Expert-led security testing, priced for impact.
Every engagement is scoped, executed, and reported by senior offensive-security specialists — not scanners. Choose the package that fits your need, or talk to us for a tailored assessment.
Three ways to work with CyVigilant.
Fixed-price proposals, a complimentary retest on every engagement, and senior testers from kickoff to closure.
Essential
Single-scope VAPT for teams that need a credible, audit-ready assessment.
Web or Mobile App VAPT
Talk to an Expert- Single Web or Mobile App VAPT
- Manual + automated testing (OWASP)
- CVSS-scored findings with PoC evidence
- Executive summary + technical report
- One complimentary retest included
- Kickoff within 48 hours of scoping
CERT-In Audit
CERT-In audit (delivered via empanelled partner) with Safe-to-Host certificate — accepted by RBI, SEBI and government bodies.
CERT-In audit report (via partner) + Safe-to-Host
Talk to an Expert- CERT-In audit report (via empanelled partner)
- Safe-to-Host certificate
- RBI / SEBI / IRDAI / DPDP alignment
- In-scope VAPT of critical systems
- Executive risk summary
- Regulatory evidence package
- One complimentary retest included
Enterprise / Red Team
Continuous testing, adversary simulation, and strategic advisory for organizations that need sustained assurance.
Continuous testing + red team + vCISO advisory
Talk to an Expert- Quarterly or continuous application testing
- Full-scope red team assessment
- Assumed-breach & adversary simulation
- Cloud infrastructure pentest
- Secure code review on release branches
- vCISO advisory sessions
- Dedicated engagement lead
- Quarterly continuous assurance programmeAdd-on
All engagements include a free retest · NDA + rules of engagement · ISO 27001:2022 certified
Common questions about our engagements
Everything you need to know before scoping a CyVigilant assessment.
CERT-In audit pricing depends on the number of in-scope systems, the depth of testing required, and the regulatory frameworks you need to align to (RBI, SEBI, IRDAI, DPDP). We scope every engagement in a free 30-minute call and provide a fixed-price proposal — no surprise charges.
CERT-In audit pricing depends on the number of in-scope systems, the depth of testing required, and the regulatory frameworks you need to align to (RBI, SEBI, IRDAI, DPDP). We scope every engagement in a free 30-minute call and provide a fixed-price proposal — no surprise charges.
The Essential package covers a single Web or Mobile App VAPT following OWASP MASVS (mobile) or ASVS (web). You receive a CVSS-scored technical report, a PoC for every finding, an executive summary, and one complimentary retest to verify remediations.
Yes. Every CyVigilant engagement includes a complimentary retest of all findings from the original scope. We retest against the same attack surface and issue a closure certificate once all critical and high findings are resolved.
We typically kick off within 48 hours of a completed scoping call and signed NDA. For CERT-In audits with a hard regulatory deadline, contact us and we will do our best to accommodate urgent timelines.
Absolutely. Many clients begin with a single VAPT and move to the CERT-In Audit package or an Enterprise retainer as their security programme matures. We retain context from previous engagements, so onboarding time shrinks on every subsequent test.
Yes. Every engagement is governed by a signed NDA and a formal rules-of-engagement document that defines scope, testing windows, and emergency contacts. We use least-privilege, time-boxed access and encrypt all evidence throughout the engagement.
Still comparing packages?
Talk to a security expertNot sure which package is right for you?
Book a 30-minute scoping call with a senior security expert. We will map your regulatory obligations, recommend the right scope, and give you a fixed-price proposal — no obligation.
