Free Tool · 5-Minute Self-Assessment

VAPT Readiness Checklist
for Indian Buyers

Twenty practitioner-grade questions to find out if you are ready to procure a Vulnerability Assessment and Penetration Test — or whether you will waste a third of your budget. No email gate.

Questions
20
Time
5 min
Output
Score band
Email gate
None

20 questions · 5 minutes · Score band on completion

Your readiness
0 / 20
The Checklist

Answer Honestly. No One Is Watching.

Five sections, twenty yes/no questions. Click Yes only if you can confidently defend a yes in front of an auditor. Score reveals at the bottom when you complete all twenty.

01

Scoping & Asset Inventory

You cannot test what you have not catalogued. Get the boundary right before you talk to vendors.

1
We have a current inventory of every internet-facing asset (web app, API, mobile app, IP range, cloud account) within the proposed scope.
2
We have mapped crown-jewel data flows and identified which user journeys touch sensitive data (PII, payment, health, regulated).
3
We have documented every authenticated user role we want tested (anonymous, customer, partner, admin, internal-support, super-admin).
4
We have decided which authentication mechanisms (SSO, MFA, JWT, API keys) are in scope and which are out.
02

Test Strategy & Compliance

The wrong methodology produces a useless report. Lock these calls before procurement.

5
We have decided black-box vs grey-box vs white-box for each asset, based on threat model and budget.
6
We have explicitly identified our compliance drivers (DPDP, RBI CSF, SEBI CSCRF, ISO 27001 A.8, SOC 2 CC4/CC7, PCI-DSS 11.3) and the required cadence.
7
We have agreed methodology requirements in writing — OWASP ASVS L2, MASVS, OWASP API Top 10, PTES, NIST SP 800-115 — as applicable.
8
We have specified that business-logic testing must be in scope, not just automated scanner output.
03

Vendor Selection

Most VAPT disappointments trace back to vendor due-diligence shortcuts in the first week.

9
We have reviewed at least 2 sanitised sample reports from the prospective vendor and verified they include manual exploitation, not just CVSS dumps.
10
We have verified consultant credentials are real and current (OSCP, OSWE, OSEP, CRTO, GPEN, GXPN, CCSAS) — not vendor-issued internal certificates.
11
We have spoken to 2 or 3 reference clients in our sector to confirm depth of work and reporting quality.
12
We have a signed mutual NDA, an MSA, and a detailed Statement of Work with line-item deliverables before any kick-off.
04

Pre-Test Logistics

Skipping these turns a VAPT engagement into an incident — or wastes 30% of the budgeted hours.

13
We have a signed Rules of Engagement document covering test windows, allowed techniques, exclusions (DoS, exfiltration, social engineering), and emergency stop authority.
14
We have allow-listed tester source IPs in our WAF, CDN, and rate-limiting layers — and informed our hosting provider where required.
15
We have provisioned test accounts at every relevant role tier with realistic but non-production data.
16
We have a named technical contact and an escalation path with a 4-hour response SLA during the test window.
05

Post-Test Capacity

A report you cannot act on is a wasted line item. Plan remediation capacity before you start.

17
We have allocated dev and ops capacity for the 3 to 6 weeks following report delivery, dedicated to remediation of high and critical findings.
18
We have a finding-tracking system (Jira, Linear, GitHub Issues) ready to ingest the catalogue with owners, severity, and target dates.
19
We have budgeted re-testing within the same SOW (typical: 30 to 60 days post-fix) and confirmed the vendor will issue a re-test letter for compliance evidence.
20
We have a board-readable executive summary planned and stakeholder owners for compliance mapping (DPDP, ISO, SOC 2).
What "Ready" Looks Like

Three Bands. Three Plays.

0–7
Critical exposure

You are not ready to procure a VAPT. A test now will produce findings you cannot act on, and you will still fail the next compliance audit. Spend 4 to 6 weeks on scoping, asset inventory, and remediation capacity first.

8–14
At risk

You can run a VAPT, but you will leave value on the table. Close the open items in the next 30 days, then proceed. Plan a tighter SOW with explicit business-logic and authorisation testing requirements.

15–20
Procurement-ready

Go to RFP. Demand methodology disclosure, sample reports, and named-consultant credentials in the response. Negotiate re-testing into the base SOW. Budget 30% of test cost for remediation capacity.

FAQ

Common Questions

How long should a VAPT engagement actually take? +

A typical Indian SME web-app VAPT runs 8 to 12 working days per asset for grey-box manual testing. A 5-app portfolio with one mobile app and one external network range is realistically a 6 to 8 week calendar engagement, including re-testing.

What is a fair price range for an Indian mid-market VAPT? +

For one customer-facing web app plus an API in 2026, expect ₹2,50,000 to ₹6,00,000 from a competent specialist firm. Below ₹1,50,000 you are getting an automated-scanner report. Above ₹10,00,000 you are paying Big-4 overhead, not better testing.

Do we really need OSCP-certified testers? +

You need at least one OSCP, OSWE, or CRTO-credentialled lead on the engagement. These are the credentials with proctored hands-on exams that signal real exploitation skill. Vendor-issued internal "certifications" tell you nothing.

How often should we re-test? +

Annually as a baseline, plus after any major architectural change, new payment integration, or merger and acquisition. RBI-regulated entities must follow CSF cadence. Significant Data Fiduciaries under DPDP should plan quarterly reviews of high-risk assets.

What is the difference between this checklist and the buyer's guide? +

This checklist diagnoses readiness in 5 minutes. The 50-page buyer's guide explains the why behind every line, gives sample SOWs, scoring rubrics, ROE templates, day-rate benchmarks, and worked pricing for 5 archetypes. Use the checklist to triage; use the guide to procure.

Ready to procure?

Skip the Vendor Roulette. Get a Defensible VAPT.

A 30-minute consultation. Walk away with a scoped SOW outline, a fair price band for your environment, and three vendor evaluation criteria specific to your sector.

No sales pitch. Responds within 24 hours.