VAPT When No Regulator Requires It
Unregulated companies still end up buying penetration tests. The requirement arrives through customers, contracts, insurers and investors — and each wants something slightly different.
Plenty of companies that no regulator names still buy penetration tests every year. The obligation arrives through commercial channels instead, and it is usually less negotiable than a regulatory one, because the counterparty can simply decline to sign.
Five sources, in roughly the order companies meet them.
1. Customer security questionnaires
The most common trigger by a distance. You reach a certain size of customer, their procurement process produces a questionnaire, and one question asks whether you conduct independent penetration testing and how often.
What they usually want is a certificate naming a relevant scope and a recent date. What they are entitled to ask for, and sometimes do, is the report itself under a non-disclosure agreement. Establish which before commissioning — see what a VAPT certificate evidences.
This is worth getting ahead of. A questionnaire arriving mid-deal with a two-week response window is the most expensive time to discover you need a test.
2. Contracts
Master services agreements and data processing agreements increasingly carry a security testing clause — annual independent testing, remediation of findings within a defined period, and sometimes a right to audit.
Two things to check before signing. First, whether the clause specifies who may perform the testing, because "independent" and "accredited" and "CERT-In empanelled" are three different bars. Second, whether the remediation window is one your release process can actually meet: a clause requiring critical findings closed in seven days is a commitment about your engineering process, not just your security programme.
3. Cyber insurance
Insurers ask about testing at underwriting, and the answers affect both whether cover is offered and what it costs. The material point is that what you tell an insurer is a representation. Describing a testing programme you do not actually run is a problem that only surfaces at claim time, which is the worst possible moment for it to surface.
4. Investors and acquirers
Technical due diligence covers security, and the absence of any testing history is a finding in itself. It rarely blocks a transaction; it commonly becomes a condition, and conditions negotiated under time pressure are worse than programmes started earlier.
An acquirer inheriting an untested codebase is also, from their side, buying an unknown — which is why acquisition is itself one of the strongest triggers for testing.
5. Certifications you chose
ISO 27001 and SOC 2 are voluntary, and neither names penetration testing as a required control in so many words. Both require you to identify and manage technical vulnerabilities, and testing is the evidence auditors ordinarily expect to see for that. In practice, organisations pursuing either end up testing.
Detail on both: ISO 27001 and SOC 2.
Where marketplaces and partners sit
App stores, payment partners and platform marketplaces frequently make testing a precondition of listing or integration. These are the least negotiable of all, because the requirement is a gate rather than a term, and they often specify the scope quite narrowly — which is useful, since it tells you exactly what to commission.
What to do first
The efficient move is to find out what will be asked before it is asked. Look at the questionnaires your sales team has already answered, the security clauses in the contracts you have signed, and the requirements of any marketplace you intend to list on.
Those three sources will usually agree on a scope — typically the customer-facing application and the API behind it — and a scope that satisfies all of them at once costs far less than three separate exercises commissioned reactively. How that scope gets counted is in how a VAPT scope gets sized; what to have ready is in preparing for your first VAPT.
If a regulator does name you, the map is in which Indian regulators require security testing.
Continue reading
All articles →Which Indian Regulators Require Security Testing
A map rather than a manual: which regulator binds you, what instrument sets the requirement, and where to read the detail that applies to your entity type.
Writing a VAPT RFP That Gets Comparable Quotes
Most VAPT tenders return responses that cannot be compared. Four ways an RFP causes that, and what to specify instead so three proposals answer the same question.
The VAPT Certificate: What It Evidences
There is no standardised VAPT certificate and no authority that issues one. What the document actually is, what it proves, what it does not, and who accepts it.