Comparing Two CERT-In Empanelled Vendors
Once both firms are empanelled, the empanelment stops helping. What the public register already tells you about each, and the three differences that survive the bar.
Once you have confirmed that two firms are both CERT-In empanelled, the empanelment stops helping. Every organisation on that list cleared the same bar; that is what a list is for. The question becomes which of them should do your work, and the usual answer — ask for proposals and compare the prices — compares the one number that is downstream of everything else.
There is more to go on than most buyers realise, and some of it is public.
Start with what they have already declared
The CERT-In register does not stop at names and addresses. After the roster it carries a section titled Snapshot of skills and competence of CERT-In empanelled organisations, in which every listed firm completes the same standard disclosure. Two of its fields are worth more than most of what you will be told in a sales call:
- Capability to audit, category wise — the kinds of audit the firm states it can perform.
- Number of audits in last 12 months, category-wise — how many of each it says it actually did.
Read the two together, for the category you are buying. A firm can list a capability and report no audits in it, which tells you the capability is aspirational. A firm can report a large number concentrated in one category and none in yours. Neither is disqualifying, and both are worth knowing before the first conversation rather than discovering in the third.
The figures are self-declared. They are also declared to the national CERT, on a standard form, sitting beside every competitor's answer — which makes them considerably more comparable than anything on a website.
Then ask the two firms the same question
Comparison only works against a constant. Send both the identical scope document, and require the estimate back in the same shape: tester-days split between testing and reporting, the testing perspective, and the exclusions written out.
Two proposals that arrive in different shapes cannot be compared, and the work of making them comparable is work you will do under time pressure with incomplete information.
Where genuinely comparable firms diverge
Three differences survive the empanelment bar, and none of them appear in a price.
What happens when the scope turns out to be wrong
It usually does. A test of "the customer portal" reaches an admin interface, an undocumented API, an integration nobody mentioned. What the firm does at that moment is the most informative thing about it: raise it and renegotiate, test it quietly and mention it in the report, or stay inside the letter of the scope and say nothing.
Ask each firm for a specific instance. The answer is either a story with details or a policy statement, and the difference between those is the answer.
What happens to a critical finding at 9pm on a Friday
Not the SLA — the mechanism. Who decides it is critical, who they call, what they do if nobody answers, and whether that has actually happened. A firm that has been through it describes it concretely.
What the report is for
Some reports are written to evidence that testing occurred. Others are written for the engineer who has to fix the finding and the auditor who has to accept the fix. Both satisfy a compliance requirement; only one is useful in February.
Request a sanitised report from each and read the same finding in both — one you understand, at the same severity. Compare whether you could reproduce it, whether you would know what to change, and whether the severity is argued or merely asserted.
What not to weight heavily
Certification counts on a slide, headcount, and years since founding are all easy to publish and weakly connected to the quality of your engagement. The people who will test your system, the methodology they follow, and the document you receive are the engagement. Everything else is context.
A workable sequence
- Confirm both are on the current register.
- Read their declared categories and 12-month volumes for your category.
- Send an identical scope; require identical estimate structure.
- Ask each the three questions above and listen for specifics.
- Read the same finding in both sample reports.
- Then look at the price, against the day counts rather than alone.
Steps one and two are free, take about ten minutes, and most buyers skip them.
Continue reading
All articles →VAPT When No Regulator Requires It
Unregulated companies still end up buying penetration tests. The requirement arrives through customers, contracts, insurers and investors — and each wants something slightly different.
Which Indian Regulators Require Security Testing
A map rather than a manual: which regulator binds you, what instrument sets the requirement, and where to read the detail that applies to your entity type.
Writing a VAPT RFP That Gets Comparable Quotes
Most VAPT tenders return responses that cannot be compared. Four ways an RFP causes that, and what to specify instead so three proposals answer the same question.