VAPT Certificate: What It Is and When You Need One
A VAPT certificate is a short document from an independent tester confirming that a vulnerability assessment and penetration test was carried out on specific systems, and that identified issues were fixed or accepted. Companies use it to satisfy customers, regulators, tenders and app marketplaces without sharing the full technical report. Scantra issues one after every retest.
Last reviewed 2026-09-28 by the Scantra Security testing team
What a VAPT certificate includes
- Name of the organisation and systems tested
- Testing dates and methodology summary
- Statement of retest outcome
- Tester organisation details and CERT-In empanelment
- Signature and validity period
Who asks for a VAPT certificate
- Enterprise customers during vendor onboarding
- Government and PSU tenders
- Banks and sponsor banks for fintech partners
- App marketplaces and platform partners
- Insurers assessing cyber risk
How long is it valid?
There is no single legal validity period. Most customers and regulators expect testing within the last twelve months, or since the last major change. The certificate states the test dates so readers can judge freshness.
Certificate vs report
The report is detailed and sensitive. The certificate is a summary safe to share externally. Some customers ask for both, in which case the full report is often shared under NDA.
How to get one
1. Scope and test
Complete a VAPT engagement.
2. Fix findings
Remediate critical and high findings at minimum.
3. Free retest
We verify the fixes.
4. Certificate issued
Signed certificate on Scantra letterhead.
Frequently asked questions
Is a certificate issued if some issues remain?
Yes, but it will state which findings remain open or were accepted as risk.
Is your certificate from a CERT-In empanelled auditor?
Yes, Scantra Security is CERT-In empanelled.
Can I get a certificate without a test?
No. A certificate is only valid when based on a real test.
