Skip to content

Assessment

Vulnerability
Assessment and
Penetration Testing

VAPT: an analyst-validated vulnerability assessment and a manual penetration test, delivered as one engagement

Assessment $1,500 per scan, pentest from $4,000, fixed scope, free retest included. See all pricing →

Get a Fixed Quote

Three fields. A senior tester reads it and replies within one business day.

Prefer the full scoping questionnaire? 
OSCP & OSCE3 certified testers150+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When you need VAPT

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • An ISO 27001 auditor, a partner in the UK or India, or a customer questionnaire uses the term and wants a VAPT report and certificate.
  • You need a full inventory of known weaknesses and proof of which ones actually matter, in one engagement rather than two vendors.
  • PCI DSS asks for quarterly vulnerability scans and an annual penetration test, and you would rather buy them together.
  • A scanner report landed on your desk with hundreds of findings and nobody can say which five to fix first.
  • You are building a baseline before a recurring testing program and want the assessment and the test done by the same senior team.

Two disciplines, one engagement

Vulnerability assessment versus penetration testing

The two halves of VAPT are often confused and often sold as if they were interchangeable. They are not, which is exactly why buying them together works.

Vulnerability assessment

Goal
Find every known weakness across the scope
Method
Automated scanning, then analyst validation
Output
A validated register ranked by real severity
Finds
Missing patches, misconfigurations, exposed services
Frequency
Monthly or quarterly
Price
$1,500 per validated scan

Penetration test

Goal
Prove what an attacker can actually do with them
Method
Manual testing, exploitation, and chaining by a senior tester
Output
Proven findings with evidence and an attack narrative
Finds
Authorization flaws, logic abuse, exploitable chains
Frequency
Annually and after significant change
Price
From $4,000, by target and size

What VAPT finds

What the assessment finds, and what the test proves

The assessment is wide. It catches every known weakness across the scope. The penetration test is deep. It shows which of those weaknesses, alone or chained, an attacker would actually use. Buying both closes the gap between a list and a risk.

Known vulnerabilities & missing patches

Software versions with published weaknesses, from the operating system to the web server to the libraries inside the application.

We test for

  • Authenticated and unauthenticated scanning of every host and application
  • Version and configuration matching against current vulnerability data
  • Manual validation of every high and critical result
  • Exploit availability and exposure checks that set real priority
  • Deduplication across hosts so one root cause is one finding

Misconfigurations & weak defaults

The settings that ship insecure and stay that way: default credentials, open management ports, permissive cloud storage, and missing security headers.

We test for

  • Default and weak credentials on services and admin panels
  • Exposed management interfaces and debug endpoints
  • TLS, certificate, and cipher configuration
  • Cloud storage, IAM, and network policy review
  • Security headers, cookies, and CORS on web applications

Exploitable chains

Where the penetration test earns its place: the low-rated findings that combine into a path to data, and the high-rated ones that turn out not to be reachable.

We test for

  • Manual exploitation of validated assessment results
  • Chaining across hosts, services, and trust relationships
  • Reachability and impact verification for every critical
  • Downgrading unreachable findings with evidence
  • Attack narrative from first foothold to objective

Authorization & business logic

Flaws no scanner can detect because they are not bugs in software but mistakes in how the application decides who may do what.

We test for

  • Object and function-level authorization across roles
  • Multi-tenant isolation with real accounts
  • Workflow, payment, and approval logic abuse
  • Race conditions and replay
  • Trust placed in client-side controls

Credential & access weaknesses

The passwords, tokens, and accounts that let an attacker skip the exploit and log in.

We test for

  • Password policy and spraying within agreed rules
  • Breached-credential exposure for your domains
  • Service account and API key hygiene
  • Multi-factor coverage on every remote entry point
  • Privilege paths in Active Directory or cloud identity

Exposure the inventory missed

Assets nobody scans because nobody remembers them: old subdomains, staging systems, and cloud resources created outside the process.

We test for

  • Subdomain, DNS, and certificate enumeration
  • Cloud asset discovery across accounts and regions
  • Comparison of discovered assets against the asset register
  • Forgotten services and abandoned deployments
  • Third-party and vendor-managed exposure

The term and where it comes from

Who asks for VAPT, and what they expect back

“VAPT” is the standard phrase in ISO 27001 programs and in the security language of the UK, India, and the Gulf, which is why US companies usually meet it in a customer questionnaire, an auditor’s evidence request, or a partner’s vendor policy. The buyer wants two things: a complete picture of known weaknesses, and confirmation from a qualified tester that the serious ones were exploited, or could not be, and then fixed.

Our combined report is built for that request. The register section answers “what did you find”, the penetration test section answers “what did it mean”, and the attestation letter answers “can you prove an independent firm did this”, which is the document most often filed as a VAPT certificate. The full explanation of the term is in our guide to vulnerability assessment and penetration testing.

Methodology

How we test

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your vulnerability assessment and penetration testing runs through.

  1. 01

    Scope & credentials

    Ranges, hosts, and authenticated versus unauthenticated coverage agreed.

  2. 02

    Scan

    Tuned scans run internally and externally on the agreed cadence.

  3. 03

    Validate

    Analysts confirm findings and remove false positives before anything reaches you.

  4. 04

    Prioritize

    Findings ranked by exploitability and exposure, not by raw scanner score.

  5. 05

    Report & trend

    Prioritized list, ticketing integration, and trend reporting over time.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope and baseline

    We agree the assets, the credentials, and the rules, then fix a price for the assessment and the test in writing.

  2. 02

    Vulnerability assessment

    Scanning across the full scope, followed by manual validation of every result. False positives are removed and severities are corrected before anything reaches the report.

  3. 03

    Penetration test

    Senior testers take the validated results and go further, exploiting and chaining findings and hunting the logic and authorization flaws no scanner reports.

  4. 04

    One report

    A combined report that keeps the two layers distinct: the validated register for your patching program and the proven findings for your risk decisions.

  5. 05

    Retest and certificate

    A free retest of the penetration test findings once fixed, and an attestation letter that serves as the VAPT certificate auditors and customers ask for.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type. The findings and outcomes are real.

All case studies →

Free

Retest on every penetration test

150+

Years combined experience

13

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

Fintech · Payments

Post-Incident Web App Assessment

Medium risk

Excessive data exposure: API responses leaked transaction metadata, including precise geolocation, enabling real-world tracking of users.

Outcome. Surfaced the exposure and hardening gaps, prioritized by how readily an attacker could chain them, and delivered fixes plus a retest to confirm closure.

8

Findings

3

Medium

Post-incident

Engagement

Read the case study

FAQ

Frequently asked questions

What teams most often ask before scoping vulnerability assessment and penetration testing.

Still have questions? 
01What is VAPT?

Vulnerability assessment and penetration testing: a combined engagement in which an analyst-validated vulnerability assessment finds every known weakness across the scope and a manual penetration test proves which of them an attacker could actually exploit. The two produce different evidence, and the combined report keeps them distinct so you can run a patching program from one half and make risk decisions from the other.

02Is VAPT the same as a penetration test?

No. A penetration test is the deep half: manual exploitation by a senior tester. A vulnerability assessment is the wide half: validated scanning across everything in scope. Many vendors sell a scan and call it a penetration test; we price and deliver them separately so the report is honest about which findings were proven by hand.

03How much does VAPT cost?

A validated vulnerability assessment is $1,500 per scan of a defined scope. The penetration test is priced by target: external network from $4,200, API from $4,000, web application from $5,200, internal network from $6,000, cloud from $6,800. Both prices are fixed in writing before we start, and the penetration test includes a free retest.

04Do you issue a VAPT certificate?

We issue an attestation letter that states what was tested, when, by whom, against which standards, and the status of the findings at the close of the engagement, including the retest. It is the document customers, ISO 27001 auditors, and partners accept as a VAPT certificate, and unlike a rubber-stamped “VAPT certified” badge it describes a real scope.

05How often should VAPT be repeated?

Run the assessment monthly or quarterly, because new vulnerabilities are published every week and PCI DSS asks for quarterly scans. Run the penetration test annually and after significant changes such as a major release, a migration, or a merger. Teams that want both on a schedule buy them as a recurring testing program at one fixed program price.

06Can VAPT satisfy ISO 27001, SOC 2, or PCI DSS?

Yes, scoped correctly. ISO 27001 auditors look for technical vulnerability management and independent testing evidence; SOC 2 auditors look for the same under the Security criteria; PCI DSS wants quarterly scans under Requirement 11.3 and an annual penetration test under 11.4. Our report maps each finding to the requirement you name, and the attestation letter summarizes the engagement for the file.

07Do you validate scanner results or just send the export?

Every high and critical result is validated by hand before it appears in the report, false positives are removed, and severities are corrected for your actual exposure. The register you receive is shorter than the raw scan and every line on it is real, which is the difference between a scan and an assessment.

Ready to test your defenses?

Talk to our team about scoping vulnerability assessment and penetration testing.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.