
Businesses often ask for one simple answer: “How many times a year should we do VAPT?” The professional answer is more useful than a fixed number. Test often enough to find meaningful weaknesses before attackers do, and test again whenever a change materially alters your exposure.
For many stable organisations, an annual independent penetration test supported by regular vulnerability scanning is a sensible baseline. Faster-moving applications, payment environments and high-impact services usually need additional assessments after significant changes.
A practical VAPT schedule
| Situation | Practical approach | Why it matters |
|---|---|---|
| Stable public website or business system | Risk-based annual VAPT, with regular vulnerability scans | Provides a repeatable independent baseline |
| Major release, new API or authentication change | Test before launch or immediately after deployment | Material changes create new attack paths |
| Cloud migration or network redesign | Assess the new architecture and exposed configuration | Security assumptions change with infrastructure |
| Important findings were remediated | Focused retest | Confirms fixes work and closes evidence gaps |
| Payment-card environment | Follow current PCI DSS annual and post-significant-change requirements | PCI-scoped systems have explicit testing obligations |
| Rapidly changing or high-impact platform | More frequent testing, supported by continuous security checks | Risk changes faster than a yearly cycle |
This table is a planning guide, not a claim that every Nepal business has the same legal requirement. Your scope should reflect contracts, sector rules, customer commitments and the consequences of a successful attack.
Seven events that should trigger a new test
- A major application release: new workflows, code and integrations can create vulnerabilities that did not exist during the previous test.
- Authentication or access changes: single sign-on, MFA, role design and password-reset flows deserve focused testing.
- A new public API or mobile application: new interfaces expand the attack surface and can expose sensitive data.
- Cloud migration or infrastructure redesign: permissions, storage, gateways and network boundaries need fresh validation.
- A merger, vendor integration or acquisition: trust relationships can connect previously separate environments.
- A serious incident or emerging attack pattern: testing can validate whether similar weaknesses remain elsewhere.
- Remediation of important findings: a retest turns “we changed it” into evidence that the weakness is no longer exploitable.
Vulnerability scanning and penetration testing are complementary
Automated vulnerability scanning is valuable because it can run frequently and identify missing patches, outdated components and common configuration issues. It does not replace human-led penetration testing.
A professional penetration test validates exploitability, connects weaknesses into realistic attack paths and explains business impact. The strongest programme uses regular scanning for coverage and periodic authorised testing for depth.
Scope matters more than the headline frequency
A yearly test of one marketing website does not provide assurance for an untested customer portal, API, VPN, cloud environment or internal network. Build an asset inventory, identify critical data flows and rotate deeper assessments where the business impact is highest.
Target domains and IP ranges, applications and APIs, user roles, environments, testing constraints, sensitive data, third-party dependencies and the business outcome you need from the assessment.
Nepal business and regulatory context
Nepal Rastra Bank’s IT guidance expects regulated institutions to assess technology risk, conduct periodic penetration testing and maintain independent audit practices. The exact scope and timing should be confirmed against the rules, directives and contractual duties applicable to your organisation.
Businesses outside regulated sectors still benefit from a documented, risk-based testing cycle—especially when customers, investors or enterprise partners request assurance before sharing data or integrating systems.
What a professional VAPT engagement should include
- Written authorisation, clear rules of engagement and safe testing windows.
- Manual testing appropriate to the target, not only an automated scanner export.
- Risk-ranked findings with evidence, affected assets and practical remediation guidance.
- A management summary that connects technical issues to business impact.
- A defined retest process for important fixes.
- Secure handling and deletion of assessment evidence.
Frequently asked questions
Is annual VAPT enough?
It can be a reasonable baseline for a stable, moderate-risk environment. Test again after significant changes and support the annual assessment with regular scanning and secure development checks.
Should VAPT be repeated after remediation?
Yes. A focused retest should verify the fix on the affected asset and confirm that the issue is no longer practically exploitable.
Does every Nepal company legally need annual VAPT?
No universal rule applies equally to every organisation. Requirements depend on sector, payment-card scope, contracts, regulators and risk. Treat annual testing as a common planning baseline, not universal legal advice.
Scope the right assessment for your environment.
Innomerc Tech provides authorised testing for web applications, APIs, networks, cloud and infrastructure, with practical remediation and retesting support.
