Vulnerability assessment and penetration testing, explained

VAPT is a combined engagement. The vulnerability assessment scans broadly and returns an inventory of known weaknesses; the penetration test manually exploits the ones that matter and proves what an attacker could actually reach. The assessment draws the map, the test walks the route. Regulated buyers purchase them together because frameworks such as PCI DSS require both, and require them on separate schedules.
For teams buying assessment and testing as one engagement
Compliance and risk owners whose framework names both scanning and manual testing, and who need one engagement that closes both lines.
Teams already running scanners who have thousands of open findings and need someone to prove which of them an attacker can actually reach.
Buyers who will have to tell an auditor exactly what was tested, on what dates, by whom, and what was fixed and re-verified afterwards.

Two deliverables, two requirement lines, one engagement
People argue about whether a vulnerability assessment and a penetration test are the same thing. For a buyer the more useful question is what each one puts in your hands, who stands behind it, and which line of your framework it closes. Compared on those terms, VAPT stops being a definition and becomes a procurement decision.
Requirement numbers refer to PCI DSS v4.0. Testing evidence supports SOC 2 and ISO/IEC 27001 programs and PCI DSS assessments; it does not certify compliance on its own.
How a VAPT engagement gets scoped
What a complete VAPT produces
Frequently asked questions
Is VAPT one engagement or two?
Commercially it is usually sold as one, and that is the point of the acronym. Technically it is two activities with different objectives: the assessment maximizes breadth and the test maximizes depth. Buying them together matters because the assessment output is what a good tester uses to decide where to spend manual effort, and because most frameworks ask for evidence of both.
Does a vulnerability scan satisfy compliance on its own?
Not where the framework names testing separately. PCI DSS v4.0 asks for internal and external vulnerability scans at least once every three months under requirements 11.3.1 and 11.3.2, and separately for internal and external penetration testing at least once every 12 months under 11.4.2 and 11.4.3, with segmentation testing under 11.4.5. ISO/IEC 27001:2022 control 8.8 covers management of technical vulnerabilities and 8.29 covers security testing in development and acceptance. Under SOC 2, penetration testing is not a mandatory control but appears as an example of an evaluation under CC4.1.
How do I scope a VAPT without over-paying?
Scope by what an attacker can reach rather than by what you own. Start with everything exposed to the internet, add the systems that hold regulated or revenue-critical data, then add the paths between them. Provide credentials and at least two privilege levels so the authenticated surface is not wasted. Write the exclusions down. Most cost overruns come from a scope that grew mid-engagement, not from a rate that was too high.
What deliverables should I insist on?
The assessment inventory, the penetration test report with reproduction steps and evidence per finding, a retest attestation once fixes ship, and an executive summary with scope, dates, methodology and tester qualifications. Ask for a redacted sample of all four before signing. If a provider cannot show you what the retest attestation looks like, assume retesting is not really included.
How often should VAPT be performed?
The regulatory floor is a schedule: quarterly scans and annual testing under PCI DSS, with both repeated after any significant change. The operational answer is different. If you deploy weekly, an annual test describes an environment that no longer exists by the time the report is read, which is why the after-a-significant-change clause exists and why continuous models have grown.
Who should perform VAPT — an internal team or a third party?
Internal teams can run the assessment side well, and many do. Auditors generally want independence for the testing side, and there is a practical argument too: the people who built a system share its blind spots. A common arrangement is internal scanning on a continuous basis with independent testing layered on top, which is also how the requirement lines are written.
If you are still deciding what to buy, start with the definition. If you already know, go straight to the compliance angle.
ALWAYS-ON PLATFORM
More than a test. A strategic layer for real security.
Our AI is powered by a proprietary data layer built from thousands of hours of pentesting and real-world validations. Strike combines autonomous execution and expert human validation to uncover complex risks, reduce noise, and prioritize actionable findings.
In-depth continuous testing
Strikers uncover high-impact vulnerabilities across multi-technology environments (web apps, APIs, mobile, cloud, and more).
AI-led retesting on-demand
Validate fixes instantly, without waiting for the next testing cycle.
Real-time fixing
AI agents guide your team step-by-step through remediation to accelerate resolution.
Step-by-step Threat emulation creation
Easily scope, launch, and track your Threat emulation with full transparency.
Human triaging & peer review
Every finding is validated by security experts to ensure accuracy and impact.
Full visibility
Track every finding with complete transparency through security expert work logs and real-time notifications.
Seamless integrations
Connect directly with Slack, Teams and Jira to streamline collaboration with your security and development teams.
Vulnerability Manager
Visualize, manage, and retest vulnerabilities in one platform, with full context on severity, sources, and remediation.
Compliance-ready reporting
Automatically generate up-to-date reports aligned with PCI DSS, HIPAA, ISO 27001, SOC 2, and more.
Ongoing partnership
Weekly check-ins with a dedicated Customer Success Manager, plus personalized onboarding and strategic planning.
More than an offensive security platform, Strike operates as a continuous validation layer for environments that never stop changing.
Trusted by security teams that lead
Human expertise.
AI power.
Superior security.
Whether you’re scaling fast, closing enterprise deals, or just tired of noisy reports, we’ll help you build a security stack that moves faster than your threats.






