Skip to content
GullySales

Notes for owners · Industry playbooks

What a buyer checks before hiring a VAPT firm

Before a CISO or IT head lets an outside firm test their systems, they look for a sample report, named testers, a clear method and proof of similar work. Here is how to be ready.

The GullySales team · Updated 6 Oct 2026 · 6 min read

On this page
  1. Why does the deadline matter more than the website?
  2. What do they ask for before they ask for a quote?
  3. How should you write about your work without exposing a client?
  4. How do RFP and empanelment buyers differ from everyone else?
  5. Where does the sale usually stall?
  6. What happens after the test?
  7. What to do next

A buyer hiring a VAPT firm checks four things before they reply: a sample report that shows how findings are written, who exactly will do the testing, a method explained in plain words, and similar work for similar companies. Price comes later. The buyer is about to show an outsider every weak point in their systems, so they read for signs of care before they read for rates.

Why does the deadline matter more than the website?

Almost nobody buys security testing because they feel like it. Something has a date on it. An ISO 27001 surveillance audit, a customer's security questionnaire, a cyber insurance proposal form, a regulator's direction that reaches banks and their vendors, or a story about a company down the road that paid a ransom.

That date decides when the search happens and how impatient the buyer is. A page that says "VAPT for companies preparing for an ISO 27001 audit" meets that buyer where they are. A page headed "Protect your business from cyber threats" meets nobody.

What do they ask for before they ask for a quote?

What the buyer wants to seeWhy they askWhat to have ready
Sample reportTo judge how clearly findings are written and ratedA redacted report with invented systems
Named testersWhoever tests will see the whole networkNames, roles and relevant certifications
Scope and methodTo know what will and will not be touchedA one-page scope template and a rules-of-engagement note
Similar clientsTo check you have done this for a company like theirsClient types you can describe, and references you can give with permission
Empanelment or certificatesSome buyers must use approved auditorsThe certificates you hold, stated plainly
RetestWhether fixing is checked afterwardsWhether a retest is included, and what it costs

Empanelment and eligibility rules differ by buyer and body and change, so check the current requirement with the issuing body or the buyer's own procurement team before you bid.

How should you write about your work without exposing a client?

You cannot publish findings from real engagements, and a buyer would be alarmed if you did. But you can write about method and about classes of problem. A post on what goes wrong in a typical staff VPN setup, how a rules-of-engagement note is written, or what a retest should include shows how you think. This is also where your testers become visible: put their names and short bios on the post.

The tone matters. A firm that explains its approach calmly beats one that opens with a skull on a dark screen. Your buyer is already anxious.

How do RFP and empanelment buyers differ from everyone else?

Banks, insurers and large companies run a formal process. They issue an RFP, compare technical responses against a scoring sheet and negotiate with the top two or three. Here the winning response is the one that answers each question as asked, with the evidence attached, rather than the one with the nicest cover.

Mid-sized companies with no CISO behave differently. They lean on whoever looks after their network, ask the auditor, and speak to two firms at most. They will not read a forty-page response. They want one page: what you will test, what they receive, who does it and what you need from them.

For example, a Pune firm with six testers is invited to respond to a mid-sized manufacturer's questionnaire that came from a European customer. The IT head has no security team. A short reply that names the two testers, attaches a redacted sample report and states what access is required wins a call. A long reply about the firm's "digital resilience" does not.

Where does the sale usually stall?

After the first call, three places. The scope is still being argued internally and nobody has told you. The proposal is with finance while the IT head waits for a budget line. Or the deadline moved, so the urgency went with it.

A follow-up that helps rather than chases works best: a scope checklist the buyer can forward to their own team, the answer to a question they raised on the call, or a note on what their auditor is likely to ask. Record each opportunity with its deadline and the person who must approve, so you know whose desk it is on. Your sales process should have stages that match this, and your content should answer the questions those stages raise.

What happens after the test?

One-off assessments are easy to buy and easy to forget. A buyer who received a clear report and a useful retest is the likeliest to ask what comes next: a standing engagement, a compliance readiness project or a managed service. Raise it with the findings, while the report is on the table.

What to do next

Look at your own website as a security head would. Can they find a sample report, the names of your testers, and what a scope looks like, in under a minute? If any of the three is missing, that is where to start.

If you want a second read on how a buyer meets your firm and where the conversation stalls, book the free audit. It is a 90-minute call, followed by a written, scored report ranking what to fix first.

Questions

Questions owners ask.

Should a security firm publish its sample report?
Publish a redacted sample, with real structure and invented system names, so the buyer sees how findings are written and rated. Never publish anything drawn from a client's real findings. Buyers trust the firm that shows its method and protects other clients' details.
Do small security firms lose every RFP to the big names?
No. Large buyers shortlist on certificates, tester credentials and similar work, and a small firm with the right credentials and a named senior tester stays in. Where the RFP needs an empanelment or a size you do not have, say so early and spend your time elsewhere.
Is fear-based marketing effective for security services?
It gets attention and loses trust. A buyer who is about to show you every gap in their systems wants a calm explanation of what you will test and what they will receive. Lead with the deadline they are working to, not the breach they dread.
Where do security buyers look for vendors?
They ask peers, their auditor and their firewall or cloud vendor's account manager, then check the firm's website, LinkedIn and published work. Be easy to confirm in all of those places, because the shortlist is usually made before anyone fills in a form.

From the blog

More notes for owners.

Your next practical step

Get a free audit of how you sell, and a scored report of where the work is.

90 minutes. A written, scored report. No invoice and no obligation.