Somebody has told you that you need a VAPT. Perhaps it was your compliance officer reading an NGX circular, a partner working through its vendor checklist, or a client who will not sign until they see a pentest report. Whatever the case, you now have a budget question, a deadline, and an acronym you may never have unpacked. This post unpacks it for you.
VAPT stands for vulnerability assessment and penetration testing. It is a security exercise with two parts: a vulnerability assessment scans your systems broadly to find and prioritize weaknesses, and a penetration test goes deeper, exploiting those weaknesses the way a real attacker would to prove which ones actually matter to your business.
What each half of VAPT does
The vulnerability assessment covers the breadth of your systems. Scanners and manual review sweep everything in scope, from web applications and APIs to servers and network devices, and produce a catalogue of weaknesses: unpatched software, weak configurations, exposed services, outdated protocols. The output is wide and deliberately shallow: what might be wrong, ranked so you know where to look first.
The penetration test is the depth half. Human testers take the most serious candidates from that catalogue, plus anything the scanners missed, and attempt to exploit them. They chain small weaknesses into full attack paths, and they document what impact they reached with proof of concept. Where the vulnerability assessment says "this port is open and the software is old", the pentest says "we used that access to reach your customer database, and here is the proof".
Neither half is enough alone. A vulnerability assessment without a pentest leaves you a long list of maybes. A pentest without a vulnerability assessment risks going deep on a few paths while an obvious weakness sits unexamined two subnets away. VAPT pairs them so the coverage is broad and the conclusions are proven.
How an engagement actually runs
A VAPT is a structured project with four recognizable phases, and knowing this helps you plan around it.
Scoping comes first. You and the testing firm agree exactly what will be tested: which applications, which IP ranges, which APIs, whether mobile apps are included. You also agree the rules of engagement, the testing window, who to call if something breaks, and the written authorization that makes the whole exercise legal.
Testing follows, usually over one to a few weeks depending on the scope. The assessment work runs first and the manual exploitation builds on it. Reputable firms work to published methodologies, typically PTES for engagement structure, the OWASP Web Security Testing Guide for applications, and NIST SP 800-115 for technical execution, so coverage is systematic.
Reporting turns the work into the document you keep. A good firm walks you through it in a read-out call.
Retest closes the loop. After your team fixes the findings, the testers verify each fix and confirm in the report what is genuinely fixed. Please confirm it is included in your package before you sign.
What you receive at the end
The deliverable is a report, and its quality is how you judge the entire engagement. It should contain an executive summary written for leadership, a methodology and scope section, and findings that each name the affected system, rate severity by business impact, show proof of concept, and give remediation steps your team can act on. After the retest, you receive a report confirming which findings were verified to be fixed. Often, this is the document your regulator cares about.
Not every report clears that bar. Some are padded scanner results with a customized cover page, and it pays to know how a scanner report differs from a real penetration test before you accept the deliverable.
Who needs a VAPT in Nigeria
For some Nigerian organizations, VAPT is a regulatory obligation. For others, it is a customer requirement or a practical check before a system goes live.
- Capital market operators: NGX rules require Trading Licence Holders operating online trading portals to complete a VAPT twice per year, using a recognized VAPT assessor. If that is what brought you here, start with how the NGX half-yearly VAPT requirement works.
- Banks and other financial institutions: CBN's risk-based cybersecurity framework expects regulated institutions to test their defences as part of managing cyber risk, and examiners ask to see the evidence.
- Anyone processing personal data: the NDPA 2023 expects organizations handling Nigerians' personal data to secure it with appropriate measures. A VAPT is one of the clearest ways to demonstrate that those measures hold up under attack.
- Anyone shipping customer-facing systems: if customers log in, pay, or store data on something you built, an attacker will eventually probe it whether a regulator requires testing or not. Testing before launch, and after major changes, is simply cheaper than the incident.
What a VAPT is not
Three misunderstandings cause most bad purchases. First, a VAPT is more than a scan. A firm that runs an automated tool and reformats the output has not done a VAPT for you. If you suspect that is what you were sold last time, the differences are laid out in how to tell whether your pentest was just a vulnerability scan.
Second, a VAPT is different from an audit. An audit reviews your policies and paperwork against a standard; a VAPT attacks your actual systems. You can pass an audit with excellent documentation and still fall to a simple exploit, which is why frameworks tend to ask for both.
Third, a VAPT is a point-in-time exercise. Your systems change with every release, and attackers do not stop between assessments. That is why NGX set a twice-yearly testing requirement for portal operators. Treat the VAPT as a recurring health check, and budget for it that way.
How to buy one well
Once you know you need a VAPT, the remaining risk is buying a bad one. The questions that matter are about people and the proof of work. Ask who will perform the testing; the answer should be named senior penetration testers. Ask which methodology the work follows, whether every finding comes with proof of concept, and whether a retest of fixed findings is included in the price. Ask for a sanitized sample report before you sign, since the report is what you are really buying.
Cost varies with scope: the number of applications and hosts, the depth of testing, and whether mobile or internal infrastructure is included. Be wary of quotes that come before anyone has asked what the scope is. A fuller checklist of questions is written in our guide on choosing a VAPT provider in Nigeria, and the scoping detail sits on our VAPT services page.
- VAPT combines a broad vulnerability assessment with a penetration test that proves impact.
- An engagement moves through scoping, testing and reporting, then closes with a retest after remediation.
- NGX portal operators, institutions under the CBN framework and organizations handling personal data all have reasons to commission one.
- A scan covers only the assessment half, and one VAPT records security at one point in time.
- Before buying, check the named testers, methodology, proof standard and retest terms.