VAPT Certification: What It Actually Covers (and What It Doesn't)
"VAPT certification" means two different things. This guide untangles the confusion between a post-test certificate, SOC 2, ISO 27001, and professional credentials.
India has one of the largest concentrations of cybersecurity vendors in Asia. Hundreds of companies offer penetration testing services, from boutique VAPT firms in Bengaluru to large IT services organizations with dedicated security practices in Mumbai and Delhi. The volume of options is not the problem. The problem is that quality varies sharply, and the vendor evaluation process most organizations use is not designed to surface that difference.
The standard approach is to get three quotes, check whether the vendor has ISO 27001 or relevant certifications, look at client logos on their website, and choose the lowest price that appears credible. That process selects adequately for compliance-checkbox engagements. It does not select for genuine security coverage.
This guide is for organizations that want actual security improvement from their penetration testing engagement, not just a certificate to show an auditor. It covers the evaluation criteria that matter, the red flags to recognize, and the questions to ask before signing with any provider in India or anywhere else.
India's penetration testing market has specific characteristics that affect how buyers should approach vendor selection.
The market is large, competitive, and price-sensitive. This has produced a segment of vendors who offer very low-cost "VAPT" engagements that are primarily automated scanner runs relabeled as penetration testing. The deliverable looks like a penetration test report: it has CVSS scores, finding counts, and severity ratings. What it lacks is actual penetration testing. No manual exploitation was attempted. No business logic was examined. No findings were confirmed through proof-of-concept evidence.
A second segment consists of genuine penetration testing firms with trained practitioners, proper methodology, and high-quality reporting. Some of these are Indian-founded companies. Some are Indian offices of global security firms. Some are agentic AI-driven platforms that operate globally including from Indian infrastructure.
Separating these two segments requires specific evaluation criteria, not logo checks.
The most important single question to ask any penetration testing vendor is: does every finding in your report include proof-of-concept evidence confirming exploitation?
A genuine penetration test reports only what was confirmed exploitable. SQL injection findings come with extracted data. Authentication bypass findings come with evidence of unauthorized access. IDOR findings come with demonstration that a second user's resource was accessed from the first user's session.
A scanner-based "VAPT" report flags theoretical vulnerabilities without confirming exploitation. The finding exists because the tool matched a signature pattern, not because an attacker actually demonstrated impact.
Ask vendors for a sample report. Count the findings with genuine PoC evidence versus findings with only a CVE reference and a generic description. That ratio tells you more about methodology than any certification on their website. What makes a VAPT report credible covers every section a quality report should contain and what weak reporting looks like in practice.
Most of the vulnerabilities that cause serious security incidents are not found by automated scanners. Business logic flaws, broken access control across user roles, race conditions in transaction handling, and second-order injection require a tester who understands what the application is supposed to do and actively tests whether that intent is enforced.
Ask vendors specifically: how do you test business logic? What is your methodology for testing authorization across multiple user roles? How do you approach multi-step workflow testing?
Vendors who cannot answer these questions specifically are vendors who do not test these areas. A vendor whose answer is "we use Burp Suite and run our standard checklist" is describing a tool-driven approach that will miss the vulnerability classes that matter most. What a real penetration test should cover maps the twelve areas a thorough web application engagement must address, which can serve as a direct evaluation checklist for vendor conversations.
Modern applications expose significant functionality through APIs. REST endpoints, GraphQL schemas, and WebSocket connections each present distinct attack surfaces that require specific testing methodology beyond standard web application scanning.
Many Indian VAPT vendors apply web application testing tools to API surfaces and produce limited coverage as a result. GraphQL introspection testing, mass assignment vulnerability testing, and broken function level authorization across API versions require deliberate methodology that standard web application checklists do not cover.
Ask whether the vendor has specific API security testing methodology. Ask whether they test GraphQL endpoints with schema introspection and query complexity abuse. Ask whether their API testing includes multiple authenticated sessions for authorization boundary testing. API vulnerabilities standard penetration tests miss covers the eight classes that fall outside standard methodology, which you can use to probe a vendor's depth.
In manual penetration testing, findings quality correlates directly with tester expertise. Ask who will actually conduct the engagement, not who is listed on the company's credentials page.
OSCP (Offensive Security Certified Professional) is the most respected hands-on penetration testing credential. Testers who have passed the OSCP exam have demonstrated ability to compromise real systems under exam conditions. CEH (Certified Ethical Hacker) from EC-Council is widely recognized in India and internationally, though it is more theoretical than OSCP. eWPT from eLearnSecurity indicates web application penetration testing specialization.
Ask whether the assigned tester holds OSCP or equivalent. Ask whether the same tester conducts the full engagement or whether work is passed between team members. Engagement continuity matters because understanding an application's behavior builds over the course of testing, and handoffs between testers disrupt that accumulated context.
A penetration test covers exactly what is in scope and nothing else. The quality of the certificate and report that come out of an engagement is bounded by the quality of the scope definition that goes into it.
Many low-cost Indian VAPT vendors produce scope documents that appear comprehensive but exclude the highest-risk surfaces in practice. APIs are "out of scope" unless specifically included. Authenticated application surfaces require credential provisioning that adds setup overhead, so they are frequently minimized. Third-party integrations are "the vendor's responsibility." Mobile applications are a separate engagement.
Before signing, get the full scope document and compare it against your actual attack surface. If your customer-facing API layer, your admin panel, and your third-party payment integration are all absent from scope, the engagement will not assess the surfaces attackers would most likely target.
Penetration test findings are only valuable if engineering teams can act on them. Generic remediation advice does not enable action.
Generic: "Implement input validation on user-supplied parameters." Specific: "The /api/v2/checkout endpoint passes the coupon_code parameter directly into the SQL query on line 84 of CheckoutService.java. Replace string concatenation with a parameterized query using PreparedStatement."
Ask for a sample report and evaluate the remediation sections. If guidance is specific to the technology stack and vulnerable code location, the vendor has done the work to understand the application. If guidance is copied from CVE descriptions, engineering teams will need to do additional investigation before they can act.
A penetration test engagement without retesting leaves a critical loop open. When engineering fixes a finding, confirming that the fix actually works requires re-executing the specific test that found the vulnerability. In many Indian VAPT engagements, retesting is either a separate paid engagement, included but scheduled weeks later, or absent entirely.
Ask whether retesting is included in the base engagement. Ask how quickly retesting happens after a fix is deployed. Ask whether retesting produces documented evidence that the specific vulnerability was confirmed closed.
The gap between "engineering says it is fixed" and "testing confirmed it is fixed" is where organizations carry unvalidated risk. This is one of the structural advantages of continuous agentic testing over periodic manual engagements: agentic pentesting and continuous security validation retests automatically when fixes are deployed and produces timestamped remediation records without scheduling overhead.
Different compliance frameworks have different requirements for what penetration testing must cover, how frequently it must occur, and what documentation must be produced.
If your organization needs to satisfy SOC 2, ISO 27001, PCI DSS, or RBI cybersecurity framework requirements, the engagement must be scoped and documented to satisfy those specific requirements. Ask vendors whether they have experience with your specific compliance framework and whether they can produce the report format that your auditor expects.
For organizations with US or Singapore operations alongside Indian operations, compliance requirements may span multiple frameworks. A vendor experienced only with Indian regulatory requirements (RBI, SEBI, IRDAI cybersecurity frameworks) may not understand what SOC 2 auditors look for in penetration test evidence, or what MAS TRM requires from testing of Singapore-facing systems.
India's penetration testing market is concentrated in its major technology hubs. Vendors in these cities range from small boutique firms to enterprise security practices.
Bengaluru has the highest concentration of cybersecurity firms, supported by the broader technology ecosystem. Firms range from startups to established security consultancies with global client bases.
Mumbai and Pune have strong financial services-oriented security practices given the concentration of banking and fintech clients in the region. Vendors here often have experience with RBI and SEBI cybersecurity framework requirements.
Delhi and NCR have government-oriented security practices alongside enterprise-focused firms, with relevant experience in NIC and CERT-In requirements.
Hyderabad and Chennai have growing security practices connected to the pharmaceutical and manufacturing sectors, with increasing IT/ITES security demand.
For organizations seeking coverage across these cities, penetration testing services in India and VAPT company services in India are the relevant starting points. City-specific PTaaS services are available in Bengaluru, Mumbai, Delhi, Pune, Hyderabad, and Chennai.
Certain vendor behaviors during the sales process are reliable signals of engagement quality.
Quote turnaround under 24 hours for a complex scope. A vendor who produces a detailed quote for a multi-application enterprise engagement within hours has not actually thought through the scope. Proper scoping takes time.
Pricing significantly below market rate. Web application VAPT for a mid-complexity application runs approximately $5,000 to $15,000 from quality vendors. Quotes significantly below this typically indicate scanner-based assessments relabeled as penetration testing.
Sample reports without PoC evidence. If the sample report contains findings without proof-of-concept demonstration, assume your report will look the same.
Inability to name the specific tester. If the vendor cannot tell you who will conduct the engagement and what certifications they hold, their staffing model for your engagement is unclear.
Compliance certifications as the primary quality signal. ISO 27001 certification of a VAPT vendor certifies their internal quality management processes. It says nothing about the depth of their testing methodology. A vendor who leads with "we are ISO 27001 certified" without being able to discuss methodology is deflecting.
No discussion of scope limitations. Any honest vendor should proactively discuss what an engagement will and will not cover. A vendor who presents every engagement as "comprehensive VAPT" without acknowledging scope constraints is not being straightforward about what you will receive.
A third option beyond traditional Indian VAPT vendors is agentic AI penetration testing, which operates continuously, covers the full defined scope on every run, and produces findings with proof-of-concept evidence without the scheduling, staffing, and scope constraints of manual engagements.
Agentic pentesting is not a replacement for every scenario: compliance frameworks that specifically require third-party human assessment by name, red team exercises, and highly domain-specific testing benefit from human judgment. But for ongoing security validation of web applications, APIs, and authenticated application surfaces, agentic testing covers the security gaps that DAST and standard scanning miss while producing findings faster and at lower cost per engagement than a comparable manual exercise.
For Indian organizations evaluating agentic penetration testing in India or PTaaS options in India, the continuous model is worth evaluating alongside traditional vendor quotes. The 10x Pentest platform covers the evaluation in full, and pricing compares the cost of continuous coverage against equivalent periodic manual engagement rates. The team is available to discuss scope and methodology for your specific application.
Q1. How much does penetration testing cost in India?
Web application penetration testing from a quality Indian vendor typically runs $3,000 to $12,000 for a mid-complexity application, which is generally lower than equivalent engagements from US or UK-based firms. Network VAPT and larger enterprise engagements scale higher based on scope. Quotes significantly below these ranges typically indicate scanner-based assessments rather than manual penetration testing. Agentic PTaaS platforms offer continuous coverage at a fraction of equivalent periodic manual engagement cost and do not scale linearly with testing frequency.
Q2. What certifications should I look for in an Indian penetration testing company?
OSCP (Offensive Security Certified Professional) held by the testers assigned to the engagement is the most reliable technical credential. CEH from EC-Council is widely held in India and broadly recognized. For the company itself, CERT-In empanelment is relevant for government and regulated sector work in India. ISO 27001 certification of the vendor organization covers quality management processes but does not directly measure testing methodology depth. The most informative evaluation is a review of a sample report, which shows methodology quality directly rather than through proxy credentials.
Q3. How long does a penetration test take in India?
A web application VAPT engagement from a quality Indian vendor typically takes one to two weeks of active testing for a mid-complexity application, plus report writing time of three to five business days. Simpler applications may complete in five to seven business days total. Large enterprise engagements covering multiple applications, APIs, and network infrastructure take longer. Agentic penetration testing compresses the timeline to hours for initial findings and days for full scope coverage, without the scheduling lead time that manual engagements require.
Q4. Is CERT-In empanelment important when choosing a VAPT vendor in India?
CERT-In (Indian Computer Emergency Response Team) empanelment is required for vendors providing security auditing services to government organizations and certain regulated entities in India. For private sector organizations without a specific regulatory requirement for CERT-In empanelled auditors, empanelment is a signal of credibility but not a technical quality guarantee. The quality of testing methodology and the depth of the sample report are more informative for private sector buyers than empanelment status alone.
Q5. Can an Indian penetration testing company handle compliance requirements for US or Singapore operations?
Yes, provided the vendor has experience with the specific frameworks relevant to those markets. SOC 2, ISO 27001, and PCI DSS are internationally applicable frameworks that India-based vendors with relevant experience can satisfy. MAS TRM in Singapore requires specific knowledge of the 2021 guidelines. HIPAA in the US requires familiarity with OCR enforcement expectations. Ask specifically whether the vendor has completed engagements for clients with these compliance requirements and whether they can produce the report format auditors in those markets expect. Do not assume cross-market compliance competency without asking for direct evidence of it.
Schedule a free consultation and see how teams like yours are strengthening their security posture — continuously.