Skip to content
Atomos TechnologiesAtomos Technologies
Security

What a VAPT engagement actually includes

VAPT combines a broad vulnerability assessment with manual penetration testing that attempts to exploit findings and establish real impact. A genuine engagement produces reproduction steps, business impact and a retest — not a scanner export with a logo on it.

Atomos Technologies3 min read

Most people who ask us for a penetration test are asking because a client, an insurer or a tender requires one. That is a perfectly good reason. But it means the buyer often cannot tell a real engagement from a scanner export, and the price difference between the two is large enough to be tempting.

Here is what you are actually buying.

Assessment and testing are different things

Vulnerability assessment enumerates known weaknesses broadly, mostly with automated tooling. It gives coverage: outdated components, missing patches, weak configuration, exposed services.

Penetration testing attempts to exploit those weaknesses the way an attacker would, to establish what is genuinely reachable and what impact it has. It is manual, and it is where the findings that matter come from.

The distinction matters because a scanner reports a "critical" that is unreachable behind authentication, and misses the logic flaw that lets one user read another's records. The second finding is the one that ends up in a news story.

What a real engagement looks like

Scoping and rules of engagement. Targets, methods, timing, escalation contacts and explicit exclusions, agreed in writing before anything is touched. If a supplier skips this, that tells you something.

Reconnaissance and threat modelling. Mapping the actual attack surface and the paths an attacker would realistically take against this system, for this business.

Testing. Automated tooling for coverage, then manual exploitation. Authentication and session handling, authorisation and access control between accounts, business logic, injection, file handling, API abuse, rate limiting, and the infrastructure the application sits on.

Reporting. Per finding: severity, reproduction steps, evidence, business impact, and specific remediation guidance. Plus an executive summary written for someone who will not read the technical section.

Retest. Verification that fixes actually closed the finding, and a clean retest letter. This is usually what your client or auditor wants to see, and a supplier who does not include retest is selling you half of the thing.

What it costs in India

ScopeTypical range
Single web application$4,000 – $12,000
Web + API + mobile app$10,000 – $25,000
External network (small estate)$3,000 – $9,000
Cloud configuration review$4,000 – $12,000
Full-scope, multi-application$25,000 – $70,000

Prices well below these ranges almost always indicate an automated scan with a report template. That has its uses, but it will not withstand a client's security team reading it.

How to tell them apart

Ask these before you sign:

  • Is testing manual, and how many days of it? A number in days is the single most revealing question.
  • Do you provide reproduction steps for every finding? A scanner cannot.
  • Is a retest included? If not, ask what it costs — you will need it.
  • Will you test business logic and authorisation between accounts? Scanners cannot do this at all, and it is where the serious findings usually are.
  • Who writes the report? If it is generated, you are buying a scan.

What it will not tell you

No security assessment proves the absence of vulnerabilities. A test reflects the systems, scope and time period assessed. A clean report means nothing was found within that scope in that window — not that the system is secure.

Anyone who tells you otherwise is selling you a certificate, not an assessment.

How often

Annually at minimum, and after any significant architectural change, new external-facing feature, or migration. Most compliance frameworks and enterprise procurement processes expect annual testing with retests after remediation.


We run VAPT across web, mobile, API, cloud and network surfaces, and we write reports for engineers and for boards separately. See our cybersecurity services, or ask us to scope an engagement.

  • vapt
  • penetration-testing
  • compliance

Tell us what you are building.

Send the brief, the half-formed idea, or the problem you have not solved yet. We reply within 24 hours.