will read the result. Coverage questions call for an assessment, impact questions call for a penetration test, and most Indian compliance obligations call for both in the form of VAPT. Before signing a scope, ask the provider how much of the engagement is manual testing and which findings will be demonstrated with evidence. Ask whether authenticated testing is included, since many serious issues only appear once a tester is logged in. Confirm that retesting of fixed findings is part of the engagement, because SEBI's framework requires revalidation and most auditors will ask for it. Check that the report format matches what your regulator expects, and confirm whether your obligation requires the work to be performed by a CERT-In empanelled auditor.
- 01Choose a vulnerability assessment when you need a regular, broad view of known weaknesses across many assets, or a baseline before your first manual test
- 02Choose a penetration test when you need to know what an attacker could reach, after launching a new application or API, or when a customer asks for proof of exploitability
- 03Choose VAPT when a regulator, auditor or customer asks for it by name, or when you need both an inventory of issues and demonstrated impact in one report
- 04Start with an external attack surface assessment when you are unsure what you expose to the internet, because every other test depends on an accurate scope
07How Faltrox can help
Faltrox offers VAPT and Vulnerability Assessment for organizations that need a broad inventory of weaknesses along with demonstrated impact, Web Application Penetration Testing for customer-facing applications and APIs, and Network Penetration Testing for internal and external infrastructure. When the scope itself is uncertain, an External Attack Surface Assessment maps what you expose to the internet before deeper testing begins. For regulated entities, the team helps you get ready for formal audits: testing ahead of the audit window, prioritizing fixes against regulatory closure timelines, and retesting remediated findings. Where a framework such as SEBI's CSCRF requires the audit itself to be performed by a CERT-In empanelled organization, that formal audit remains with the empanelled auditor.
