+91 98804 42758

Types of VAPT Testing Explained

Scope and methodology are two separate decisions. Here's how each one actually works

Sudhakar Varma Delivery Head, Avantcert
August 13, 2026 8 min read

The Short Answer

VAPT testing types split along two independent axes: scope (what's being tested) and methodology (how much access the tester starts with). Every engagement needs both decided separately, they aren't alternatives to each other. See our VAPT service guide or our VAPT cost breakdown by scope.


Testing Scope: What's Being Tested

  • Web application testing — the application itself: authentication, authorization, input handling, business logic, against methodologies like OWASP Top 10.
  • Mobile application testing — iOS and Android-specific risks: insecure local storage, certificate pinning, reverse engineering exposure, alongside API calls the app makes.
  • External network testing — internet-facing infrastructure, what an outside attacker could reach without any internal access.
  • Internal network testing — what an attacker (or compromised insider) could do once already inside the network perimeter.
  • API testing — the API layer specifically, authentication, authorization, rate limiting, data exposure, increasingly its own dedicated scope as applications go API-first.
  • Cloud configuration testing — how AWS, Azure, or GCP services are configured: IAM permissions, storage access, security group rules.
  • Wireless testing — Wi-Fi network security, relevant mainly to organizations with a physical office footprint.

Testing Methodology: How Much Access the Tester Starts With

  • Black-box testing — the tester starts with no internal information, mimicking an external attacker with zero prior access. Most realistic, but the reconnaissance phase costs time.
  • Grey-box testing — the tester starts with limited information, typically a standard user account, testing from a position closer to what a real attacker often achieves after initial access. The practical standard for most compliance-driven engagements.
  • White-box testing — the tester has full access, including source code and architecture documentation, enabling the deepest possible review, often faster since no time is spent on reconnaissance.

A "web application, grey-box" engagement and a "web application, black-box" engagement test the same scope with different starting assumptions, and typically produce different cost and timeline profiles even for an identical application.

Not sure which scope and methodology fit your situation?

We'll scope the right combination based on what's actually exposed, not a generic checklist.

Get a Free Quote

Where Most SaaS Companies Should Start

Web application testing is the natural starting point for most SaaS companies, since that's typically where the product and customer data actually live. API testing is a close second if the application exposes significant API surface beyond the web client itself. Network testing matters more for organizations running substantial self-managed infrastructure than for fully cloud-native companies on managed services, where cloud configuration review is often the more relevant scope.

Compliance Frameworks Rarely Mandate a Specific Type

Most frameworks that require VAPT, PCI DSS and ISO 27001 among them, require regular testing without specifying exact scope or methodology, leaving that judgment to a risk-based assessment of what's actually exposed. This is exactly where an under-scoped test can technically check a compliance box while missing the risk that actually matters, testing a marketing site thoroughly while leaving the customer-data-handling API untested, for example.

Ready to scope the right combination of tests?

We've guided organisations across 40+ markets through risk-appropriate VAPT scoping.

Talk to an Avantcert Expert

Frequently asked questions about VAPT testing types

What's the difference between scope and methodology in VAPT testing?

Scope is what's being tested, a web application, a network, an API. Methodology is how much information the tester starts with, black-box, grey-box, or white-box. Every engagement needs both decided: a scope choice and a methodology choice, they're independent variables, not alternatives to each other.

Which testing scope should a typical SaaS company start with?

Web application testing, since that's usually where the actual product and customer data live. API testing is a close second if the application exposes a significant API surface. Network testing matters more for companies running substantial self-managed infrastructure rather than a fully cloud-native, managed-service stack.

Is grey-box testing a compromise, or is it actually the standard approach?

For most compliance-driven engagements, grey-box is the practical standard. It gives testers enough context, typically a standard user account, to test efficiently without the unrealistic time cost of pure black-box reconnaissance, while still testing from something close to a real attacker's starting position.

Do compliance frameworks specify which VAPT type is required?

Rarely with precision. Most frameworks, including PCI DSS and ISO 27001, require regular testing without mandating a specific scope or methodology, leaving the choice to a risk-based judgment about what's actually exposed. This is where working with an experienced provider matters, since an under-scoped test can technically satisfy a checkbox while missing real risk.

What is cloud configuration testing, and is it different from network testing?

Yes, meaningfully different. Cloud configuration testing reviews how cloud services like AWS, Azure, or GCP are configured, IAM permissions, storage bucket access, security group rules, rather than testing network perimeter defenses the way traditional network testing does. Misconfigurations, not exploitable network vulnerabilities, are usually the bigger risk in cloud-native environments.

Should a company test its mobile app separately from its web app if they share a backend?

Generally yes. Mobile apps introduce testing surface that a web app doesn't, insecure local storage, certificate pinning, reverse engineering risk, even when both clients hit the same API. A shared backend can sometimes be tested once via the API layer, but client-specific risks still need their own attention.

About Avantcert. Avantcert is a compliance consultancy that has guided 3,000+ organisations across 40+ markets through risk-appropriate VAPT scoping and testing. See our VAPT service or request a free quote.

Ready to get certified?

Join 3,000+ organizations that trust Avantcert. Get a free, scoped quote today.