The All-in-One IT Management Software That Replaces 10 Tools — VAPT Built In.

One platform for server monitoring, IT assets, helpdesk & vulnerability assessment and penetration testing (VAPT) — tenant-isolated, audit-ready, live in under 30 minutes.

New · Release 2026.04 — Multi-tenant audit exports & SLA dashboards now live See changelog →
Security & Compliance

VAPT Certification Explained: Testers and Certificates (2026)

Two very different things share the name "VAPT certification": the credentials a penetration tester holds (OSCP, CEH, GPEN, CREST, BSCP, GWAPT, OSCE³) and the certificate your organisation receives after an engagement. This guide covers both — what each proves, what each costs, and why no accredited global VAPT certification body exists.

Written by the Infronest Security Research Team — CEH, OSCP, GPEN and ISO 27001 Lead Auditor certified, with 10+ years of hands-on VAPT delivery. Certification details reflect publicly published scheme information at the time of writing; exam formats and fees change, so verify current pricing with the awarding body before you budget. Methodology references follow PTES, NIST SP 800-115 and the OWASP Testing Guide v4.2.

ShareLinkedInX

"VAPT certification" is one search term covering two unrelated things. If you are hiring, it means the professional credentials a penetration tester holds — OSCP, CEH, GPEN, GWAPT, CREST, BSCP or OSCE³ — each of which validates a different skill at a different level of difficulty and cost. If you are buying testing for your organisation, it means the certificate or attestation letter your vendor issues once the engagement closes, which procurement teams and auditors then ask you to produce. The second one is the source of most confusion, so it is worth stating plainly at the top: a VAPT certificate is a vendor-issued attestation, not an accredited standard. There is no ISO-style global body that certifies organisations as "VAPT certified". Its value comes entirely from who signed it, what scope it covers and whether a real report sits behind it.

Definition

What is VAPT certification?

VAPT certification refers to either (a) the industry credentials held by the individuals performing vulnerability assessment and penetration testing, or (b) the certificate of testing issued to an organisation at the end of a VAPT engagement. The two are frequently conflated in tender documents and job descriptions, and treating them as the same thing leads to bad buying decisions.

On the tester side, certification is a competence signal issued by an awarding body after an exam. The well-recognised ones for VAPT work are OSCP and the OSCE³ family (Offensive Security), CEH (EC-Council), GPEN and GWAPT (GIAC/SANS), the CREST ladder (CPSA, CRT, CCT), and BSCP (PortSwigger). Several are hands-on and proctored; a few are multiple-choice only, which matters a great deal when you are judging whether someone can actually break into a system.

On the organisation side, the certificate is a one- or two-page attestation stating that a named scope was tested, over named dates, using a named methodology, and that findings were remediated and retested. No accreditation body sits behind it. ISO 27001 certificates are issued by certification bodies accredited under ISO/IEC 17021-1; PCI DSS assessments are performed by Qualified Security Assessors approved by the PCI Security Standards Council. VAPT has no equivalent scheme. Anyone can print a certificate — which is exactly why the report, the scope statement and the issuer's own credentials are the parts that carry weight.

For testers

The certifications a VAPT tester holds — and what each actually validates

Fees below are approximate, published list prices at the time of writing and change regularly; treat them as budgeting order-of-magnitude, not quotes. Difficulty is judged on how much of the exam is hands-on exploitation versus recall.

  • OSCP (Offensive Security Certified Professional) — the default baseline for hands-on network and host exploitation. The exam is a proctored practical lasting just under 24 hours against a live lab, followed by a 24-hour window to submit a professional report. Course-plus-exam bundles start at roughly USD 1,650, with annual subscription options closer to USD 2,700. Hard, and the report requirement is the reason it maps well to real client delivery. The renewable OSCP+ variant carries a three-year validity.
  • CEH (Certified Ethical Hacker, EC-Council) — the most widely name-checked credential in Indian tenders, HR filters and government panels, largely because it is ANSI/ISO 17024 accredited and appears on the US DoD 8140 approved list. The core exam is 125 multiple-choice questions over four hours — knowledge, not exploitation. CEH Practical adds a six-hour hands-on challenge exam; holding both earns CEH Master. Budget roughly USD 950–1,200 for the exam voucher plus an eligibility application fee if you are self-study; official training packages cost several times that. Treat CEH alone as breadth, not proof of exploitation skill.
  • GPEN (GIAC Penetration Tester) — the certification attached to SANS SEC560, covering scoping, reconnaissance, exploitation, password attacks and Active Directory. The proctored exam is open-book and includes CyberLive hands-on tasks in a live VM, and the certification renews on a four-year cycle. The SANS course plus exam attempt commonly lands near USD 9,000; a standalone certification attempt without training is far cheaper, around USD 999. Expensive, but well regarded by regulated-industry buyers.
  • GWAPT (GIAC Web Application Penetration Tester) — the web-application counterpart, tied to SANS SEC542: injection, authentication and session flaws, client-side attacks and OWASP-aligned test methodology. Same pricing and renewal model as GPEN. Choose GWAPT over GPEN when the work is predominantly application testing rather than infrastructure.
  • CREST (CPSA → CRT → CCT INF / CCT APP) — a UK-headquartered scheme with international recognition, structured as a ladder from practitioner-level CPSA through the CRT practical to the Certified Tester exams for infrastructure and applications. Exam fees run from a few hundred pounds to roughly GBP 1,500–2,000 at the CCT tier. CREST matters most where it is contractually mandated — CBEST in UK financial services and CREST-recognised schemes in Singapore, Australia and Hong Kong. Note that CREST also accredits companies, not just individuals; for a buyer, the company accreditation is often the more meaningful signal.
  • BSCP (Burp Suite Certified Practitioner, PortSwigger) — a four-hour practical web exam where you must fully compromise two unfamiliar applications, escalating to administrative access and extracting protected data. At roughly USD 99 per attempt, with the free Web Security Academy as preparation, it is the best value-for-money credential in web testing and a genuinely difficult exam. Narrow by design: it says nothing about network or Active Directory work.
  • OSCE³ (Offensive Security Certified Expert 3) — no longer a single exam. It is the expert designation awarded for holding all three of OSWE (web exploitation, WEB-300), OSEP (evasion and advanced penetration testing, PEN-300) and OSED (Windows exploit development, EXP-301). Each course-and-exam bundle is priced similarly to OSCP and each exam is a multi-day practical. This is a specialist tier; expect it on red-team and exploit-development CVs, not on routine VAPT delivery teams.

Buying signal

How to read tester certifications when you are hiring a vendor

Certifications set a floor, not a ceiling. A team of OSCP holders will find and exploit the standard issues reliably; it does not follow that they will understand your payment flow, your multi-tenant authorisation model or your OT network. Ask three follow-up questions that certifications cannot answer: who specifically will test the engagement (named CVs, not a pool), what methodology they follow (PTES, NIST SP 800-115, OWASP WSTG v4.2), and can they share a sanitised sample report. Report quality separates competent providers faster than any credential list.

In India, the credential buyers most often need is not an individual one at all. CERT-In maintains a list of empanelled information security auditing organisations, and a large share of government and public-sector tenders — plus the safe-to-host clearance required before hosting on NIC or state data centres — will only accept audit work from an empanelled organisation. If your requirement is driven by a government contract, confirm empanelment status first; individual OSCP or CEH holders on the team do not substitute for it. Similarly, UK financial-services work under CBEST looks for CREST-accredited firms, not just CREST-certified staff.

Be sceptical of certification inflation in proposals. A vendor listing fifteen acronyms across a five-person team is telling you less than one that names the two testers on your engagement and shows you what they produced last quarter. Also check currency: GIAC certifications renew on a four-year cycle and several Offensive Security credentials now carry renewable variants, so a certificate number without a valid-until date deserves a question.

For organisations

The VAPT certificate your organisation receives after an engagement

When a client, an insurer or a procurement portal asks you for "your VAPT certificate", they are asking for the attestation document your testing vendor issues at the close of an engagement. It typically states that a defined scope was tested between two dates, using a stated methodology, that the findings were shared, and that the critical and high-severity issues were remediated and verified by retest. Some vendors call it a certificate of penetration testing, a security attestation letter, or — in Indian government hosting workflows performed by CERT-In empanelled auditors — a security audit clearance or safe-to-host certificate.

What it is not: an accredited certification. There is no international body that audits testing firms and confers "VAPT certified" status on their clients, no register you can look an organisation up in, and no common criteria for what the document must say. Two certificates issued by two vendors for the same environment can differ wildly in rigour. That is not a scandal — it simply means the certificate is a summary artefact, and the report behind it is the real deliverable. If a vendor offers a certificate without a full technical report, walk away.

The certificate is also strictly point-in-time. It describes the state of a defined scope on defined dates and nothing else. With more than 11,000 CVEs published by March 2026 alone, and given that most environments deploy code weekly, a certificate dated six months ago tells a reader what your posture used to be. Industry convention treats twelve months as the practical shelf life, and PCI DSS effectively enforces that by requiring annual testing plus retesting after any significant change — but the vendor's own "valid until" line is a convention, not an accreditation rule.

Checklist

What a credible VAPT certificate must contain

Use this as an acceptance checklist when you receive the document, and as a requirement list when you write the statement of work. If a field is missing, ask for a reissue before you hand the certificate to a client.

  • Issuer identity and standing — the legal entity name of the testing firm, plus any relevant accreditation or empanelment (CREST-accredited company, CERT-In empanelled auditor) with a reference number that can be verified independently.
  • Precise scope — the exact IP ranges, hostnames, URLs, API base paths, mobile application build numbers and environments tested. "Corporate network" is not a scope. A reader must be able to tell whether the system they care about was actually in the test.
  • Test window dates — start and end dates of active testing, and the date of any retest. A certificate that carries only an issue date hides how stale the underlying work is.
  • Test type and methodology — black-box, grey-box or white-box; credentialed or unauthenticated; and the standard followed (PTES, NIST SP 800-115, OWASP Testing Guide v4.2, OWASP MASVS for mobile). This is what an ISO 27001 or PCI assessor reads first.
  • Findings summary by severity — counts of critical, high, medium, low and informational findings, scored with CVSS. A certificate claiming a clean result with no severity table is not credible; almost every real engagement produces findings.
  • Remediation and retest status — which findings were fixed, which were accepted as risk with a named owner, and the date the retest verified the fixes. Retest verification is the single most audit-relevant line on the page.
  • Tester attribution — the names and certifications of the individuals who performed the work, and an authorised signature. Anonymous certificates are unverifiable by definition.
  • An explicit point-in-time caveat — a statement that the assessment reflects the scope as configured during the test window and does not warrant future security. Its presence is a sign of an honest issuer, not a weakness.

Compliance

How the certificate is used for client and compliance evidence

The certificate is a cover sheet. In almost every formal assessment, the evidence that counts is the report, the scope statement and the retest record. Knowing which reviewer accepts which artefact saves a lot of late-stage friction.

  • PCI DSS 4.0 — requirement 11.4 mandates internal and external penetration testing at least annually and after significant change, following a defined methodology (11.4.1), with exploitable vulnerabilities corrected and testing repeated to verify (11.4.4). A QSA will ask for the methodology document, the full report and the retest evidence. A certificate alone will not close the requirement.
  • ISO 27001:2022 — Annex A 8.8 (management of technical vulnerabilities) and A 8.26 (application security requirements) are what testing supports. Auditors look for a repeatable process: scope rationale, findings tracked to closure in your risk treatment records, and evidence of retest. The certificate is useful as an index into that evidence, not as a substitute for it.
  • SOC 2 Type II — CC7.1 and CC7.2 cover detection and response to vulnerabilities. Testing reports and remediation tickets serve as evidence over the observation window, so the audit trail matters more than any single document.
  • India-specific regimes — RBI's cyber security framework and SEBI's CSCRF both require periodic VAPT for regulated entities, and government hosting workflows require security audit clearance from a CERT-In empanelled auditor. Confirm which artefact each regulator or department expects before scheduling the test.
  • Customer security questionnaires and vendor due diligence — this is where the certificate genuinely earns its keep. A signed one-pager with clear scope and dates answers a procurement question in minutes without disclosing exploitable detail, with the full report released under NDA when a customer insists.
  • Cyber insurance and enterprise onboarding — underwriters and large buyers increasingly ask for evidence of regular testing. Consistency matters more than any single result: an annual cadence with tracked remediation reads far better than one spotless certificate.

Infronest

Conclusion

Infronest does not issue accredited certifications, and no software product can — the certificate comes from whoever performs your testing. What the Security & VAPT module does is manage the engagement record that gives the certificate its substance: engagements with defined scope, findings documented and scored with CVSS, evidence upload, peer review before findings are published, audit-ready PDF report generation, and retest tracking so you can show an assessor exactly when each critical finding was verified as closed.

Because Infronest is an all-in-one platform of 16 modules in one tenant-isolated workspace, the testing record sits alongside the IT asset inventory that defines your scope, the patch management and MDM data that shows how fixes were rolled out, and the helpdesk tickets that track remediation owners — which is usually the evidence chain an ISO 27001 or PCI assessor asks for next. If you need an accredited scheme, go to a CREST-accredited or CERT-In empanelled provider; if you need the workflow and audit trail around it, that is what this module is for. Start a 14-day free trial at infronest.com — no credit card required.

Sources

  • IBM — Cost of a Data Breach Report 2025 (USD 4.44M global average breach cost)
  • Gartner — Information Security Spending Forecast 2026 (USD 244.2B)
  • MarketsandMarkets — Penetration Testing Market, USD 4.39B by 2031 at 14.2% CAGR
  • CVE Program / NVD — over 11,000 CVEs published by March 2026
  • Awarding-body scheme documentation: Offensive Security (OSCP, OSWE, OSEP, OSED), EC-Council (CEH, CEH Practical), GIAC/SANS (GPEN SEC560, GWAPT SEC542), CREST (CPSA, CRT, CCT), PortSwigger (BSCP)
  • PCI DSS v4.0 requirement 11.4; ISO/IEC 27001:2022 Annex A 8.8 and A 8.26; SOC 2 CC7.1–CC7.2; NIST SP 800-115; OWASP Testing Guide v4.2; CERT-In empanelment of information security auditing organisations

Frequently Asked Questions

Is there an official VAPT certification body?
No. Unlike ISO 27001, where certificates are issued by certification bodies accredited under ISO/IEC 17021-1, or PCI DSS, where assessments are performed by PCI SSC-approved QSAs, there is no accreditation scheme that certifies organisations as "VAPT certified". Any certificate you receive is an attestation issued by your testing vendor, and its credibility rests on that vendor's own standing — for example CREST company accreditation or CERT-In empanelment in India. Always ask for the full technical report that sits behind the certificate.
Which VAPT certification is best: OSCP or CEH?
They test different things. OSCP is a practical exam — just under 24 hours of live exploitation plus a 24-hour reporting window — so it evidences that someone can actually compromise systems and write it up. CEH is primarily a 125-question multiple-choice exam covering breadth of knowledge, though CEH Practical adds a six-hour hands-on component. For hiring testers, prioritise OSCP or a CREST practical; for tender eligibility and HR filters in India, CEH is the credential most often named explicitly.
How long is a VAPT certificate valid?
There is no formally defined validity period because no accreditation body governs the document. Industry convention treats twelve months as the practical shelf life, and PCI DSS 4.0 effectively enforces that by requiring penetration testing at least annually and after any significant change. Treat the certificate as strictly point-in-time evidence: it describes a named scope on named dates, and any major deployment, migration or architecture change invalidates it in practice regardless of the date printed on it.
How much does VAPT certification cost?
For testers, expect roughly USD 99 per attempt for PortSwigger's BSCP, around USD 950–1,200 for a CEH exam voucher, from about USD 1,650 for an OSCP course-and-exam bundle, several hundred to around GBP 2,000 per CREST exam depending on tier, and close to USD 9,000 for a SANS course plus GPEN or GWAPT attempt. For organisations, the certificate itself is not a separate purchase — it is included in the engagement fee, which varies with scope. Verify current pricing with each awarding body, as fees change.
Can I get a VAPT certificate from an automated scan alone?
Some vendors will issue one, but it is weak evidence and experienced reviewers spot it immediately. A scan-derived certificate has no exploitation proof, no manual business-logic or authorisation testing, and usually no retest record, which means a PCI QSA or ISO 27001 auditor will reject it as evidence for penetration-testing requirements. Look for a certificate that names the methodology followed, the individual testers, and the date findings were verified as remediated.

About the Author

Infronest

Infronest Security Research Team

Certified security professionals (CEH, OSCP, GPEN, ISO 27001 Lead Auditor) with 10+ years of hands-on delivery. Content reviewed against PTES, NIST SP 800-115 and the OWASP Testing Guide v4.2.

Ready to unify your IT operations?

Start a 14-day free trial or book a demo — explore monitoring, assets, tickets, and security in one tenant-isolated workspace.