Skip to content

VAPT Services in Nepal

eNeoteric delivers VAPT (Vulnerability Assessment and Penetration Testing) services for organisations in Nepal, remotely, by our India-based delivery team, with on-site coordination available where an engagement calls for it. For banks, Payment Service Providers (PSPs) and Payment Service Operators (PSOs), engagements are scoped against Nepal Rastra Bank's Cyber Resilience Guidelines (CRG), 2023 — whose "Testing" pillar explicitly calls out vulnerability assessments, penetration testing, and red-team exercises.

Request Proposal WhatsApp Now
NRB Cyber Resilience Guidelines-AlignedPSP/PSO & Bank Testing ScopeFree Re-Test Included8+ Years ExperienceIndia-Based Delivery Team

VAPT scoped to Nepal's regulatory environment

Nepal's clearest, most specific penetration-testing mandate comes from Nepal Rastra Bank's Cyber Resilience Guidelines (CRG), effective August 27, 2023. The CRG applies to licensed financial institutions, Payment Service Providers (PSPs), and Payment Service Operators (PSOs), and is structured around five pillars — Governance, Identify, Protect, Detect, and Response-Recovery — plus a dedicated Testing pillar that explicitly references vulnerability assessments, penetration testing, and red-team exercises. This is the strongest, most citable regulatory hook for VAPT in Nepal today — but its scope is the financial and payments sector specifically, not all businesses.

NRB's older 2012 IT Guidelines cover general IT governance and security more broadly, but only "recommend" periodic penetration testing as good practice — a weaker, secondary expectation compared to the CRG's explicit Testing pillar.

Outside the financial sector, Nepal's regulatory landscape is genuinely thinner. The Individual Privacy Act, 2018 (2075 B.S.), in force since September 2018, is Nepal's only dedicated privacy statute — it requires consent and authorised handling of personal data and covers both physical and informational privacy. It is not a GDPR-style comprehensive data protection law: there is no dedicated Data Protection Authority (enforcement runs through ordinary District Courts), implementing regulations reportedly have not yet been issued, and the Act lacks detailed minimum security standards. We frame it plainly — as Nepal's foundational privacy law, though it lacks detailed technical security standards or a dedicated enforcement authority.

Nepal also does not yet have a dedicated Cyber Security Act in force. A National Cyber Security Policy 2023 sets policy direction (it is not binding law), and a draft Information Technology and Cyber Security Bill is still pending passage. National CERT capability is similarly still consolidating — split across a government coordination effort at Joint-Secretary level (Ministry of Communication and Information Technology), an industry-run "Nepal CERT" under the CAN Federation, and telecom-sector CERT initiatives from the Nepal Telecommunications Authority.

Why Nepal organisations choose eNeoteric

Frequently asked questions

Does Nepal Rastra Bank require penetration testing for financial institutions?
Yes — for licensed financial institutions, Payment Service Providers (PSPs), and Payment Service Operators (PSOs), Nepal Rastra Bank's Cyber Resilience Guidelines (CRG), effective August 27, 2023, include a dedicated "Testing" pillar that explicitly references vulnerability assessments, penetration testing, and red-team exercises. This is a specific, financial/payments-sector mandate, not a general requirement across all businesses. NRB's earlier 2012 IT Guidelines separately "recommend" periodic penetration testing as general good practice, but that is a weaker, non-mandatory expectation.
Does Nepal have a comprehensive data protection or cybersecurity law?
Not yet, in the comprehensive sense. The Individual Privacy Act, 2018 (2075 B.S.) is Nepal's only dedicated privacy statute — it requires consent and authorised handling of personal data — but it is not a GDPR-style law: there's no dedicated Data Protection Authority (enforcement runs through ordinary District Courts), implementing regulations reportedly have not yet been issued, and it lacks detailed minimum security standards. On the cyber law side, there is no dedicated Cyber Security Act in force — the National Cyber Security Policy 2023 is a policy document, not binding law, and a draft Information Technology and Cyber Security Bill is still pending passage. We're upfront with clients about this rather than overstating what the law currently requires.
Who is Nepal's national CERT, and does it matter for VAPT engagements?
Nepal's national CERT function is still consolidating — it's split across a government coordination effort at Joint-Secretary level (Ministry of Communication and Information Technology), an industry-run "Nepal CERT" under the CAN Federation (a private association, not a government body), and separate telecom-sector CERT initiatives from the Nepal Telecommunications Authority. There is no single, unambiguous "the" Nepal CERT to report findings through today, so our engagements focus on getting you clean, actionable findings and remediation evidence rather than routing through a specific CERT process.
Do you have a local office in Nepal?
No — unlike some of our other regional engagements, we don't have a physical office in Nepal. Engagements are delivered remotely by our India-based team (registered office in Bengaluru), with on-site coordination available if a specific engagement needs it.
How long does a typical VAPT engagement take in Nepal?
Most single-application or network engagements run 7-12 business days from kickoff to draft report, depending on scope. NRB CRG-aligned engagements for banks, PSPs, and PSOs may take longer depending on system count and testing cadence requirements. Contact us with your requirements for an exact timeline.

Have more questions?

Book Free Consultation

Explore related VAPT services

All Penetration Testing  VAPT Vendor Comparison  View all Cybersecurity

Request Proposal  WhatsApp Now

Nepal VAPT Pricing

Transparent, scope-based pricing — know your investment before you start.

General Enterprise
Enterprise Web + Network VAPT
Custom / scope-based
Web application and network VAPT for non-financial enterprises, scoped to industry best practice.
  • Network + web app VAPT
  • CVSS-scored findings
  • Complimentary re-test

* All prices are indicative in USD and vary by scope and system count. Contact us for a fixed-price proposal.

Get exact quote →  WhatsApp for pricing

Request a Callback

Drop your details and we'll call you back within one business day. Engagements are delivered remotely by our India-based team, with on-site coordination available — or reach us directly on +91 91080 15170.

💬 Chat on WhatsApp instead