Penetration Testing / Nepal
VAPT Services in Nepal
eNeoteric delivers VAPT (Vulnerability Assessment and Penetration Testing) services for organisations in Nepal, remotely, by our India-based delivery team, with on-site coordination available where an engagement calls for it. For banks, Payment Service Providers (PSPs) and Payment Service Operators (PSOs), engagements are scoped against Nepal Rastra Bank's Cyber Resilience Guidelines (CRG), 2023 — whose "Testing" pillar explicitly calls out vulnerability assessments, penetration testing, and red-team exercises.
VAPT scoped to Nepal's regulatory environment
Nepal's clearest, most specific penetration-testing mandate comes from Nepal Rastra Bank's Cyber Resilience Guidelines (CRG), effective August 27, 2023. The CRG applies to licensed financial institutions, Payment Service Providers (PSPs), and Payment Service Operators (PSOs), and is structured around five pillars — Governance, Identify, Protect, Detect, and Response-Recovery — plus a dedicated Testing pillar that explicitly references vulnerability assessments, penetration testing, and red-team exercises. This is the strongest, most citable regulatory hook for VAPT in Nepal today — but its scope is the financial and payments sector specifically, not all businesses.
NRB's older 2012 IT Guidelines cover general IT governance and security more broadly, but only "recommend" periodic penetration testing as good practice — a weaker, secondary expectation compared to the CRG's explicit Testing pillar.
Outside the financial sector, Nepal's regulatory landscape is genuinely thinner. The Individual Privacy Act, 2018 (2075 B.S.), in force since September 2018, is Nepal's only dedicated privacy statute — it requires consent and authorised handling of personal data and covers both physical and informational privacy. It is not a GDPR-style comprehensive data protection law: there is no dedicated Data Protection Authority (enforcement runs through ordinary District Courts), implementing regulations reportedly have not yet been issued, and the Act lacks detailed minimum security standards. We frame it plainly — as Nepal's foundational privacy law, though it lacks detailed technical security standards or a dedicated enforcement authority.
Nepal also does not yet have a dedicated Cyber Security Act in force. A National Cyber Security Policy 2023 sets policy direction (it is not binding law), and a draft Information Technology and Cyber Security Bill is still pending passage. National CERT capability is similarly still consolidating — split across a government coordination effort at Joint-Secretary level (Ministry of Communication and Information Technology), an industry-run "Nepal CERT" under the CAN Federation, and telecom-sector CERT initiatives from the Nepal Telecommunications Authority.
- NRB CRG Testing-pillar scoping — Engagements for banks, PSPs, and PSOs structured to produce evidence against the CRG's Testing pillar expectations.
- Honest, conservative framing — We describe Nepal's data protection and cyber law landscape accurately as still developing, rather than overselling a compliance story that doesn't yet exist.
- Full VAPT scope — Network infrastructure, web applications, mobile apps, and APIs, following the same methodology detailed on our penetration testing services page.
- Remote delivery, on-site coordination available — Engagements delivered by our India-based team, with on-site coordination available for Nepal-based organisations that need it.
- Free re-test included — A complimentary re-test verifies every finding has been remediated.
Why Nepal organisations choose eNeoteric
- Financial-sector focus — Practical experience scoping VAPT engagements against NRB's CRG 2023 Testing pillar for banks, PSPs, and PSOs.
- Certified engineers — OSCP, CEH, and OSWE certified testers with financial-services and enterprise engagement experience.
- Honest regulatory framing — We describe Nepal's regulatory landscape accurately — strong for regulated financial entities under the CRG, still developing elsewhere — so your team gets precise, defensible language for management and auditor reporting.
- Clean, structured reports — CVSS-scored findings, proof-of-concept evidence, and remediation guidance suitable for NRB-facing documentation.
- Re-test included — A complimentary re-test verifies every finding has been remediated.
Frequently asked questions
- Does Nepal Rastra Bank require penetration testing for financial institutions?
- Yes — for licensed financial institutions, Payment Service Providers (PSPs), and Payment Service Operators (PSOs), Nepal Rastra Bank's Cyber Resilience Guidelines (CRG), effective August 27, 2023, include a dedicated "Testing" pillar that explicitly references vulnerability assessments, penetration testing, and red-team exercises. This is a specific, financial/payments-sector mandate, not a general requirement across all businesses. NRB's earlier 2012 IT Guidelines separately "recommend" periodic penetration testing as general good practice, but that is a weaker, non-mandatory expectation.
- Does Nepal have a comprehensive data protection or cybersecurity law?
- Not yet, in the comprehensive sense. The Individual Privacy Act, 2018 (2075 B.S.) is Nepal's only dedicated privacy statute — it requires consent and authorised handling of personal data — but it is not a GDPR-style law: there's no dedicated Data Protection Authority (enforcement runs through ordinary District Courts), implementing regulations reportedly have not yet been issued, and it lacks detailed minimum security standards. On the cyber law side, there is no dedicated Cyber Security Act in force — the National Cyber Security Policy 2023 is a policy document, not binding law, and a draft Information Technology and Cyber Security Bill is still pending passage. We're upfront with clients about this rather than overstating what the law currently requires.
- Who is Nepal's national CERT, and does it matter for VAPT engagements?
- Nepal's national CERT function is still consolidating — it's split across a government coordination effort at Joint-Secretary level (Ministry of Communication and Information Technology), an industry-run "Nepal CERT" under the CAN Federation (a private association, not a government body), and separate telecom-sector CERT initiatives from the Nepal Telecommunications Authority. There is no single, unambiguous "the" Nepal CERT to report findings through today, so our engagements focus on getting you clean, actionable findings and remediation evidence rather than routing through a specific CERT process.
- Do you have a local office in Nepal?
- No — unlike some of our other regional engagements, we don't have a physical office in Nepal. Engagements are delivered remotely by our India-based team (registered office in Bengaluru), with on-site coordination available if a specific engagement needs it.
- How long does a typical VAPT engagement take in Nepal?
- Most single-application or network engagements run 7-12 business days from kickoff to draft report, depending on scope. NRB CRG-aligned engagements for banks, PSPs, and PSOs may take longer depending on system count and testing cadence requirements. Contact us with your requirements for an exact timeline.
Have more questions?
Book Free ConsultationExplore related VAPT services
All Penetration Testing VAPT Vendor Comparison View all Cybersecurity
Nepal VAPT Pricing
Transparent, scope-based pricing — know your investment before you start.
- Network + web app VAPT
- CRG Testing pillar-aligned report
- CVSS-scored findings
- Complimentary re-test
- Network + web app VAPT
- CVSS-scored findings
- Complimentary re-test
* All prices are indicative in USD and vary by scope and system count. Contact us for a fixed-price proposal.
Get in touch
Request a Callback
Drop your details and we'll call you back within one business day. Engagements are delivered remotely by our India-based team, with on-site coordination available — or reach us directly on +91 91080 15170.