Notes for owners · Industry playbooks
What a buyer checks before hiring a VAPT firm
Before a CISO or IT head lets an outside firm test their systems, they look for a sample report, named testers, a clear method and proof of similar work. Here is how to be ready.
The GullySales team · Updated 6 Oct 2026 · 6 min read
On this page
- Why does the deadline matter more than the website?
- What do they ask for before they ask for a quote?
- How should you write about your work without exposing a client?
- How do RFP and empanelment buyers differ from everyone else?
- Where does the sale usually stall?
- What happens after the test?
- What to do next
A buyer hiring a VAPT firm checks four things before they reply: a sample report that shows how findings are written, who exactly will do the testing, a method explained in plain words, and similar work for similar companies. Price comes later. The buyer is about to show an outsider every weak point in their systems, so they read for signs of care before they read for rates.
Why does the deadline matter more than the website?
Almost nobody buys security testing because they feel like it. Something has a date on it. An ISO 27001 surveillance audit, a customer's security questionnaire, a cyber insurance proposal form, a regulator's direction that reaches banks and their vendors, or a story about a company down the road that paid a ransom.
That date decides when the search happens and how impatient the buyer is. A page that says "VAPT for companies preparing for an ISO 27001 audit" meets that buyer where they are. A page headed "Protect your business from cyber threats" meets nobody.
What do they ask for before they ask for a quote?
| What the buyer wants to see | Why they ask | What to have ready |
|---|---|---|
| Sample report | To judge how clearly findings are written and rated | A redacted report with invented systems |
| Named testers | Whoever tests will see the whole network | Names, roles and relevant certifications |
| Scope and method | To know what will and will not be touched | A one-page scope template and a rules-of-engagement note |
| Similar clients | To check you have done this for a company like theirs | Client types you can describe, and references you can give with permission |
| Empanelment or certificates | Some buyers must use approved auditors | The certificates you hold, stated plainly |
| Retest | Whether fixing is checked afterwards | Whether a retest is included, and what it costs |
Empanelment and eligibility rules differ by buyer and body and change, so check the current requirement with the issuing body or the buyer's own procurement team before you bid.
How should you write about your work without exposing a client?
You cannot publish findings from real engagements, and a buyer would be alarmed if you did. But you can write about method and about classes of problem. A post on what goes wrong in a typical staff VPN setup, how a rules-of-engagement note is written, or what a retest should include shows how you think. This is also where your testers become visible: put their names and short bios on the post.
The tone matters. A firm that explains its approach calmly beats one that opens with a skull on a dark screen. Your buyer is already anxious.
How do RFP and empanelment buyers differ from everyone else?
Banks, insurers and large companies run a formal process. They issue an RFP, compare technical responses against a scoring sheet and negotiate with the top two or three. Here the winning response is the one that answers each question as asked, with the evidence attached, rather than the one with the nicest cover.
Mid-sized companies with no CISO behave differently. They lean on whoever looks after their network, ask the auditor, and speak to two firms at most. They will not read a forty-page response. They want one page: what you will test, what they receive, who does it and what you need from them.
For example, a Pune firm with six testers is invited to respond to a mid-sized manufacturer's questionnaire that came from a European customer. The IT head has no security team. A short reply that names the two testers, attaches a redacted sample report and states what access is required wins a call. A long reply about the firm's "digital resilience" does not.
Where does the sale usually stall?
After the first call, three places. The scope is still being argued internally and nobody has told you. The proposal is with finance while the IT head waits for a budget line. Or the deadline moved, so the urgency went with it.
A follow-up that helps rather than chases works best: a scope checklist the buyer can forward to their own team, the answer to a question they raised on the call, or a note on what their auditor is likely to ask. Record each opportunity with its deadline and the person who must approve, so you know whose desk it is on. Your sales process should have stages that match this, and your content should answer the questions those stages raise.
What happens after the test?
One-off assessments are easy to buy and easy to forget. A buyer who received a clear report and a useful retest is the likeliest to ask what comes next: a standing engagement, a compliance readiness project or a managed service. Raise it with the findings, while the report is on the table.
What to do next
Look at your own website as a security head would. Can they find a sample report, the names of your testers, and what a scope looks like, in under a minute? If any of the three is missing, that is where to start.
If you want a second read on how a buyer meets your firm and where the conversation stalls, book the free audit. It is a 90-minute call, followed by a written, scored report ranking what to fix first.