How to Choose a VAPT Vendor in India: A Practical Checklist for Security Buyers
Selecting a VAPT vendor in India is harder than it should be. The market has expanded significantly over the past five years, ranging from solo practitioners offering cut-price scans to large GRC consulting firms where the VAPT is a checkbox in a broader compliance engagement. In between are firms that vary enormously in manual testing depth, auditor seniority, reporting quality, and post-engagement support. For security buyers evaluating vendors for a regulatory engagement or a genuine security programme, the evaluation criteria need to go beyond price and certifications to the substance of what the engagement will actually deliver.
CERT-In empanelment: necessary but not sufficient
CERT-In empanelment is the minimum threshold for regulated engagements — RBI, SEBI, IRDAI, government, and PSU requirements all effectively mandate empanelled auditors. Checking a firm's empanelment status on the CERT-In public list (updated periodically at cert-in.org.in) should be the first filter. But empanelment is a floor, not a ceiling. It certifies that the firm meets a minimum standard of auditor qualifications, methodology documentation, and infrastructure security. It does not differentiate between a firm that does predominantly automated scanning with a thin manual layer and a firm that conducts deep manual penetration testing with OSCP/OSWE-certified practitioners. Ask specifically: what percentage of your engagements involve manual testing beyond automated tool output? What is the seniority profile of the testers who will work on my engagement?
Auditor certifications: what to look for
Certifications are imperfect proxies for practitioner skill, but they provide useful signals. For offensive security work (penetration testing, red team), the certifications with the highest signal value are: OSCP (Offensive Security Certified Professional) — a hands-on, proctored examination requiring exploitation of multiple machines in a 24-hour window; OSWE (Offensive Security Web Expert) — equivalent depth for web application exploitation; CRTP (Certified Red Team Professional) — focused on Active Directory attack paths; and OSED/OSEP for more advanced exploitation techniques. These certifications cannot be passed by memorising multiple-choice answers — they require demonstrated technical skill.
For compliance-focused audit work (IS audits, CERT-In audits, ISO 27001 audits), the relevant certifications are CISA (Certified Information Systems Auditor), CISSP, and CISM. A strong VAPT firm for regulated environments will have practitioners holding both offensive certifications and audit certifications — the technical depth to find real vulnerabilities and the audit methodology to produce a report that satisfies regulatory examination. Ask for the CV or certification profile of the specific practitioners who will be assigned to your engagement, not just the firm's aggregate credential list.
Testing methodology: questions to ask before signing
Methodology is where the substantive differentiation lies. The questions to ask: What standard do you test to for web application assessments — OWASP ASVS Level 1, 2, or 3? For network assessments, do you follow PTES (Penetration Testing Execution Standard) or a proprietary methodology? For mobile apps, do you test to OWASP MASVS? How do you test for IDOR and business logic vulnerabilities — these are manually intensive and cannot be automated? Can you show us an anonymised sample report from a comparable engagement? The sample report review is the single most informative step in vendor evaluation — it reveals whether the firm is documenting real exploitation evidence (screenshots, proof-of-concept code, attack chain narrative) or boilerplate descriptions mapped to CWE IDs with no exploitation evidence.
Report quality: the evidence standard
A VAPT report is the primary deliverable of the engagement. Its quality determines whether developers can actually remediate findings, whether the report satisfies a regulatory examination, and whether the engagement produced genuine security insight rather than a compliance checkbox. A high-quality report includes: an executive summary written for non-technical leadership (risk posture, business impact, recommended priorities); a technical findings register with CVSS v3.1 or v4.0 scores, CWE references, a narrative description of the finding, exploitation evidence (screenshots or proof-of-concept demonstrating the vulnerability was actually exploited, not just detected), affected URLs/IPs/components, and a concrete remediation recommendation. It should not include findings that are informational observations dressed up as vulnerabilities to inflate the findings count, or findings that are duplicates of each other under different names.
Retest commitment matters too. A vendor who offers a fixed-price retest as part of the engagement scope is aligned with your security outcome. A vendor who charges separately for retest at a rate that makes it uneconomical to close the loop is not. CERT-In empanelled audits for regulatory purposes require a retest and closure confirmation — confirm this is included before signing.
Turnaround time and communication during the engagement
A full-scope web application pentest on a medium-complexity application should take five to ten working days of active testing. Network pentests vary by asset count. Report delivery typically follows within five to seven working days of test completion. Be cautious of vendors who quote turnaround times that are implausibly short — a two-day "comprehensive VAPT" of a complex application is a scan, not a pentest. Communication cadence during the engagement also matters: your team should receive interim findings notifications for critical findings before the final report, so they can begin remediation in parallel with testing. Ask about the communication protocol before engaging.
Commercial questions: red flags in proposals
Price is not quality. The cheapest proposal is almost always cheaper because it is thinner — less manual testing time, less senior practitioners, less thorough reporting. Beyond price, watch for these red flags: a scope that is defined by a fixed number of IP addresses or URLs without any methodology specification (you may be paying for a scan of those IPs, nothing more); a report delivered in 24 hours of testing completion (no practitioner can complete testing, analysis, and report writing in that timeframe for a real assessment); no mention of retest or remediation verification; and an inability to show you a sample report or name the practitioners who will work on your engagement.
If you are evaluating VAPT vendors for a regulatory engagement or a genuine security programme, explore our services and see what a CyVigilant engagement delivers, or talk to an expert for a scoping conversation and a sample report.
Put this into action.
Book a 30-minute scoping call with a CERT-In empanelled security expert.
Talk to an ExpertMore articles
SEBI CSCRF 2024: A Compliance Roadmap for Stock Brokers and Market Infrastructure Institutions
SEBI CSCRF 2024: VAPT cadence, audit documentation, CERT-In empanelment, and compliance timelines for brokers and MIIs.
May 12, 2026IRDAI Cyber Security Guidelines: What Annual IS Audits and VAPT Mean for Insurers
IRDAI IS audit and VAPT obligations for insurers explained: annual audit scope, CERT-In empanelment, DPDP Act implications, and what regulators examine.
May 12, 2026What CERT-In Empanelment Means for Your Security Audit
CERT-In empanelment explained: what it is, why it matters for RBI/SEBI/IRDAI regulated entities, Safe-to-Host certificates, and what to expect from a compliant audit.
