Cybersecurity • Oct 24, 2024

VAPT Company for Enterprise: Scope, SLAs, and Vendor Governance at Scale

VAPT Company for Enterprise: Scope, SLAs, and Vendor Governance at Scale

Enterprise VAPT is not a larger version of startup VAPT. It is a fundamentally different operation. A startup tests one application and one API. An enterprise governs a VAPT programme spanning 50 to 200 applications across multiple business units, cloud environments on three providers, legacy systems running software from the previous decade, acquired companies on independent infrastructure, and compliance requirements that differ by business unit, geography, and data type.

The technical testing methodology is the same. The VAPT process still combines automated vulnerability assessment (breadth) with manual penetration testing (depth). But at enterprise scale, the challenge shifts from "can we find vulnerabilities?" to "can we find vulnerabilities across everything, fix them within defined timelines, satisfy six compliance frameworks with one programme, and prove to leadership that our security posture is improving year over year?"

This guide addresses what makes enterprise VAPT different: scoping across a complex organization, setting SLAs that drive remediation accountability, governing VAPT vendors at scale, managing multi-framework compliance, and measuring programme effectiveness. For the VAPT provider selection criteria, see our enterprise provider guide.

Enterprise VAPT Scope: Covering the Full Attack Surface

Why Enterprise Scoping Is Hard

Enterprises don't have a single, well-defined attack surface. They have multiple overlapping attack surfaces that shift continuously.

What enterprise VAPT must cover:

Customer-facing web applications across multiple business units (often 30 to 100+ applications). API ecosystems connecting frontend channels, mobile apps, partners, and internal services (hundreds to thousands of endpoints). Cloud infrastructure across multiple providers and accounts. Corporate networks spanning headquarters, branch offices, and data centres (external and internal). Mobile applications serving customers and employees. Legacy systems that nobody wants to touch but everyone depends on. Acquired company systems in various integration states.

The Tiered Scoping Model

Not every system warrants the same testing depth. Enterprise VAPT uses risk-based tiering.

Tier 1: Critical systems (annual deep VAPT).Customer-facing applications handling sensitive data. Payment processing systems (PCI DSS scope). Core business platforms. Identity infrastructure (Active Directory, SSO). Cloud environments hosting production data.

Tier 1 receives full VAPT: comprehensive vulnerability assessment plus deep manual penetration testing including business logic, access control, and vulnerability chaining.

Tier 2: Important systems (annual standard VAPT).Internal applications with broad employee access. Secondary cloud environments. Partner-facing systems. Business applications with moderate data sensitivity.

Tier 2 receives standard VAPT: vulnerability assessment plus manual testing covering OWASP Top 10 and common vulnerability patterns.

Tier 3: Lower-risk systems (biennial VAPT or vulnerability assessment only).Internal tools with limited data access. Static content platforms. Development environments. Systems tested on a rotating schedule or when significant changes occur.

Tier 4: Monitoring only.Systems covered by continuous vulnerability scanning and configuration monitoring. VAPT triggered by significant findings or material changes.

Scope Governance

Annual scope review committee. Representatives from each business unit, cloud engineering, infrastructure, compliance, and security review the complete asset inventory against the tiering model. New applications, acquisitions, and decommissioned systems are reflected.

Scope gap identification. Compare the VAPT scope against the complete asset inventory. Every Tier 1 system must be covered. Every Tier 2 system must be covered. Gaps are escalated to the CISO.

Acquisition integration. When the enterprise acquires a company, the acquired systems enter the VAPT scope immediately as Tier 1 (unknown risk) until assessed and reclassified. See our M&A pentesting guide.

Enterprise VAPT Cadence

System TierVAPT CadenceVulnerability AssessmentTriggered TestingTier 1 CriticalAnnual (deep)QuarterlyAfter major changesTier 2 ImportantAnnual (standard)QuarterlyAfter major changesTier 3 Lower-riskBiennial or rotatingSemi-annualAfter significant changesTier 4 MonitoringNone (scanning only)Monthly or continuousAfter critical findingsNewly acquired systemsImmediatelyImmediately--Post-major-releaseWithin 2 weeksWithin 1 week--

Why Annual VAPT Isn't Enough for Enterprises

Enterprises deploy code across dozens of applications weekly. Annual VAPT provides a snapshot. Between snapshots, vulnerabilities accumulate.

Continuous penetration testing and PTaaS (Penetration Testing as a Service) bridge the gap by providing ongoing testing triggered by changes and available on demand. See our continuous vs annual comparison and PTaaS guide.

Recommended enterprise model: Annual VAPT (comprehensive baseline) + continuous testing for Tier 1 systems with high change velocity + annual red team exercise for holistic validation.

Remediation SLAs: Driving Accountability

Why SLAs Matter at Enterprise Scale

Without SLAs, findings accumulate. A vulnerability discovered in January sits unresolved in December. The next annual VAPT finds the same vulnerability again (now classified as "recurring"). The CISO's board report shows thousands of open findings with no trend improvement. The VAPT programme generates reports. It doesn't improve security.

SLAs transform findings from information into obligations.

The Enterprise SLA Framework

SeverityRemediation SLAEscalation TriggerSecond EscalationCritical14 calendar daysDay 7 if not in progressDay 14: CISO risk acceptanceHigh30 calendar daysDay 14 if not assignedDay 30: VP-level risk acceptanceMedium90 calendar daysDay 45 if not in progressDay 90: Director-level reviewLowNext quarterNo automatic escalationAnnual review

SLA Governance Mechanics

Day 0: Finding assignment. Every finding assigned to a named application or infrastructure owner within 48 hours of report delivery. Not a team. A person. Accountability requires individual ownership.

SLA midpoint: Progress check. Automated check: is remediation in progress? If the owner hasn't started, escalate to the owner's manager. The goal isn't punishment. It's ensuring the finding isn't lost in competing priorities.

SLA deadline: Resolution or risk acceptance. If the finding is fixed, the VAPT provider retests to confirm. If the finding is unresolved, formal risk acceptance is required: the finding, its business impact, compensating controls, and an executive signature accepting the residual risk. Risk acceptance documentation has an expiration date (typically 90 days) requiring re-evaluation.

Post-SLA tracking. Overdue findings appear on the CISO's monthly dashboard. Trends by business unit, severity, and age provide management visibility. Persistently overdue business units face budget or resource review.

Tracking and Reporting

Centralised finding tracker. All VAPT findings across all business units tracked in a single system. Not scattered across individual pentest reports. Dashboard showing open findings by severity, business unit, age, and SLA compliance.

Monthly metrics to the security team: Open finding count by severity. SLA compliance rate by business unit. Average remediation time by severity. Overdue findings requiring escalation.

Quarterly metrics to the CISO: Year-over-year critical finding trend. Recurring finding rate. Business unit remediation performance. Programme coverage percentage. See our penetration testing reports guide for report quality expectations.

Vendor Governance: Managing the VAPT Company Relationship

Single Vendor vs Multi-Vendor

Single VAPT vendor advantages: Consistent methodology. Institutional knowledge of your environment. Year-over-year comparison using identical standards. Simplified vendor management. Consolidated reporting and metrics.

Multi-vendor advantages: Fresh perspective (prevents blind spots). Reduces single-point-of-failure. Different strengths for different testing types (one vendor may excel at cloud, another at application testing).

Enterprise recommendation: Primary VAPT vendor handling 70% to 80% of testing (building institutional knowledge). Secondary vendor for periodic validation (fresh eyes every 2 to 3 years) or specialized testing. Different vendor for red teaming (attacker simulation benefits from the adversary not knowing your architecture).

Vendor Quality Requirements

Enterprise VAPT vendors must meet higher standards than providers serving smaller organisations.

Non-negotiable requirements:

CREST certification verified at the company level. Manual testing depth demonstrated through sample reports and reference calls. Zero false positive commitment (enterprise remediation teams cannot waste cycles on false findings). Multi-framework compliance mapping (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, DORA, and regulatory requirements). See our evaluating quality guide.

Enterprise-specific requirements:

Scalable capacity (testing 50+ applications across concurrent workstreams without quality degradation). Enterprise architecture experience (legacy systems, hybrid cloud, multi-domain Active Directory, complex microservices). Secure data handling (the vendor accesses your most sensitive systems; their operational security must be verifiable). Executive-level reporting alongside technical detail. Flexible engagement models (annual + continuous + on-demand). Dedicated account management for the enterprise relationship.

Vendor SLAs

Hold your VAPT vendor to the same SLA discipline you apply internally.

Vendor SLATargetMeasurementTesting start within agreed window100%Days from scheduled start to actual startReport delivery post-testing5 to 7 business daysDays from testing completion to report deliveryCritical finding escalationWithin 4 hours of discoveryTime from discovery to client notificationRetesting turnaround5 business days from requestDays from retesting request to completionRemediation support responseWithin 1 business dayTime from question to responseReport quality (zero false positives)100%False positive count per engagement

Annual Vendor Review

Evaluate vendor performance annually against quality metrics (finding depth, false positive rate, report quality), operational metrics (SLA adherence, responsiveness, escalation timeliness), relationship metrics (account management, communication, flexibility), and value metrics (findings per dollar, coverage per engagement, improvement contribution).

Multi-Framework Compliance at Enterprise Scale

The Enterprise Compliance Stack

Large enterprises typically maintain 4 to 8 compliance frameworks simultaneously.

FrameworkTypical Enterprise ApplicabilityVAPT RequirementSOC 2SaaS products, customer-facing servicesExpected (penetration testing evidence)ISO 27001Global operations, international customersRequired (A.8.8 vulnerability management)PCI DSSPayment card processingMandatory (Req 11.3 annual pentest)HIPAAHealth data processing (US)Expected (risk analysis)GDPREU personal data processingExpected (Art 32 testing)NYDFSNY-regulated financial entitiesMandatory (annual pentest)DORAEU financial entitiesMandatory (TLPT for significant entities)MAS TRMSingapore financial entitiesMandatory (annual pentest)NIST CSFUS government contracts, risk frameworkExpected (DE.CM detection, ID.RA risk assessment)

See our penetration testing compliance guide for complete framework mapping.

One Programme, All Frameworks

Enterprise VAPT should satisfy every framework through a single programme.

How it works:

Scope = superset. The VAPT scope includes every system in scope for any framework. The PCI DSS CDE systems, the SOC 2 boundary systems, the ISO 27001 ISMS systems, and the regulatory-scope systems are all tested through one programme.

Methodology = most prescriptive. The testing methodology follows the most demanding framework (typically PCI DSS). Testing that satisfies PCI DSS Requirement 11.3 also satisfies SOC 2, ISO 27001, HIPAA, and other frameworks.

Reporting = multi-mapped. Each finding maps to every applicable framework. One finding appears in the SOC 2 section, the ISO 27001 section, and the PCI DSS section with framework-specific context. Auditors for each framework receive relevant evidence without separate engagements.

Savings: Consolidated VAPT costs 30% to 40% less than separate engagements per framework while producing evidence for all simultaneously. For SOC 2 specifics, ISO 27001 specifics, and PCI DSS specifics, see our dedicated guides.

Measuring Enterprise VAPT Programme Effectiveness

Posture Metrics

Year-over-year critical finding count. The most important metric. Decreasing critical findings across annual VAPT cycles indicates improving prevention. Increasing critical findings with stable scope indicates degrading security or improving testing depth (distinguish by analyzing finding types).

Recurring finding rate. Percentage of findings that appeared in the previous VAPT cycle and reappear in the current one. High recurrence (above 10%) indicates remediation is fixing instances but not root causes. Target: below 10%.

Mean time to remediate (MTTR) by severity. How quickly does the organisation fix findings after VAPT delivery? Track MTTR trends. Decreasing MTTR indicates improving operational response.

SLA compliance rate. Percentage of findings remediated within SLA by severity and business unit. Target: 95%+ for Critical and High. Below 80% indicates systemic remediation problems.

Coverage Metrics

Tier 1 coverage. Percentage of Tier 1 systems tested within the past 12 months. Target: 100%. Below 100% means critical systems have gone a year or more without testing.

Tier 2 coverage. Percentage of Tier 2 systems tested within the past 12 months. Target: 100%.

Scope completeness. Percentage of the total asset inventory covered by the VAPT programme (at any tier). Target: 95%+. The gap represents systems outside VAPT governance.

Programme Efficiency Metrics

Cost per finding. Total VAPT programme cost divided by total validated findings. Benchmark against previous years. Increasing cost per finding with decreasing severity indicates maturing security (harder to find things because the easy vulnerabilities are fixed).

Findings per application. Average findings per tested application. Track by business unit to identify teams with consistently higher or lower vulnerability rates.

Testing schedule adherence. Percentage of planned VAPT engagements completed on schedule. Below 90% indicates planning or resource problems.

Enterprise VAPT Programme Governance

Programme Structure

VAPT Programme Owner. Named individual (typically Director or VP level within the CISO organisation) accountable for programme strategy, scope, vendor management, and reporting. This is not delegated to business units. Central ownership ensures completeness and consistency.

Scope Committee. Cross-functional group reviewing and approving the annual VAPT scope. Includes business unit security leads, cloud engineering, infrastructure, compliance, and the VAPT programme owner. Meets annually for scope planning and quarterly for scope updates.

Remediation Owners. Each business unit designates a security lead accountable for remediating findings within their systems. The business unit lead ensures findings are assigned to individual developers or engineers within their team.

Executive Sponsor. CISO or equivalent providing executive authority for the programme. Receives quarterly reports. Signs off on annual scope and budget. Escalation point for cross-business-unit disputes.

Reporting Cadence

ReportAudienceFrequencyContentFinding statusRemediation ownersWeeklyOpen findings, approaching SLA deadlines, overdue itemsProgramme dashboardSecurity leadershipMonthlySLA compliance, MTTR trends, coverage, vendor performanceCISO reportCISOQuarterlyPosture trend, critical findings, BU performance, budgetBoard reportBoard / Audit committeeAnnuallyYear-over-year posture improvement, compliance status, risk summary

Common Enterprise VAPT Mistakes

Mistake 1: Decentralised VAPT Without Central Governance

Each business unit procures VAPT independently. No central scope review. Gaps between business unit coverage go unnoticed. Inconsistent vendor quality. No cross-enterprise finding tracking. No comparable metrics. The enterprise has testing but not a programme.

Fix: Centralise programme ownership. Standardise scope, vendors, methodology, SLAs, and reporting. Business units participate in scope definition. Central team manages execution and governance.

Mistake 2: Findings Without Fixing

Thousands of findings across annual VAPT. No centralised tracking. No SLA enforcement. No escalation. The programme generates impressive reports that don't improve security posture.

Fix: Centralised finding tracker. SLAs by severity. Automated escalation. Executive visibility on overdue findings. Budget for remediation capacity alongside testing budget.

Mistake 3: Treating VAPT as Compliance-Only

Testing scoped exclusively to satisfy auditors. PCI DSS CDE is tested. SOC 2 boundary is tested. Everything outside compliance scope is ignored. The highest-risk systems may fall outside compliance boundaries.

Fix: Risk-based scoping starting with "what are our highest-risk systems?" Then map compliance requirements onto the risk-prioritised scope. Compliance is satisfied as a byproduct of risk-driven testing.

Mistake 4: Annual Testing for Daily Deployment

Applications deploying code daily receive VAPT once per year. Fifty deployments between tests, each introducing potential vulnerabilities. The VAPT report is stale within weeks.

Fix: Continuous testing or PTaaS for high-velocity Tier 1 systems. Annual VAPT provides the baseline. Continuous testing keeps it current.

Mistake 5: Ignoring Legacy Systems

"That mainframe is being decommissioned." Five years later, it's still running, still processing critical data, and still never tested. Legacy systems often have the weakest security because they predate modern security practices.

Fix: If a system processes sensitive data, it's in scope for VAPT regardless of planned retirement date.

Enterprise VAPT Checklist

Programme Foundation

  • Programme owner designated within CISO organisation
  • Annual scope review process established
  • Asset inventory complete across all business units
  • Systems classified into priority tiers (1 through 4)
  • VAPT methodology standards documented
  • Remediation SLAs defined by severity with escalation path
  • Centralised finding tracking system operational
  • Executive reporting cadence established

Vendor Management

  • Primary VAPT vendor CREST certified and quality verified
  • Vendor SLAs defined (report delivery, escalation, retesting, support)
  • Annual vendor performance review process established
  • Secondary vendor identified for periodic fresh-perspective testing
  • Vendor data handling and security verified
  • Multi-framework reporting capability confirmed

Scope and Coverage

  • All Tier 1 systems tested annually
  • All Tier 2 systems tested annually
  • Tier 3 systems tested on rotation or trigger
  • Acquired systems assessed immediately post-acquisition
  • Cloud environments tested semi-annually
  • Change-triggered testing process operational
  • Scope gaps reviewed quarterly

Compliance

  • All framework requirements mapped to VAPT programme
  • Report format satisfies all framework auditors
  • Multi-framework mapping confirmed with VAPT vendor
  • Compliance evidence centralised for audit access
  • Framework-specific requirements addressed (PCI segmentation, DORA TLPT)

Metrics and Reporting

  • Year-over-year critical finding trend tracked
  • Recurring finding rate tracked (target: below 10%)
  • MTTR tracked by severity
  • SLA compliance rate tracked by business unit
  • Coverage percentage tracked (target: 100% Tier 1 and 2)
  • Quarterly CISO report delivered
  • Annual board report delivered

How AppSecure Delivers Enterprise VAPT

AppSecure provides enterprise-scale VAPT with the governance support large organisations require.

Enterprise-Scale Coverage. Testing across all enterprise asset types: web applications, APIs, cloud infrastructure, networks, mobile applications, and IoT. Application security assessment and offensive security testing for end-to-end validation.

Flexible Engagement Models. Annual VAPT for comprehensive baselines. Continuous penetration testing for high-velocity systems. PTaaS for on-demand testing capacity. Red teaming for holistic adversary simulation.

Multi-Framework Reports. Findings mapped to SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NYDFS, DORA, MAS TRM, and NIST CSF. One programme, all frameworks covered.

CREST Certified. Zero False Positives. Enterprise remediation teams fix confirmed vulnerabilities. 3-Week Delivery per engagement. 90-day remediation support. Complimentary retesting.

Contact AppSecure:

Frequently Asked Questions

1. How is enterprise VAPT different from standard VAPT?

Enterprise VAPT operates at larger scale (50 to 200+ applications across business units), requires centralised governance (programme ownership, scope committee, executive reporting), spans multiple compliance frameworks simultaneously, demands vendor management discipline (SLAs, performance reviews, multi-vendor strategies), and measures programme effectiveness through posture metrics. The testing methodology is the same. The programme governance surrounding it is fundamentally different.

2. How should enterprises scope their VAPT programme?

Use risk-based tiering. Tier 1 (critical systems handling sensitive data): annual deep VAPT with business logic and access control testing. Tier 2 (important systems): annual standard VAPT. Tier 3 (lower risk): biennial or change-triggered. Tier 4 (monitoring only): vulnerability scanning without manual testing. Annual scope review committee ensures completeness. Acquired systems enter as Tier 1 until assessed.

3. What SLAs should enterprises set for VAPT remediation?

Critical: 14 calendar days with Day 7 escalation. High: 30 days with Day 14 escalation. Medium: 90 days with Day 45 progress check. Low: next quarter. SLAs require enforcement mechanisms: automated tracking, escalation to management, and executive risk acceptance for overdue findings. Without enforcement, SLAs are suggestions.

4. Should enterprises use one VAPT vendor or multiple?

Primary vendor for 70% to 80% of testing (building institutional knowledge, consistent methodology, year-over-year comparison). Secondary vendor every 2 to 3 years for fresh perspective. Different vendor for red teaming (benefits from attacker unfamiliarity). Centralise vendor management through the programme owner regardless of vendor count.

5. How does enterprise VAPT satisfy multiple compliance frameworks?

Define VAPT scope as the superset of all framework requirements. Use methodology satisfying the most prescriptive framework (typically PCI DSS). Map findings to each framework in a single report. One programme produces compliance evidence for SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, and regulatory requirements simultaneously. Saves 30% to 40% versus separate engagements.

6. What metrics indicate a mature enterprise VAPT programme?

100% Tier 1 and Tier 2 coverage annually. Decreasing critical finding count year-over-year. Recurring finding rate below 10%. SLA compliance above 95% for Critical and High findings. MTTR trending downward. Programme coverage above 95% of total asset inventory. Red team exercises validating detection and response.

7. How do enterprises manage VAPT vendor performance?

Define vendor SLAs (report delivery, escalation, retesting, support response). Track performance against SLAs monthly. Conduct annual vendor review evaluating quality, operational, and relationship metrics. Maintain a secondary vendor option for competitive tension. Replace underperforming vendors based on documented performance data.

8. What is the right VAPT cadence for enterprises?

Tier 1 critical: annual deep VAPT plus continuous testing for high-velocity systems. Tier 2 important: annual standard VAPT. Quarterly vulnerability assessment across all tiers. Change-triggered testing after major releases, architecture changes, and acquisitions. Annual red team exercise for mature programmes. The goal: no critical system goes more than 12 months untested.

9. How should enterprises handle VAPT finding remediation at scale?

Centralised finding tracker (not distributed across individual reports). Every finding assigned to a named individual within 48 hours. Automated SLA monitoring with escalation triggers. Overdue findings require executive risk acceptance. Monthly dashboard to security leadership. Quarterly metrics to the CISO. Budget for remediation capacity alongside testing budget.

10. What should the annual enterprise VAPT board report include?

Year-over-year posture trend (critical finding count, recurring rate, MTTR). Programme coverage (percentage of systems tested). SLA compliance by business unit (identifying where remediation needs attention). Compliance status across all frameworks. Key risks requiring board awareness. Budget utilisation and next-year investment recommendation. Avoid technical jargon. Focus on trend direction and business risk implication.

Have questions about who we are?

Reach out to our team — we'd love to connect.

Contact Us