Home / FAQ

FAQ

Straight answers for UK buyers.

CREST, CAF, Cyber Essentials, CMA 1990, invoices, on-site. If it is not here, email pentest@vapt.uk.

Westminster from the Thames. UK buyers, UK law, UK hours.
Westminster from the Thames. UK buyers, UK law, UK hours.
VAPT is a structured attempt to break your systems, prove the holes, and tell you how to close them — before a criminal or a customer’s pentester does. UK organisations commission it for Cyber Essentials Plus, UK GDPR due diligence, ISO 27001, PCI DSS, and enterprise security questionnaires.
Most UK work is remote during GMT/BST hours. On-site scoping, workshops and debriefs can be arranged in London and other major UK cities when the engagement needs it.
We do not currently hold CREST or NCSC CHECK membership, and we will not pretend otherwise. What you get is a manual-first test with CVSS, reproducible proof, ISO 27001 / NCSC CAF mapping, and a free re-test — the packet most UK auditors and procurement teams actually read.
Focused web application: 3–5 working days. Mobile or API: 4–7 days. Cloud or internal network: 1–2 weeks. Dates are agreed on the scoping call before any contract is signed.
A five-minute executive summary, a full technical report (severity, screenshots, exact steps, fix), a free re-test after you patch, and a letter of attestation on request.
Yes. We issue a signed authorisation letter covering the Computer Misuse Act 1990. NDA on request. We only touch what you signed off. After close we delete collected data and retain the report as agreed.
GBP. VAT treatment is confirmed in the statement of work. We do not invent a VAT number on this website; it appears on the invoice.
No. Cyber Essentials (and CE+) is a baseline questionnaire plus technical verification. A pentest is an attacker simulation. UK buyers often need both. See our article on the difference.
Yes, as a mapping — not as a CAF assessment. CAF is an outcome framework for organisations. A pentest produces evidence against some of those outcomes. We say which, and we say which we did not cover.
UK GDPR applies to the engagement file. We process what we must to test and report, under contract. After close we delete collected target data and retain the report as agreed. Details on the privacy page.
If you authorise it, with agreed hours and exclusions. Staging is preferred when it is a true copy. A staging host that is not production is not a production test — we will say so.
Yes. That is a common pattern: you are the contracting party, the UK client is the beneficiary of the letter of attestation. Scope and identities still need the asset owner’s authorisation.

Ready to scope a UK engagement?

A thirty-minute call. Assets, timeline, a quote in pounds sterling.

Request a quote