Skip to content

VAPT Services in Sri Lanka

eNeoteric delivers VAPT (Vulnerability Assessment and Penetration Testing) services for organisations in Sri Lanka, delivered remotely by our India-based team, with on-site coordination available. For licensed banks, engagements are scoped to satisfy the Central Bank of Sri Lanka (CBSL)'s Banking Act Directions No. 16 of 2021 on Technology Risk Management and Resilience — a binding Direction that explicitly names penetration testing among its required technology risk management controls.

Request Proposal WhatsApp Now
CBSL Technology Risk Management-AlignedExplicit Pentest Requirement (Direction No. 16)Free Re-Test Included8+ Years ExperienceIndia-Based Delivery Team

VAPT scoped to Sri Lanka's regulatory environment

For Sri Lanka's licensed banking sector, the Central Bank of Sri Lanka (CBSL)'s Banking Act Directions No. 16 of 2021 — the Regulatory Framework on Technology Risk Management and Resilience for Licensed Banks (issued 9 December 2021, amended by Circular No. 5 of 2023) — is a binding Direction, not a discretionary guideline. It requires licensed banks to maintain an Information Security Committee chaired by the CEO, and it explicitly names penetration testing as part of the required technology risk management controls. CBSL followed this with Circular No. 2 of 2025 on Reporting of IT and Cybersecurity Incidents of Licensed Banks — evidence of an active, evolving regulatory regime around technology risk in Sri Lanka's banking sector.

On data protection, Sri Lanka's Personal Data Protection Act No. 9 of 2022 (enacted 19 March 2022) is a comprehensive data protection law now partially in force: Part V took effect in July 2023, other key parts commenced in December 2023, and some provisions remain pending gazette notification. The Data Protection Authority of Sri Lanka was established in August 2023 to oversee the Act. On the cyber law side, Sri Lanka does not yet have a comprehensive Cyber Security Act in force — a draft is in progress alongside a National Cyber Security Strategy 2025-2029. The Online Safety Act No. 9 of 2024 exists separately and addresses online content and harms, not technical cybersecurity. Sri Lanka's national CERT, Sri Lanka CERT|CC, has operated since 2006 as the government's designated National Centre for Cyber Security under the Ministry of Digital Economy, running a 24x7 National Cyber Security Operation Center (NCSOC).

Why Sri Lanka organisations choose eNeoteric

Frequently asked questions

Does CBSL require penetration testing for licensed banks?
Yes. CBSL's Banking Act Directions No. 16 of 2021 — the Regulatory Framework on Technology Risk Management and Resilience for Licensed Banks (issued 9 December 2021, amended by Circular No. 5 of 2023) — is a binding Direction, not a mere guideline, and it explicitly names penetration testing as part of the required technology risk management controls. It also requires an Information Security Committee chaired by the CEO. CBSL's follow-up Circular No. 2 of 2025 on Reporting of IT and Cybersecurity Incidents of Licensed Banks shows this is an active and evolving regulatory regime, not a one-off requirement.
Does Sri Lanka have a comprehensive Cyber Security Act?
Not yet in force. A draft Cyber Security Act is in progress alongside a National Cyber Security Strategy 2025-2029. Separately, the Online Safety Act No. 9 of 2024 already exists, but it addresses online content and harms rather than technical cybersecurity — it should not be read as covering penetration testing or technical security obligations. In the meantime, Sri Lanka CERT|CC has operated since 2006 as the government's designated National Centre for Cyber Security, running a 24x7 National Cyber Security Operation Center, so there is an active operational body even while comprehensive cyber security legislation is still pending.
What is the status of Sri Lanka's Personal Data Protection Act?
The Personal Data Protection Act No. 9 of 2022 was enacted on 19 March 2022 and is a comprehensive data protection law now partially in force: Part V took effect in July 2023, other key parts commenced in December 2023, and some provisions are still pending gazette notification. The Data Protection Authority of Sri Lanka was established in August 2023 to oversee compliance. We scope VAPT reporting to be useful evidence of your technical security controls as the Act's requirements progressively take effect.
Do you have a local office in Sri Lanka?
No — unlike our Singapore office, we do not have a physical office in Sri Lanka. Engagements are delivered remotely by our India-based technical team, with on-site coordination available for kickoff workshops, stakeholder meetings, or on-premises testing requirements where needed.
How long does a typical VAPT engagement take for a Sri Lanka-based organisation?
Most single-application or network engagements run 7-12 business days from kickoff to draft report, depending on scope, coordinated remotely by our India-based team. Contact us with your requirements for an exact timeline.

Have more questions?

Book Free Consultation

Explore related VAPT services

All Penetration Testing  VAPT Vendor Comparison  View all Cybersecurity

Request Proposal  WhatsApp Now

Sri Lanka VAPT Pricing

Transparent, scope-based pricing — know your investment before you start.

General Enterprise
Enterprise Web + Network VAPT
USD 1,800 / starting
Web application and network VAPT for general enterprise and IT-sector organisations.
  • Network + web app VAPT
  • PDPA-aware reporting
  • CVSS-scored findings
  • Complimentary re-test

* All prices are indicative in USD and vary by scope and system count. Contact us for a fixed-price proposal.

Get exact quote →  WhatsApp for pricing

Request a Callback

Drop your details and we'll call you back within one business day — or reach us directly on +91 91080 15170.

💬 Chat on WhatsApp instead