Onwyn › Standards › VAPT / Security Testing

Scheme / framework · 2026

VAPT / Security Testing

A practical security-testing checklist for EU-facing products: define the scope and authorization, confirm the attack surface, test safely, capture evidence, rate the findings, track remediation, and retest before closeout. It is written to support the kind of consultant-led VAPT work that sits alongside ISO 27001 and other EU security obligations.

7
Requirements
5
Areas
0
Recommended documents
0
Mapped frameworks
Start VAPT / Security Testing free Have us do it instead

What this standard asks for

Every requirement in VAPT / Security Testing, grouped the way the standard groups them. In the Semantic Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

Scope & authorization

1 requirement

  • VAPT-01Written authorization and scope

Assets & attack surface

1 requirement

  • VAPT-02Current asset and exposure list

Test execution

2 requirements

  • VAPT-03Rules of engagement and safe testing window
  • VAPT-04Authenticated and unauthenticated passes

Reporting & remediation

2 requirements

  • VAPT-05Evidence capture and severity rationale
  • VAPT-06Remediation owner and due date

Retest & closeout

1 requirement

  • VAPT-07Retest and closeout

Start VAPT / Security Testing today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.