Penetration Testing / Bhutan
VAPT Services in Bhutan
eNeoteric delivers VAPT (Vulnerability Assessment and Penetration Testing) services for organisations operating in Bhutan. We have no physical office in Bhutan — engagements are delivered remotely by our India-based team, with on-site coordination available for scoping and kickoff. Testing follows international standards — OWASP methodology and CVSS-scored findings — and is framed to support Bhutan's emerging cybersecurity landscape, including the National Cybersecurity Strategy 2024-2029 and BtCIRT-coordinated incident readiness.
VAPT for Bhutan's emerging cybersecurity landscape
Bhutan does not currently have a standalone, comprehensive data protection statute equivalent to GDPR. Privacy-related coverage comes from the Information, Communications and Media Act (ICMA) 2018 — described by outside observers as providing only a minimal privacy framework — and the more recent National Digital Identity (NDI) Act, 2023 (targeted for full implementation from January 2025), which governs digital identity specifically rather than data protection broadly. The ICMA also established the Bhutan InfoComm and Media Authority (BICMA), which holds limited investigative and dispute-resolution powers.
There is no single, consolidated Cyber Security Act in Bhutan. Relevant provisions are spread across the ICMA 2018 — which added a dedicated Cybersecurity Chapter empowering the Bhutan Computer Incident Response Team (BtCIRT) — and a separate Computer Crime Act. Bhutan's National Cybersecurity Strategy (NCS) 2024-2029, driven by a dedicated Cybersecurity Division within the Government Technology Agency (GovTech), signals the direction Bhutan is moving toward a more structured national cybersecurity posture, even as the formal regulatory and testing-mandate framework is still developing.
In the financial sector, the Royal Monetary Authority of Bhutan (RMA) has published documents titled "Cybersecurity Directives for Banks" and "Guidelines on Data Privacy and Data Protection 2021." We confirmed these documents exist; we were not able to independently verify their specific technical testing requirements. Organisations should confirm specific technical testing requirements directly with RMA or their compliance advisor — we align our methodology to general international good practice (OWASP, CVSS) in the absence of a confirmed local technical mandate.
- International-standard methodology — OWASP testing methodology and CVSS-scored findings, applied consistently regardless of any specific local mandate.
- BtCIRT-aware delivery — Reporting structured to be useful for coordination with Bhutan's national CERT, BtCIRT, should an incident occur.
- Aligned to national direction — Testing scope and reporting reflect the priorities signalled by Bhutan's National Cybersecurity Strategy 2024-2029.
- Full VAPT scope — Network infrastructure, web applications, mobile apps, and APIs, following the same methodology detailed on our penetration testing services page.
- Remote delivery, India-based team — No physical office in Bhutan; engagements are delivered remotely, with on-site coordination available where needed.
Why Bhutan organisations choose eNeoteric
- Methodology rigor — Structured OWASP and CVSS-based testing regardless of whether a specific local mandate applies to your organisation.
- Certified engineers — OSCP, CEH, and OSWE certified testers with regional experience across South Asia.
- Honest, cautious reporting — We do not overstate Bhutan's regulatory requirements; findings and framing are accurate and defensible for board and auditor review.
- Clean, structured reports — CVSS-scored findings, proof-of-concept evidence, and remediation guidance suitable for internal governance and, where relevant, RMA-facing documentation.
- Re-test included — A complimentary re-test verifies every finding has been remediated.
Frequently asked questions
- Does Bhutan legally require penetration testing?
- We could not confirm any specific law in Bhutan that legally mandates penetration testing for organisations generally. In the financial sector, the Royal Monetary Authority of Bhutan (RMA) has published documents titled "Cybersecurity Directives for Banks" and "Guidelines on Data Privacy and Data Protection 2021" — these documents exist, but we were unable to independently verify whether they specify a technical testing requirement. If you are RMA-regulated, we recommend confirming exact obligations directly with RMA or your compliance advisor. Regardless of a confirmed local mandate, eNeoteric tests to international standards (OWASP, CVSS) as a matter of practice.
- How does eNeoteric coordinate with BtCIRT?
- The Bhutan Computer Incident Response Team (BtCIRT), established in 2016 and operating under the Government Technology Agency (GovTech), is Bhutan's national CERT. We structure our VAPT reports — findings, severity ratings, proof-of-concept evidence — in a format that supports coordination with BtCIRT if an incident response scenario arises. We are not affiliated with BtCIRT and do not submit reports on your behalf.
- How does VAPT support Bhutan's National Cybersecurity Strategy 2024-2029?
- The National Cybersecurity Strategy 2024-2029, driven by GovTech's Cybersecurity Division, signals Bhutan's direction toward a more structured national cybersecurity posture. Regular, methodical VAPT — even ahead of any formal enforcement mechanism — helps organisations get ahead of that direction by identifying and remediating vulnerabilities using the same internationally recognised methodology (OWASP, CVSS) that underpins most modern national strategies.
- Does eNeoteric have an office in Bhutan?
- No. We do not have a physical office in Bhutan. Engagements are delivered remotely by our India-based team, with on-site coordination available for kickoff, scoping, or workshop sessions where needed.
- How long does a typical VAPT engagement take for a Bhutan-based organisation?
- Most single-application or network engagements run 7-12 business days from kickoff to draft report, delivered remotely, depending on scope. Contact us with your requirements for an exact timeline.
Have more questions?
Book Free ConsultationExplore related VAPT services
All Penetration Testing VAPT Vendor Comparison View all Cybersecurity
Bhutan VAPT Pricing
Transparent, scope-based pricing — know your investment before you start.
- Network + web app VAPT
- OWASP-aligned methodology
- CVSS-scored findings
- Complimentary re-test
- Readiness gap assessment
- OWASP/CVSS-based testing
- Compliance-facing report structure
* All prices are indicative in USD and vary by scope and system count. Contact us for a fixed-price proposal.
Get in touch
Request a Callback
Drop your details and we'll call you back within one business day — or reach us directly on +91 91080 15170.