Penetration Testing / Sri Lanka
VAPT Services in Sri Lanka
eNeoteric delivers VAPT (Vulnerability Assessment and Penetration Testing) services for organisations in Sri Lanka, delivered remotely by our India-based team, with on-site coordination available. For licensed banks, engagements are scoped to satisfy the Central Bank of Sri Lanka (CBSL)'s Banking Act Directions No. 16 of 2021 on Technology Risk Management and Resilience — a binding Direction that explicitly names penetration testing among its required technology risk management controls.
VAPT scoped to Sri Lanka's regulatory environment
For Sri Lanka's licensed banking sector, the Central Bank of Sri Lanka (CBSL)'s Banking Act Directions No. 16 of 2021 — the Regulatory Framework on Technology Risk Management and Resilience for Licensed Banks (issued 9 December 2021, amended by Circular No. 5 of 2023) — is a binding Direction, not a discretionary guideline. It requires licensed banks to maintain an Information Security Committee chaired by the CEO, and it explicitly names penetration testing as part of the required technology risk management controls. CBSL followed this with Circular No. 2 of 2025 on Reporting of IT and Cybersecurity Incidents of Licensed Banks — evidence of an active, evolving regulatory regime around technology risk in Sri Lanka's banking sector.
On data protection, Sri Lanka's Personal Data Protection Act No. 9 of 2022 (enacted 19 March 2022) is a comprehensive data protection law now partially in force: Part V took effect in July 2023, other key parts commenced in December 2023, and some provisions remain pending gazette notification. The Data Protection Authority of Sri Lanka was established in August 2023 to oversee the Act. On the cyber law side, Sri Lanka does not yet have a comprehensive Cyber Security Act in force — a draft is in progress alongside a National Cyber Security Strategy 2025-2029. The Online Safety Act No. 9 of 2024 exists separately and addresses online content and harms, not technical cybersecurity. Sri Lanka's national CERT, Sri Lanka CERT|CC, has operated since 2006 as the government's designated National Centre for Cyber Security under the Ministry of Digital Economy, running a 24x7 National Cyber Security Operation Center (NCSOC).
- CBSL Direction No. 16-aligned reporting — Findings and remediation evidence structured for review by your Information Security Committee and CBSL-facing reporting.
- Explicit regulatory grounding — Direction No. 16 explicitly names penetration testing as a required control for licensed banks, not a discretionary supervisory expectation.
- PDPA-aware scoping — Testing methodology accounts for Sri Lanka's Personal Data Protection Act No. 9 of 2022 as its provisions progressively come into force.
- Full VAPT scope — Network infrastructure, web applications, mobile apps, and APIs, following the same methodology detailed on our penetration testing services page.
- Remote delivery, India-based team — Engagements delivered remotely by our India-based technical bench, with on-site coordination available for kickoff workshops and stakeholder meetings.
Why Sri Lanka organisations choose eNeoteric
- Licensed banking sector experience — Engagements scoped to CBSL Direction No. 16's technology risk management requirements, including evidence packages suitable for Information Security Committee review.
- Certified engineers — OSCP, CEH, and OSWE certified testers with financial-services and enterprise engagement experience.
- Honest regulatory framing — We describe Sri Lanka's regulatory landscape precisely: Direction No. 16 as a binding requirement, the PDPA as partially in force, and the Cyber Security Act as still in draft — your compliance team gets defensible language for board and regulator reporting.
- Clean, structured reports — CVSS-scored findings, proof-of-concept evidence, and remediation guidance suitable for CBSL and board-level documentation.
- Re-test included — A complimentary re-test verifies every finding has been remediated.
Frequently asked questions
- Does CBSL require penetration testing for licensed banks?
- Yes. CBSL's Banking Act Directions No. 16 of 2021 — the Regulatory Framework on Technology Risk Management and Resilience for Licensed Banks (issued 9 December 2021, amended by Circular No. 5 of 2023) — is a binding Direction, not a mere guideline, and it explicitly names penetration testing as part of the required technology risk management controls. It also requires an Information Security Committee chaired by the CEO. CBSL's follow-up Circular No. 2 of 2025 on Reporting of IT and Cybersecurity Incidents of Licensed Banks shows this is an active and evolving regulatory regime, not a one-off requirement.
- Does Sri Lanka have a comprehensive Cyber Security Act?
- Not yet in force. A draft Cyber Security Act is in progress alongside a National Cyber Security Strategy 2025-2029. Separately, the Online Safety Act No. 9 of 2024 already exists, but it addresses online content and harms rather than technical cybersecurity — it should not be read as covering penetration testing or technical security obligations. In the meantime, Sri Lanka CERT|CC has operated since 2006 as the government's designated National Centre for Cyber Security, running a 24x7 National Cyber Security Operation Center, so there is an active operational body even while comprehensive cyber security legislation is still pending.
- What is the status of Sri Lanka's Personal Data Protection Act?
- The Personal Data Protection Act No. 9 of 2022 was enacted on 19 March 2022 and is a comprehensive data protection law now partially in force: Part V took effect in July 2023, other key parts commenced in December 2023, and some provisions are still pending gazette notification. The Data Protection Authority of Sri Lanka was established in August 2023 to oversee compliance. We scope VAPT reporting to be useful evidence of your technical security controls as the Act's requirements progressively take effect.
- Do you have a local office in Sri Lanka?
- No — unlike our Singapore office, we do not have a physical office in Sri Lanka. Engagements are delivered remotely by our India-based technical team, with on-site coordination available for kickoff workshops, stakeholder meetings, or on-premises testing requirements where needed.
- How long does a typical VAPT engagement take for a Sri Lanka-based organisation?
- Most single-application or network engagements run 7-12 business days from kickoff to draft report, depending on scope, coordinated remotely by our India-based team. Contact us with your requirements for an exact timeline.
Have more questions?
Book Free ConsultationExplore related VAPT services
All Penetration Testing VAPT Vendor Comparison View all Cybersecurity
Sri Lanka VAPT Pricing
Transparent, scope-based pricing — know your investment before you start.
- CBSL Direction No. 16-aligned scope
- Information Security Committee-ready report
- CVSS-scored findings
- Complimentary re-test
- Network + web app VAPT
- PDPA-aware reporting
- CVSS-scored findings
- Complimentary re-test
* All prices are indicative in USD and vary by scope and system count. Contact us for a fixed-price proposal.
Get in touch
Request a Callback
Drop your details and we'll call you back within one business day — or reach us directly on +91 91080 15170.