Problem Threats Stories How it works Blogs Pricing
Security Testing

Vulnerability assessment vs penetration testing: what is VAPT, and which one do you need?

A vulnerability assessment lists what might be wrong. A penetration test proves what an attacker can actually reach. Here is how the two differ, how VAPT works, and how often the rules say to run each.

By Arxiis ResearchUpdated 21 min read

Key takeaways

  • VAPT stands for vulnerability assessment and penetration testing: the assessment lists known weaknesses across many systems, and the penetration test proves which of them an attacker can actually use.
  • In the Verizon 2026 DBIR, exploiting a vulnerability became the most common way into a breached organisation, at 31% of breaches, ahead of stolen credentials.4
  • 48,185 CVEs were published in 2025, about 132 a day, so scanning must be frequent and its results need review before anyone acts on them.6
  • RBI's 2026 Cyber Security Directions ask for a vulnerability assessment at least every six months and a penetration test at least every 12 months on critical systems.8
  • PCI DSS v4.0.1 treats them as two separate duties: scans every three months (requirement 11.3) and a penetration test every 12 months and after significant changes (requirement 11.4).2
  • Finding is only half the job: just 26% of CISA known exploited vulnerabilities were fully fixed in the DBIR data, with a median of 43 days, so retesting matters as much as testing.5

Your auditor asks for a VAPT report. One vendor sends a scan export that runs to dozens of pages and flags hundreds of issues. Another sends a short report that shows how a tester went from a forgotten login page to your customer database. Both are sold as VAPT. They are not the same thing. One tells you what could go wrong. The other shows you what will go wrong if nobody acts. This guide explains both in plain words, shows where each one fits, and gives you a tool to pick the right mix for your team.

Last reviewed on 24 September 2026 against NIST SP 800-115, PCI DSS v4.0.1, the RBI Cyber Security Directions 2026, SEBI CSCRF and the Verizon 2026 DBIR.

What is VAPT?

VAPT (vulnerability assessment and penetration testing) is a combined security testing service. The vulnerability assessment scans many systems for known weaknesses and ranks them. The penetration test then tries to exploit the most important ones, the way a real attacker would, to prove what can actually be reached. Together they give you both breadth and depth.

VAPT meaning
VAPT full form: Vulnerability Assessment and Penetration Testing. A two-part test. Part one (VA) finds and ranks known security weaknesses across your systems. Part two (PT) safely attacks a chosen scope to show which weaknesses can be used, chained together, and turned into real business harm.

Think of an office building. A vulnerability assessment walks every floor and notes each door that looks open. A penetration test picks a few of those doors, opens them, and sees how far inside it can get. The first gives you a long list. The second gives you a short, proven story.

The term VAPT is especially common in India. Banks, NBFCs, insurers and capital market firms see it in audit letters, in RBI and SEBI rules, and in the reports of auditing firms. SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) even has a standard for it, DE.CM.S5, with its own timelines.10 CERT-In, India's national cyber agency, publishes a list of over 200 empanelled information security auditing organisations that many regulated firms hire for this work.12

Outside India, you will more often see the two parts named separately. NIST's technical guide to security testing, SP 800-115, treats vulnerability scanning and penetration testing as different techniques with different strengths.1 PCI DSS gives them separate requirement numbers.2 The bundle name matters less than knowing which part you are actually buying.

A scan tells you which doors might be open. A pentest tells you which room the attacker reaches.

What is a vulnerability assessment?

A vulnerability assessment is a systematic check of your systems for known security weaknesses, such as missing patches, weak settings and outdated software. A vulnerability assessment is mostly automated, covers many assets at once, and ends with a ranked list of findings. It tells you what might be wrong, not what an attacker can do with it.

What a vulnerability assessment looks at

  • Servers and endpoints: missing operating system patches, old software versions, unsafe services left running.
  • Network devices: firewalls, VPNs and routers with known flaws or default settings.
  • Web applications: common issues a scanner can spot from the outside, such as outdated libraries or missing security headers.
  • Cloud accounts: storage open to the internet, over-broad permissions, logging turned off.
  • Configuration: weak password rules, old encryption settings, unneeded admin shares.

What you get at the end

The output is a list of findings. Each one usually carries a CVE ID (a public name for a known flaw, such as CVE-2025-12345) and a CVSS score (a 0 to 10 severity rating). Good reports also add which asset is affected, why it matters to your business, and how to fix it. Weak reports stop at the raw scanner export.

Why the volume problem keeps growing

The number of known flaws rises every year. That makes the scanning part more useful and the reading part harder.

48,185CVEs published in 2025, up 20.6% on 2024CVE data review, 20266
31%of breaches began with exploiting a vulnerability, now the top way inVerizon DBIR 20264
26%of CISA known exploited vulnerabilities were fully fixedVerizon DBIR 20265
43 daysmedian time to fully patch those known exploited flawsVerizon DBIR 20265

At about 132 new CVEs a day, no team can fix everything a scanner reports. The job becomes picking the right few. A vulnerability assessment helps you sort by severity. It cannot tell you which finding opens a path to your core banking system and which one sits on an isolated test box. That is where the second half of VAPT comes in.

A scan finding is a lead, not proof. NIST SP 800-115 warns that vulnerability scanners can report flaws that are not really there (false positives), so a person with the right skills has to interpret the results.1 Scanners also miss flaws they have no check for, such as broken business logic.

What is penetration testing?

Penetration testing is an authorised, simulated attack on your systems. A skilled tester, or a tool built to act like one, tries to exploit weaknesses and chain them together. NIST SP 800-115 describes it as mimicking real-world attacks to find ways around security controls. A penetration test answers one question: what can an attacker actually reach?

What a penetration test proves

  • Exploitability: whether a flagged weakness can really be used in your setup, or is blocked by another control.
  • Chains: how three "medium" issues combine into one critical path, for example a leaked password, a reused admin account and an unpatched file server.
  • Impact: what data, money or systems the attacker ends up controlling.
  • Detection: whether your monitoring team noticed anything while the test ran.

How standards describe the work

NIST SP 800-115 lays out a four-phase method: planning, discovery, attack and reporting. It notes that discovery and attack often loop, because each new foothold reveals more to test.1 The Penetration Testing Execution Standard (PTES) splits the same work into seven sections: pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post exploitation and reporting.14 For web applications, the OWASP Web Security Testing Guide lists these and other methods and gives detailed test cases.13

What a penetration test does not do

A pentest is deep but narrow. It covers the scope you agreed, inside a fixed time window. It will not check every server in your estate. It is also a snapshot: the day after it ends, your team ships new code and the picture changes. We covered that gap in why an annual pentest leaves most of the year untested.

Vulnerability assessment vs penetration testing: what are the key differences?

The main difference between vulnerability assessment and penetration testing is depth. A vulnerability assessment scans wide to list known weaknesses across many systems. A penetration test goes deep on a chosen scope to exploit weaknesses and prove impact. A vulnerability assessment is mostly automated and frequent. A penetration test is expert-led and usually less frequent.

Vulnerability assessment vs penetration testing: 12 differences
FactorVulnerability assessment (VA)Penetration test (PT)
Main questionWhat weaknesses do we have?What can an attacker do with them?
GoalFind and rank known flawsProve real impact and attack paths
MethodAutomated scans plus human reviewManual or automated exploitation, chaining and pivoting
DepthShallow: stops at "this looks vulnerable"Deep: goes in and follows the path
BreadthWide: every asset in scopeNarrow: a chosen set of targets
AutomationHighLow to medium for manual tests, high for automated pentesting
False positivesCommon, needs triageRare, because each finding is shown to work
OutputRanked list with CVE IDs, CVSS scores and fixesNarrative of attack paths with evidence, impact and fixes
Who runs itSecurity or IT team, or a vendorSkilled testers, internal red team, or a pentest platform
Typical frequencyOften: monthly or quarterly, and after changesLess often: yearly or half-yearly, and after major changes
Time per cycleShort: mostly machine timeLonger: mostly human time, plus scoping and retest
Cost per cycleLowerHigher, driven by scope and tester effort

For a rupee view of that last row, see our breakdown of VAPT cost in India in 2026.

Breadth vs depthVA · PT · the 6-step VAPT flow
Breadth vs depth: vulnerability assessment compared with penetration testing, and the six-step VAPT process Left panel: a vulnerability assessment is wide and shallow. It checks all ten assets for known flaws, flags four, and does not test chained weaknesses or business impact. It is mostly automated. Right panel: a penetration test is narrow and deep. It picks two assets and follows one path from an entry point to a foothold, then lateral movement, to the crown jewels. It is expert-led and proves impact. Bottom: the six VAPT steps with one fact each. 1 Scope: rules of engagement are signed first (PTES). 2 Discover: map assets, users and entry points (NIST SP 800-115). 3 Scan: 48,185 CVEs were published in 2025. 4 Exploit: 31% of breaches start with an exploit (Verizon DBIR 2026). 5 Report: SEBI CSCRF asks for the report within 1 month and closure within 3 months. 6 Retest: only 48% of pentest findings get fixed (Cobalt 2025). VULNERABILITY ASSESSMENT Wide and shallow Checks every asset for known flaws Chained weaknesses: not tested Business impact: not shown Coverage: every asset Proof: flags possible issues Style: mostly automated PENETRATION TEST Narrow and deep Follows a few paths as far as they go Foothold → lateral movement Crown jewels reached Coverage: a chosen scope Proof: exploits show impact Style: expert-led, tool-assisted ↔ BREADTH = HOW MANY ASSETS · ↕ DEPTH = HOW FAR AN ATTACKER GETS THE VAPT PROCESS · 6 STEPS 01 Scope Rules of engagement signed first (PTES) 02 Discover Map assets, users and entry points (NIST) 03 Scan 48,185 CVEs published in 2025 (CVE review) 04 Exploit 31% of breaches start with an exploit (DBIR) 05 Report SEBI: report in 1 month, close in 3 months 06 Retest Only 48% of findings get fixed (Cobalt) Breadth vs depth, and the six-step VAPT process (mobile layout) A vulnerability assessment is wide and shallow: it checks all assets for known flaws but does not test chained weaknesses or business impact. A penetration test is narrow and deep: it follows a path from an entry point through a foothold and lateral movement to the crown jewels. The six VAPT steps: scope (PTES), discover (NIST SP 800-115), scan (48,185 CVEs in 2025), exploit (31% of breaches start with an exploit, DBIR 2026), report (SEBI: within 1 month, close within 3 months), retest (only 48% of pentest findings get fixed, Cobalt 2025). VULNERABILITY ASSESSMENT Wide and shallow Checks every asset for known flaws Chained weaknesses: not tested Business impact: not shown Coverage: every asset Proof: flags possible issues Style: mostly automated PENETRATION TEST Narrow and deep Follows a few paths all the way Foothold → lateral move Crown jewels reached Coverage: a chosen scope Proof: exploits show impact Style: expert-led ↔ BREADTH: HOW MANY ASSETS ↕ DEPTH: HOW FAR AN ATTACKER GETS THE VAPT PROCESS · 6 STEPS 01 Scope Rules of engagement signed before testing (PTES) 02 Discover Map assets, users and entry points (NIST SP 800-115) 03 Scan 48,185 CVEs were published in 2025 alone 04 Exploit 31% of breaches now start with an exploit (DBIR 2026) 05 Report SEBI: report within 1 month, close findings in 3 months 06 Retest Only 48% of pentest findings ever get fixed (Cobalt 2025)
Illustrative model of test coverage. Step facts: PTES; NIST SP 800-115; CVE data review 2026; Verizon DBIR 2026; SEBI CSCRF (20 August 2024); Cobalt State of Pentesting 2025. See sources 1, 4, 6, 10, 14 and 15.

Why the difference matters more in 2026

For years, stolen passwords were the favourite way in. The Verizon 2026 Data Breach Investigations Report found that exploiting a vulnerability has now taken the top spot, at 31% of breaches.4 Attackers are also fast. VulnCheck counted 884 known exploited vulnerabilities first seen exploited in 2025, and 28.96% of them were exploited on or before the day the CVE was published.7 In those cases a scan that looks for published flaws is late by design. A penetration test that looks at how your systems fit together can still find the path, even when the specific bug is new.

Is vulnerability scanning the same as a vulnerability assessment?

Vulnerability scanning is not the same as a vulnerability assessment, though people often use the words as if they were. Scanning is the automated step: a tool probes systems and matches what it sees against known flaws. A vulnerability assessment adds scoping, human review, removal of false positives, business risk ranking and a fix plan.

It helps to see the three as a ladder. Each step up adds more human judgement and more proof.

  1. Vulnerability scan: a tool run. Output is raw. Good for frequent, wide checks.
  2. Vulnerability assessment: scans plus review. Output is a cleaned, ranked list tied to your assets and business.
  3. Penetration test: assessment plus exploitation. Output is proven attack paths and their impact.

So "vulnerability scanning vs penetration testing" is the widest gap of all. A scan says a door might be open. A pentest walks through it.

PCI DSS shows how seriously the scan step is taken on its own. Requirement 11.3.1 asks for internal scans at least once every three months, and 11.3.2 asks for external scans by an Approved Scanning Vendor (ASV) on the same cycle.2 The PCI Security Standards Council's FAQ adds that you need four "passing" quarterly scans in the past 12 months. For external scans, passing means no vulnerabilities scored 4.0 or higher on CVSS.3 Even so, PCI DSS still asks for a separate penetration test under requirement 11.4. A clean scan does not count as one.

What are the types of penetration testing?

The main types of penetration testing are external network, internal network, web application, API, mobile app, cloud, Active Directory, wireless and social engineering tests. Each one targets a different way in. Tests are also grouped by how much the tester knows at the start: black box (nothing), grey box (some access) and white box (full details).

Types of penetration testing and what each one finds
TypeWhat it testsTypical finding
External networkInternet-facing IPs, VPNs, firewalls, mail serversUnpatched VPN appliance that gives remote access
Internal networkWhat an insider or a phished laptop can reachFlat network that lets one PC reach the database servers
Web applicationLogin, sessions, access control, input handlingOne customer can view another customer's statements
APIEndpoints used by apps and partnersAPI returns more data than the app shows
Mobile appApp code, local storage, traffic to the backendTokens stored in plain text on the phone
CloudIdentity roles, storage, network rules, keysOver-broad role that lets a test account read all storage
Active DirectoryWindows domain, accounts, trusts, group policyPath from a normal user to domain admin
WirelessOffice Wi-Fi, guest networks, rogue access pointsGuest Wi-Fi that reaches the corporate network
Social engineeringPeople and processes: phishing, calls, physical entryStaff share one-time passwords over the phone

Active Directory deserves a special mention. Once an attacker is inside, the Windows domain is often the fastest road to everything else. Our guide to Active Directory penetration testing covers what a good test checks, and why attackers log in instead of breaking in explains the credential side.

Black box, grey box and white box

  • Black box: the tester starts with nothing but a company name or a URL, like an outside attacker. Realistic, but time is spent on discovery.
  • Grey box: the tester gets a normal user account or some documents. This is the most common choice because it copies a phished employee or a malicious customer.
  • White box: the tester sees source code, architecture diagrams and admin access. Deepest coverage for the time spent.

How does the VAPT process work, step by step?

The VAPT process usually runs in six steps: agree the scope and rules, discover assets, scan for known weaknesses, safely exploit the important ones, report with evidence and fixes, then retest to confirm the fixes work. Standards such as NIST SP 800-115 and PTES describe the same flow in slightly different words.

  1. Scope. Agree what is in and out, the testing windows, who to call if something breaks, and whether production is included. PTES calls this pre-engagement interactions and puts it first for a reason.14 Get the rules of engagement signed.
  2. Discover. Map domains, IP ranges, cloud accounts, apps, users and exposed services. NIST SP 800-115 treats this discovery phase as the base for everything after it.1 Forgotten assets found here are often the most useful result.
  3. Scan. Run vulnerability scans across the full scope. Review results, remove false positives and rank what is left by severity and business value. This is the VA half.
  4. Exploit. Safely try the most promising weaknesses. Chain them. Move sideways where the rules allow. Stop at agreed limits, for example reading a sample record, not downloading a table. This is the PT half.
  5. Report. Write two layers: a short summary for leadership and detailed findings with evidence, risk ratings and fix steps for engineers. Under SEBI CSCRF, the VAPT report is due within one month of completing the activity.10
  6. Retest. After fixes, test again to prove each issue is closed. SEBI CSCRF expects findings closed within three months of the report and revalidation within five months of the VAPT.10 PCI DSS 11.4.4 also requires fixing exploitable findings and repeating the test to confirm.2

Put the retest in the contract. Cobalt's 2025 pentest data found that less than half (48%) of pentest findings are ever fixed, and the median time to resolve issues was 67 days, even though most firms target 14 days for serious ones.15 A report nobody retests is a list of good intentions.

How often should you run a vulnerability assessment and a penetration test?

How often you run each test depends on your regulator and how fast you change. RBI's 2026 Directions set a vulnerability assessment at least every six months and a penetration test at least every 12 months for critical systems. PCI DSS asks for scans every three months. Teams that ship weekly or daily should scan more often.

Minimum VA and PT cadence by rule set (summary)
Rule setVulnerability assessment or scansPenetration testAlso note
RBI Cyber Security Directions 2026 (banks, SFBs, NBFCs and others)At least once every six months for critical systems and DMZ systems with customer interfacesAt least once every 12 months for the same systemsRisk-based for non-critical systems.8 After an IT project or upgrade, VA/PT on production (NBFC Directions, para 124).9
SEBI CSCRF (20 August 2024)VAPT at least once a year, starting in the first quarter; at least twice a year (once in each half) for protected systemsReport in 1 month, close in 3 months, revalidate in 5 months.10 Qualified stock brokers: half-yearly.11
PCI DSS v4.0.1Internal and external scans at least every three months (11.3.1, 11.3.2) and after significant changesInternal and external at least every 12 months and after significant changes (11.4.2, 11.4.3)Fix and retest (11.4.4).2
No sector regulatorSet by change pace and exposureYearly is a common floor, plus after major changesUse the tool below to size it

The RBI rules are the same in spirit across the seven types of regulated entity. The Small Finance Bank Directions, for example, say VA shall be conducted at least once in every six months and PT at least once in 12 months for critical systems and those in the DMZ with customer interfaces.8 The NBFC version (RBI/DoS/2026-27/461) uses the same cadence in paragraph 121.9 Read the full breakdown in our guide to RBI Cyber Security Directions 2026 and their VAPT rules. For capital market firms, see SEBI CSCRF VAPT requirements, and for auditor and reporting duties, see CERT-In guidelines on 6-hour reporting and VAPT audits.

Minimums, not targets. This table summarises rules as published on the dates shown. It is not legal advice. Categories, scopes and timelines differ by entity type, so check the latest text of the rule that applies to you.

Triggers that should start a test, whatever the calendar says

  • A new internet-facing app, API or portal goes live.
  • A major release changes login, payments or access control.
  • You move a workload to the cloud or change network zones.
  • You merge with or connect to another company's network.
  • A critical CVE lands in a product you run on the edge.
Decision helper

Which test do I need?

Answer five quick questions. Your recommended VA and PT mix updates as you click.

1. What is your main goal?
2. Which rules apply to you?
3. How often do you ship changes?
4. How many internet-facing assets do you have?
5. When was your last penetration test?
Recommended mix
Vulnerability assessmentEvery month (RBI floor: every six months)
Penetration testEvery 12 months, plus after every major change
Continuous testingWorth adding this year to cover the gap between pentests.

RBI's 2026 Directions ask for VA at least every six months and PT at least every 12 months on critical and customer-facing systems, plus testing on production after big changes.

Exposure risk if you only do VA: High (60/100)

A VA alone will not show whether flaws chain together, and it will not meet your regulator's penetration testing rule.

Indicative only. The mix is a planning aid built from the cadences cited in this article, not legal or audit advice. Your regulator's latest text and your auditor's scope decide the final plan.

Talk to us about your VAPT plan →

What are the most common VAPT myths?

The most common VAPT myths are that a clean scan means you are safe, that one pentest a year keeps you covered, that VAPT is only for compliance, that automated testing is just scanning, and that the job ends when the report arrives. Each myth leaves a gap that attackers are happy to use.

Myth 1: "Our scan came back clean, so we are secure"

A clean scan means the scanner found none of the flaws it knows how to check. It says nothing about broken access control, business logic, weak processes or chained paths. Nearly 29% of the flaws VulnCheck tracked were exploited on or before disclosure day, before most scanners had a check for them.7

Myth 2: "One pentest a year keeps us covered"

An annual pentest meets many minimum rules. It does not cover the months in between, when new code, new cloud resources and new CVEs arrive. Your pentest is a photo. The attacker is filming.

Myth 3: "VAPT is only a compliance box"

Regulators set VAPT rules because exploitation now leads breach causes.4 Treat the report as a risk tool first. If it only lives in the audit folder, the findings stay open.

Myth 4: "Automated means scanning"

Some tools only scan. Others actually attempt exploitation and chain steps, the way a pentester does. The label matters less than the output: does it show a proven path, or just a list? We compare both in automated vs manual penetration testing.

Myth 5: "The report is the finish line"

Only 26% of CISA known exploited vulnerabilities were fully fixed in the DBIR data, with a median of 43 days to patch.5 The finish line is a passed retest, not a delivered PDF.

Where does automated penetration testing fit?

Automated penetration testing sits between scanning and a manual pentest. Like a scanner, it runs often and covers many systems. Like a pentester, it tries to exploit weaknesses and chain them to show real impact. Automated penetration testing does not replace expert testers for complex business logic, but it closes the long gaps between manual tests.

Here is a practical way to combine the three layers:

  • Scan continuously or weekly to catch new CVEs and misconfigurations across every asset.
  • Run automated pentests monthly or after big changes to confirm which findings are really exploitable and how they chain.
  • Book expert-led pentests at least at your regulatory cadence, and aim them at what automation handles poorly: payment logic, approval flows, multi-step fraud scenarios.

This layered model is close to what Gartner calls continuous threat exposure management, or CTEM: a repeating cycle of scoping, discovering, prioritising, validating and mobilising fixes. Our CTEM explainer shows how VA and PT fit inside that loop. The point is simple. A vulnerability assessment tells you where to look. A penetration test tells you what matters. Doing both, often, tells you whether you are getting safer.

Frequently asked questions

What is the full form of VAPT?

VAPT stands for Vulnerability Assessment and Penetration Testing. The vulnerability assessment part scans your systems for known weaknesses and ranks them by risk. The penetration testing part safely attacks a chosen scope to prove which weaknesses can actually be used. Together they show both how many problems you have and how much damage an attacker could do with them.

What is the difference between vulnerability assessment and penetration testing?

A vulnerability assessment is wide and mostly automated. It checks many systems for known flaws and produces a ranked list. A penetration test is narrow and deep. A tester or pentest tool tries to exploit the flaws, chain them together and reach sensitive data. The assessment says what might be wrong. The penetration test proves what an attacker can do.

Can a vulnerability scan replace a penetration test?

No. A vulnerability scan only matches your systems against known flaws and can report false positives. It does not test whether flaws can be exploited or chained. Rules such as PCI DSS v4.0.1 list scanning and penetration testing as separate requirements, and RBI's 2026 Directions set separate cadences for VA and PT. You need both to meet those rules.

Is VAPT mandatory in India?

For many regulated firms, yes. RBI's 2026 Cyber Security Directions require VA at least every six months and PT at least every 12 months for critical systems. SEBI's CSCRF requires VAPT at least once a year, and twice for protected systems. Other sectors follow their own regulator or contract terms. Check the latest text of the rule that applies to you.

How often should penetration testing be done?

At least once a year for most regulated firms, and after every major change such as a new app, a cloud move or a network redesign. PCI DSS v4.0.1 asks for internal and external pentests every 12 months and after significant changes. Teams that ship code weekly or daily should add automated or continuous testing between those manual tests.

What are black box, grey box and white box penetration tests?

They describe how much the tester knows at the start. In a black box test the tester has almost nothing, like an outside attacker. In a grey box test the tester has a normal user account or some documents. In a white box test the tester sees code, diagrams and admin access. Grey box is the most common balance of realism and depth.

What happens after a VAPT report?

Your teams fix the findings, starting with the most critical, and the tester runs a retest to confirm each fix works. SEBI's CSCRF expects findings to be closed within three months of the report and revalidated within five months of the VAPT. PCI DSS also requires fixing exploitable issues and repeating the test. Track open items until the retest passes.

Is automated penetration testing a real penetration test?

It can be, if the tool actually attempts exploitation and chains steps to show impact, rather than only scanning. Automated penetration testing is good at running often and covering many systems. Expert testers are still better at complex business logic and creative fraud scenarios. Many teams use automated tests between scheduled manual pentests to close the gap.

Where Arxiis fits

Get the depth of a pentest at the pace of a scan

The hard part of VAPT is not knowing the difference. It is affording depth often enough. Scans run every week. Deep tests happen once or twice a year. Everything that changes in between is a guess.

Arxiis is an autonomous AI red teaming and penetration testing platform built to narrow that gap. It attacks your environment the way a pentester would, then hands your team proof and fixes in hours instead of weeks.

  • Depth, not just a list: 26 security modules across 6 attack vectors (ransomware, Active Directory, cloud, web applications, containers and credentials).
  • A multi-agent AI crew for OSINT, exploitation, lateral movement and reporting, so findings show real attack paths.
  • Audit-ready output: CVSS-scored, MITRE ATT&CK-mapped findings with compliance overlays for 11 frameworks, including RBI, CERT-In, SEBI CSCRF and PCI DSS.
  • Your data stays with you: fully on-premise deployment and an MIT-licensed open-source core.

Arxiis does not replace an empanelled auditor where your regulator asks for one. It helps you arrive at that audit with fewer surprises.

Sources

  1. NIST, "SP 800-115: Technical Guide to Information Security Testing and Assessment", September 2008. nist.gov
  2. PCI Security Standards Council, "PCI DSS v4.0.1" (requirements 11.3 and 11.4), June 2024. pcisecuritystandards.org
  3. PCI Security Standards Council, "FAQ 1152: Can entities be PCI DSS compliant if they have performed vulnerability scans at least once every three months, but do not have four passing scans?", January 2024. pcisecuritystandards.org
  4. Verizon, "2026 Data Breach Investigations Report", May 2026. verizon.com
  5. Help Net Security, "Verizon DBIR: Vulnerability exploitation is the dominant initial access vector", 20 May 2026. helpnetsecurity.com
  6. Jerry Gamblin, "2025 CVE Data Review", 1 January 2026. jerrygamblin.com
  7. VulnCheck, "State of Exploitation 2026", 2026. vulncheck.com
  8. Reserve Bank of India, "Reserve Bank of India (Small Finance Banks: Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026", RBI/DoS/2026-27/419, 31 July 2026. rbi.org.in
  9. TaxGuru, "RBI Issues NBFC Cybersecurity and Technology Risk Directions, 2026" (text of RBI/DoS/2026-27/461, paras 121 and 124), August 2026. taxguru.in
  10. SEBI, "Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities", circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024 (Tables 18 and 19, standard DE.CM.S5). sebi.gov.in
  11. SEBI, "Frequently Asked Questions on Cybersecurity and Cyber Resilience Framework", June 2025. sebi.gov.in
  12. CERT-In, "Empanelled Information Security Auditing Organisations by CERT-In", current list, accessed September 2026. cert-in.org.in
  13. OWASP, "Web Security Testing Guide: Penetration Testing Methodologies", stable edition. owasp.org
  14. PTES, "The Penetration Testing Execution Standard", version 1.1 documentation. pentest-standard.readthedocs.io
  15. Cobalt, "Key takeaways from the State of Pentesting Report 2025", 14 April 2025. cobalt.io
Arxiis Research

Written by the Arxiis research team. Facts checked against primary sources on 24 September 2026. Not legal advice.