{"id":597,"date":"2026-08-11T11:17:19","date_gmt":"2026-08-11T11:17:19","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=597"},"modified":"2026-08-11T11:17:19","modified_gmt":"2026-08-11T11:17:19","slug":"vapt","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/vapt\/","title":{"rendered":"VAPT"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: VAPT\n     Type scale from safe-blog-theme\/style.css v2.7.4 (Inter, 17px\/1.75)\n     Palette: brand navy + muted pastel family per section\n     Paste the whole block into one Custom HTML block. No H1 (WP adds it).\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">VAPT stands for Vulnerability Assessment and Penetration Testing: two security testing methods run together, one for breadth and one for depth, to find and prove exploitable weaknesses in your applications, APIs, cloud and networks.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Testing &amp; scanning<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>VAPT combines automated scanning, which identifies known weaknesses across a system, with manual expert-led exploitation, which confirms which of those weaknesses an attacker could actually use. The output is a prioritised report of validated findings with remediation steps and, after fixes, a retest.<\/p>\n<\/div>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#difference\">Assessment vs penetration testing<\/a><\/li>\n    <li><a href=\"#scope\">What a VAPT covers<\/a><\/li>\n    <li><a href=\"#process\">How an engagement runs<\/a><\/li>\n    <li><a href=\"#compliance\">Where frameworks require it<\/a><\/li>\n    <li><a href=\"#osto\">How Osto runs VAPT<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<p>The term is used mainly in India and across APAC. North America and Europe split the same work into two phrases, vulnerability scanning and penetration testing.<\/p>\n\n<p>Most startups meet it when a questionnaire, an auditor or an investor asks for one. That is late: a critical finding then blocks a deal instead of becoming a sprint ticket.<\/p>\n\n<h2 id=\"difference\">Assessment vs penetration testing<\/h2>\n\n<p>The assessment half asks where you are exposed. The testing half asks what happens when someone actually tries.<\/p>\n\n<p>Only the second one finds business logic flaws. Changing an order ID and getting back another customer&#8217;s invoice is something a human notices and a scanner never will.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 320\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Vulnerability assessment covers every asset at the surface; penetration testing follows one path through every layer.\">\n  <defs>\n    <marker id=\"va1\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#4a52a8\"\/><\/marker>\n    <marker id=\"va2\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#1c267a\"\/><\/marker>\n  <\/defs>\n\n  <text x=\"18\" y=\"28\" font-family=\"Inter,sans-serif\" font-size=\"16\" font-weight=\"700\" fill=\"#4a52a8\">Vulnerability Assessment<\/text>\n  <text x=\"18\" y=\"49\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#0f1538\">Wide coverage, surface level, automated<\/text>\n  <rect x=\"8\" y=\"62\" width=\"356\" height=\"238\" rx=\"18\" fill=\"#f4f5fd\"\/>\n\n  <g>\n    <rect x=\"38\" y=\"92\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"38\" y=\"92\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n    <rect x=\"104\" y=\"92\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"104\" y=\"92\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n    <rect x=\"170\" y=\"92\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"170\" y=\"92\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n    <rect x=\"236\" y=\"92\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"236\" y=\"92\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n    <rect x=\"302\" y=\"92\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"302\" y=\"92\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n\n    <rect x=\"38\" y=\"148\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"38\" y=\"148\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n    <rect x=\"104\" y=\"148\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"104\" y=\"148\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n    <rect x=\"170\" y=\"148\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"170\" y=\"148\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n    <rect x=\"236\" y=\"148\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"236\" y=\"148\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n    <rect x=\"302\" y=\"148\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"302\" y=\"148\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n\n    <rect x=\"38\" y=\"204\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"38\" y=\"204\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n    <rect x=\"104\" y=\"204\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"104\" y=\"204\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n    <rect x=\"170\" y=\"204\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"170\" y=\"204\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n    <rect x=\"236\" y=\"204\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"236\" y=\"204\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n    <rect x=\"302\" y=\"204\" width=\"46\" height=\"40\" rx=\"9\" fill=\"#ffffff\"\/><rect x=\"302\" y=\"204\" width=\"46\" height=\"12\" rx=\"6\" fill=\"#cfd5f2\"\/>\n  <\/g>\n  <line x1=\"38\" y1=\"266\" x2=\"338\" y2=\"266\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#va1)\"\/>\n  <text x=\"188\" y=\"288\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#0f1538\">Every asset, top layer only<\/text>\n\n  <text x=\"406\" y=\"28\" font-family=\"Inter,sans-serif\" font-size=\"16\" font-weight=\"700\" fill=\"#1c267a\">Penetration Testing<\/text>\n  <text x=\"406\" y=\"49\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#0f1538\">One path, all the way down, manual<\/text>\n  <rect x=\"396\" y=\"62\" width=\"356\" height=\"238\" rx=\"18\" fill=\"#f1f7fb\"\/>\n\n  <rect x=\"424\" y=\"88\" width=\"266\" height=\"38\" rx=\"10\" fill=\"#e2eff7\"\/>\n  <text x=\"440\" y=\"112\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#2f6a89\">Public login page<\/text>\n  <rect x=\"424\" y=\"136\" width=\"266\" height=\"38\" rx=\"10\" fill=\"#c2d9ec\"\/>\n  <text x=\"440\" y=\"160\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#25547a\">Authenticated user session<\/text>\n  <rect x=\"424\" y=\"184\" width=\"266\" height=\"38\" rx=\"10\" fill=\"#7b9dc9\"\/>\n  <text x=\"440\" y=\"208\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#ffffff\">Internal admin API<\/text>\n  <rect x=\"424\" y=\"232\" width=\"266\" height=\"38\" rx=\"10\" fill=\"#1c267a\"\/>\n  <text x=\"440\" y=\"256\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#ffffff\">Customer data<\/text>\n\n  <line x1=\"712\" y1=\"84\" x2=\"712\" y2=\"268\" stroke=\"#1c267a\" stroke-width=\"3\" stroke-dasharray=\"7 5\" marker-end=\"url(#va2)\"\/>\n  <text x=\"574\" y=\"288\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#0f1538\">One chained attack path, proven<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>A scanner tells you a door looks unlocked. A tester walks through it and shows you what is in the room.<\/figcaption>\n<\/figure>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Dimension<\/th><th>Vulnerability assessment<\/th><th>Penetration testing<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Question answered<\/strong><\/td><td>What weaknesses exist?<\/td><td>What can an attacker actually do?<\/td><\/tr>\n    <tr><td><strong>Method<\/strong><\/td><td>Automated scanning for known CVEs<\/td><td>Manual testing and chained exploits<\/td><\/tr>\n    <tr><td><strong>Business logic flaws<\/strong><\/td><td>Not found<\/td><td>Found<\/td><\/tr>\n    <tr><td><strong>False positives<\/strong><\/td><td>Common, needs triage<\/td><td>Low, proven by exploitation<\/td><\/tr>\n    <tr><td><strong>Cadence<\/strong><\/td><td>Continuous<\/td><td>Annually, plus after big releases<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">How to tell them apart in five seconds<\/p>\n  <p>Hundreds of findings and no proof of exploitation is a vulnerability assessment. A dozen findings with reproduction steps and evidence is a penetration test. A real VAPT contains both.<\/p>\n<\/div>\n\n<h2 id=\"scope\" class=\"c-sage\">What a VAPT covers<\/h2>\n\n<p>Scope decides whether a VAPT is useful or theatre. Testing the marketing site while customer data sits behind an open internal API produces a clean report and no security.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Scope<\/th><th>What gets tested<\/th><th>When to add it<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Web application<\/strong><\/td><td>Auth, sessions, tenant isolation, injection<\/td><td>First, the usual scope<\/td><\/tr>\n    <tr><td><strong>API<\/strong><\/td><td>Broken object level auth, rate limits, shadow endpoints<\/td><td>With the web app<\/td><\/tr>\n    <tr><td><strong>Cloud<\/strong><\/td><td>IAM sprawl, public storage, open security groups<\/td><td>Past one cloud account<\/td><\/tr>\n    <tr><td><strong>Mobile app<\/strong><\/td><td>Local storage, cert pinning, hardcoded secrets<\/td><td>If you ship a mobile client<\/td><\/tr>\n    <tr><td><strong>Network<\/strong><\/td><td>Exposed services, VPN, TLS, lateral movement<\/td><td>Self-managed infrastructure<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Engagements are also described by how much the tester starts with:<\/p>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Black box<\/p>\n    <p class=\"g\">No access<\/p>\n    <p>Mirrors an external attacker, but burns hours on reconnaissance.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Grey box<\/p>\n    <p class=\"g\">User credentials<\/p>\n    <p>The usual SaaS choice, since most real attacks start with a valid account.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">White box<\/p>\n    <p class=\"g\">Full source and credentials<\/p>\n    <p>Most thorough per hour spent, and the fastest route to depth.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"process\" class=\"c-apri\">How an engagement runs<\/h2>\n\n<p>Five phases. Teams skip the last one, which is the only one that produces the document an auditor or enterprise buyer asks for.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 170\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Five VAPT phases: plan, find, prove, fix, verify.\">\n  <defs><marker id=\"vpA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#b9c0d4\"\/><\/marker><\/defs>\n\n  <rect x=\"8\" y=\"34\" width=\"130\" height=\"82\" rx=\"14\" fill=\"#e9ecfa\"\/>\n  <text x=\"73\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#4a52a8\">1. Plan<\/text>\n  <text x=\"73\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Scope, windows,<\/text>\n  <text x=\"73\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">written sign-off<\/text>\n  <line x1=\"144\" y1=\"75\" x2=\"158\" y2=\"75\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#vpA)\"\/>\n\n  <rect x=\"164\" y=\"34\" width=\"130\" height=\"82\" rx=\"14\" fill=\"#e3f0e9\"\/>\n  <text x=\"229\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#3a6f5d\">2. Find<\/text>\n  <text x=\"229\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Map the surface,<\/text>\n  <text x=\"229\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">then scan it<\/text>\n  <line x1=\"300\" y1=\"75\" x2=\"314\" y2=\"75\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#vpA)\"\/>\n\n  <rect x=\"320\" y=\"34\" width=\"130\" height=\"82\" rx=\"14\" fill=\"#c2d9ec\"\/>\n  <text x=\"385\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#25547a\">3. Prove<\/text>\n  <text x=\"385\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Exploit, drop<\/text>\n  <text x=\"385\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">false positives<\/text>\n  <line x1=\"456\" y1=\"75\" x2=\"470\" y2=\"75\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#vpA)\"\/>\n\n  <rect x=\"476\" y=\"34\" width=\"130\" height=\"82\" rx=\"14\" fill=\"#7b9dc9\"\/>\n  <text x=\"541\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">4. Fix<\/text>\n  <text x=\"541\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#eaf1f8\">Rank by business<\/text>\n  <text x=\"541\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#eaf1f8\">impact, remediate<\/text>\n  <line x1=\"612\" y1=\"75\" x2=\"626\" y2=\"75\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#vpA)\"\/>\n\n  <rect x=\"632\" y=\"34\" width=\"120\" height=\"82\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"692\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">5. Verify<\/text>\n  <text x=\"692\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">Retest and<\/text>\n  <text x=\"692\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">record closure<\/text>\n\n  <text x=\"380\" y=\"152\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Get written authorisation before phase 2 touches anything in production<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<p>Ask to see a sample report first. It needs an executive summary, the exact scope and dates, evidence and reproduction steps per finding, named fixes, and a retest section.<\/p>\n\n<h2 id=\"compliance\" class=\"c-plum\">Where frameworks require it<\/h2>\n\n<p>Only one of these actually names penetration testing as mandatory.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Framework<\/th><th>Status<\/th><th>Where it appears<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr>\n      <td><strong>PCI DSS v4.0<\/strong><\/td>\n      <td><span class=\"pill p-req\">Required<\/span><\/td>\n      <td>Requirement 11.3: annual internal and external pentests, plus quarterly scans.<\/td>\n    <\/tr>\n    <tr>\n      <td><strong>ISO 27001:2022<\/strong><\/td>\n      <td><span class=\"pill p-exp\">Expected<\/span><\/td>\n      <td>Annex A 8.8 (technical vulnerabilities) and A 8.29 (security testing).<\/td>\n    <\/tr>\n    <tr>\n      <td><strong>SOC 2<\/strong><\/td>\n      <td><span class=\"pill p-exp\">Expected<\/span><\/td>\n      <td>Not named in the <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-controls-cc1-cc9\/\">Criteria<\/a>. Auditors want remediation evidence under CC4.1 and CC7.1, usually a VAPT report plus retest.<\/td>\n    <\/tr>\n    <tr>\n      <td><strong>DPDP Act, 2023<\/strong><\/td>\n      <td><span class=\"pill p-imp\">Implied<\/span><\/td>\n      <td>Requires reasonable security safeguards, not a named test. VAPT is the standard way to evidence them.<\/td>\n    <\/tr>\n    <tr>\n      <td><strong>Buyer questionnaires<\/strong><\/td>\n      <td><span class=\"pill p-ask\">Asked<\/span><\/td>\n      <td>Date of your last test, who ran it, whether findings were fixed.<\/td>\n    <\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout c-plum\">\n  <p class=\"k\">The order that works<\/p>\n  <p>Close the findings first, then map the evidence to the framework. Teams that <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-for-startups\/\">chase the certificate first<\/a> end up with mapped controls, an open critical finding, and a report they cannot send to a customer.<\/p>\n<\/div>\n\n<h2 id=\"osto\" class=\"c-sky\">How Osto runs VAPT<\/h2>\n\n<p>Osto runs VAPT inside the platform, not as a one-off engagement. Expert-led testing covers the depth; an AI scanner covers the breadth on a schedule instead of once a year.<\/p>\n\n<p>Because testing sits in the same stack as the WAF, CSPM, code security and compliance modules, remediation and retest reports come out where the evidence already lives. That is why VAPT fits inside Osto&#8217;s 7-day SOC 2 readiness phase. The certificate is a byproduct of the security.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">See what an attacker would find first<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Expert-led VAPT plus continuous AI scanning across your apps, APIs and cloud. Tell us your scope and we will tailor a plan.<\/p>\n  <a href=\"https:\/\/www.osto.one\/contact\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:'Inter',-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/www.osto.one\/book-demo\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Findings delivered in 7 days &middot; Retest included &middot; One platform, everything<\/p>\n<\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is the full form of VAPT?<\/summary>\n  <p>VAPT stands for Vulnerability Assessment and Penetration Testing: a combined engagement using automated scanning to find known weaknesses and manual expert testing to confirm which are actually exploitable.<\/p>\n<\/details>\n\n<details>\n  <summary>Is VAPT the same as a penetration test?<\/summary>\n  <p>No. A penetration test is one half of VAPT. The assessment gives breadth across all in-scope assets, the pentest gives depth on what matters most. A report containing only scanner output is not a pentest, and an auditor will not accept it as one.<\/p>\n<\/details>\n\n<details>\n  <summary>How long does a VAPT take?<\/summary>\n  <p>It depends on scope. A single web application is typically a few days to two weeks including reporting. Web, mobile, APIs and internal networks together can run several weeks. Automated scanning is far faster and runs continuously alongside the manual work.<\/p>\n<\/details>\n\n<details>\n  <summary>Is VAPT mandatory for SOC 2?<\/summary>\n  <p>The SOC 2 Trust Services Criteria do not name it as a required control. In practice auditors expect evidence that vulnerabilities are found and fixed under criteria such as CC4.1 and CC7.1, and a VAPT report with a retest is the usual way to provide it. PCI DSS does explicitly require annual pentesting under Requirement 11.3.<\/p>\n<\/details>\n\n<details>\n  <summary>How often should a startup run VAPT?<\/summary>\n  <p>A full penetration test at least annually and after any significant change, such as a new payment flow, a new auth provider or a cloud migration. Automated scanning continuously in between, and a retest after every remediation cycle.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/penetration-testing\/\">Penetration Testing<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-assessment\/\">Vulnerability Assessment<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-scanning\/\">Vulnerability Scanning<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability Management<\/a> &middot; DAST &middot; CTEM<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>VAPT stands for Vulnerability Assessment and Penetration Testing: two security testing methods run together, one for breadth and one for\u2026<\/p>\n","protected":false},"author":8,"featured_media":598,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[181,183,186,182,185],"class_list":["post-597","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-vapt","tag-vapt-full-form","tag-vapt-process","tag-vapt-testing","tag-vapt-vs-penetration-testing"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/597","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=597"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/597\/revisions"}],"predecessor-version":[{"id":599,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/597\/revisions\/599"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/598"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=597"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=597"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=597"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}