CERT-In penetration testing

CERT-In Penetration Testing

CERT-In penetration testing usually means a penetration test that helps an Indian organisation meet CERT-In guidelines and directions, or a test requested by a regulator or customer that names CERT-In. Some government and regulated buyers specifically require the test to be performed by a CERT-In empanelled auditor, so check your requirement before you choose a provider.

Scantra Security delivers penetration tests with reports aligned to CERT-In guidance. Ask us on the call whether your requirement needs an empanelled auditor.

  • Manual, expert-led testing
  • CVSS-rated report with fixes
  • Retest after you fix
  • Written scope before work starts

Talk to our Security Experts

Tell us what needs testing, then pick a 30-minute slot.

Get a tailored scope, timeline and pricing on the call.

What CERT-In expects from organisations

CERT-In's April 2022 directions require organisations to report specified cyber incidents within six hours, synchronise system clocks, and keep logs for 180 days, among other obligations. Regular vulnerability assessment and penetration testing is the practical way to show security controls are working.

Empanelled vs aligned

A CERT-In empanelled auditor is on CERT-In's published list. Some tenders, government projects and regulators require one. Many private customers and auditors only need a competent third-party test with a clear report. Confirm which you need, ideally in writing, before you start.

Requirements Indian businesses usually test for

In India, the trigger for a test is often regulatory. RBI expects regulated entities and their technology vendors to run periodic VAPT. SEBI's cybersecurity framework asks market intermediaries for regular testing. CERT-In directions require organisations to maintain security practices and report incidents. The Digital Personal Data Protection (DPDP) Act 2023 requires reasonable security safeguards for personal data.

Enterprise customers also ask vendors for a recent third-party pentest report during security reviews. We write reports so the same document can be shared with a regulator, an auditor or a customer's security team.

How the engagement runs

  1. 1. Scoping call (30 minutes)

    We agree targets, user roles, environments, testing windows and the compliance reason for the test.

  2. 2. Written scope and quote

    You get a scope document and an INR or USD quote based on the real size of the work.

  3. 3. Discovery and manual testing

    Automated tooling for coverage, then manual testing of authentication, access control and business logic.

  4. 4. Report

    Executive summary, CVSS-rated findings with evidence, reproduction steps and remediation guidance.

  5. 5. Retest

    Once your team ships fixes, we verify each finding and issue an updated report.

What the report contains

  • Executive summary for leadership, customers and auditors
  • Findings rated by CVSS severity with screenshots and request evidence
  • Step-by-step reproduction for your developers
  • Specific remediation guidance, not generic advice
  • Compliance mapping (ISO 27001, SOC 2, PCI DSS, RBI, SEBI, CERT-In guidelines) where relevant
  • Retest status showing which findings are open and closed

Certifications our testers hold

Every engagement is led by a certified senior tester.

OSCP. Offensive Security Certified Professional
OSCP
OSWE. Offensive Security Web Expert
OSWE
CEH. Certified Ethical Hacker
CEH
eJPT. Junior Penetration Tester
eJPT
CREST. CREST Penetration Testing
CREST
CRTP. Certified Red Team Professional
CRTP
CISSP. Certified Information Systems Security Professional
CISSP
CNSP. Certified Network Security Practitioner
CNSP

Frequently asked questions

Is Scantra CERT-In empanelled?

Ask us on the scoping call about your specific requirement, and check CERT-In's published list for any provider you consider.

How much does it cost?

Price depends on the number of targets, user roles and depth of manual testing. Use the VAPT cost estimator for an INR range, or book a call for a written quote.

Related services

Get started

Ready to find what attackers will?

Talk to a senior pentester. Get a tailored scope, sample report and timeline within 24 hours.