Vulnerability assessment and penetration testing, explained

Threat emulation schedule with dates, sources, statuses, and a vulnerabilities list with severity and fix status.

VAPT is a combined engagement. The vulnerability assessment scans broadly and returns an inventory of known weaknesses; the penetration test manually exploits the ones that matter and proves what an attacker could actually reach. The assessment draws the map, the test walks the route. Regulated buyers purchase them together because frameworks such as PCI DSS require both, and require them on separate schedules.

For teams buying assessment and testing as one engagement

Compliance and risk owners whose framework names both scanning and manual testing, and who need one engagement that closes both lines.

Teams already running scanners who have thousands of open findings and need someone to prove which of them an attacker can actually reach.

Buyers who will have to tell an auditor exactly what was tested, on what dates, by whom, and what was fixed and re-verified afterwards.

User interface with sections titled 'Strikers assigned' showing two profile pictures and their details, and an 'Export' panel with options to include Findings Summary, Assessment Updates, and Compliance Checklist, with a Download button.
[ VA + PT AS ONE PURCHASE ]

Two deliverables, two requirement lines, one engagement

People argue about whether a vulnerability assessment and a penetration test are the same thing. For a buyer the more useful question is what each one puts in your hands, who stands behind it, and which line of your framework it closes. Compared on those terms, VAPT stops being a definition and becomes a procurement decision.

How you actually buy it
Vulnerability assessment
Penetration test
Continuous VAPT (Strike)
What lands in your hands
A prioritized inventory of known weaknesses across the scoped estate
A report of exploited paths, with evidence and business impact
A live queue of validated findings, plus report and attestation on demand
Who stands behind a finding
The tool, and whoever ran it
The named tester and the provider, for the duration of the engagement
The named Striker who validated that specific finding
Triage cost to your team
High. Deciding what is real is your job
Low, but only for the findings inside the scoped window
Low and continuous: 97% accuracy, under 3% false positives
Requirement line it closes
The scanning line — PCI DSS 11.3.1 and 11.3.2 ask for scans at least every three months
The testing line — PCI DSS 11.4.2 and 11.4.3 ask for internal and external tests at least every 12 months
Both lines, plus the after-a-significant-change clause that sits on each of them
What happens to a new asset
Picked up on the next scheduled scan, if it is in the range
Tested only if it was named in the agreed scope
Discovered and tested when it appears, not when the calendar allows
Re-verifying a fix
A rescan. The absence of a signature is treated as a fix
A retest, if you contracted one
Included, on demand, with a retest attestation you can hand to an auditor

Requirement numbers refer to PCI DSS v4.0. Testing evidence supports SOC 2 and ISO/IEC 27001 programs and PCI DSS assessments; it does not certify compliance on its own.

How a VAPT engagement gets scoped

Asset inventory, agreed in writing
IP ranges, domains and subdomains, applications, APIs, cloud accounts and mobile builds. The single most common cause of a disappointing engagement is an inventory that was already out of date on the day it was signed.
Environments and data handling
Production, staging or a production-like clone, and what the rules are for each. Decide up front what happens if the tester finds live customer data in a non-production system, because that conversation is worse when it happens unplanned.
Credentials and roles
Unauthenticated testing describes what a stranger sees. Most of the damaging findings live behind the login, and finding broken authorization requires at least two accounts at different privilege levels. Provision them before the window opens, not during it.
Testing windows and rate limits
Agree when testing runs, whether WAF and rate limiting stay on, and who to call if something falls over. If protective controls are left on, say so in the report: an auditor reads a blocked attempt differently from an unattempted one.
Exclusions, written down
Third-party SaaS you do not own, denial-of-service testing, social engineering, physical access. Every exclusion is a gap someone will eventually ask you about, so record the reason alongside it.
Change handling
Define what happens when a new subdomain, service or release appears mid-engagement. In a point-in-time model this is a change order. In a continuous model it is just the next thing tested.

What a complete VAPT produces

The vulnerability assessment output
A full inventory of identified weaknesses across the scoped estate, with severity, affected assets and the source of each detection. This is the breadth artefact: it tells you the size of the surface, not the size of the risk.
The penetration test report
Exploited paths with reproduction steps, evidence, business impact and remediation guidance, plus an executive summary. This is the depth artefact: it tells you which of the weaknesses above an attacker can actually chain into damage.
Retest attestation
A record that each fix was re-tested and the finding closed, with the date and the tester. Auditors ask for this more often than teams expect, and reconstructing it months later is painful.
Executive summary and evidence pack
Scope, dates, methodology, tester qualifications and results in a form a non-technical reader can follow. This is the part that supports SOC 2 and ISO/IEC 27001 programs and PCI DSS assessments — supports, not certifies.

Frequently asked questions

Is VAPT one engagement or two?

Commercially it is usually sold as one, and that is the point of the acronym. Technically it is two activities with different objectives: the assessment maximizes breadth and the test maximizes depth. Buying them together matters because the assessment output is what a good tester uses to decide where to spend manual effort, and because most frameworks ask for evidence of both.

Does a vulnerability scan satisfy compliance on its own?

Not where the framework names testing separately. PCI DSS v4.0 asks for internal and external vulnerability scans at least once every three months under requirements 11.3.1 and 11.3.2, and separately for internal and external penetration testing at least once every 12 months under 11.4.2 and 11.4.3, with segmentation testing under 11.4.5. ISO/IEC 27001:2022 control 8.8 covers management of technical vulnerabilities and 8.29 covers security testing in development and acceptance. Under SOC 2, penetration testing is not a mandatory control but appears as an example of an evaluation under CC4.1.

How do I scope a VAPT without over-paying?

Scope by what an attacker can reach rather than by what you own. Start with everything exposed to the internet, add the systems that hold regulated or revenue-critical data, then add the paths between them. Provide credentials and at least two privilege levels so the authenticated surface is not wasted. Write the exclusions down. Most cost overruns come from a scope that grew mid-engagement, not from a rate that was too high.

What deliverables should I insist on?

The assessment inventory, the penetration test report with reproduction steps and evidence per finding, a retest attestation once fixes ship, and an executive summary with scope, dates, methodology and tester qualifications. Ask for a redacted sample of all four before signing. If a provider cannot show you what the retest attestation looks like, assume retesting is not really included.

How often should VAPT be performed?

The regulatory floor is a schedule: quarterly scans and annual testing under PCI DSS, with both repeated after any significant change. The operational answer is different. If you deploy weekly, an annual test describes an environment that no longer exists by the time the report is read, which is why the after-a-significant-change clause exists and why continuous models have grown.

Who should perform VAPT — an internal team or a third party?

Internal teams can run the assessment side well, and many do. Auditors generally want independence for the testing side, and there is a practical argument too: the people who built a system share its blind spots. A common arrangement is internal scanning on a continuous basis with independent testing layered on top, which is also how the requirement lines are written.

ALWAYS-ON PLATFORM

More than a test. A strategic layer for real security.

Our AI is powered by a proprietary data layer built from thousands of hours of pentesting and real-world validations. Strike combines autonomous execution and expert human validation to uncover complex risks, reduce noise, and prioritize actionable findings.

In-depth continuous testing

Strikers uncover high-impact vulnerabilities across multi-technology environments (web apps, APIs, mobile, cloud, and more).

AI-led retesting on-demand

Validate fixes instantly, without waiting for the next testing cycle.

Real-time fixing

coming soon

AI agents guide your team step-by-step through remediation to accelerate resolution.

Step-by-step Threat emulation creation

Easily scope, launch, and track your Threat emulation with full transparency.

Human triaging & peer review

Every finding is validated by security experts to ensure accuracy and impact.

Full visibility

Track every finding with complete transparency through security expert work logs and real-time notifications.

Seamless integrations

Connect directly with Slack, Teams and Jira to streamline collaboration with your security and development teams.

Vulnerability Manager

Visualize, manage, and retest vulnerabilities in one platform, with full context on severity, sources, and remediation.

Compliance-ready reporting

Automatically generate up-to-date reports aligned with PCI DSS, HIPAA, ISO 27001, SOC 2, and more.

Ongoing partnership

Weekly check-ins with a dedicated Customer Success Manager, plus personalized onboarding and strategic planning.

More than an offensive security platform, Strike operates as a continuous validation layer for environments that never stop changing.

Boost your experience with Hybrid Testing Booster

Continuous Hybrid Testing

Emulated, deep stealth-based attacks executed by creative, unconventional security experts. Find out how real attackers would breach your systems, and stop them before they do.

Testimonial

Trusted by security teams that lead

"Product was great! The team was exceptional when addressing our sense of urgency with regards to an important timeline, and they were able to deliver effectively and finding important vulnerabilities within our systems."

Gartner 4
Gartner review, Head of Engineering, Banking

"Good option for agile testing, especially if GTM timelines are tight. This is especially important when the release train comes with a lot of new products and releases, making it hard to keep the pace in a traditional ad-hoc business model."

Gartner 3
Gartner review, Product Security Leader Cybersecurity, Hardware

“Strike provides continuous pentesting for our critical web and mobile features. Each month they help us validate new functionalities in production, delivering relevant vulnerabilities and strong value for money. We are very satisfied with their innovative and customer-centric approach.”

Gartner 2
Gartner review, Chief Information Security Officer, Retail

"Strike team was fast and provided the exact solution we needed for our use case. We decided to go for Strike because they provide a pen-testing suite that fits the way we work in terms of speed and communication. Highly recommended!"

Gartner review
Gartner 1
Gartner Review, Chief Technical Officer, Banking

"We greatly value our partnership with Strike. Their exceptional penetration testing services and effective communication have significantly enhanced our cybersecurity, ensuring the safety and trust of our customers' financial information."

Ozan Özgür Özyüksel
Information Security Officer, Plum

"The management of communication channels and the centralization of interactions with the team made the experience much more agile and effective. Having everything in one place was a huge advantage and allowed us to complete the pentest within just a few weeks."

Miguel Langone
CTO at Horizon

“Working with Strike is extremely important to us, especially because they deliver quality work over our products in a continuous way, and provide constant follow-up when it comes to managing the already found vulnerabilities. Moreover, they are constantly making improvements in their SaaS platform so we can have the best experience possible. In case we have a problem, they listen and help us. That’s invaluable.”

Ileana Barrionuevo
Sr AppSec Red Team, NaranjaX

“Working with Strike was an excellent experience for us. We were able to create our own pentests and change their scope each month. The Strikers are world-class professionals who provide us with relevant findings quickly and efficiently. Also, automated tools like Phishing Monitor are really interesting for our company, because they help us spot fake domains trying to impersonate PedidosYa.”

Eduardo Gimenez
CISO, Pedidos Ya

“For us at pier, security is the most important aspect, not only on the surface but throughout our entire product. When we reached out to Strike, we were looking for someone that could test & find vulnerabilities across our entire stack. We are very happy that we have found the right partner to achieve that, and we are looking forward to continuing this important work together.”

Andras Hejj
CEO & CTO, Pier

Human expertise.
AI power.
Superior security.

Whether you’re scaling fast, closing enterprise deals, or just tired of noisy reports, we’ll help you build a security stack that moves faster than your threats.

Book a Demo