Contact
Cyber Security

What is VAPT? Vulnerability Assessment & Penetration Testing, Explained

What is VAPT? Vulnerability assessment vs penetration testing, Singapore compliance drivers (MAS TRM, PCI DSS, PDPA), engagement steps and real cost ranges.

September 17, 2026 8 min read
Short answer: VAPT stands for Vulnerability Assessment and Penetration Testing – two different security tests usually bought together. A vulnerability assessment (VA) is a largely automated scan that lists known weaknesses: missing patches, misconfigurations, outdated software. A penetration test (PT) is a human expert actually attempting to exploit those weaknesses, the way a real attacker would. VA tells you what looks weak; PT proves what an attacker can actually reach. In Singapore, VAPT is driven less by curiosity than by obligation – MAS expectations for financial institutions, PCI DSS for anyone handling card data, and PDPA’s duty to protect personal data.

If you have been asked for a “VAPT report” by a client, auditor or regulator and quietly wondered what is VAPT exactly – this guide is for you. It explains the two tests, who needs them in Singapore, what an engagement looks like, and what it costs, without the vendor fog.

VA and PT are two different tests

Bundling them under one acronym hides how different they are. Buying a VA when your auditor wants a PT is an expensive way to fail an audit, so here is the split:

Factor Vulnerability Assessment (VA) Penetration Test (PT)
Method Automated scanning Manual, human-led exploitation
Question answered What looks vulnerable? What can an attacker actually do?
Output List of findings by severity Proven attack paths + evidence
Depth Broad and shallow Narrow and deep
Typical frequency Quarterly or monthly Annually + after major changes
Relative cost Lower Higher (skilled hours)

Penetration testing Singapore: who actually needs it

The penetration testing Singapore market is shaped by four compliance drivers, and knowing which applies to you decides the scope you should buy:

  • MAS-regulated firms – the MAS Technology Risk Management Guidelines expect financial institutions to conduct penetration testing on internet-facing systems regularly (annually is the accepted baseline) and to remediate findings.
  • Anyone handling card payments – PCI DSS requires penetration testing at least annually and after significant changes to systems in scope of cardholder data.
  • Every business holding personal data – the PDPA obliges organisations to make reasonable security arrangements to protect personal data; VAPT is one of the clearest ways to demonstrate that duty was taken seriously.
  • Certification and customers – CSA’s Cyber Essentials and Cyber Trust marks, ISO 27001, and increasingly enterprise procurement teams all ask for evidence of security testing before signing.

The six common VAPT scopes

  • External network – what an attacker on the internet can reach: firewalls, VPN gateways, exposed services.
  • Internal network – what an attacker (or rogue laptop) already inside the office can reach.
  • Web applications – your website, portals and APIs, tested against injection, broken authentication and the rest of the OWASP Top 10. OWASP publishes the OWASP Top 10 as the reference standard for the most critical web application security risks.
  • Mobile applications – the app plus the backend it talks to.
  • Cloud configuration – misconfigured storage buckets, over-broad IAM permissions, exposed management consoles.
  • Social engineering – phishing simulations against staff, usually paired with awareness training.

How a VAPT engagement runs

  1. Scoping – agree targets, test window, and rules of engagement in writing. This protects both sides.
  2. Reconnaissance and scanning – the VA phase: automated discovery of hosts, services and known weaknesses.
  3. Manual exploitation – the PT phase: testers chain findings into real attack paths, capturing evidence at each step.
  4. Reporting – findings ranked by severity (typically CVSS scores), each with reproduction steps and a concrete fix. NIST’s vulnerability metrics guidance explains how CVSS produces a numerical score and a qualitative severity rating.
  5. Remediation – your team or your IT provider closes the gaps, worst first.
  6. Re-test – the testers verify the fixes actually closed the paths. A report without a re-test is half a report.

You can test a proposal against this sequence before you sign it. Ask for the scope in writing, with named targets and a test window, and check that the report will rank findings by severity with reproduction steps and a fix for each, not just a scanner export. Then look for the re-test: if it is missing, or priced as an optional extra, the engagement ends at the report and you are left to confirm your own fixes. If someone asks what is VAPT in practice, the honest answer is these six steps run in order, not a tool name. Keep the scoping document and the re-test confirmation together; they are the first things an auditor, a client’s procurement team or an insurer will ask to see.

White, grey or black box?

These labels describe how much knowledge the testers start with. Black box – nothing, like an outside attacker; realistic but spends budget on discovery. White box – full documentation and credentials; maximum coverage per dollar. Grey box – partial knowledge, such as a standard user login; the pragmatic default for most SME web and network tests, because it simulates a compromised user or leaked password – the most common real-world starting point.

What VAPT costs in Singapore

About the prices below: every figure is a published Singapore market range, given so you can sanity-check a quote and size a budget. They are not Rezolva prices and not a quotation. Actual cost depends on scope, environment size and testing depth, and the only way to get a real number is a scoping call.

These are published Singapore market ranges, pulled 24 September 2026, because scope drives everything. A standalone vulnerability assessment or scan-only package starts from about S$1,500-S$2,000. A web-application penetration test runs about S$3,000-S$9,000 for a small single-role app and S$9,000-S$25,000 for a mid-size authenticated, multi-role application; two Singapore cost guides put the whole web / mobile / API band at S$4,000-S$16,000. A network or infrastructure penetration test starts around S$4,000 for one narrow scope and runs S$12,000-S$35,000 once subnets, Active Directory and lateral movement are in play; one Singapore guide summarises the market as S$5,000-S$30,000 per engagement. On the annual and retest side, a Singapore PTaaS retainer bundling continuous testing and retests is published at S$25,000-S$85,000 a year, while self-serve testing platforms list their plans in US dollars – about US$2,999 a year for automated pentesting and US$5,999 a year once manual testing is included (US dollars as listed, not converted to SGD). Retesting sits outside many published prices, so ask whether it is in scope. Cheap “VAPT” quotes at a few hundred dollars are usually an automated scan with a new cover page – a VA sold as a PT. Ask exactly how many manual testing days are included; that number is the price.

How often should you test?

The working rhythm we recommend: vulnerability scans quarterly (they are cheap and automated), a penetration test annually, and an extra test after any major change – new public-facing app, office move, cloud migration, merger. Between tests, the boring controls do most of the protecting: patching, MFA, backups and monitoring, which is exactly the layer a managed security service keeps running.

Rezolva angle: Rezolva coordinates VAPT for Singapore SMEs as part of our cyber security services – scoping the right test for your compliance driver, engaging accredited testers, then actually fixing the findings and standing the re-test. Most providers hand you a PDF; the value is in the remediation, and that is the part we own.

Frequently asked questions

What is the difference between VA and PT?

A vulnerability assessment (VA) is an automated scan that lists known weaknesses – missing patches, misconfigurations, outdated software – ranked by severity. A penetration test (PT) is a skilled human attempting to exploit weaknesses and chain them into real attack paths, with evidence. VA answers “what looks weak”; PT answers “what can an attacker actually do”. Audits and regulators usually want both: scans regularly, a pentest annually.

How many types of VAPT are there?

Six scopes cover most engagements: external network, internal network, web application, mobile application, cloud configuration, and social engineering. Separately, tests are run white box (full knowledge), grey box (partial, such as a user login) or black box (no knowledge). Most Singapore SMEs start with an external network plus web application test in grey box mode.

Who can do VAPT testing?

Qualified security firms with accredited testers – look for recognised credentials such as CREST accreditation or certifications like OSCP among the testing team, and ask for a sample report before engaging. Independence matters too: the firm that tests should not be marking its own homework, which is why we coordinate testing by accredited third parties and handle the remediation side.

Is VAPT mandatory in Singapore?

It depends who you are. MAS-regulated financial institutions are expected to run regular penetration tests under the TRM Guidelines. Businesses handling card payments must pentest at least annually under PCI DSS. For everyone else it is not named in law, but the PDPA requires reasonable security arrangements for personal data – and VAPT is one of the clearest ways to evidence that, which is why enterprise clients and certifications increasingly demand it.

Which tools are used for VAPT?

Scanning typically uses tools like Nessus, OpenVAS or Qualys; web testing leans on Burp Suite and OWASP ZAP; network mapping on Nmap; exploitation frameworks like Metasploit support the manual phase. But tools are the smaller half – the value of a penetration test is the human who chains individually minor findings into a working attack path no scanner would report.

How long does a VAPT take?

A small external scan can run in a day. A typical SME engagement – external network plus a web application – takes about one to two weeks including reporting, with manual testing spread over several days. Add a few days after remediation for the re-test. The calendar constraint is usually scoping and scheduling, so start the paperwork three to four weeks before you need the report.

About the author

Written by the Rezolva IT team – we scope and coordinate VAPT for Singapore SMEs, then do the part that matters: remediation and the re-test. Compliance references are to MAS TRM Guidelines, PCI DSS and the PDPA as at August 2026; cost figures are Singapore market ballparks.