Skip to content

VAPT Services in Bhutan

eNeoteric delivers VAPT (Vulnerability Assessment and Penetration Testing) services for organisations operating in Bhutan. We have no physical office in Bhutan — engagements are delivered remotely by our India-based team, with on-site coordination available for scoping and kickoff. Testing follows international standards — OWASP methodology and CVSS-scored findings — and is framed to support Bhutan's emerging cybersecurity landscape, including the National Cybersecurity Strategy 2024-2029 and BtCIRT-coordinated incident readiness.

Request Proposal WhatsApp Now
OWASP + CVSS MethodologyBtCIRT-Aware DeliveryFree Re-Test Included8+ Years ExperienceIndia-Based Delivery Team

VAPT for Bhutan's emerging cybersecurity landscape

Bhutan does not currently have a standalone, comprehensive data protection statute equivalent to GDPR. Privacy-related coverage comes from the Information, Communications and Media Act (ICMA) 2018 — described by outside observers as providing only a minimal privacy framework — and the more recent National Digital Identity (NDI) Act, 2023 (targeted for full implementation from January 2025), which governs digital identity specifically rather than data protection broadly. The ICMA also established the Bhutan InfoComm and Media Authority (BICMA), which holds limited investigative and dispute-resolution powers.

There is no single, consolidated Cyber Security Act in Bhutan. Relevant provisions are spread across the ICMA 2018 — which added a dedicated Cybersecurity Chapter empowering the Bhutan Computer Incident Response Team (BtCIRT) — and a separate Computer Crime Act. Bhutan's National Cybersecurity Strategy (NCS) 2024-2029, driven by a dedicated Cybersecurity Division within the Government Technology Agency (GovTech), signals the direction Bhutan is moving toward a more structured national cybersecurity posture, even as the formal regulatory and testing-mandate framework is still developing.

In the financial sector, the Royal Monetary Authority of Bhutan (RMA) has published documents titled "Cybersecurity Directives for Banks" and "Guidelines on Data Privacy and Data Protection 2021." We confirmed these documents exist; we were not able to independently verify their specific technical testing requirements. Organisations should confirm specific technical testing requirements directly with RMA or their compliance advisor — we align our methodology to general international good practice (OWASP, CVSS) in the absence of a confirmed local technical mandate.

Why Bhutan organisations choose eNeoteric

Frequently asked questions

Does Bhutan legally require penetration testing?
We could not confirm any specific law in Bhutan that legally mandates penetration testing for organisations generally. In the financial sector, the Royal Monetary Authority of Bhutan (RMA) has published documents titled "Cybersecurity Directives for Banks" and "Guidelines on Data Privacy and Data Protection 2021" — these documents exist, but we were unable to independently verify whether they specify a technical testing requirement. If you are RMA-regulated, we recommend confirming exact obligations directly with RMA or your compliance advisor. Regardless of a confirmed local mandate, eNeoteric tests to international standards (OWASP, CVSS) as a matter of practice.
How does eNeoteric coordinate with BtCIRT?
The Bhutan Computer Incident Response Team (BtCIRT), established in 2016 and operating under the Government Technology Agency (GovTech), is Bhutan's national CERT. We structure our VAPT reports — findings, severity ratings, proof-of-concept evidence — in a format that supports coordination with BtCIRT if an incident response scenario arises. We are not affiliated with BtCIRT and do not submit reports on your behalf.
How does VAPT support Bhutan's National Cybersecurity Strategy 2024-2029?
The National Cybersecurity Strategy 2024-2029, driven by GovTech's Cybersecurity Division, signals Bhutan's direction toward a more structured national cybersecurity posture. Regular, methodical VAPT — even ahead of any formal enforcement mechanism — helps organisations get ahead of that direction by identifying and remediating vulnerabilities using the same internationally recognised methodology (OWASP, CVSS) that underpins most modern national strategies.
Does eNeoteric have an office in Bhutan?
No. We do not have a physical office in Bhutan. Engagements are delivered remotely by our India-based team, with on-site coordination available for kickoff, scoping, or workshop sessions where needed.
How long does a typical VAPT engagement take for a Bhutan-based organisation?
Most single-application or network engagements run 7-12 business days from kickoff to draft report, delivered remotely, depending on scope. Contact us with your requirements for an exact timeline.

Have more questions?

Book Free Consultation

Explore related VAPT services

All Penetration Testing  VAPT Vendor Comparison  View all Cybersecurity

Request Proposal  WhatsApp Now

Bhutan VAPT Pricing

Transparent, scope-based pricing — know your investment before you start.

Financial Sector
Financial Sector Cybersecurity Readiness Assessment
Custom / scoped assessment
Structured assessment to support your internal RMA compliance review — confirm specific technical requirements with RMA directly.
  • Readiness gap assessment
  • OWASP/CVSS-based testing
  • Compliance-facing report structure

* All prices are indicative in USD and vary by scope and system count. Contact us for a fixed-price proposal.

Get exact quote →  WhatsApp for pricing

Request a Callback

Drop your details and we'll call you back within one business day — or reach us directly on +91 91080 15170.

💬 Chat on WhatsApp instead