As of 11 October 2026. This guide explains scoping practice and the regulatory context. It is not legal advice. Confirm what your regulator, customer contracts or insurer require before you commission a test.
Most VAPT problems start in the scope
A vulnerability assessment and penetration test (VAPT) is only as useful as its scope. Tests that miss the systems attackers actually reach, run without credentials, or are stopped halfway because nobody agreed a testing window produce reports that look thorough and change little. This guide sets out what to decide before testing starts, so the report answers the question you are really asking.
Assessment versus penetration test
| Vulnerability assessment | Penetration test | |
|---|---|---|
| Question answered | Which known weaknesses exist across these systems? | Can an attacker achieve a defined objective, and how? |
| Method | Largely automated scanning, verified by an analyst | Manual exploitation and chaining of weaknesses |
| Coverage | Broad | Deep along the paths tested |
| Typical output | Prioritised list of findings | Attack narrative, evidence, and findings |
Most engagements combine both: broad assessment to find weaknesses, then manual testing to confirm which ones matter. NIST SP 800-115 describes this range of technical testing and assessment techniques, and the OWASP Web Security Testing Guide (WSTG, current stable version 4.2; version 5 is in development) is the usual reference for web application testing.
Scoping checklist
| Decide | Why it matters | Example answer |
|---|---|---|
| Objective | Drives depth and method | “Can an external attacker reach customer data?” |
| In-scope assets | Untested systems are unassessed risk | Public IP ranges, domains, web apps, APIs, VPN, Microsoft 365 tenant |
| Out of scope | Protects fragile or third-party systems | Payment gateway (provider-owned), OT network, production database writes |
| Test types | Each needs different skills | External network, internal network, web app, API, cloud configuration, Wi-Fi, phishing |
| Perspective | Unauthenticated tests miss most application flaws | Unauthenticated plus one standard user and one admin test account per app |
| Environment | Production testing carries real risk | Staging for destructive tests; production for configuration and exposure |
| Testing windows | Avoids business impact and alarm confusion | Weekdays 22:00–06:00 IST for internal tests |
| Third-party permissions | You may not own everything you use | Check your cloud and hosting providers’ penetration testing policies |
| Data handling | Testers will see sensitive data | No data leaves the client environment; evidence redacted in the report |
| Retest | Proves remediation | One retest of critical and high findings within an agreed period |
Rules of engagement
Put the scope into a signed rules-of-engagement document before testing starts. An illustrative template outline:
1. Parties, authorising signatory and date
2. Objective and in-scope assets (IP ranges, URLs, accounts) — attached as a list
3. Explicit exclusions
4. Test types and techniques allowed (e.g. no denial-of-service, no data modification)
5. Testing windows and time zone (IST)
6. Source IP addresses the testers will use
7. Emergency contacts on both sides and a stop-testing procedure
8. What happens if testers find evidence of an existing compromise
9. Data handling, evidence retention and report confidentiality
10. Deliverables, severity scheme and retest terms
Clause 8 matters more in India than many teams expect. See the next section.
The Indian context: CERT-In directions
CERT-In’s directions of 28 April 2022, issued under section 70B(6) of the IT Act and in force about 60 days later, apply to service providers, intermediaries, data centres, body corporates and government organisations. Three requirements affect a VAPT engagement:
- 6-hour incident reporting. Covered incidents must be reported to CERT-In within 6 hours of noticing them. If testers find signs of a real compromise, the client may have to report, so agree in advance who is told, how fast, and who decides.
- 180-day logs in India. Logs of ICT systems must be kept securely for a rolling 180 days within Indian jurisdiction. Testing activity will appear in those logs; record tester source IPs and windows so later investigations can separate testing from attacks.
- Time synchronisation. System clocks must sync to NIC or NPL NTP servers (or sources traceable to them). Consistent time makes the test timeline and the client’s logs line up.
Empanelled auditors
CERT-In maintains a list of empanelled information security auditing organisations. Some sector regulators, government buyers and customer contracts require an audit by an organisation on that list. If yours does, confirm it before scoping and check the auditor on CERT-In’s current list yourself. If your requirement is risk reduction rather than a regulatory audit, any competent tester with a clear scope can do the work.
Severity and the report
Ask for findings rated with a published scheme. CVSS version 4.0 from FIRST uses Base, Threat and Environmental metric groups, plus supplemental metrics that do not change the score. Base scores alone overstate some findings and understate others; the Environmental metrics let you reflect your own exposure and the systems affected.
A useful report contains:
- An executive summary written for management, with the objective answered plainly.
- Each finding with affected assets, evidence, reproduction steps, severity and specific remediation.
- Attack paths that chain several lower-severity findings into a serious outcome.
- What was not tested, and why.
- Retest results, recorded against the original findings.
After the test
Assign every critical and high finding an owner and a date, fix, then retest. Feed recurring finding types back into build standards so they do not reappear next year. For help scoping or running an assessment, see VAPT & security audit services.
Sources
Primary sources used for this article (checked 11 October 2026):
- CERT-In: Directions under section 70B(6) of the IT Act, 28 April 2022
- CERT-In website (including the list of empanelled auditing organisations)
- OWASP Web Security Testing Guide
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment
- FIRST: Common Vulnerability Scoring System v4.0