Skip to content

VAPT Services in Maldives

eNeoteric delivers VAPT (Vulnerability Assessment and Penetration Testing) services for organisations in the Maldives, with engagements scoped to the Cyber Security Act 2023 (Act 17/2023) and the National Cyber Security Agency (NCSA)'s Essential Eight-based National Baseline Cybersecurity Framework. Delivered remotely by our India-based team, with on-site coordination available for Critical Information Infrastructure (CII) organisations in banking, telecom, energy, and transport.

Request Proposal WhatsApp Now
Cyber Security Act 2023-AlignedEssential Eight Baseline TestingCII Sector ExperienceFree Re-Test IncludedIndia-Based Delivery Team

VAPT for the Maldives' Cyber Security Act 2023

The Cyber Security Act (Act 17/2023) came into effect on 14 November 2023, establishing the Maldives' first national cybersecurity framework. The Act designates Critical Information Infrastructure (CII) operators — explicitly including telecom, banking, energy, and transport — as subject to formal cybersecurity obligations, enforced by the National Cyber Security Agency (NCSA), established under a Presidential Directive on 18 March 2024. NCSA also runs a National Cyber Security Strategy 2024–2029 and a National Baseline Cybersecurity Framework built on the "Essential Eight" model — a well-known best-practice framework whose mitigation strategies include patching, application control, and regular security testing. We scope our VAPT engagements to produce evidence directly usable against this baseline.

On banking specifically: the Cyber Security Act 2023 designates banking as CII requiring formal cybersecurity measures under NCSA oversight. Our research did not turn up a published Maldives Monetary Authority (MMA)-specific IT security or penetration-testing mandate for banks or NBFIs — this appears to be a genuine gap rather than something we've overlooked. Rather than claim a specific named MMA requirement we couldn't verify, we align engagements to the Act's CII obligations and NCSA's Essential Eight-based baseline framework.

On data protection: the Maldives does not yet have a comprehensive data protection law in force. Only a constitutional right to privacy applies today — Article 24 of the Constitution of the Maldives (2008) guarantees "respect for private and family life, home and private communications." A Privacy and Personal Data Protection Bill was released for public consultation in May 2023 and has since been submitted to Parliament, but it remains pending — not yet enacted law. We won't scope an engagement against a statute that doesn't exist; our reports are structured so the technical evidence they contain will still hold up once the Bill is passed.

Why Maldives organisations choose eNeoteric

Frequently asked questions

Does the Maldives have a data protection law?
Not yet. The Maldives does not currently have a comprehensive data protection law in force. Only a constitutional right to privacy applies — Article 24 of the Constitution of the Maldives (2008) — which covers "respect for private and family life, home and private communications." A Privacy and Personal Data Protection Bill was released for public consultation in May 2023 and has been submitted to Parliament, but it remains pending and has not been enacted. We flag this honestly rather than scoping an engagement against a law that doesn't yet exist.
Is penetration testing required for banks in the Maldives?
The Cyber Security Act 2023 designates banking as Critical Information Infrastructure (CII), requiring formal cybersecurity measures under National Cyber Security Agency (NCSA) oversight. During our research we did not find a separate, published Maldives Monetary Authority (MMA)-specific penetration-testing mandate for banks or NBFIs — so rather than claim a specific named requirement we can't verify, we align engagements to the Act's CII obligations and NCSA's Essential Eight-based baseline framework, which explicitly includes regular security testing as a mitigation strategy.
What is the Essential Eight framework, and how does it apply to VAPT?
The Essential Eight is a well-known cybersecurity best-practice framework covering mitigation strategies such as patching, application control, restricting administrative privileges, and regular security testing. NCSA's National Baseline Cybersecurity Framework is built on this model. We scope our VAPT engagements to generate evidence directly against the Essential Eight's testing-related expectations, so results map cleanly to what NCSA and CII-sector auditors look for.
Do you have an office in the Maldives?
No — eNeoteric does not have a physical office in the Maldives. Engagements are delivered remotely by our India-based technical team, with on-site coordination available for CII-sector clients (banking, telecom, energy, transport) that need it for kickoff, scoping, or sensitive on-premise testing.
How long does a typical VAPT engagement take in the Maldives?
Most single-application or network engagements run 7-12 business days from kickoff to draft report, depending on scope. Contact us with your requirements for an exact timeline.

Have more questions?

Book Free Consultation

Explore related VAPT services

All Penetration Testing  VAPT Vendor Comparison  View all Cybersecurity

Request Proposal  WhatsApp Now

Maldives VAPT Pricing

Transparent, scope-based pricing — know your investment before you start.

General Enterprise
Enterprise Web + Network VAPT
USD 1,500 / starting
Standard web application and network VAPT for non-CII organisations.
  • Web app + network VAPT
  • CVSS-scored findings
  • Complimentary re-test

* All prices are indicative in USD and vary by scope and system count. Contact us for a fixed-price proposal.

Get exact quote →  WhatsApp for pricing

Request a Callback

Drop your details and we'll call you back within one business day — or reach us directly on +91 91080 15170.

💬 Chat on WhatsApp instead