If you have been asked for a “VAPT report” by a client, auditor or regulator and quietly wondered what is VAPT exactly – this guide is for you. It explains the two tests, who needs them in Singapore, what an engagement looks like, and what it costs, without the vendor fog.
VA and PT are two different tests
Bundling them under one acronym hides how different they are. Buying a VA when your auditor wants a PT is an expensive way to fail an audit, so here is the split:
| Factor | Vulnerability Assessment (VA) | Penetration Test (PT) |
|---|---|---|
| Method | Automated scanning | Manual, human-led exploitation |
| Question answered | What looks vulnerable? | What can an attacker actually do? |
| Output | List of findings by severity | Proven attack paths + evidence |
| Depth | Broad and shallow | Narrow and deep |
| Typical frequency | Quarterly or monthly | Annually + after major changes |
| Relative cost | Lower | Higher (skilled hours) |
Penetration testing Singapore: who actually needs it
The penetration testing Singapore market is shaped by four compliance drivers, and knowing which applies to you decides the scope you should buy:
- MAS-regulated firms – the MAS Technology Risk Management Guidelines expect financial institutions to conduct penetration testing on internet-facing systems regularly (annually is the accepted baseline) and to remediate findings.
- Anyone handling card payments – PCI DSS requires penetration testing at least annually and after significant changes to systems in scope of cardholder data.
- Every business holding personal data – the PDPA obliges organisations to make reasonable security arrangements to protect personal data; VAPT is one of the clearest ways to demonstrate that duty was taken seriously.
- Certification and customers – CSA’s Cyber Essentials and Cyber Trust marks, ISO 27001, and increasingly enterprise procurement teams all ask for evidence of security testing before signing.
The six common VAPT scopes
- External network – what an attacker on the internet can reach: firewalls, VPN gateways, exposed services.
- Internal network – what an attacker (or rogue laptop) already inside the office can reach.
- Web applications – your website, portals and APIs, tested against injection, broken authentication and the rest of the OWASP Top 10. OWASP publishes the OWASP Top 10 as the reference standard for the most critical web application security risks.
- Mobile applications – the app plus the backend it talks to.
- Cloud configuration – misconfigured storage buckets, over-broad IAM permissions, exposed management consoles.
- Social engineering – phishing simulations against staff, usually paired with awareness training.
How a VAPT engagement runs
- Scoping – agree targets, test window, and rules of engagement in writing. This protects both sides.
- Reconnaissance and scanning – the VA phase: automated discovery of hosts, services and known weaknesses.
- Manual exploitation – the PT phase: testers chain findings into real attack paths, capturing evidence at each step.
- Reporting – findings ranked by severity (typically CVSS scores), each with reproduction steps and a concrete fix. NIST’s vulnerability metrics guidance explains how CVSS produces a numerical score and a qualitative severity rating.
- Remediation – your team or your IT provider closes the gaps, worst first.
- Re-test – the testers verify the fixes actually closed the paths. A report without a re-test is half a report.
You can test a proposal against this sequence before you sign it. Ask for the scope in writing, with named targets and a test window, and check that the report will rank findings by severity with reproduction steps and a fix for each, not just a scanner export. Then look for the re-test: if it is missing, or priced as an optional extra, the engagement ends at the report and you are left to confirm your own fixes. If someone asks what is VAPT in practice, the honest answer is these six steps run in order, not a tool name. Keep the scoping document and the re-test confirmation together; they are the first things an auditor, a client’s procurement team or an insurer will ask to see.
White, grey or black box?
These labels describe how much knowledge the testers start with. Black box – nothing, like an outside attacker; realistic but spends budget on discovery. White box – full documentation and credentials; maximum coverage per dollar. Grey box – partial knowledge, such as a standard user login; the pragmatic default for most SME web and network tests, because it simulates a compromised user or leaked password – the most common real-world starting point.
What VAPT costs in Singapore
These are published Singapore market ranges, pulled 24 September 2026, because scope drives everything. A standalone vulnerability assessment or scan-only package starts from about S$1,500-S$2,000. A web-application penetration test runs about S$3,000-S$9,000 for a small single-role app and S$9,000-S$25,000 for a mid-size authenticated, multi-role application; two Singapore cost guides put the whole web / mobile / API band at S$4,000-S$16,000. A network or infrastructure penetration test starts around S$4,000 for one narrow scope and runs S$12,000-S$35,000 once subnets, Active Directory and lateral movement are in play; one Singapore guide summarises the market as S$5,000-S$30,000 per engagement. On the annual and retest side, a Singapore PTaaS retainer bundling continuous testing and retests is published at S$25,000-S$85,000 a year, while self-serve testing platforms list their plans in US dollars – about US$2,999 a year for automated pentesting and US$5,999 a year once manual testing is included (US dollars as listed, not converted to SGD). Retesting sits outside many published prices, so ask whether it is in scope. Cheap “VAPT” quotes at a few hundred dollars are usually an automated scan with a new cover page – a VA sold as a PT. Ask exactly how many manual testing days are included; that number is the price.
How often should you test?
The working rhythm we recommend: vulnerability scans quarterly (they are cheap and automated), a penetration test annually, and an extra test after any major change – new public-facing app, office move, cloud migration, merger. Between tests, the boring controls do most of the protecting: patching, MFA, backups and monitoring, which is exactly the layer a managed security service keeps running.
Frequently asked questions
What is the difference between VA and PT?
A vulnerability assessment (VA) is an automated scan that lists known weaknesses – missing patches, misconfigurations, outdated software – ranked by severity. A penetration test (PT) is a skilled human attempting to exploit weaknesses and chain them into real attack paths, with evidence. VA answers “what looks weak”; PT answers “what can an attacker actually do”. Audits and regulators usually want both: scans regularly, a pentest annually.
How many types of VAPT are there?
Six scopes cover most engagements: external network, internal network, web application, mobile application, cloud configuration, and social engineering. Separately, tests are run white box (full knowledge), grey box (partial, such as a user login) or black box (no knowledge). Most Singapore SMEs start with an external network plus web application test in grey box mode.
Who can do VAPT testing?
Qualified security firms with accredited testers – look for recognised credentials such as CREST accreditation or certifications like OSCP among the testing team, and ask for a sample report before engaging. Independence matters too: the firm that tests should not be marking its own homework, which is why we coordinate testing by accredited third parties and handle the remediation side.
Is VAPT mandatory in Singapore?
It depends who you are. MAS-regulated financial institutions are expected to run regular penetration tests under the TRM Guidelines. Businesses handling card payments must pentest at least annually under PCI DSS. For everyone else it is not named in law, but the PDPA requires reasonable security arrangements for personal data – and VAPT is one of the clearest ways to evidence that, which is why enterprise clients and certifications increasingly demand it.
Which tools are used for VAPT?
Scanning typically uses tools like Nessus, OpenVAS or Qualys; web testing leans on Burp Suite and OWASP ZAP; network mapping on Nmap; exploitation frameworks like Metasploit support the manual phase. But tools are the smaller half – the value of a penetration test is the human who chains individually minor findings into a working attack path no scanner would report.
How long does a VAPT take?
A small external scan can run in a day. A typical SME engagement – external network plus a web application – takes about one to two weeks including reporting, with manual testing spread over several days. Add a few days after remediation for the re-test. The calendar constraint is usually scoping and scheduling, so start the paperwork three to four weeks before you need the report.
About the author
Written by the Rezolva IT team – we scope and coordinate VAPT for Singapore SMEs, then do the part that matters: remediation and the re-test. Compliance references are to MAS TRM Guidelines, PCI DSS and the PDPA as at August 2026; cost figures are Singapore market ballparks.