The VAPT Process, Step by Step: How a Pentest Works

The six-stage VAPT process from scoping to remediation
The VAPT Process, Step by Step: How a Pentest Works | Osto

A professional VAPT is a disciplined sequence, not a single scan. Here is what happens at each stage, from defining scope to proving that your fixes actually worked.

Osto Security Team8 min readSecurity Testing

TL;DR

A VAPT runs through defined stages: scoping and rules of engagement, reconnaissance, scanning to find weaknesses, controlled exploitation to prove real risk, then risk analysis, reporting, and remediation with a retest to confirm fixes.

The value is in the whole sequence. Scanning finds candidates, exploitation proves impact, and the report translates it into prioritised fixes. A good VAPT ends with a retest that verifies the issues are actually closed, not just a document.

Why the VAPT process matters

The difference between a genuine VAPT and a superficial scan is the process behind it. A real engagement follows a structured methodology so that nothing important is missed, findings are proven rather than guessed, and the output is something you can act on. Understanding the stages helps you tell a serious test from a checkbox exercise, and helps you get real value from the engagement rather than just a PDF.

A disciplined sequence
VAPT follows a repeatable path
Plan and scope
Define what is tested, how, and the rules of engagement.
Test and exploit
Scan for weaknesses, then safely prove what is exploitable.
Report and fix
Turn findings into prioritised, actionable remediation, then retest.

The six stages of a VAPT

While methodologies vary, a thorough VAPT moves through six logical stages, ending with a loop back to verify the fixes.

The process
Six stages from scope to fix
A professional VAPT is methodical. Each stage builds on the last, ending not with a list of problems but with fixes proven by a retest.
1 Scope 2 Recon 3 Scan 4 Exploit 5 Report 6 Remediate & retest

Each stage explained

StageWhat happens
1. ScopingDefine targets, depth, approach, and rules of engagement up front
2. ReconnaissanceGather information about the targets and map the attack surface
3. ScanningIdentify weaknesses across the in-scope systems
4. ExploitationSafely and deliberately attempt to exploit weaknesses to prove risk
5. Analysis and reportingAssess impact, prioritise by severity, and document clear findings
6. Remediation and retestFix the issues, then retest to confirm they are genuinely closed
Scoping decides everything
The first stage quietly determines the value of the whole test. A clear scope, the right targets, the chosen approach, and agreed rules of engagement, ensures the test focuses on real risk and runs safely. Rushing scope is where weak engagements begin.

The heart of the engagement is the move from scanning to exploitation. Scanning produces candidates, potential weaknesses. Exploitation is where skilled testers prove which of those are genuinely dangerous by safely demonstrating what an attacker could actually do, including chaining smaller issues into a serious one. That proof is what separates VAPT from a plain assessment.

Controlled, not reckless
Exploitation in a VAPT is deliberate and safe, testers work within agreed rules of engagement to demonstrate risk without causing damage. The goal is proof of impact, achieved responsibly, not disruption.

The retest that closes the loop

A frequently overlooked but critical stage is the retest. After you remediate the reported findings, testers verify that the fixes actually resolved the issues and did not introduce new ones. Without this step, you have a report and some fixes, but no proof they worked. The retest is what turns a VAPT from a snapshot of problems into evidence that your security actually improved, which is exactly what auditors and enterprise buyers want to see.

The lean-team path through the VAPT process

Running this full process, scoping, testing, analysis, reporting, remediation tracking, and a retest, is a lot for a lean team to coordinate across separate vendors and tools, especially the follow-through after the report lands. The efficient path is a process that carries findings all the way to a verified fix in one place.

Run the whole VAPT loop, through to a verified fix.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Take VAPT from scope to exploitation to remediation and retest, with reports at every step, on one platform. No security team required.

Book a Demo →

Frequently asked questions

What are the stages of a VAPT?

Typically six: scoping and rules of engagement, reconnaissance, scanning for weaknesses, controlled exploitation to prove risk, analysis and reporting, and remediation with a retest to confirm fixes. The sequence takes you from planning to verified improvement.

What is the difference between scanning and exploitation in a VAPT?

Scanning identifies potential weaknesses across your systems. Exploitation is where testers safely and deliberately attempt to exploit those weaknesses to prove which are genuinely dangerous and what an attacker could actually achieve. Scanning finds; exploitation proves.

Is exploitation during a pentest safe?

Yes, when done professionally. Exploitation is controlled and bound by agreed rules of engagement, designed to demonstrate real risk without causing damage or disruption. The aim is proof of impact achieved responsibly.

What is a retest in VAPT?

After you fix the reported findings, testers verify that the fixes actually resolved the issues without introducing new ones. The retest turns a VAPT from a list of problems into evidence that your security genuinely improved, which auditors and buyers value.

Why is scoping so important in a VAPT?

Scoping determines what gets tested, how deeply, with which approach, and under what rules. A clear scope focuses the test on real risk and keeps it safe, while a rushed or vague scope is where weak, low-value engagements begin.

How long does a VAPT take?

It varies with scope, the number and complexity of targets, and the depth of testing. A focused application test is shorter than a broad, multi-target engagement. Scoping is where the timeline and effort are set, which is another reason it matters.