VAPT in India
A practical map of vulnerability assessment and penetration testing for Indian SaaS, fintech and product teams — services, cost, RFQ hygiene and when CERT-In empanelment actually matters. Start with the commercial page that matches your intent, then use the guides to buy well.
What buyers usually mean by “VAPT India”
In Indian procurement language, VAPT usually means a commercial bundle: vulnerability assessment plus penetration-test-style validation, delivered as a report you can hand to customers, auditors or internal security. It is not the same as running a scanner overnight. Useful VAPT shows what an attacker could realistically achieve inside an agreed scope — authentication and authorisation failures, business-logic abuse, tenant isolation gaps, API object-level issues, cloud identity exposure and perimeter weaknesses — then supports remediation with a retest.
PocForge is a human-led boutique. We use automation where it improves coverage, then spend engagement time on attack paths that matter to your product. We publish indicative INR bands and an honest stance on CERT-In: we do not claim empanelment we do not have. If your contract requires an empanelled auditor, verify the official CERT-In PDF before you shortlist anyone. PocForge is based in Delhi (NCR) and delivers remotely nationwide; the city pages are buyer context, not a claim of a city headquarters.
Start here by intent
Buy VAPT services
Scope matrix, surfaces, deliverables and indicative India pricing.
Choose a company
Engagement model, who we fit, process and proof orientation.
Understand cost
2026 INR ranges, cost drivers and how to compare quotes fairly.
India surface landers
When stakeholders need locale-focused pages for a specific attack surface:
- Web application penetration testing in India
- API security testing in India
- Mobile app security testing in India
- Cloud security assessment in India
- External infrastructure pentesting in India
- Network & Active Directory pentesting in India
- Desktop / Electron pentesting in India
- AI / LLM security testing in India
Global methodology pages also exist for international positioning (for example web application penetration testing). For India-intent searches and INR conversations, prefer the India landers above or the VAPT services hub.
Buyer guides that prevent bad RFQs
- How to write a VAPT RFQ in India — paste-ready scope checklist for SaaS teams.
- Penetration test vs vulnerability scan — so you do not buy a scan when you need validated testing.
- VAPT for SOC 2 / ISO 27001 — evidence expectations when CERT-In empanelment is not the requirement.
- Do you need CERT-In empanelled VAPT? — decision guide with a link to the official empanelment PDF.
How PocForge approaches India engagements
- Scope workshop — assets, environments, roles, exclusions and success criteria.
- Rules of engagement — windows, contacts, data handling and escalation.
- Discovery + manual attack-path testing — prioritise authz, business logic and chaining.
- Evidence-backed report — severity, reproduction, impact and remediation guidance.
- Retest — closure notes for in-scope remediated findings within the agreed window.
Indicative openers (exclusive of GST; final quote after scope) typically sit slightly under broad market package openers for comparable manual web work — see the cost guide for published bands. We do not invent client counts, CVE theatre or unobserved rankings.
Who this hub is for
Good fit: product and security teams at Indian startups and growing SaaS/fintech companies, remote-first organisations buying India-market testing, and teams gathering SOC 2 / ISO-style testing evidence without a statutory empanelment clause.
May need a different vendor path: regulated programmes that contractually require a CERT-In empanelled auditor. Empanelment is a procurement attribute — not a synonym for quality. Read the CERT guide, then verify the official list.
Next step
If you already know the surface, open the matching India lander. If you want a scoped commercial conversation, start with VAPT services in India or request a free scope review. For anonymised engagement shapes, see case studies.
What “good” looks like in an India VAPT quote
Strong proposals name environments (staging vs production constraints), roles under test, inclusions and exclusions, report format, retest window and commercial assumptions. Weak proposals sell “unlimited vulnerabilities” or a single fixed price without asking about auth models, tenants or API surface. Use our RFQ checklist so vendors answer the same questions. Compare methodology and evidence quality — not only the lowest INR line. For regulated scopes, separate the empanelment question from the testing-quality question; both can matter, but they are not interchangeable.
If you are buying for enterprise questionnaires or SOC 2 / ISO evidence rather than a statutory CERT-In audit, say that in the RFQ. It changes how reports should be framed and which vendor attributes actually matter. See VAPT for SOC 2 / ISO 27001.
VAPT by city (India tech hubs)
Local-intent landers for common India searches. Delivery is remote-first nationwide; city pages explain local buyer context and industries — not thin doorway copies.
International VAPT landers (remote delivery)
Remote-first country pages for buyers outside India. Same human-led methodology; local currency bands and timezone overlap. Footer stays India-focused — these links live in hub body only.
Frequently asked questions
Is VAPT the same as penetration testing?
In India, VAPT usually markets assessment plus pentest-style validation as one engagement. Penetration testing emphasises adversarial validation of exploit paths. PocForge leans toward validated testing with assessment coverage of the agreed surface — see our pentest vs scan guide.
Do I need a CERT-In empanelled vendor?
Only when your regulator, customer or contract says so. Many SaaS and product reviews need strong testing evidence, not empanelment. Read our CERT-In decision guide and verify the official PDF.
Where should I go for pricing?
Use the 2026 cost guide and the homepage estimator. Final quotes follow a short scope review.
How do I write a useful RFQ?
Follow the VAPT RFQ checklist for India SaaS — assets, roles, environments, exclusions and deliverables beat vague “full VAPT” wording.
Ready to scope an India VAPT engagement?
Tell us the surfaces, environments and timeline. We will return a clear scope outline — no badge theatre, no invented stats.
Talk to a pentester →