You need a VAPT company. Your auditor asked for vulnerability assessment and penetration testing evidence. Your customer's security questionnaire requires it. Your compliance framework mandates it. You search "VAPT company" and find dozens of providers, all claiming expertise, all listing similar services, all referencing OWASP and NIST.
How do you tell which VAPT company will find the vulnerabilities attackers would exploit versus which will run a scanner and reformat the output?
The difference between a quality VAPT provider and a poor one is enormous. A quality provider combines automated vulnerability assessment (scanning every system for known weaknesses) with expert manual penetration testing (human testers exploiting vulnerabilities, testing business logic, and chaining findings into real attack paths). A poor provider runs a scanner, relabels the output as "VAPT," and charges you for the branded report.
This guide covers what VAPT actually includes, what to look for in a VAPT company, how to evaluate providers, the red flags that should disqualify a vendor, and how to make the selection decision. For the technical VAPT process, see our VAPT process guide. For enterprise provider evaluation, see our VAPT provider selection guide.
What VAPT Actually Includes
The Two Components
VAPT is not a single activity. It is two complementary testing methodologies delivered together.
Vulnerability Assessment (the VA). Automated scanning identifying known vulnerabilities across your systems. Scanners check for missing patches, common misconfigurations, default credentials, outdated software with known CVEs, and weak encryption. Vulnerability assessment provides breadth: it covers every system in scope for known vulnerability patterns.
Penetration Testing (the PT). Expert human testers attempting to exploit vulnerabilities, test business logic, evaluate access control, and chain findings into real attack paths. Penetration testing provides depth: it validates which vulnerabilities are genuinely exploitable and discovers vulnerability classes that scanners cannot find.
For the distinction between these two, see our vulnerability assessment vs penetration testing comparison.
Why You Need Both
Vulnerability assessment without penetration testing produces hundreds of potential findings without proving which ones matter. Your team wastes time on false positives and theoretical risks.
Penetration testing without vulnerability assessment may miss basic hygiene issues (missing patches, known CVEs) because manual testers focus their limited time on complex testing rather than comprehensive scanning.
Together, VA provides the breadth (finding every known weakness) and PT provides the depth (proving which weaknesses are exploitable and discovering what scanners miss). A quality VAPT company delivers both.
What to Look For in a VAPT Company
Criterion 1: Manual Testing, Not Just Scanning
This is the single most important criterion. Many VAPT companies deliver only the VA (automated scanning) and call it VAPT. The penetration testing component, the expert human testing that discovers authentication bypass, privilege escalation, business logic abuse, and vulnerability chains, is what separates real VAPT from an expensive scanner report.
How to verify: Ask what percentage of the engagement is manual testing versus automated scanning. Ask the provider to describe how they test for business logic vulnerabilities. Ask for a sample report and check whether findings include exploitation evidence (proof the vulnerability was actually exploited) or just scanner output.
Red flag: If the provider can't articulate their manual testing approach, or if the proposal lists only scanner tool names (Nessus, Qualys, Burp Scanner) without describing manual methodology, the engagement will be predominantly automated.
Criterion 2: CREST Certification
CREST certification is the internationally recognised quality standard for penetration testing companies. CREST-certified companies undergo independent assessment of methodology, tester qualifications, data handling, and operational security.
Why it matters: Compliance frameworks and regulators accept CREST certification as evidence of qualified testing. Individual CREST certifications (CRT, CCT) demonstrate tester skill through practical exams. CREST companies must maintain quality standards to retain certification.
Criterion 3: Zero False Positive Commitment
Every finding in the VAPT report should be validated through exploitation. The tester proved the vulnerability is real, demonstrated its impact, and documented the evidence.
Why it matters: False positives waste your remediation team's time, erode trust in the testing programme, and create noise that obscures real findings. A report with 200 findings where 80 are false positives is worse than a report with 40 confirmed, exploitable findings.
How to verify: Ask directly: "Do you commit to zero false positives?" Review the sample report for exploitation evidence on each finding. See our evaluating testing quality guide.
Criterion 4: Comprehensive Testing Capability
Your needs may expand. Choose a VAPT company that covers the full testing spectrum.
Web application testing. API testing. Cloud testing. Network testing (external and internal). Mobile testing. Red teaming. A provider covering all types ensures consistent methodology and a single relationship that grows with your needs.
Criterion 5: Compliance Report Mapping
If your VAPT is compliance-driven, the report must map findings to your framework requirements. SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR. One engagement should produce compliance evidence for multiple frameworks. See our compliance guide.
Criterion 6: Remediation Support and Retesting
Finding vulnerabilities is half the value. The other half is helping you fix them and proving they're fixed.
Remediation support: Post-report availability for questions (30 to 90 days). Technical guidance when your team needs help implementing fixes. Architecture advice for systemic issues.
Retesting: After remediation, the provider retests to confirm fixes work. This should be included in the engagement, not charged separately. Compliance auditors want to see retesting evidence.
Criterion 7: Report Quality
The report is your primary deliverable. It must serve technical teams (for remediation) and leadership (for risk understanding).
What quality reports include: Executive summary for non-technical leadership. Each finding with severity, exploitation evidence, business impact, and specific remediation guidance. Compliance framework mapping. Methodology documentation. Tester qualifications. See our reports guide.
Criterion 8: Industry Experience
A VAPT company with experience in your industry understands your specific risks.
Banking and financial services have transaction logic vulnerabilities. Healthcare has ePHI exposure risks. SaaS has multi-tenant isolation requirements. Fintech has payment fraud vectors. Industry experience means testers know where to look.
Criterion 9: Ongoing Testing Options
Annual VAPT is the compliance minimum. Applications change faster than once per year. Evaluate whether the provider offers continuous testing or PTaaS for ongoing validation between annual engagements. See our continuous vs annual comparison.
Red Flags That Disqualify a VAPT Company
How to Evaluate: Step by Step
Step 1: Define Your Requirements
What systems need testing? What compliance frameworks apply? What testing depth do you need? What budget and timeline do you have? See our penetration testing cost guide for pricing context.
Step 2: Shortlist 3 to 4 Providers
Start from CREST-certified providers and industry referrals. Filter for capability match (do they test what you need tested?) and industry relevance.
Step 3: Request Proposals
Issue a clear scope (URLs, IP ranges, API endpoints, cloud accounts) with compliance requirements and expected deliverables. Evaluate proposals for tailoring versus generic content.
Step 4: Review Sample Reports
This is the most important step. The sample report shows exactly what your deliverable will look like.
Check for: Exploitation evidence on every finding (not just scanner severity ratings). Executive summary that leadership can understand. Remediation guidance specific enough to implement. Compliance mapping. Professional formatting.
If the sample report reads like scanner output with a branded cover page, that's what you'll receive.
Step 5: Conduct Vendor Calls
Ask about manual testing methodology, business logic testing approach, tester qualifications, critical finding escalation, and remediation support. Listen for specificity versus vagueness. Good providers describe exactly how they'd approach your environment. Poor providers give generic answers.
Step 6: Score and Decide
Use a weighted comparison across the 9 criteria above. Factor in communication quality (a predictor of engagement experience), reference feedback, and growth fit (can this provider scale with your needs?).
VAPT Company Selection by Context
For Startups
Right-sized scope (web application and APIs first). SOC 2 report mapping. Affordable pricing without sacrificing manual testing depth. See our startup penetration testing services.
For SaaS Companies
Multi-tenant isolation testing. API security depth. SOC 2 and ISO 27001 mapping. Continuous testing for frequent deployments. See our SaaS penetration testing guide.
For Financial Services
Transaction logic testing. Multi-framework compliance (PCI DSS, SOC 2, ISO 27001, NYDFS, DORA). Red teaming capability. See our financial services testing criteria.
For Singapore
Providers with MAS TRM compliance understanding. Local testing capability. CREST certification recognised by MAS. See our VAPT services in Singapore.
VAPT Provider Selection Checklist
Qualifications
- CREST certified (company-level)
- Individual tester certifications verified (OSCP, CREST CRT/CCT)
- Relevant industry experience demonstrated
- References available from similar organisations
Methodology
- Manual testing approach clearly articulated
- Business logic testing methodology described
- VA and PT components both included (not scanning only)
- Methodology references industry standards (PTES, OWASP, NIST)
Deliverables
- Sample report reviewed and meets quality expectations
- Every finding includes exploitation evidence
- Executive summary included for leadership
- Compliance mapping available for applicable frameworks
- Remediation guidance is specific and actionable
Engagement Terms
- Zero false positive commitment confirmed
- Remediation support included (30 to 90 days)
- Retesting included at no additional cost
- Critical finding escalation process defined
- Continuous testing or PTaaS option available
Pricing
- Pricing reflects adequate manual testing hours (not just scanning)
- Scope clearly defined and tailored to your environment
- No hidden costs for retesting or remediation support
Understanding VAPT Pricing
Pricing significantly below these ranges indicates automated scanning with minimal manual testing. The vulnerabilities that cause breaches (broken access control, business logic abuse, authentication bypass) require human expertise. Budget for quality VAPT, not just a scanner report with a "VAPT" label.
How AppSecure Delivers VAPT
AppSecure provides VAPT that combines automated assessment breadth with expert manual testing depth.
Real VAPT. Automated vulnerability assessment scanning every system for known weaknesses. Expert manual penetration testing exploiting vulnerabilities, testing business logic, validating access controls, and chaining findings. Both components, delivered together, as VAPT should be.
Comprehensive Coverage. Web application, API, cloud, network, mobile. Application security assessment and offensive security testing for end-to-end coverage.
Multi-Framework Reports. Findings mapped to SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, DORA, and MAS TRM. One engagement, all frameworks covered.
CREST Certified. Zero False Positives. 3-Week Delivery. 90-day remediation support. Complimentary retesting. Continuous testing and PTaaS for ongoing validation.
Contact AppSecure:
Frequently Asked Questions
1. What is a VAPT company?
A VAPT company provides vulnerability assessment and penetration testing services. Vulnerability assessment uses automated scanners to identify known weaknesses across your systems (breadth). Penetration testing uses expert human testers to exploit vulnerabilities, test business logic, and validate access controls (depth). A quality VAPT company delivers both components together. Many providers deliver only the scanning component and label it "VAPT," which is why evaluating for manual testing depth is the most important selection criterion.
2. How do I know if a VAPT company does real penetration testing?
Ask what percentage of the engagement is manual testing versus automated scanning. Ask the provider to describe their business logic testing approach. Review their sample report: findings with exploitation evidence (screenshots, request/response pairs, proof-of-concept) indicate real penetration testing. Findings that read like scanner output (severity rating, CVE number, generic description) indicate automated scanning relabelled as VAPT.
3. What certifications should a VAPT company have?
CREST certification at the company level is the most widely recognised quality standard. Individual tester certifications to look for include OSCP, CREST CRT, CREST CCT, and OSWE. CREST certification is accepted by financial regulators globally and indicates independently verified methodology, qualified testers, and secure operations. Without certification, quality claims are unverified.
4. How much does VAPT cost?
Single web application: $15,000 to $30,000. Web plus API: $20,000 to $40,000. External network: $10,000 to $25,000. Comprehensive multi-scope: $50,000 to $100,000+. Pricing below these ranges typically indicates scanning-only engagements without meaningful manual penetration testing. The manual testing component is what costs more per hour and delivers the most value.
5. What should a VAPT report include?
An executive summary for leadership. Each finding with severity rating, exploitation evidence, business impact, and specific remediation guidance. Compliance mapping to applicable frameworks (SOC 2, ISO 27001, PCI DSS). Methodology documentation referencing industry standards. Tester qualifications. Retesting results confirming remediated findings are resolved. Quality reports have zero false positives because every finding is validated through exploitation.
6. Should retesting be included in the VAPT engagement?
Yes. Retesting verifies that remediated vulnerabilities are actually fixed. Fixes sometimes fail (bypassable input filters, incomplete configuration changes). Compliance auditors want retesting evidence confirming resolution. Retesting should be included in the engagement fee, not charged as a separate engagement. Ask during evaluation whether retesting is included and what scope it covers.
7. What is the difference between VAPT and a vulnerability scan?
A vulnerability scan is only the VA component: automated tools checking for known patterns. VAPT includes both VA (automated breadth) and PT (manual depth). A vulnerability scan misses business logic flaws, access control failures, authentication bypass, and vulnerability chains because scanners cannot understand application context. VAPT discovers these through the penetration testing component. Compliance frameworks that require VAPT or penetration testing expect the manual testing component, not just scanning.
8. How often should VAPT be conducted?
Annual VAPT at minimum for compliance (SOC 2, ISO 27001, PCI DSS). Semi-annual for applications with frequent code changes. After major releases, architecture changes, cloud migrations, and new integrations. Quarterly vulnerability scanning between VAPT engagements. Continuous testing or PTaaS for organisations with high deployment velocity. Testing frequency should match change velocity.
9. Can one VAPT engagement satisfy multiple compliance frameworks?
Yes. A well-scoped VAPT engagement can satisfy SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, and regulatory requirements simultaneously. The scope must cover the superset of all framework requirements. The methodology must satisfy the most prescriptive framework. The report must map findings to each applicable framework. This requires a provider with multi-framework mapping capability. One engagement, multiple compliance deliverables.
10. What are the biggest mistakes when choosing a VAPT company?
Choosing on price alone (cheapest means scanning without manual testing). Not reviewing the sample report (the single most revealing evaluation artifact). Accepting "VAPT" that's actually just vulnerability scanning (no manual penetration testing component). No retesting inclusion (no verification that fixes work). Ignoring communication quality during evaluation (predicts engagement experience). Starting the search too late (quality providers are booked 2 to 4 weeks out).
SecureLayer