The best way to choose a VAPT company in India is to compare person-days and manual testing ratio, not headline prices. Two quotes for the same application routinely differ by a factor of seven, and the gap almost always comes down to whether senior humans are testing your application or a scanner is generating a report.

The Indian VAPT market ranges from dedicated offensive security firms with published research to consultancies where security testing is one line in a broad services portfolio. This guide covers how to tell them apart, the five questions that shortlist for you, and the red flags worth walking away from.

Decide What You Are Actually Buying First

Before you contact anyone, settle three things. Vendors will scope around whatever you leave vague.

  • Which framework, if any, is driving this? A test for SOC 2 or ISO 27001 has different documentation and retest requirements than a test you are running because a release worried you. PCI-DSS is more prescriptive still.
  • What is in scope? Applications, APIs, network, cloud configuration, mobile. APIs are the most commonly under-scoped, and increasingly where the real risk sits.
  • Authenticated or unauthenticated? Most genuine risk lives behind a login. Unauthenticated-only testing is cheaper and tells you much less.

A vendor who gives you a price before asking these questions is quoting a template, not your environment.

The Five Questions That Shortlist For You

Hand-drawn diagram of five questions to ask a VAPT company in India — manual percentage, person-days, retest, certifications held and sample report

1. What percentage of the engagement is manual?

This single answer explains most price variation. Automated scanning is machine time; manual testing is senior human time. Only the second finds business logic flaws, chained privilege escalation and authorisation failures — which are precisely the categories that dominate the OWASP Top 10:2025.

If the answer is vague, you are buying a scan with a cover page. That is a legitimate product at the right price; it is not what most compliance controls specify.

2. How many person-days, and at what seniority?

This is the honest way to compare two very different numbers. A ₹90,000 quote and a ₹6,00,000 quote stop being mysterious once you learn one is two days of junior time and the other is nine days across two senior testers.

3. Is the retest included, and how many rounds?

The most commonly excluded line item, and the one your auditor will ask for. A test without a retest proves you looked. It does not prove anything was fixed. Get the answer in writing before signing.

4. What certifications do the actual testers hold?

Note the wording — the testers, not the firm. OSCP, OSWE and similar hands-on offensive credentials are the relevant signal here. A company's ISO 27001 certificate says something about how it runs itself, not about whether its people can break into your application.

5. Can I see a redacted sample report?

This tells you more than any proposal. Read the remediation guidance specifically: is it precise enough for one of your engineers to act on without a follow-up call, or is it generic advice lifted from scanner output? A firm confident in its reports will share one.

Reading a Proposal

How to choose a VAPT company in India — criteria, red flags and questions that matter

Green flags: retest priced in rather than quoted separately · named testers with hands-on offensive certifications · a redacted sample report offered without being asked twice · questions about your compliance framework before any number is given · same-day escalation of critical findings written into the process.

Red flags: a quote arriving before a scoping call · a promised "certificate in 48 hours" · no stated split between manual and automated work · a price far below every other quote you have received · reluctance to name who will do the testing.

That last one deserves emphasis. Many firms subcontract or use a partner network. That is not inherently a problem — plenty of good work is delivered that way — but you should know who is doing it, what they are certified in, and who carries the liability. Ask directly and note whether the answer is straight.

Types of Provider in the Indian Market

TypeStrongest forWatch for
Dedicated offensive security firmsDeep manual testing, published vulnerability research, complex applicationsOften priced at the top of the market; may not help you remediate
Compliance-led consultanciesAudit-ready documentation, framework mapping, evidence packagesTesting depth varies — ask the manual percentage question
Cloud and DevOps partnersTesting plus remediation, and fixing root causes in the pipelineConfirm who performs the offensive testing and their credentials
Large system integratorsEnterprise programmes, multi-year engagementsGenerally oversized and slow for a single application test
Low-cost scan providersFast, cheap coverage of known CVEsRarely satisfies a control that specifies penetration testing

None of these is the right answer universally. A fintech preparing for PCI-DSS wants the first or second. A team that keeps finding the same class of issue every year needs the third, because the problem is not detection.

Where SquareOps Fits

We are an AWS Advanced Tier Services Partner and ISO 27001 certified, and our VAPT services are delivered alongside the infrastructure work — cloud security, DevSecOps and the pipeline controls that stop findings recurring.

That combination is the honest differentiator. Most testing firms hand you a report and leave; most consultancies cannot fix what a test finds. If your findings keep repeating year on year, the value is in remediation and prevention rather than in another report.

We are a reasonable fit if you are on AWS, need testing tied to a compliance deadline, and want the same team to close the findings.

We are not the right choice if you specifically want a boutique offensive research house with a published CVE record — those firms exist in this market and they are the honest answer for adversary-simulation work at the top end.

Budgeting Realistically

Manual web application testing in India generally starts around ₹40,000 and runs to ₹2,00,000 for a single application, with mid-sized applications plus APIs typically ₹1,50,000 to ₹3,50,000 and compliance-grade engagements higher. Our full breakdown of VAPT cost in India covers what each band buys.

The cheapest quote is frequently the most expensive outcome — a scan that passes the compliance checkbox and misses the authorisation flaw leaves you with a certificate and the vulnerability.

A Sensible Selection Process

  1. Write your scope down before contacting anyone, including framework and authentication.
  2. Approach three to five providers across at least two of the categories above.
  3. Ask all five questions and record the answers side by side.
  4. Request sample reports and compare remediation quality, not page count.
  5. Compare person-days at seniority, not totals.
  6. Confirm retest and certificate timing in the contract, not the proposal.

If you want your scope reviewed against what your auditor or customer is actually asking for, explore our VAPT services or talk to our team. We will tell you what a realistic engagement looks like for your estate — including when a different type of provider would serve you better.

Related reading: what a VAPT audit covers and AWS Security Agent vs manual penetration testing.