What a VAPT engagement actually includes
VAPT combines a broad vulnerability assessment with manual penetration testing that attempts to exploit findings and establish real impact. A genuine engagement produces reproduction steps, business impact and a retest — not a scanner export with a logo on it.
Most people who ask us for a penetration test are asking because a client, an insurer or a tender requires one. That is a perfectly good reason. But it means the buyer often cannot tell a real engagement from a scanner export, and the price difference between the two is large enough to be tempting.
Here is what you are actually buying.
Assessment and testing are different things
Vulnerability assessment enumerates known weaknesses broadly, mostly with automated tooling. It gives coverage: outdated components, missing patches, weak configuration, exposed services.
Penetration testing attempts to exploit those weaknesses the way an attacker would, to establish what is genuinely reachable and what impact it has. It is manual, and it is where the findings that matter come from.
The distinction matters because a scanner reports a "critical" that is unreachable behind authentication, and misses the logic flaw that lets one user read another's records. The second finding is the one that ends up in a news story.
What a real engagement looks like
Scoping and rules of engagement. Targets, methods, timing, escalation contacts and explicit exclusions, agreed in writing before anything is touched. If a supplier skips this, that tells you something.
Reconnaissance and threat modelling. Mapping the actual attack surface and the paths an attacker would realistically take against this system, for this business.
Testing. Automated tooling for coverage, then manual exploitation. Authentication and session handling, authorisation and access control between accounts, business logic, injection, file handling, API abuse, rate limiting, and the infrastructure the application sits on.
Reporting. Per finding: severity, reproduction steps, evidence, business impact, and specific remediation guidance. Plus an executive summary written for someone who will not read the technical section.
Retest. Verification that fixes actually closed the finding, and a clean retest letter. This is usually what your client or auditor wants to see, and a supplier who does not include retest is selling you half of the thing.
What it costs in India
| Scope | Typical range |
|---|---|
| Single web application | $4,000 – $12,000 |
| Web + API + mobile app | $10,000 – $25,000 |
| External network (small estate) | $3,000 – $9,000 |
| Cloud configuration review | $4,000 – $12,000 |
| Full-scope, multi-application | $25,000 – $70,000 |
Prices well below these ranges almost always indicate an automated scan with a report template. That has its uses, but it will not withstand a client's security team reading it.
How to tell them apart
Ask these before you sign:
- Is testing manual, and how many days of it? A number in days is the single most revealing question.
- Do you provide reproduction steps for every finding? A scanner cannot.
- Is a retest included? If not, ask what it costs — you will need it.
- Will you test business logic and authorisation between accounts? Scanners cannot do this at all, and it is where the serious findings usually are.
- Who writes the report? If it is generated, you are buying a scan.
What it will not tell you
No security assessment proves the absence of vulnerabilities. A test reflects the systems, scope and time period assessed. A clean report means nothing was found within that scope in that window — not that the system is secure.
Anyone who tells you otherwise is selling you a certificate, not an assessment.
How often
Annually at minimum, and after any significant architectural change, new external-facing feature, or migration. Most compliance frameworks and enterprise procurement processes expect annual testing with retests after remediation.
We run VAPT across web, mobile, API, cloud and network surfaces, and we write reports for engineers and for boards separately. See our cybersecurity services, or ask us to scope an engagement.
- vapt
- penetration-testing
- compliance