BUYER GUIDE · INDIA · 2026

Boutique vs Big-Four VAPT in India: how to choose

An honest, no-named-competitor guide to what actually differs between a boutique specialist, a large audit firm and a PTaaS platform — tester access, depth, price, reporting and empanelment — so Indian buyers can match the engagement model to the job.

The short answer

It depends on three things: whether your contract or regulator needs a CERT-In empanelled legal entity, how deep the manual testing must go on your highest-risk surfaces, and what budget and turnaround you can defend to stakeholders. A large empanelled firm is often the right call for regulated procurement theatre; a boutique specialist is usually better when you need senior time on a defined product; an automated/PTaaS platform is enough only when the goal is continuous coverage of known classes of issues, not attack-path proof.

How to choose — a six-point checklist

  1. Who actually tests? Ask for the seniority and availability of the people who will hold the keyboard, not only the brand on the cover page.
  2. Manual depth vs tooling. Scanners find known classes of issues; human-led work is for authz, business logic, multi-tenant isolation and chained paths. See penetration test vs vulnerability scan.
  3. Retest included? A finding without a retest window is only half a deliverable. Confirm what is in scope for retest and how long the window lasts.
  4. Reporting you can hand to engineering. Prefer evidence, reproduction steps and severity rationale over template prose.
  5. Empanelment need — yes or no? If a contract names CERT-In empanelment, verify the official list and match the legal entity. If it does not, treat empanelment as optional. Read Do you need CERT-In empanelled VAPT?.
  6. Data handling and access. Staging vs production, secrets handling, VPN/bastion assumptions and where evidence is stored should be written into the SOW before kickoff.

At a glance

Categories, not named vendors. Ranges are indicative; final commercials follow scope.

DimensionBoutique specialistLarge audit firmPTaaS / platform
Tester seniority on the keyboardUsually high; small benchVariable; brand ≠ assigned teamMixed; often tooling-led with analyst review
Manual depth (authz, logic, chains)Strong when scoped tightlyStrong on paper; depth depends on hours boughtLimited for novel logic; good for known classes
Indicative price band (India)Transparent project quotes; see cost guideOften higher opener; package + change ordersSubscription / credit models
TurnaroundDays to a few weeks for small web/APIWeeks; calendar driven by firm capacityContinuous or on-demand scans
RetestUsually included in SOW windowConfirm; sometimes billed separatelyRe-scan; human retest varies
CERT-In empanelmentOften not claimed (verify always)Common among large firms (verify list)Usually not relevant
Best fitProduct SaaS, focused attack-path workRegulated RFPs that name empanelmentRegression / continuous known-issue coverage

What a year of testing costs

One engagement is not a programme. Buyers who need audit evidence plus ongoing product risk usually mix a deeper annual (or release-gated) manual test with lighter continuous checks. Indicative INR bands and cost drivers are published on penetration testing cost in India 2026. Use how to write a VAPT RFQ in India so vendors quote the same scope.

When a large empanelled firm is the right call

  • The RFP or customer contract explicitly requires a CERT-In empanelled auditor and will check the legal entity name.
  • Procurement needs a widely recognised brand for board or insurer comfort more than senior hands-on time on one product.
  • The scope is a broad enterprise programme (many apps, many owners) where programme management matters as much as a single deep test.

Even then: ask who tests, how many manual hours land on your highest-risk app, and what the retest looks like. Empanelment is a procurement attribute, not a measure of testing depth — see CERT-In empanelment.

When a boutique specialist is the right call

  • You need senior time on web, API, mobile, cloud or desktop/Electron attack paths within a clear SOW.
  • You want published pricing intent, a named retest window and reporting engineers can action.
  • Empanelment is not a contractual requirement (or you will separately engage an empanelled firm only for the badge work).

PoCForge (Cyber Security) is a Delhi NCR boutique in this category: human-led testing, remote-first with on-site across NCR when the scope needs it, and no CERT-In empanelment claim we do not have. Start from VAPT services in India or VAPT India.

When an automated / PTaaS platform is enough (and when it is not)

Platforms and continuous scanners are useful for regression of known vulnerability classes, backlog triage and keeping a baseline between deeper tests. They are not a substitute when the question is “can an attacker chain authz flaws across tenants?” or “what happens after an assumed foothold?” Pair them with manual work rather than replacing it. Background: penetration test vs vulnerability scan and how we test.

Questions people ask

Is Big-Four or large-firm VAPT always deeper?

No. Depth tracks hours, seniority and scope quality more than logo size. Ask for the assigned team and the manual-hour split on your critical apps.

Do I need CERT-In empanelment for SaaS selling to enterprises?

Often no. Many enterprise questionnaires accept a competent non-empanelled report. Empanelment matters when a contract or regulator names it. Verify the official list.

Can I use a boutique for the test and a large firm for the certificate?

Sometimes buyers split badge work from depth work. Make sure both scopes and data-handling rules are explicit so you do not pay twice for the same surface without a reason.

Where do PoCForge prices sit?

We publish indicative INR bands that sit slightly under many broad market package openers for comparable manual work. Final quotes follow scope. See the cost guide.

What should I put in the RFQ so quotes are comparable?

Assets, roles, environments, exclusions, retest window, report format, data handling and whether empanelment is mandatory. Use our RFQ guide.

Does this guide recommend a specific large firm?

No. It compares categories only. Named-competitor claims are out of scope for this page.

How we wrote this guide

This page summarises how Indian product and security buyers typically trade off empanelment, depth, price and reporting when shortlisting VAPT vendors. It uses categories (boutique / large audit firm / PTaaS), not named competitors. Pricing pointers link to our published cost guide rather than inventing metrics. Method and evidence standards for our own work are on How we test & write research.

What this guide cannot tell you

  • Which named vendor to hire — that depends on your contract, risk and chemistry with the assigned team.
  • Whether your specific RFP requires empanelment — read the contract and the official CERT-In list.
  • A single “best” price — scope drives cost; bands are indicative only.

Update log

  • 2026-10-07 — First draft published for review (draft status).

Related guides

VAPT India · VAPT services in India · CERT-In empanelled VAPT? · Cost in India · VAPT RFQ · Pentest vs scan · Methodology