October 10, 2026
Breadth Finds the Forgotten Server, Depth Finds the Breach: What VAPT Actually Buys
How a vulnerability scan and a penetration test differ, when you need each, and how to spot a scan being sold at test prices

By Invadel
4 min read
A buyer sent me two "VAPT" proposals last quarter and asked why one was a quarter the price of the other. The cheap one, read closely, was a subscription scanner with a report template. The expensive one was that same scan plus a person spending a week trying to break in. Both used the same four letters on the cover.
That is where most of the confusion around VAPT lives. The acronym stands for Vulnerability Assessment and Penetration Testing, and it bundles two genuinely different activities. Treat them as one thing, and you end up buying one while believing you bought the other.
So here is how I separate the two halves for clients: what each one actually does, what a real combined engagement looks like, what the pieces cost, and how to tell when a bargain is not a bargain.
What the two halves actually do
A vulnerability assessment is about breadth. Automated tooling walks your systems and reports known weaknesses: missing patches, outdated software versions, weak TLS settings, default credentials, published CVEs. It is fast, repeatable, cheap enough to run continuously, and it hands you a long list ranked by severity score.
A penetration test is about depth. A human tester tries to exploit what exists, chains findings together, and proves impact. It surfaces the flaws no scanner detects: broken access control between user roles, business logic that lets someone skip a payment step, an authorization gap that exposes another tenant's data.
I put the distinction in one line for people who are new to it. A vulnerability assessment tells you what might be wrong. A penetration test proves what an attacker could actually do. The practical differences follow from that:
- Goal: the assessment finds known weaknesses across everything in scope; the test proves what an attacker can reach.
- Method: automated scanning versus human-led exploitation.
- Coverage: broad, every known CVE, versus focused on real attack paths.
- Output: a ranked list of findings versus proven exploit chains with impact.
- False positives: common in a raw scan, validated out in a test.
- Logic flaws: a scanner misses them; a tester is the only one who finds them.
- Cadence: scanning runs continuous or monthly; testing runs annual or per release.
Why the industry bundles them under one acronym
Because a mature program needs both, and they answer different questions. The scan gives you coverage across everything you own, catching the unpatched server nobody remembered. The test gives you truth about the systems that matter, catching the flaw that would actually cause a breach.
Run only scanning and you get a comfortable, incomplete picture: hundreds of medium-severity findings and no idea which of them combine into a critical one. Run only an annual test and you are blind for the other fifty-one weeks while your patch levels quietly drift.
For most organizations the sensible pattern is a layered one. Continuous or quarterly scanning across the whole estate for breadth and drift detection. Annual, or per-release, penetration testing on the systems that hold real risk. And a retest after remediation to confirm the fixes actually held.
What a real combined engagement runs through
A well-scoped VAPT engagement moves through four phases, and the order matters.
- Reconnaissance and asset discovery. Establish what actually exists: the assets you know about, plus the ones you forgot. Shadow IT and abandoned subdomains turn up here.
- Automated vulnerability assessment. Authenticated and unauthenticated scanning across in-scope hosts and applications, producing the breadth layer.
- Manual penetration testing. Testers confirm which scanner findings are real, then go after what scanners cannot see: authorization boundaries, business logic, chained privilege escalation, and the routes between systems.
- Reporting and retest. An executive summary for decision-makers, technical detail with reproduction steps for engineers, findings ranked by genuine business impact rather than raw CVSS, and a verification pass once fixes land.
Scope usually spans web applications and APIs, external and internal network infrastructure, cloud configuration, and, where relevant, mobile applications and wireless.
What the two halves cost, and why the gap matters
Pricing tracks scope and depth, and the two halves are priced on entirely different models. Scanning is cheap and often subscription-based: a flat rate per scan or per asset. Testing is priced on tester time against a defined scope. Here is what we publish:
- Vulnerability scan or assessment: from $1,500 for up to 250 devices, $2,500 for up to 1,000; larger estates quoted.
- API penetration test: from $4,000, set by endpoints and roles.
- External network penetration test: from $4,200, set by live internet-facing hosts.
- Web application penetration test: from $5,200, set by roles and application size.
- Internal network penetration test: from $6,000, set by hosts, sites and domains.
Every penetration test price is fixed in writing before work begins, and includes a free retest of remediated findings. Quarterly or monthly scanning runs as a recurring program at those same per-scan prices.
That cost gap is exactly where buyers get taken. A "VAPT" quote dramatically below market is almost always scanning with a report template, sold at penetration-testing prices. Before you compare two numbers, ask what proportion of the engagement is manual and who performs it. That single question tells you which product you are actually buying.
What compliance frameworks expect
Most frameworks expect both halves, even though they rarely use the acronym.
- PCI DSS is the most explicit. Requirement 11.3 mandates quarterly vulnerability scanning, with external scans run by an ASV, and Requirement 11.4 mandates annual penetration testing, including segmentation testing.
- ISO 27001 expects technical vulnerability management under Annex A 8.8 plus evidence that controls are effective. Scanning satisfies the former, testing the latter.
- SOC 2 auditors look for a documented vulnerability management process alongside independent testing of the systems in your boundary.
- HIPAA requires a risk analysis and periodic technical evaluation under 164.312; scanning plus testing is how organizations evidence both.
How to decide what you need
Start with vulnerability scanning if you have no current visibility, a large or unmapped estate, or an immediate compliance deadline for quarterly scans. It is the cheapest way to find the obvious problems fast.
Go straight to penetration testing if you have a specific high-value application, an enterprise customer or auditor demanding independent testing, or you already scan and keep surfacing the same low-severity noise.
Buy both as a program if you hold sensitive data at scale, operate under PCI DSS or a similar regime, or have reached the point where "we scanned it" no longer satisfies the people asking the question.
The short version
- VAPT is not a product. It is the combination of breadth (automated assessment) and depth (human testing).
- Scanning tells you what might be wrong; a test proves what an attacker could reach.
- A VAPT quote with no manual testing is a vulnerability assessment wearing a different label.
- Scanning keeps you honest month to month; testing tells you what a breach would actually cost you.
- The value comes from running both deliberately, not from buying one and assuming it covers the other.
This article is based on Invadel's guide "Vulnerability Assessment and Penetration Testing (VAPT)": https://invadel.com/blog/vulnerability-assessment-and-penetration-testing-vapt/ โ read it for the full detail. Mark Kiss is the founder of Invadel, a penetration-testing firm โ https://invadel.com/ has the services and fixed prices.