People • Technology • Possibilities+91 74199 74199[email protected]
Home / Insights / VAPT Scoping
Security Assessment

Scoping a VAPT Engagement in India

What to decide before a vulnerability assessment and penetration test starts: objectives, scope, rules of engagement, CERT-In requirements, severity scoring and what a useful report contains.

Scoping a penetration test
Security Assessment

As of 11 October 2026. This guide explains scoping practice and the regulatory context. It is not legal advice. Confirm what your regulator, customer contracts or insurer require before you commission a test.

Most VAPT problems start in the scope

A vulnerability assessment and penetration test (VAPT) is only as useful as its scope. Tests that miss the systems attackers actually reach, run without credentials, or are stopped halfway because nobody agreed a testing window produce reports that look thorough and change little. This guide sets out what to decide before testing starts, so the report answers the question you are really asking.

Assessment versus penetration test

Vulnerability assessmentPenetration test
Question answeredWhich known weaknesses exist across these systems?Can an attacker achieve a defined objective, and how?
MethodLargely automated scanning, verified by an analystManual exploitation and chaining of weaknesses
CoverageBroadDeep along the paths tested
Typical outputPrioritised list of findingsAttack narrative, evidence, and findings

Most engagements combine both: broad assessment to find weaknesses, then manual testing to confirm which ones matter. NIST SP 800-115 describes this range of technical testing and assessment techniques, and the OWASP Web Security Testing Guide (WSTG, current stable version 4.2; version 5 is in development) is the usual reference for web application testing.

Scoping checklist

DecideWhy it mattersExample answer
ObjectiveDrives depth and method“Can an external attacker reach customer data?”
In-scope assetsUntested systems are unassessed riskPublic IP ranges, domains, web apps, APIs, VPN, Microsoft 365 tenant
Out of scopeProtects fragile or third-party systemsPayment gateway (provider-owned), OT network, production database writes
Test typesEach needs different skillsExternal network, internal network, web app, API, cloud configuration, Wi-Fi, phishing
PerspectiveUnauthenticated tests miss most application flawsUnauthenticated plus one standard user and one admin test account per app
EnvironmentProduction testing carries real riskStaging for destructive tests; production for configuration and exposure
Testing windowsAvoids business impact and alarm confusionWeekdays 22:00–06:00 IST for internal tests
Third-party permissionsYou may not own everything you useCheck your cloud and hosting providers’ penetration testing policies
Data handlingTesters will see sensitive dataNo data leaves the client environment; evidence redacted in the report
RetestProves remediationOne retest of critical and high findings within an agreed period

Rules of engagement

Put the scope into a signed rules-of-engagement document before testing starts. An illustrative template outline:

1. Parties, authorising signatory and date
2. Objective and in-scope assets (IP ranges, URLs, accounts) — attached as a list
3. Explicit exclusions
4. Test types and techniques allowed (e.g. no denial-of-service, no data modification)
5. Testing windows and time zone (IST)
6. Source IP addresses the testers will use
7. Emergency contacts on both sides and a stop-testing procedure
8. What happens if testers find evidence of an existing compromise
9. Data handling, evidence retention and report confidentiality
10. Deliverables, severity scheme and retest terms

Clause 8 matters more in India than many teams expect. See the next section.

The Indian context: CERT-In directions

CERT-In’s directions of 28 April 2022, issued under section 70B(6) of the IT Act and in force about 60 days later, apply to service providers, intermediaries, data centres, body corporates and government organisations. Three requirements affect a VAPT engagement:

  • 6-hour incident reporting. Covered incidents must be reported to CERT-In within 6 hours of noticing them. If testers find signs of a real compromise, the client may have to report, so agree in advance who is told, how fast, and who decides.
  • 180-day logs in India. Logs of ICT systems must be kept securely for a rolling 180 days within Indian jurisdiction. Testing activity will appear in those logs; record tester source IPs and windows so later investigations can separate testing from attacks.
  • Time synchronisation. System clocks must sync to NIC or NPL NTP servers (or sources traceable to them). Consistent time makes the test timeline and the client’s logs line up.

Empanelled auditors

CERT-In maintains a list of empanelled information security auditing organisations. Some sector regulators, government buyers and customer contracts require an audit by an organisation on that list. If yours does, confirm it before scoping and check the auditor on CERT-In’s current list yourself. If your requirement is risk reduction rather than a regulatory audit, any competent tester with a clear scope can do the work.

Severity and the report

Ask for findings rated with a published scheme. CVSS version 4.0 from FIRST uses Base, Threat and Environmental metric groups, plus supplemental metrics that do not change the score. Base scores alone overstate some findings and understate others; the Environmental metrics let you reflect your own exposure and the systems affected.

A useful report contains:

  • An executive summary written for management, with the objective answered plainly.
  • Each finding with affected assets, evidence, reproduction steps, severity and specific remediation.
  • Attack paths that chain several lower-severity findings into a serious outcome.
  • What was not tested, and why.
  • Retest results, recorded against the original findings.

After the test

Assign every critical and high finding an owner and a date, fix, then retest. Feed recurring finding types back into build standards so they do not reappear next year. For help scoping or running an assessment, see VAPT & security audit services.

Sources

Primary sources used for this article (checked 11 October 2026):

Frequently Asked Questions

About the Author

Lalit Bhardwaj — Founder & Technology Strategist, XOOPIE. Lalit leads XOOPIE with a hands-on technology strategy and infrastructure engineering approach, focused on understanding how an organization actually operates and translating that reality into an appropriate, resilient technical design.

Read Lalit Bhardwaj's full profile →