Skip to main content

VAPT When No Regulator Requires It

Unregulated companies still end up buying penetration tests. The requirement arrives through customers, contracts, insurers and investors, and each of them wants something slightly different.

By Abhinav A
August 18, 20263 min read

Plenty of companies that no regulator names still buy penetration tests every year. The obligation arrives through commercial channels instead, and it is usually less negotiable than a regulatory one, because the counterparty can simply decline to sign.

Five sources, in roughly the order companies meet them.

1. Customer security questionnaires

The most common trigger by a distance. You reach a certain size of customer, their procurement process produces a questionnaire, and one question asks whether you conduct independent penetration testing and how often.

What they usually want is a certificate naming a relevant scope and a recent date. What they are entitled to ask for, and sometimes do, is the report itself under a non-disclosure agreement. Establish which before commissioning. See what a VAPT certificate evidences.

Get ahead of it. A questionnaire arriving mid-deal with a two-week response window is the most expensive time to discover you need a test.

2. Contracts

Master services agreements and data processing agreements increasingly carry a security testing clause: annual independent testing, remediation of findings within a defined period, and sometimes a right to audit.

Two things to check before signing. First, whether the clause specifies who may perform the testing, because "independent" and "accredited" and "CERT-In empanelled" are three different bars. Second, whether the remediation window is one your release process can actually meet: a clause requiring critical findings closed in seven days commits your engineering process as much as your security programme.

3. Cyber insurance

Insurers ask about testing at underwriting, and the answers affect both whether cover is offered and what it costs. What you tell an insurer is a representation. Describing a testing programme you do not actually run is a problem that only surfaces at claim time.

4. Investors and acquirers

Technical due diligence covers security, and the absence of any testing history is a finding in itself. It rarely blocks a transaction; it commonly becomes a condition, and conditions negotiated under time pressure are worse than programmes started earlier.

An acquirer inheriting an untested codebase is buying an unknown. Acquisition is among the strongest triggers for testing.

5. Certifications you chose

ISO 27001 and SOC 2 are voluntary, and neither names penetration testing as a required control in so many words. Both require you to identify and manage technical vulnerabilities, and testing is the evidence auditors ordinarily expect to see for that. In practice, organisations pursuing either end up testing.

Detail on both: ISO 27001 and SOC 2.

Where marketplaces and partners sit

App stores, payment partners and platform marketplaces frequently make testing a precondition of listing or integration. These are the least negotiable of all, because the requirement gates the listing itself. They often specify the scope narrowly, which tells you exactly what to commission.

What to do first

The efficient move is to find out what will be asked before it is asked. Look at the questionnaires your sales team has already answered, the security clauses in the contracts you have signed, and the requirements of any marketplace you intend to list on.

Those three sources will usually agree on a scope, typically the customer-facing application and the API behind it. One scope that satisfies all of them costs far less than three separate exercises commissioned reactively. How that scope gets counted is in how a VAPT scope gets sized; what to have ready is in preparing for your first VAPT.

If a regulator does name you, the map is in which Indian regulators require security testing.

About the author

Abhinav A

Lead — VAPT & Security Assessments

Leads Security Brigade's VAPT delivery team, having progressed from Security Consultant to Team Lead. Has executed advanced penetration tests across BFSI, fintech, QSR and telecom.