Fraud Alert
Network Security Testing Company in India: Three Services, One Label, and How to Tell Them Apart in 2026

Network Security Testing Company in India: Three Services, One Label, and How to Tell Them Apart in 2026

Share

"Network security testing company in India" describes at least three different businesses. Some firms run automated scans across your IP ranges and return a tool export. Some run manual penetration tests that exploit what a scanner only flagged, to prove which weaknesses an attacker could actually chain together. Some sell managed detection and response, a continuous monitoring service with no end date. All three rank for the same search, and all three will happily quote you for "network security testing." Buyers who skip the taxonomy end up comparing three incompatible proposals on price alone, and then paying for work they did not need.

Where this sits: a standalone buyer's guide within Vervali's testing and QA coverage, anchored to network security testing services in India. It covers vendor selection at the network and infrastructure layer. For the wider discipline this sits inside, including application, API and compliance testing, see Vervali's security testing services.

What You'll Learn

  • How NIST, CIS and ISO independently draw the same line between scanning, penetration testing and continuous detection

  • Why CERT-In, RBI, SEBI and IRDAI each mandate something different, and how that fragmentation shows up in your quotes

  • The eleven items you can verify about a vendor before signing, including one binary public check

  • Why no independent price benchmark exists for Indian VAPT, and what actually drives the number you are quoted

Metric Value Source
Cyber incidents CERT-In handled in 2025 29.44 lakh PIB, Government of India, Jan 2026
RBI minimum vulnerability assessment frequency, critical and DMZ systems Once every 6 months RBI IT Governance Directions, 2023
RBI minimum penetration test frequency, same systems Once every 12 months RBI IT Governance Directions, 2023
SEBI remediation window after a VAPT report 3 months, graded by criticality SEBI CSCRF, Aug 2024
SEBI window for high-severity unpatched vulnerabilities 1 week SEBI CSCRF FAQ, Jun 2025
CERT-In cyber incident reporting window 6 hours from notice CERT-In Directions, Apr 2022
CERT-In ICT log retention, held in Indian jurisdiction 180 days rolling CERT-In Directions, Apr 2022
DPDP reasonable-security-safeguard rules commence 13 May 2027 MeitY, DPDP Rules 2025
Independent published price benchmark for Indian VAPT None located Vervali research, July 2026

What "Network Security Testing" Actually Means in Three Different Contracts

The three services are separated at the standards level, by three bodies that never coordinated on it.

NIST Special Publication 800-115, still the current version of the U.S. federal standard and the document that replaced the older SP 800-42 "Guideline on Network Security Testing," files vulnerability scanning and penetration testing under two different chapters of its own taxonomy. Scanning is a target identification and analysis technique. Penetration testing is a target vulnerability validation technique. NIST states the difference plainly: "While vulnerability scanners check only for the possible existence of a vulnerability, the attack phase of a penetration test exploits the vulnerability to confirm its existence."

The Center for Internet Security reaches the same split from a different direction. Control 7, Continuous Vulnerability Management, asks organisations to "develop a plan to continuously assess and track vulnerabilities on all enterprise assets within the enterprise's infrastructure, in order to remediate, and minimize, the window of opportunity for attackers." Control 18, Penetration Testing, asks something else entirely: "Test the effectiveness and resiliency of enterprise assets through identifying and exploiting weaknesses in controls (people, processes, and technology), and simulating the objectives and actions of an attacker." Two of eighteen top-level controls, eleven numbers apart.

ISO/IEC 27002:2022 folds technical vulnerability management into a single control, 8.8, which consolidated two separate 2013-edition controls. Its guidance names scanning tools and documented penetration tests as distinct activities inside that one control. The practical consequence for a buyer is worth sitting with: a vendor can hold a valid ISO 27001 certificate while running only scans, only penetration tests, or both, and the certificate itself will not tell you which.

The third category has a different kind of anchor. Managed detection and response is not periodic assessment at all, and India's own regulator treats it separately. The CERT-In Directions of 28 April 2022 require organisations to "mandatorily enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days," held within Indian jurisdiction, and to report listed cyber incidents "within 6 hours of noticing such incidents." The first item on that mandatory-reportable list is "Targeted scanning/probing of critical networks/systems." You cannot report within six hours what you were not watching for continuously, and no annual penetration test produces that capability.

Automated vulnerability scanning Penetration testing Managed detection and response
What you receive A list of known weaknesses found across your assets Evidence of which weaknesses an attacker can chain into real access Alerts and response actions against live attacker activity
Standards anchor CIS Control 7; NIST SP 800-115 §4.3 CIS Control 18; NIST SP 800-115 §5.2; PTES seven phases CERT-In 180-day logs and 6-hour incident reporting
Natural cadence Continuous or quarterly Annual for most estates, half-yearly for regulated critical systems Always on
Priced against Count of live IPs, hosts and applications Days of skilled tester time and depth of scope Monthly, per asset or per volume of log data
Fails when Findings arrive with no environmental context The report reads like a scanner export with a cover page Alerts fire with nobody rostered to act on them

Key Finding: "While vulnerability scanners check only for the possible existence of a vulnerability, the attack phase of a penetration test exploits the vulnerability to confirm its existence." Source: NIST SP 800-115, Section 5.2.1.

Four Regulators, Four Answers, and Why Your Quotes Do Not Match

Ask three Indian vendors what cadence you need and you may get three defensible answers, because four regulators say four different things to overlapping populations. A listed bank answers to RBI and SEBI at once. Nobody's single rulebook resolves that for you.

Regulator Instrument Testing cadence it actually sets What it does not settle
CERT-In (MeitY) Directions under Section 70B, No. 20(3)/2022, dated 28 April 2022 None. It sets 6-hour incident reporting, 180-day ICT log retention inside India, and 20 reportable incident categories Sets no vulnerability assessment or penetration test frequency at all
RBI IT Governance, Risk, Controls and Assurance Practices Directions, 2023, in effect from 1 April 2024 VA at least once every six months and PT at least once in 12 months, for critical information systems and DMZ systems with customer interface Excludes Local Area Banks and NBFC-Core Investment Companies from scope
SEBI CSCRF circular dated 20 August 2024, plus the official June 2025 FAQ VAPT twice yearly for protected systems and CII, once yearly for other regulated entities; cyber audit twice yearly for MIIs and Qualified REs; Qualified Stock Brokers half-yearly regardless of category Uses different entity categories for VAPT than for cyber audit, which is a common source of scoping error
IRDAI Information and cyber security guideline regime; the 7 April 2017 base guideline was extended to all insurance intermediaries on 2 September 2022 No single published VA or PT frequency comparable to RBI's numeric mandate Which version is current is ambiguous in the public record; insurers should confirm the operative text with the regulator directly

RBI's language is the most quotable because it is the most numeric: "For critical information systems and/ or those in the De-Militarized Zone (DMZ) having customer interface, VA shall be conducted at least once in every six months and PT at least once in 12 months." The same Direction adds a clause buyers routinely miss, requiring assessment "throughout their lifecycle (pre-implementation, post implementation, after major changes, etc.)." A vendor quoting you two calendar events per year has not read that clause.

SEBI attaches deadlines to the findings rather than only to the test. Vulnerabilities must be closed within three months of report submission on a graded approach, and high-severity items traced to unpatched software carry a one-week patch window. A proposal that ends at report delivery, with retesting priced as a change request, will not survive that timetable.

Minimum mandated security assessments per year by Indian regulator - Source: RBI IT Governance Directions 2023 and SEBI CSCRF 2024

One deadline sits ahead of all of this and is widely misdescribed. The Digital Personal Data Protection Rules 2025 were notified by gazette G.S.R. 846(E) on 13 November 2025, and MeitY's own commencement clause staggers them: some rules took effect on publication, Rule 4 on consent managers takes effect one year later, and the substantive data-fiduciary obligations take effect "eighteen months after the date of publication of this Gazette." That lands on 13 May 2027. Rule 6, which specifies what reasonable security safeguards actually mean under Section 8(5), sits in that final tranche. Any vendor telling you today that DPDP already requires a penetration test is selling you urgency that the gazette does not support. The accurate framing is a runway: you have until May 2027 to have the controls, the evidence trail and the testing cadence in place.

Watch Out: Vendor content across this category routinely presents DPDP security obligations as already binding, and badges NIST SP 800-115 as a 2026 document when it was published in September 2008 and has never been replaced. Both errors are easy to check, and a vendor who makes them in marketing will make them in a compliance report.

The Threat India Faces Is a Scanning Problem First

CERT-In handled 29.44 lakh cyber incidents during 2025 and issued 1,530 alerts, 390 vulnerability notes and 65 advisories across the same year, per the Press Information Bureau. Government-sourced reporting of the underlying breakdown puts unauthorised network scanning and probing at close to 83 percent of that total, which would make automated reconnaissance more common than defacement, phishing and malware combined by a wide margin.

That distribution has a direct procurement consequence. Reconnaissance against your perimeter is continuous and automated, so the control that meets it has to be continuous too. An annual penetration test tells you how deep a skilled human could get on one week in one quarter. It says nothing about the new host somebody exposed six weeks later.

NIST reached the same conclusion from the cost side rather than the threat side: "Because of its high cost and potential impact, penetration testing of an organization's network and systems on an annual basis may be sufficient," paired with the recommendation that "a well-designed program of regularly scheduled network and vulnerability scanning, interspersed with periodic penetration testing, can help prevent many types of attacks and reduce the potential impact of successful ones." Scanning carries the frequency. Penetration testing carries the proof. Buying one and calling it the other is the single most expensive mistake in this category.

Pro Tip: Write the cadence into the statement of work as two separate line items with two separate deliverables, then price them separately. A single blended "VAPT" line is the wrapper that lets a scan-only engagement pass as a full assessment, and you will not discover the difference until the report lands.

The Rubric: Eleven Things You Can Verify Before You Sign

Most of this category's evaluation advice is subjective. These items are not.

What to check What a credible answer looks like
CERT-In empanelment The vendor's exact legal entity appears on the live list at cert-in.org.in. Verify it yourself rather than accepting a logo
Which category is in scope The SOW names scanning, penetration testing or monitoring explicitly, with separate deliverables for each
Named methodology PTES phases, OWASP WSTG for the application and API layer, or NIST SP 800-115, cited by name and mapped to your scope
Sanitized sample report Provided before contract, not after
Finding prioritisation Severity triaged against your environment and business impact, not a raw CVSS export
Retest and closure Included in the base price with committed dates that fit your regulator's remediation window
Named lead tester Identified with certifications before you sign, not staffed after
Data residency Report, evidence and logs stay in Indian jurisdiction where CERT-In's 180-day rule applies
Lifecycle coverage Pre-implementation and post-major-change testing included, per RBI's lifecycle clause
Escalation terms A defined route for a critical live-system finding mid-engagement, with safe-harbour language
AI tooling disclosure If the vendor uses AI-assisted tooling, how your data is handled inside it

Empanelment deserves a note because it is the one binary check available to you. CERT-In runs a four-stage empanelment process covering documentation review, an offline practical skill test, a dedicated VA and PT practical skill test, and a personal interaction session at CERT-In headquarters, with the 2026 application window open from 1 July to 30 September 2026. The empanelled list is published openly and describes itself as "up-to-date" and "updated by us as soon as there is any change in it." A claim of empanelment that the current list does not carry ends the evaluation.

The list has grown considerably since 2022, which cuts both ways. Empanelment is the floor for regulated work, and it no longer separates the firms standing on it. The rest of the rubric does that.

The AI row is newer than the others. The World Quality Report 2025-26 found data privacy risk cited by 67 percent of respondents as a top challenge in adopting AI for quality engineering, ahead of integration complexity at 64 percent. If your assessment vendor pipes your network topology through a third-party model, that is a data-processing question worth asking at procurement.

Five Answers That Should End the Conversation

A quote arrives before scoping. Nobody can price host coverage they have not counted. A number produced from a two-line email describes the vendor's standard package rather than your estate.

Empanelment is claimed but not listed. The list is public and current. This is a thirty-second check with a binary outcome.

The sample report is refused. A sanitized report from a past engagement reveals prioritisation quality, remediation specificity and whether a human wrote the analysis. Refusal usually means the report is a tool export.

"VAPT" is sold as one indivisible product. Scanning and penetration testing have different labour models, different cadences and different outputs. A vendor unwilling to separate them in the SOW is protecting a margin that depends on you not looking.

Data residency gets a vague answer. If a vendor cannot state where your findings, evidence and logs will be stored, they have not read the CERT-In Directions, and their report will not help you evidence compliance to anybody.

Cost, Engagement Models, and Why Nobody Publishes an Honest Price

There is no independent price benchmark for network security testing in India. That is the finding rather than a gap in this article. Every rupee figure in circulation traces back to a vendor's own marketing page, which is sellers pricing their own category. Cross-checking the most-cited pricing pages produced further drift: figures attributed to one well-known Indian vendor in secondary write-ups do not match what that vendor's own page states. Treat any published band as positioning.

What moves the number is knowable, and you can estimate it yourself:

  1. Live host and IP count in scope, which is the primary driver for scanning work

  2. Internal perimeter, external perimeter, or both, since internal testing needs access provisioning and coordination

  3. Credentialed versus uncredentialed, which changes depth substantially

  4. Days of manual tester time, the dominant cost in real penetration testing

  5. Retest included or billed separately, which matters enormously against SEBI's three-month closure window

  6. Evidence depth required by your regulator, since audit-grade documentation costs more to produce than an engineering summary

Engagement structure follows the category. Project work suits a scoped annual penetration test with a fixed deliverable. Retainers suit continuous scanning, where the value is cadence rather than a one-off report. An embedded team suits organisations releasing frequently, where security testing has to move at pipeline speed instead of arriving quarterly. Our breakdown of QA outsourcing pricing and engagement models in India covers the commercial mechanics of each, and the dedicated software development teams model shows how the embedded structure works in practice.

What India's Security Testing Market Looks Like Going Into 2027

The supply side is expanding faster than buyer sophistication, which is the underlying reason a taxonomy is worth this much of your time. Data Security Council of India research reported by Business Standard in December 2025 put India's cybersecurity product companies on track for close to 6 billion dollars in revenue during 2026, up from 4.46 billion dollars in 2025, with more than 400 such companies growing at a 34 percent compound annual rate over five years from a combined 1.05 billion dollars in 2020.

India cybersecurity product company revenue 2020 to 2026 - Source: DSCI research reported by Business Standard, December 2025

Those figures cover product companies, while most buyers of network security testing transact on the services side, so read them as direction rather than a services benchmark. Capital and headcount are entering the category quickly, credentials are becoming more common rather than scarcer, and the gap between two similarly-credentialed vendors is widening. Market-size estimates for Indian cybersecurity overall diverge across research firms by nearly a factor of two for the same year, so carry the attribution with any headline number you quote. The structure of India's delivery market, including vendor tiers and buyer economics, is covered in our analysis of India's software testing outsourcing market.

Sector Patterns That Change the Scope

Banking, NBFCs and capital markets carry the heaviest overlap. A listed bank sits inside RBI's six-month VA and twelve-month PT mandate and SEBI's CSCRF cadence simultaneously, with different entity categories applying to each. The practical answer is one consolidated testing calendar mapped against both instruments, rather than two uncoordinated engagements that duplicate scope and still leave a gap.

Healthcare and diagnostics buyers usually arrive with a mix of Indian obligations and international ones, since patient data flowing to overseas partners pulls HIPAA and FDA 21 CFR Part 11 expectations into scope alongside domestic rules. Vervali's healthcare compliance testing work addresses that combination directly.

E-commerce and payments scope is dominated by PCI DSS and by an internet-facing estate that is usually larger and more volatile than internal teams estimate. Scanning cadence matters more here than almost anywhere, since the attack surface changes with every release. Compliance testing against PCI DSS, ISO 27001 and SOC 2 generally runs as a separate workstream from the network assessment.

Public systems and critical infrastructure operators face CERT-In's protected-systems regime and the highest evidentiary bar of any group here. Log retention inside Indian jurisdiction stops being a preference and becomes a design constraint on where your assessment vendor is permitted to store anything.

Connected-device estates break the standard scoping model. An OT or IoT segment expands host counts well past what an application-focused scope anticipates, and it needs its own conversation about what can safely be scanned in production at all.

Where Vervali Fits This Taxonomy, and Where It Does Not

Applying this article's own rubric to Vervali is the fairest way to close it.

Vervali is trusted by 200 or more product teams across 15 countries, and its security work sits inside the QA lifecycle rather than arriving as a standalone annual event. Its service architecture reflects the taxonomy argued here: the security testing practice names ten separate sub-disciplines, among them vulnerability testing, network security testing, application security testing, API security testing and compliance testing, each scoped as its own engagement instead of blended into one product. Its published guidance recommends running network security testing at least quarterly or whenever network infrastructure changes materially, matching the cadence logic the regulators and NIST both reach.

The directly demonstrable capability sits at the application and interface layer. Vervali's API testing services identify authentication, authorization and encryption vulnerabilities through OWASP-aligned and fuzz testing, which is security testing embedded in a delivery pipeline rather than bolted onto the end of one. Vulnerability assessment and testing maps to the first category in the taxonomy above.

Now the limits. On Clutch, where reviews are verified through client interviews rather than self-submitted, Vervali holds 4.7 out of 5 across 10 reviews, with a service mix weighted toward application testing at 40 percent and cybersecurity at 10 percent. That is the profile of an application testing and engineering firm with a security testing line, which is a different purchase from a dedicated offensive security house holding CERT-In empanelment for statutory audit work. If you need a red-team engagement or an audit signed by an empanelled auditor, the rubric above is how to evaluate that vendor, and Vervali's penetration testing service page is where to start a scoping conversation about where the boundary falls.

The same discipline applies to case studies, including ours. Vervali's India delivery record includes a Mumbai-based scheduled commercial bank's mortgage operations platform, where integration across identity verification and core lending systems delivered 100 percent compliance and cut agent onboarding time by 50 percent, and a Chennai-based diagnostics provider's booking and reports platform, where page load improved by up to 40 percent and development cycles shortened by 30 to 40 percent. Both are functional QA and engineering engagements. Neither is a network penetration test, and presenting them as security proof would fail the sample-report test this article just asked you to apply to everyone else. Internationally, Vervali built and tested an Australian AI-driven cybersecurity validation platform, holding 99.9 percent stability during high-intensity DDoS simulation and cutting vulnerability validation time by 60 percent. That was QA of a security product owned by the client rather than an attack against anyone's live network, and buyers should insist on hearing that distinction drawn by every vendor they shortlist.

TL;DR: Decide which of the three categories you are buying before you request a single quote. Scanning carries the cadence, penetration testing carries the proof, and detection carries the six-hour clock. Check CERT-In empanelment against the live list, demand a sanitized sample report, and confirm retesting is inside the base price against your regulator's closure window. Ignore published price bands, since none of them come from an independent survey. Treat DPDP as a 13 May 2027 deadline you are preparing for, and treat any vendor who calls it a present-tense requirement as having told you something useful about their research.


Ready to Scope Your Network Security Testing Properly?

Vervali's testing teams work with 200 or more product teams across 15 countries, running security testing continuously inside the QA lifecycle instead of once a year. Explore network security testing services in India or schedule a consultation to map your regulatory cadence to a testing calendar that fits it.

Related reading: buyers evaluating vendors across GCC markets can compare the regulatory approach used here against our guide to VAPT and compliance frameworks for UAE enterprises.

Sources

  1. Scarfone, K., Souppaya, M., Cody, A., Orebaugh, A. (2008). "NIST Special Publication 800-115: Technical Guide to Information Security Testing and Assessment." National Institute of Standards and Technology. https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf

  2. CERT-In, Ministry of Electronics and Information Technology (2022). "Directions under sub-section 6 of section 70B of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In." https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf

  3. CERT-In. "Empanelment of Information Security Auditing Organisations." https://www.cert-in.org.in/s2cMainServlet?pageid=CERTEMPANEL

  4. CERT-In. "Empanelled Information Security Auditing Organisations." https://www.cert-in.org.in/PDF/Empanel_org.pdf

  5. Reserve Bank of India (2023). "Reserve Bank of India Information Technology Governance, Risk, Controls and Assurance Practices Directions, 2023." https://www.rbi.org.in/scripts/BS_ViewMasDirections.aspx?id=12562

  6. Securities and Exchange Board of India (2024). "Cybersecurity and Cyber Resilience Framework for SEBI Regulated Entities," circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, and the official CSCRF FAQ, June 2025. https://www.sebi.gov.in/legal/circulars/aug-2024/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html

  7. Ministry of Electronics and Information Technology (2025). "Digital Personal Data Protection Rules, 2025," gazette notification G.S.R. 846(E), 13 November 2025. https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025

  8. Insurance Regulatory and Development Authority of India (2022). "Guidelines on Information and Cyber Security," Ref. IRDAI/GA&HR/GDL/MISC/184/09/2022. https://irdai.gov.in/document-detail?documentId=1354286

  9. Center for Internet Security. "CIS Critical Security Control 7: Continuous Vulnerability Management." https://www.cisecurity.org/controls/continuous-vulnerability-management

  10. Center for Internet Security. "CIS Critical Security Control 18: Penetration Testing." https://www.cisecurity.org/controls/penetration-testing

  11. Press Information Bureau, Government of India (23 January 2026). CERT-In cyber incident statistics for 2025. https://pib.gov.in/PressReleasePage.aspx?PRID=2217537

  12. OWASP Foundation. "OWASP Web Security Testing Guide." https://owasp.org/www-project-web-security-testing-guide/latest/

  13. Penetration Testing Execution Standard project. "PTES Technical Guidelines." https://pentest-standard.readthedocs.io/en/latest/tree.html

  14. Capgemini, Sogeti and OpenText (13 November 2025). "World Quality Report 2025-26." https://www.prnewswire.com/news-releases/world-quality-report-2025-ai-adoption-surges-in-quality-engineering-but-enterprise-level-scaling-remains-elusive-302614772.html

  15. Business Standard (4 December 2025), reporting Data Security Council of India research. "Indian cybersecurity product firms may generate $6 bn revenue in 2026: DSCI." https://www.business-standard.com/industry/news/indian-cybersecurity-product-companies-expected-to-generate-6bn-revenue-2026-dsci-125120401066_1.html

FAQ

Frequently Asked Questions

Quick answers to common questions about this article.

The label covers three separate services. Automated vulnerability scanning identifies known weaknesses across your hosts and IP ranges and reports them without exploiting anything. Penetration testing exploits those weaknesses to prove which ones give an attacker real access, which NIST SP 800-115 classifies as a different technique category from scanning. Managed detection and response is continuous monitoring of live attacker activity, so confirm which of the three a vendor is quoting before you compare prices.

Scanning checks whether a known weakness is present, while penetration testing exploits it to confirm the weakness is real and reachable. NIST SP 800-115 states that vulnerability scanners check only for the possible existence of a vulnerability, whereas the attack phase of a penetration test exploits the vulnerability to confirm its existence. The Center for Internet Security separates them into two of its eighteen top-level controls, numbers 7 and 18. They run on different cadences and different labour models, so treat them as two line items rather than one blended purchase.

It depends entirely on which regulator you answer to. RBI's 2023 IT Governance Directions require vulnerability assessment at least once every six months and penetration testing at least once in twelve months for critical information systems and DMZ systems with a customer interface. SEBI's CSCRF requires VAPT twice yearly for protected systems and critical information infrastructure and once yearly for other regulated entities, with Qualified Stock Brokers on a half-yearly cycle regardless of category. CERT-In sets no testing frequency at all, only six-hour incident reporting and 180-day log retention.

No. The Digital Personal Data Protection Rules 2025 were notified by gazette G.S.R. 846(E) on 13 November 2025, and the substantive data-fiduciary obligations commence eighteen months later, on 13 May 2027. Rule 6, which specifies what reasonable security safeguards mean under Section 8(5), sits in that final tranche. Treat DPDP as a compliance-readiness deadline you are preparing for rather than a present-tense legal trigger, and be cautious with any vendor who tells you otherwise.

CERT-In empanels information security auditing organisations through a four-stage process covering documentation review, an offline practical skill test, a dedicated vulnerability assessment and penetration testing skill test, and a personal interaction session at CERT-In headquarters. The empanelled list is published openly at cert-in.org.in and describes itself as updated as soon as there is any change in it. Indian sectoral regulators require the use of an empanelled auditor for certain mandated audits, so the check matters for regulated buyers. Verify a vendor's exact legal entity against the live list rather than accepting a logo on a website.

No independent price benchmark exists for the Indian market. Every pricing band in public circulation traces back to a vendor's own marketing page, which is sellers pricing their own category rather than a survey, and the figures drift between sources. Cost is driven by live host and IP count in scope, whether testing is internal or external and credentialed or uncredentialed, days of manual tester time, whether retesting is included, and the evidence depth your regulator demands. Scope those variables first, then compare quotes that describe the same work.

Ask for a sanitized sample report before contract, the name and certifications of the lead tester, and the methodology by name, whether PTES, OWASP WSTG or NIST SP 800-115. Confirm that retesting and closure sit inside the base price with dates that fit your regulator's remediation window, since SEBI requires findings closed within three months of report submission and high-severity unpatched items within one week. Confirm where your report, evidence and logs will be stored, because CERT-In requires ICT logs retained for 180 days within Indian jurisdiction. A vendor who quotes before scoping has priced their standard package rather than your estate.

No. Managed detection and response is continuous monitoring of live attacker activity, while vulnerability assessment and penetration testing are periodic assessments with a start and an end date. India's regulatory framework treats them separately: CERT-In's Directions require 180-day ICT log retention within Indian jurisdiction and incident reporting within six hours of notice, with targeted scanning or probing of critical networks listed first among the reportable incident types. No annual penetration test produces that detection capability, so budget for them as separate purchases.

Banking, NBFCs and capital markets carry the heaviest load, and a listed bank sits inside RBI's six-month and twelve-month cadence and SEBI's CSCRF cadence at the same time. Healthcare and diagnostics buyers often add HIPAA and FDA 21 CFR Part 11 expectations when patient data reaches overseas partners. E-commerce and payments scope is driven by PCI DSS and by an internet-facing estate that changes with every release. Public systems and critical infrastructure operators face CERT-In's protected-systems regime and the strictest data-residency constraints.

Need Expert QA or
Development Help?

Our Expertise

contact
  • AI & DevOps Solutions
  • Custom Web & Mobile App Development
  • Manual & Automation Testing
  • Performance & Security Testing
contact-leading

Trusted by 150+ Leading Brands

contact-strong

A Strong Team of 275+ QA and Dev Professionals

contact-work

Worked across 450+ Successful Projects

new-contact-call-icon Call Us
721 922 5262

Collaborate with Vervali