On this page
- How we chose these VAPT companies
- 1. Summit
- 2. Payatu
- 3. Kratikal
- 4. Network Intelligence
- 5. CyberNX
- VAPT companies in India compared
- How to choose a VAPT company in India
- What VAPT should cover for most Indian businesses
- Does location matter when choosing a VAPT company?
- CERT-In empanelment explained
- How VAPT is priced in India
- Questions to ask on the first call
- Red flags when choosing a VAPT provider
- What a typical VAPT engagement looks like
- Deliverables to expect from any VAPT provider
- Why teams choose Summit
- Frequently asked questions
Disclosure
This list is published by Summit, one of the companies on it. We have tried to describe every provider fairly, using information from their own websites, and to be clear about where another firm may suit you better. Credentials such as CERT-In empanelment change, so verify them directly before you decide.
How we chose these VAPT companies
There are hundreds of firms offering VAPT in India, from individual consultants to large consultancies. We focused on providers that publicly offer vulnerability assessment and penetration testing as a core service, serve Indian businesses, and publish enough about their services and credentials to compare. We then looked at five criteria that matter to buyers:
- Depth of manual testing
- How much of the work is done by skilled testers rather than automated scanners
- Coverage
- Web, API, mobile, network, cloud and other specialist areas
- Credentials
- CERT-In empanelment, ISO certifications and similar, as stated by each provider
- Reporting and support
- Report quality, compliance mapping, remediation help and retesting
- Fit
- The type of client each provider is best suited to
1. Summit
Based in: New Delhi (Okhla Industrial Estate) · Website: sumrite.com
Summit is a penetration testing and security compliance firm that focuses on manual, human-led VAPT for SaaS companies, fintech and enterprise teams that need evidence for customers, auditors and regulators. Every finding is verified by a tester before it reaches the report, and scanner output is never sold as a penetration test.
Services
Web application VAPT, API security testing, mobile app VAPT, network VAPT, cloud security assessment, source code review, thick client VAPT, phishing simulations and red team operations.
Strengths
Manual testing with verified evidence, a VAPT report typically within 48 hours of testing finishing, quotes usually within 15 minutes, NDA before scope, and retesting of fixed findings included.
Compliance fit
Reports mapped to SOC 2, ISO 27001, PCI DSS, India DPDP and regional regimes in the Gulf, Europe and Australia.
Consider another provider if
A regulator or contract specifically requires an auditor on CERT-In's empanelled list. Summit does not claim CERT-In empanelment.
Best for: SaaS and technology companies that need fast, credible VAPT reports for SOC 2, ISO 27001, enterprise security reviews and DPDP readiness. See our services and a sample VAPT report.
2. Payatu
Based in: Pune · Founded: 2011
Payatu is a research-led security firm founded in Pune by the team behind the nullcon security conference, which also started hardwear.io. According to its website, Payatu is empanelled by CERT-In and describes itself as India’s first cybersecurity testing lab accredited to ISO/IEC 17025.
Services
Web, mobile and cloud security testing, secure code review, IoT and product security, AI/ML security audits, OT/ICS security, red team assessments and SOC services.
Strengths
Deep research culture and community presence, and unusual depth in hardware, IoT and embedded device testing.
Best for: Product companies with connected devices, hardware or complex technology, and organisations that want research-heavy testing.
3. Kratikal
Based in: Noida · Founded: 2013
Kratikal was founded in 2013 by students at MNNIT Allahabad and is headquartered in Noida, with offices in other Indian cities, the USA and the Middle East. Its website states that it was empanelled by CERT-In in 2021.
Services
VAPT for web, mobile and network, plus compliance audits including SOC 2, ISO 27001 and RBI IS audits.
Products
AutoSecT, an AI-driven pentest and vulnerability management platform, and ThreatCop for phishing simulation and security awareness.
Best for: Organisations that want CERT-In empanelled VAPT alongside security awareness and vulnerability management products from one vendor.
4. Network Intelligence
Based in: Mumbai · Founded: 2001
Network Intelligence is one of India’s longer-established security consultancies, founded in 2001 and based in Mumbai, with offices in the Middle East, Asia-Pacific, Europe and North America.
Services
Vulnerability assessment and penetration testing, security consulting and managed security services for enterprises.
Strengths
Long track record, international footprint and accreditation recognised by many global buyers.
Best for: Large enterprises and multinationals that want one provider across several countries and service lines.
5. CyberNX
Based in: Mumbai · Founded: 2019
CyberNX was founded in 2019 with a cloud-first security focus and operates a cyber defence centre in Mumbai. Its website states that it achieved CERT-In empanelment in 2023.
Services
Vulnerability assessment, penetration testing and red teaming, alongside managed detection and cloud security services.
Strengths
CERT-In empanelled testing combined with managed security, useful for organisations that want testing and monitoring from one partner.
Best for: Companies, particularly in regulated sectors, that need a CERT-In empanelled auditor and are also looking for managed security operations.
VAPT companies in India compared
- Summit
- New Delhi · manual VAPT for SaaS and compliance · retest included · not CERT-In empanelled
- Payatu
- Pune · research-led, strong in IoT and hardware · CERT-In empanelled (per its website)
- Kratikal
- Noida · VAPT plus security products · CERT-In empanelled (per its website)
- Network Intelligence
- Mumbai · enterprise consultancy · offices across the Middle East, Asia-Pacific, Europe and North America
- CyberNX
- Mumbai · VAPT with managed security · CERT-In empanelled (per its website)
How to choose a VAPT company in India
A list like this is a starting point. The right provider depends on why you need testing and what you are testing. These are the questions we would ask any provider, including us.
- Is CERT-In empanelment required? Check your regulator, government contract or customer requirement. If it is required, shortlist only firms on CERT-In’s current empanelled list. If it is not, focus on testing quality.
- Can I see a sample report? Look for real evidence for each finding, remediation specific to your technology, a clear executive summary and a retest section.
- Who will test, and how much is manual? Ask about the testers’ experience and certifications, and what proportion of time goes to manual testing.
- What methodology do you follow? Expect references to OWASP, NIST SP 800-115, PTES or similar, and authenticated, multi-role testing for applications.
- Is retesting included? You need evidence that findings were fixed, especially for SOC 2, ISO 27001 and customer reviews.
- How is my data protected? Expect an NDA, controlled handling of credentials and findings, and secure report delivery.
- Will the report work for my audience? If your auditor or customer expects a mapping to SOC 2, ISO 27001, PCI DSS or the DPDP Act, ask for it up front.
Watch out for cheap automated VAPT
Very low prices for large scopes usually mean an automated scan with a branded cover page. Scans have their place, but they miss broken access control and business logic flaws, the issues behind most serious data leaks, and enterprise buyers and auditors increasingly reject them as penetration test evidence. Our guide to what a VAPT assessment is explains the difference.
What VAPT should cover for most Indian businesses
SaaS and product companies
Web application and API testing with multiple roles and tenants, plus a cloud configuration review.
Fintech and lending
Application, API and mobile testing, plus checks against RBI and payment security expectations.
Healthtech and edtech
Applications and APIs holding sensitive and children's data, with DPDP Act safeguards in mind.
Enterprises
External and internal network testing, Active Directory, cloud and critical business applications.
If you are preparing for a specific framework, our guides to the SOC 2 VAPT report, ISO 27001 VAPT and the DPDP Act explain what each expects.
Does location matter when choosing a VAPT company?
India’s security testing market clusters in a few cities: Delhi NCR (Delhi, Noida and Gurugram), Mumbai, Bengaluru, Pune and Hyderabad. For most application, API and cloud testing, location matters far less than people expect, because testing is done remotely over the internet or a VPN, and reports and debriefs happen online.
Location does matter in a few cases:
- Internal network and physical testing, where testers may need to be on site or ship a testing device to your office
- Regulated or government work, where contracts may require data to stay in India or testers to be based in India
- Workshops and board briefings, which some teams prefer in person
- Time zones and language, which affect how easily you can reach the testers during the engagement
Summit is based in New Delhi and works remotely with clients across India and abroad. Payatu is in Pune, Kratikal in Noida, and Network Intelligence and CyberNX in Mumbai, and all of them also work with clients outside their home cities.
CERT-In empanelment explained
CERT-In, the Indian Computer Emergency Response Team, maintains a list of empanelled information security auditing organisations. Empanelment means the organisation has met CERT-In’s eligibility and technical evaluation for conducting security audits.
It matters in specific situations:
- Government ministries, departments and public sector organisations generally must use empanelled auditors
- Some regulators require it for certain audits, for example SEBI’s cybersecurity framework for cyber audits of regulated entities
- Some customer contracts and tenders specify it
It is not a general quality ranking, and it is not required for most private-sector testing, such as VAPT for SOC 2, ISO 27001, enterprise customer reviews or DPDP readiness. Many strong firms are empanelled and many strong firms are not. If you need it, check the provider’s name on the current list on CERT-In’s website rather than relying on a badge.
How VAPT is priced in India
Providers quote in different ways, which makes comparison hard. The common models are:
Fixed price per scope
A set fee for a defined set of applications, APIs or IP ranges. Easiest to compare and budget; make sure the scope document is specific.
Per tester-day
A day rate multiplied by estimated effort. Transparent about effort, but the total depends on the estimate.
Per asset or per IP
Common for network testing. Watch for very low per-IP prices, which usually mean automated scanning.
Annual programme
A yearly fee covering scheduled tests, retests and sometimes continuous scanning. Useful once testing is routine.
Whatever the model, ask the same three questions: how many days of manual testing are included, is a retest included, and what exactly is out of scope.
Questions to ask on the first call
- What do you need from us to scope this accurately?
- Which of your testers would work on our engagement, and what have they tested before?
- How do you test multi-tenant access control in SaaS applications?
- How do you handle production testing safely?
- What does your report look like, and can we see a redacted sample?
- How quickly can you start, and when would we receive the report?
- What happens if we disagree with a finding’s severity?
Red flags when choosing a VAPT provider
- A quote before they understand your scope
- No sample report, or a sample that is plainly scanner output
- Promises of “zero false positives” or “100% coverage”
- No NDA or vague answers about how your data and credentials are handled
- Retests charged at full price, or not offered at all
- Pressure to buy unrelated products as part of the test
What a typical VAPT engagement looks like
Whichever provider you choose, a well-run engagement for a single web application and API usually follows this rhythm:
Day 0: scoping and NDA
Share asset details, roles and environment. Receive a written scope, quote and rules of engagement.
Days 1 to 2: kick-off and access
Test accounts, VPN or allowlisting, and a named contact on each side.
Days 2 to 8: testing
Reconnaissance, scanning and manual testing. Critical issues are reported immediately, not held for the report.
Report delivery
Executive summary and detailed findings, followed by a debrief call with the testers.
Remediation and retest
Your team fixes the findings, then the provider retests and issues updated results or a retest letter.
Deliverables to expect from any VAPT provider
- A written scope and rules of engagement before testing starts
- Immediate notice of critical findings during testing
- A report with an executive summary, methodology, evidence-backed findings and specific fixes
- A debrief call with the people who did the testing
- A retest of fixed findings with updated status
- On request, an attestation letter you can share with customers, and a mapping to the framework you are working towards
Why teams choose Summit
- Manual testing by experienced testers, with every finding verified and evidenced
- Reports written for three readers: leadership, engineers and auditors
- Fast turnaround: quotes usually within 15 minutes and a report typically within 48 hours of testing finishing
- NDA before scope, and retesting of fixed findings included
- Compliance mapping for SOC 2, ISO 27001, PCI DSS, DPDP and regional regimes
- Based in New Delhi, working with clients across India and worldwide
Compare us on your own scope
Send us what you need tested and we will return a fixed scope and quote, with a sample report so you can compare like for like. Get a quote or explore our services.
Frequently asked questions
Which is the best VAPT company in India?
There is no single best provider for everyone. The right choice depends on what you need tested, whether a regulator requires a CERT-In empanelled auditor, your budget, and how much manual testing and support you need. Compare providers on sample reports, tester experience, methodology and whether retesting is included.
Do I need a CERT-In empanelled company for VAPT?
Only when a regulator, government body or contract requires it, for example some audits for government entities and regulated financial institutions. Many private companies need VAPT for SOC 2, ISO 27001 or customer due diligence, where CERT-In empanelment is not required. Check your specific requirement and CERT-In's current empanelled list.
How much does VAPT cost in India?
Prices depend on scope: the number of applications, APIs, mobile apps and hosts, testing depth and whether a retest is included. Ask several providers to quote against the same written scope, and ask how much of the effort is manual testing rather than automated scanning.
How long does a VAPT take?
A single web application or API typically needs three to ten working days of testing, plus reporting and a retest after fixes. Larger scopes such as internal networks or multiple applications take longer.
What should a VAPT report from an Indian provider include?
An executive summary, scope and dates, methodology, each finding with severity, evidence and specific remediation, a findings summary and a retest section. If you need it for compliance, ask for a mapping to the relevant framework, such as SOC 2, ISO 27001 or RBI guidelines.