"VA", "PT" and "VAPT" are often used interchangeably in proposals — but they describe very different levels of assurance. Buying the wrong one is the most common way organisations overpay for little security value, or fail an audit they thought they'd passed.
The short answer
A vulnerability assessment (VA) is a broad, largely automated search for known weaknesses. A penetration test (PT) is a focused, human-led attempt to exploit weaknesses and prove impact. VAPT combines both: scan widely, then manually exploit what matters.
Side-by-side comparison
| Vulnerability assessment | Penetration test | |
|---|---|---|
| Goal | Find as many known issues as possible | Prove what an attacker can achieve |
| Method | Mostly automated scanners | Mostly manual, tool-assisted |
| Depth | Broad and shallow | Narrow and deep |
| Finds business-logic flaws? | Rarely | Yes |
| Exploitation | No | Yes, safely and within agreed rules |
| False positives | Common | Validated by testers |
| Frequency | Weekly to monthly | Annually and after major changes |
| Typical cost | Low (tooling + analyst time) | Higher (skilled tester-days) |
| Satisfies pentest requirements? | Usually not | Yes, when properly scoped |
When a vulnerability assessment is enough
- Continuous hygiene between penetration tests
- Large estates where you need breadth — thousands of hosts
- Checking patch levels and known CVEs after updates
- Requirements that explicitly call for scanning (for example, PCI DSS quarterly scans)
When you need a penetration test
- Compliance frameworks requiring a penetration test (PCI DSS, many SOC 2 and ISO 27001 programs)
- Customer security questionnaires asking for a third-party pentest report
- New applications, major releases, or infrastructure migrations
- Applications handling payments, health data or personal data at scale
- When you need to know whether your controls actually stop an attacker
Why most organisations need both
The most effective programs combine continuous scanning to catch known issues quickly with periodic manual penetration testing to uncover the complex, high-impact flaws scanners miss. That is exactly what a well-run VAPT program delivers.
What a well-run VAPT program looks like
A VAPT program is more than two services bought together. The value comes from how scanning and manual testing feed each other over a year:
- Asset inventoryMaintain a list of internet-facing domains, IPs, cloud accounts and applications. You can't scan or test what you don't know exists.
- Continuous or monthly scanningRun authenticated vulnerability scans of infrastructure and DAST scans of key applications, and fix known issues within agreed timelines.
- Risk-based penetration testingAt least annually — and after major changes — have humans test the highest-risk applications, APIs and networks in depth.
- Remediation and retestFix root causes, then verify with a retest. Feed recurring issues back into secure coding training and code review.
- MeasureTrack mean time to remediate, repeat findings and coverage, and report them to leadership.
VAPT frequency by organisation type
| Organisation | Scanning | Penetration testing |
|---|---|---|
| Early-stage startup | Monthly | Before first enterprise deal or SOC 2, then annually |
| Growing SaaS company | Weekly to monthly | Annually plus major releases |
| Card-processing business | Quarterly internal and external (PCI DSS) | At least every 12 months and after significant change |
| Bank, NBFC or regulated fintech | Continuous | As required by regulator; often semi-annual for critical systems |
| Enterprise | Continuous | Rolling program across the portfolio, plus periodic red teaming |
How to tell if a "pentest" is really a scan
- The quote doesn't ask about user roles, workflows or business logic.
- Turnaround is a day or two for a full application.
- Findings are generic descriptions with scanner plugin IDs.
- No proof-of-concept steps or screenshots of exploitation.
- No access-control or authorization findings at all on a multi-role application.
Explore our VAPT & vulnerability management program, or get a VAPT quote.