Key takeaways
- VAPT stands for vulnerability assessment and penetration testing: the assessment lists known weaknesses across many systems, and the penetration test proves which of them an attacker can actually use.
- In the Verizon 2026 DBIR, exploiting a vulnerability became the most common way into a breached organisation, at 31% of breaches, ahead of stolen credentials.4
- 48,185 CVEs were published in 2025, about 132 a day, so scanning must be frequent and its results need review before anyone acts on them.6
- RBI's 2026 Cyber Security Directions ask for a vulnerability assessment at least every six months and a penetration test at least every 12 months on critical systems.8
- PCI DSS v4.0.1 treats them as two separate duties: scans every three months (requirement 11.3) and a penetration test every 12 months and after significant changes (requirement 11.4).2
- Finding is only half the job: just 26% of CISA known exploited vulnerabilities were fully fixed in the DBIR data, with a median of 43 days, so retesting matters as much as testing.5
Your auditor asks for a VAPT report. One vendor sends a scan export that runs to dozens of pages and flags hundreds of issues. Another sends a short report that shows how a tester went from a forgotten login page to your customer database. Both are sold as VAPT. They are not the same thing. One tells you what could go wrong. The other shows you what will go wrong if nobody acts. This guide explains both in plain words, shows where each one fits, and gives you a tool to pick the right mix for your team.
Last reviewed on 24 September 2026 against NIST SP 800-115, PCI DSS v4.0.1, the RBI Cyber Security Directions 2026, SEBI CSCRF and the Verizon 2026 DBIR.
What is VAPT?
VAPT (vulnerability assessment and penetration testing) is a combined security testing service. The vulnerability assessment scans many systems for known weaknesses and ranks them. The penetration test then tries to exploit the most important ones, the way a real attacker would, to prove what can actually be reached. Together they give you both breadth and depth.
- VAPT meaning
- VAPT full form: Vulnerability Assessment and Penetration Testing. A two-part test. Part one (VA) finds and ranks known security weaknesses across your systems. Part two (PT) safely attacks a chosen scope to show which weaknesses can be used, chained together, and turned into real business harm.
Think of an office building. A vulnerability assessment walks every floor and notes each door that looks open. A penetration test picks a few of those doors, opens them, and sees how far inside it can get. The first gives you a long list. The second gives you a short, proven story.
The term VAPT is especially common in India. Banks, NBFCs, insurers and capital market firms see it in audit letters, in RBI and SEBI rules, and in the reports of auditing firms. SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) even has a standard for it, DE.CM.S5, with its own timelines.10 CERT-In, India's national cyber agency, publishes a list of over 200 empanelled information security auditing organisations that many regulated firms hire for this work.12
Outside India, you will more often see the two parts named separately. NIST's technical guide to security testing, SP 800-115, treats vulnerability scanning and penetration testing as different techniques with different strengths.1 PCI DSS gives them separate requirement numbers.2 The bundle name matters less than knowing which part you are actually buying.
A scan tells you which doors might be open. A pentest tells you which room the attacker reaches.
What is a vulnerability assessment?
A vulnerability assessment is a systematic check of your systems for known security weaknesses, such as missing patches, weak settings and outdated software. A vulnerability assessment is mostly automated, covers many assets at once, and ends with a ranked list of findings. It tells you what might be wrong, not what an attacker can do with it.
What a vulnerability assessment looks at
- Servers and endpoints: missing operating system patches, old software versions, unsafe services left running.
- Network devices: firewalls, VPNs and routers with known flaws or default settings.
- Web applications: common issues a scanner can spot from the outside, such as outdated libraries or missing security headers.
- Cloud accounts: storage open to the internet, over-broad permissions, logging turned off.
- Configuration: weak password rules, old encryption settings, unneeded admin shares.
What you get at the end
The output is a list of findings. Each one usually carries a CVE ID (a public name for a known flaw, such as CVE-2025-12345) and a CVSS score (a 0 to 10 severity rating). Good reports also add which asset is affected, why it matters to your business, and how to fix it. Weak reports stop at the raw scanner export.
Why the volume problem keeps growing
The number of known flaws rises every year. That makes the scanning part more useful and the reading part harder.
At about 132 new CVEs a day, no team can fix everything a scanner reports. The job becomes picking the right few. A vulnerability assessment helps you sort by severity. It cannot tell you which finding opens a path to your core banking system and which one sits on an isolated test box. That is where the second half of VAPT comes in.
A scan finding is a lead, not proof. NIST SP 800-115 warns that vulnerability scanners can report flaws that are not really there (false positives), so a person with the right skills has to interpret the results.1 Scanners also miss flaws they have no check for, such as broken business logic.
What is penetration testing?
Penetration testing is an authorised, simulated attack on your systems. A skilled tester, or a tool built to act like one, tries to exploit weaknesses and chain them together. NIST SP 800-115 describes it as mimicking real-world attacks to find ways around security controls. A penetration test answers one question: what can an attacker actually reach?
What a penetration test proves
- Exploitability: whether a flagged weakness can really be used in your setup, or is blocked by another control.
- Chains: how three "medium" issues combine into one critical path, for example a leaked password, a reused admin account and an unpatched file server.
- Impact: what data, money or systems the attacker ends up controlling.
- Detection: whether your monitoring team noticed anything while the test ran.
How standards describe the work
NIST SP 800-115 lays out a four-phase method: planning, discovery, attack and reporting. It notes that discovery and attack often loop, because each new foothold reveals more to test.1 The Penetration Testing Execution Standard (PTES) splits the same work into seven sections: pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post exploitation and reporting.14 For web applications, the OWASP Web Security Testing Guide lists these and other methods and gives detailed test cases.13
What a penetration test does not do
A pentest is deep but narrow. It covers the scope you agreed, inside a fixed time window. It will not check every server in your estate. It is also a snapshot: the day after it ends, your team ships new code and the picture changes. We covered that gap in why an annual pentest leaves most of the year untested.
Vulnerability assessment vs penetration testing: what are the key differences?
The main difference between vulnerability assessment and penetration testing is depth. A vulnerability assessment scans wide to list known weaknesses across many systems. A penetration test goes deep on a chosen scope to exploit weaknesses and prove impact. A vulnerability assessment is mostly automated and frequent. A penetration test is expert-led and usually less frequent.
| Factor | Vulnerability assessment (VA) | Penetration test (PT) |
|---|---|---|
| Main question | What weaknesses do we have? | What can an attacker do with them? |
| Goal | Find and rank known flaws | Prove real impact and attack paths |
| Method | Automated scans plus human review | Manual or automated exploitation, chaining and pivoting |
| Depth | Shallow: stops at "this looks vulnerable" | Deep: goes in and follows the path |
| Breadth | Wide: every asset in scope | Narrow: a chosen set of targets |
| Automation | High | Low to medium for manual tests, high for automated pentesting |
| False positives | Common, needs triage | Rare, because each finding is shown to work |
| Output | Ranked list with CVE IDs, CVSS scores and fixes | Narrative of attack paths with evidence, impact and fixes |
| Who runs it | Security or IT team, or a vendor | Skilled testers, internal red team, or a pentest platform |
| Typical frequency | Often: monthly or quarterly, and after changes | Less often: yearly or half-yearly, and after major changes |
| Time per cycle | Short: mostly machine time | Longer: mostly human time, plus scoping and retest |
| Cost per cycle | Lower | Higher, driven by scope and tester effort |
For a rupee view of that last row, see our breakdown of VAPT cost in India in 2026.
Why the difference matters more in 2026
For years, stolen passwords were the favourite way in. The Verizon 2026 Data Breach Investigations Report found that exploiting a vulnerability has now taken the top spot, at 31% of breaches.4 Attackers are also fast. VulnCheck counted 884 known exploited vulnerabilities first seen exploited in 2025, and 28.96% of them were exploited on or before the day the CVE was published.7 In those cases a scan that looks for published flaws is late by design. A penetration test that looks at how your systems fit together can still find the path, even when the specific bug is new.
Is vulnerability scanning the same as a vulnerability assessment?
Vulnerability scanning is not the same as a vulnerability assessment, though people often use the words as if they were. Scanning is the automated step: a tool probes systems and matches what it sees against known flaws. A vulnerability assessment adds scoping, human review, removal of false positives, business risk ranking and a fix plan.
It helps to see the three as a ladder. Each step up adds more human judgement and more proof.
- Vulnerability scan: a tool run. Output is raw. Good for frequent, wide checks.
- Vulnerability assessment: scans plus review. Output is a cleaned, ranked list tied to your assets and business.
- Penetration test: assessment plus exploitation. Output is proven attack paths and their impact.
So "vulnerability scanning vs penetration testing" is the widest gap of all. A scan says a door might be open. A pentest walks through it.
PCI DSS shows how seriously the scan step is taken on its own. Requirement 11.3.1 asks for internal scans at least once every three months, and 11.3.2 asks for external scans by an Approved Scanning Vendor (ASV) on the same cycle.2 The PCI Security Standards Council's FAQ adds that you need four "passing" quarterly scans in the past 12 months. For external scans, passing means no vulnerabilities scored 4.0 or higher on CVSS.3 Even so, PCI DSS still asks for a separate penetration test under requirement 11.4. A clean scan does not count as one.
What are the types of penetration testing?
The main types of penetration testing are external network, internal network, web application, API, mobile app, cloud, Active Directory, wireless and social engineering tests. Each one targets a different way in. Tests are also grouped by how much the tester knows at the start: black box (nothing), grey box (some access) and white box (full details).
| Type | What it tests | Typical finding |
|---|---|---|
| External network | Internet-facing IPs, VPNs, firewalls, mail servers | Unpatched VPN appliance that gives remote access |
| Internal network | What an insider or a phished laptop can reach | Flat network that lets one PC reach the database servers |
| Web application | Login, sessions, access control, input handling | One customer can view another customer's statements |
| API | Endpoints used by apps and partners | API returns more data than the app shows |
| Mobile app | App code, local storage, traffic to the backend | Tokens stored in plain text on the phone |
| Cloud | Identity roles, storage, network rules, keys | Over-broad role that lets a test account read all storage |
| Active Directory | Windows domain, accounts, trusts, group policy | Path from a normal user to domain admin |
| Wireless | Office Wi-Fi, guest networks, rogue access points | Guest Wi-Fi that reaches the corporate network |
| Social engineering | People and processes: phishing, calls, physical entry | Staff share one-time passwords over the phone |
Active Directory deserves a special mention. Once an attacker is inside, the Windows domain is often the fastest road to everything else. Our guide to Active Directory penetration testing covers what a good test checks, and why attackers log in instead of breaking in explains the credential side.
Black box, grey box and white box
- Black box: the tester starts with nothing but a company name or a URL, like an outside attacker. Realistic, but time is spent on discovery.
- Grey box: the tester gets a normal user account or some documents. This is the most common choice because it copies a phished employee or a malicious customer.
- White box: the tester sees source code, architecture diagrams and admin access. Deepest coverage for the time spent.
How does the VAPT process work, step by step?
The VAPT process usually runs in six steps: agree the scope and rules, discover assets, scan for known weaknesses, safely exploit the important ones, report with evidence and fixes, then retest to confirm the fixes work. Standards such as NIST SP 800-115 and PTES describe the same flow in slightly different words.
- Scope. Agree what is in and out, the testing windows, who to call if something breaks, and whether production is included. PTES calls this pre-engagement interactions and puts it first for a reason.14 Get the rules of engagement signed.
- Discover. Map domains, IP ranges, cloud accounts, apps, users and exposed services. NIST SP 800-115 treats this discovery phase as the base for everything after it.1 Forgotten assets found here are often the most useful result.
- Scan. Run vulnerability scans across the full scope. Review results, remove false positives and rank what is left by severity and business value. This is the VA half.
- Exploit. Safely try the most promising weaknesses. Chain them. Move sideways where the rules allow. Stop at agreed limits, for example reading a sample record, not downloading a table. This is the PT half.
- Report. Write two layers: a short summary for leadership and detailed findings with evidence, risk ratings and fix steps for engineers. Under SEBI CSCRF, the VAPT report is due within one month of completing the activity.10
- Retest. After fixes, test again to prove each issue is closed. SEBI CSCRF expects findings closed within three months of the report and revalidation within five months of the VAPT.10 PCI DSS 11.4.4 also requires fixing exploitable findings and repeating the test to confirm.2
Put the retest in the contract. Cobalt's 2025 pentest data found that less than half (48%) of pentest findings are ever fixed, and the median time to resolve issues was 67 days, even though most firms target 14 days for serious ones.15 A report nobody retests is a list of good intentions.
How often should you run a vulnerability assessment and a penetration test?
How often you run each test depends on your regulator and how fast you change. RBI's 2026 Directions set a vulnerability assessment at least every six months and a penetration test at least every 12 months for critical systems. PCI DSS asks for scans every three months. Teams that ship weekly or daily should scan more often.
| Rule set | Vulnerability assessment or scans | Penetration test | Also note |
|---|---|---|---|
| RBI Cyber Security Directions 2026 (banks, SFBs, NBFCs and others) | At least once every six months for critical systems and DMZ systems with customer interfaces | At least once every 12 months for the same systems | Risk-based for non-critical systems.8 After an IT project or upgrade, VA/PT on production (NBFC Directions, para 124).9 |
| SEBI CSCRF (20 August 2024) | VAPT at least once a year, starting in the first quarter; at least twice a year (once in each half) for protected systems | Report in 1 month, close in 3 months, revalidate in 5 months.10 Qualified stock brokers: half-yearly.11 | |
| PCI DSS v4.0.1 | Internal and external scans at least every three months (11.3.1, 11.3.2) and after significant changes | Internal and external at least every 12 months and after significant changes (11.4.2, 11.4.3) | Fix and retest (11.4.4).2 |
| No sector regulator | Set by change pace and exposure | Yearly is a common floor, plus after major changes | Use the tool below to size it |
The RBI rules are the same in spirit across the seven types of regulated entity. The Small Finance Bank Directions, for example, say VA shall be conducted at least once in every six months and PT at least once in 12 months for critical systems and those in the DMZ with customer interfaces.8 The NBFC version (RBI/DoS/2026-27/461) uses the same cadence in paragraph 121.9 Read the full breakdown in our guide to RBI Cyber Security Directions 2026 and their VAPT rules. For capital market firms, see SEBI CSCRF VAPT requirements, and for auditor and reporting duties, see CERT-In guidelines on 6-hour reporting and VAPT audits.
Minimums, not targets. This table summarises rules as published on the dates shown. It is not legal advice. Categories, scopes and timelines differ by entity type, so check the latest text of the rule that applies to you.
Triggers that should start a test, whatever the calendar says
- A new internet-facing app, API or portal goes live.
- A major release changes login, payments or access control.
- You move a workload to the cloud or change network zones.
- You merge with or connect to another company's network.
- A critical CVE lands in a product you run on the edge.
Which test do I need?
Answer five quick questions. Your recommended VA and PT mix updates as you click.
RBI's 2026 Directions ask for VA at least every six months and PT at least every 12 months on critical and customer-facing systems, plus testing on production after big changes.
Exposure risk if you only do VA: High (60/100)
A VA alone will not show whether flaws chain together, and it will not meet your regulator's penetration testing rule.
Indicative only. The mix is a planning aid built from the cadences cited in this article, not legal or audit advice. Your regulator's latest text and your auditor's scope decide the final plan.
Talk to us about your VAPT plan →What are the most common VAPT myths?
The most common VAPT myths are that a clean scan means you are safe, that one pentest a year keeps you covered, that VAPT is only for compliance, that automated testing is just scanning, and that the job ends when the report arrives. Each myth leaves a gap that attackers are happy to use.
Myth 1: "Our scan came back clean, so we are secure"
A clean scan means the scanner found none of the flaws it knows how to check. It says nothing about broken access control, business logic, weak processes or chained paths. Nearly 29% of the flaws VulnCheck tracked were exploited on or before disclosure day, before most scanners had a check for them.7
Myth 2: "One pentest a year keeps us covered"
An annual pentest meets many minimum rules. It does not cover the months in between, when new code, new cloud resources and new CVEs arrive. Your pentest is a photo. The attacker is filming.
Myth 3: "VAPT is only a compliance box"
Regulators set VAPT rules because exploitation now leads breach causes.4 Treat the report as a risk tool first. If it only lives in the audit folder, the findings stay open.
Myth 4: "Automated means scanning"
Some tools only scan. Others actually attempt exploitation and chain steps, the way a pentester does. The label matters less than the output: does it show a proven path, or just a list? We compare both in automated vs manual penetration testing.
Myth 5: "The report is the finish line"
Only 26% of CISA known exploited vulnerabilities were fully fixed in the DBIR data, with a median of 43 days to patch.5 The finish line is a passed retest, not a delivered PDF.
Where does automated penetration testing fit?
Automated penetration testing sits between scanning and a manual pentest. Like a scanner, it runs often and covers many systems. Like a pentester, it tries to exploit weaknesses and chain them to show real impact. Automated penetration testing does not replace expert testers for complex business logic, but it closes the long gaps between manual tests.
Here is a practical way to combine the three layers:
- Scan continuously or weekly to catch new CVEs and misconfigurations across every asset.
- Run automated pentests monthly or after big changes to confirm which findings are really exploitable and how they chain.
- Book expert-led pentests at least at your regulatory cadence, and aim them at what automation handles poorly: payment logic, approval flows, multi-step fraud scenarios.
This layered model is close to what Gartner calls continuous threat exposure management, or CTEM: a repeating cycle of scoping, discovering, prioritising, validating and mobilising fixes. Our CTEM explainer shows how VA and PT fit inside that loop. The point is simple. A vulnerability assessment tells you where to look. A penetration test tells you what matters. Doing both, often, tells you whether you are getting safer.
Frequently asked questions
What is the full form of VAPT?
VAPT stands for Vulnerability Assessment and Penetration Testing. The vulnerability assessment part scans your systems for known weaknesses and ranks them by risk. The penetration testing part safely attacks a chosen scope to prove which weaknesses can actually be used. Together they show both how many problems you have and how much damage an attacker could do with them.
What is the difference between vulnerability assessment and penetration testing?
A vulnerability assessment is wide and mostly automated. It checks many systems for known flaws and produces a ranked list. A penetration test is narrow and deep. A tester or pentest tool tries to exploit the flaws, chain them together and reach sensitive data. The assessment says what might be wrong. The penetration test proves what an attacker can do.
Can a vulnerability scan replace a penetration test?
No. A vulnerability scan only matches your systems against known flaws and can report false positives. It does not test whether flaws can be exploited or chained. Rules such as PCI DSS v4.0.1 list scanning and penetration testing as separate requirements, and RBI's 2026 Directions set separate cadences for VA and PT. You need both to meet those rules.
Is VAPT mandatory in India?
For many regulated firms, yes. RBI's 2026 Cyber Security Directions require VA at least every six months and PT at least every 12 months for critical systems. SEBI's CSCRF requires VAPT at least once a year, and twice for protected systems. Other sectors follow their own regulator or contract terms. Check the latest text of the rule that applies to you.
How often should penetration testing be done?
At least once a year for most regulated firms, and after every major change such as a new app, a cloud move or a network redesign. PCI DSS v4.0.1 asks for internal and external pentests every 12 months and after significant changes. Teams that ship code weekly or daily should add automated or continuous testing between those manual tests.
What are black box, grey box and white box penetration tests?
They describe how much the tester knows at the start. In a black box test the tester has almost nothing, like an outside attacker. In a grey box test the tester has a normal user account or some documents. In a white box test the tester sees code, diagrams and admin access. Grey box is the most common balance of realism and depth.
What happens after a VAPT report?
Your teams fix the findings, starting with the most critical, and the tester runs a retest to confirm each fix works. SEBI's CSCRF expects findings to be closed within three months of the report and revalidated within five months of the VAPT. PCI DSS also requires fixing exploitable issues and repeating the test. Track open items until the retest passes.
Is automated penetration testing a real penetration test?
It can be, if the tool actually attempts exploitation and chains steps to show impact, rather than only scanning. Automated penetration testing is good at running often and covering many systems. Expert testers are still better at complex business logic and creative fraud scenarios. Many teams use automated tests between scheduled manual pentests to close the gap.
Get the depth of a pentest at the pace of a scan
The hard part of VAPT is not knowing the difference. It is affording depth often enough. Scans run every week. Deep tests happen once or twice a year. Everything that changes in between is a guess.
Arxiis is an autonomous AI red teaming and penetration testing platform built to narrow that gap. It attacks your environment the way a pentester would, then hands your team proof and fixes in hours instead of weeks.
- Depth, not just a list: 26 security modules across 6 attack vectors (ransomware, Active Directory, cloud, web applications, containers and credentials).
- A multi-agent AI crew for OSINT, exploitation, lateral movement and reporting, so findings show real attack paths.
- Audit-ready output: CVSS-scored, MITRE ATT&CK-mapped findings with compliance overlays for 11 frameworks, including RBI, CERT-In, SEBI CSCRF and PCI DSS.
- Your data stays with you: fully on-premise deployment and an MIT-licensed open-source core.
Arxiis does not replace an empanelled auditor where your regulator asks for one. It helps you arrive at that audit with fewer surprises.
Sources
- NIST, "SP 800-115: Technical Guide to Information Security Testing and Assessment", September 2008. nist.gov
- PCI Security Standards Council, "PCI DSS v4.0.1" (requirements 11.3 and 11.4), June 2024. pcisecuritystandards.org
- PCI Security Standards Council, "FAQ 1152: Can entities be PCI DSS compliant if they have performed vulnerability scans at least once every three months, but do not have four passing scans?", January 2024. pcisecuritystandards.org
- Verizon, "2026 Data Breach Investigations Report", May 2026. verizon.com
- Help Net Security, "Verizon DBIR: Vulnerability exploitation is the dominant initial access vector", 20 May 2026. helpnetsecurity.com
- Jerry Gamblin, "2025 CVE Data Review", 1 January 2026. jerrygamblin.com
- VulnCheck, "State of Exploitation 2026", 2026. vulncheck.com
- Reserve Bank of India, "Reserve Bank of India (Small Finance Banks: Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026", RBI/DoS/2026-27/419, 31 July 2026. rbi.org.in
- TaxGuru, "RBI Issues NBFC Cybersecurity and Technology Risk Directions, 2026" (text of RBI/DoS/2026-27/461, paras 121 and 124), August 2026. taxguru.in
- SEBI, "Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities", circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024 (Tables 18 and 19, standard DE.CM.S5). sebi.gov.in
- SEBI, "Frequently Asked Questions on Cybersecurity and Cyber Resilience Framework", June 2025. sebi.gov.in
- CERT-In, "Empanelled Information Security Auditing Organisations by CERT-In", current list, accessed September 2026. cert-in.org.in
- OWASP, "Web Security Testing Guide: Penetration Testing Methodologies", stable edition. owasp.org
- PTES, "The Penetration Testing Execution Standard", version 1.1 documentation. pentest-standard.readthedocs.io
- Cobalt, "Key takeaways from the State of Pentesting Report 2025", 14 April 2025. cobalt.io