VAPT, contractedand authorisedthe right way.
SIRI Law LLP structures vulnerability assessment and penetration testing engagements, whether you are commissioning a VAPT vendor or providing testing services yourself.
- Free first consultation
- CERT-In aware
- Fixed-fee contract review
- Hyderabad and online
VAPT Legal Advisory
VAPT engagements sit right next to the line between authorised security testing and unauthorised access. The contract and authorisation letter is what keeps your testing firmly on the right side of that line, for both you and your vendor.
Companies commissioning VAPT
Contracts and authorisation that protect you and your chosen vendor.
VAPT and security testing firms
Client contracts and liability terms that protect your business.
Regulated entities
VAPT documentation that satisfies regulator expectations for periodic testing.
Companies preparing for compliance certification
VAPT scoped and documented to support your certification requirements.
Roadmap
Where we help, across the engagement.
From vendor selection to the findings report and remediation.
- 01Before testing
Select and contract the vendor
The vendor agreement sets the terms for the entire engagement.
- VAPT vendor agreement drafting or review
- CERT-In empanelment verification, where relevant
- Liability and insurance terms
- Confidentiality for testing methodology and findings
- 02Before testing
Authorise the testing
Written authorisation is what makes the testing lawful.
- Scope definition, systems and networks included
- Testing window and authorised activities
- Emergency stop and escalation procedure
- Data handling rules for anything accessed
- 03During testing
Support the engagement
Legal support stays available if something unexpected arises.
- Point of contact for real-time issues
- Guidance if testing causes unintended impact
- Evidence and finding confidentiality protocols
- 04After testing
Act on the findings
The findings report itself needs careful handling.
- Confidentiality terms for the report
- Remediation timeline agreement
- Retest scope and terms
- Documentation for compliance or regulatory purposes
What we do
VAPT engagements, properly papered.
Contracts and authorisation for both commissioning companies and testing firms.
VAPT vendor agreements
Contracts governing the relationship between you and your testing provider.
- Vendor agreements
- VAPT
- Contracts
Testing authorisation documents
The written authorisation that makes testing activity lawful.
- Authorisation
- Scope
- Legal basis
Liability and insurance structuring
Allocating risk correctly if testing causes unintended disruption.
- Liability
- Insurance
- Risk allocation
CERT-In empanelment advisory
Guidance for testing firms navigating empanelment requirements.
- CERT-In
- Empanelment
- Compliance
Findings report confidentiality
Contractual protection for the sensitive vulnerability findings a VAPT report contains.
- Confidentiality
- Findings
- Reports
Compliance-aligned VAPT scoping
Scoping testing to satisfy SOC 2, ISO 27001 or PCI DSS requirements.
- Compliance
- Scoping
- Certification
Where we come in
Five mistakes we often see.
Each one creates legal exposure for the commissioning company or the testing firm.
Testing without a signed authorisation letter
Without written authorisation from someone with authority over the systems, testing activity can be treated as unauthorised access under the IT Act.
Vague scope definitions
Ambiguity about what systems are in or out of scope is how testing accidentally touches production systems or third-party infrastructure.
No confidentiality terms for the findings report
A report cataloguing your vulnerabilities has no default legal protection without contractual confidentiality terms.
Assuming CERT-In empanelment when it has not been verified
Some regulatory contexts require testing by CERT-In empanelled auditors specifically, and this should be verified, not assumed.
No plan for unintended disruption
Testing can occasionally cause unintended impact. A contract without an escalation and liability framework leaves both parties exposed.
Ready to start?
Commissioning or providing VAPT services and need the paperwork right? Call for a free first consultation.
Tell us about your engagement and we will get the documentation ready. Calls are answered by an advocate.
Why clients choose us
We protect both sides of the engagement.
Retain us for a single matter or for the long run. Either way you deal with the same accountable team.
Both commissioning companies and vendors
We understand what each side of a VAPT engagement actually needs from the contract.
CERT-In and IT Act aware
Documentation drafted with an eye to India's specific cybersecurity regulatory framework.
Fast turnaround
VAPT engagements often have fixed windows, and we work to your schedule.
Google reviews
See what our clients say on Google.
We would rather you read independent reviews than take our word for it. Every review is on our Google Business Profile.
Questions
Common questions.
General information only, not legal advice. Every situation differs, so speak to us about yours.
Do we need CERT-In empanelled auditors for our VAPT?
This depends on your sector and specific regulatory obligations. Some contexts specifically require empanelled auditors, others do not.
We help you confirm what applies to your situation.
What should our VAPT vendor contract cover?
Scope, authorisation, liability allocation, confidentiality for findings, and remediation and retest terms are the areas most often left too vague.
We draft or review these to close common gaps.
Who should sign the testing authorisation?
Someone with actual authority over the systems being tested, which matters significantly if authorisation is ever challenged later.
We help you identify the right signatory within your organisation.
What happens if testing causes an unintended outage?
Your contract and authorisation should specify an escalation and emergency stop procedure, along with how liability for any resulting impact is allocated.
We build this into every engagement we help structure.
Is our VAPT report confidential by default?
No, confidentiality needs to be established contractually. Without it, a report cataloguing your vulnerabilities has no automatic legal protection.
This is one of the most commonly overlooked terms in VAPT contracts.
How much does this cost?
Contract and authorisation documentation is available as a fixed fee, scaled to the complexity of the engagement.
Fees are agreed in writing before work starts.
Related
Often needed alongside.
VAPT engagements often involve these services too.
Red Teaming
Adversarial testing, legally scoped.
Explore →Cybersecurity & Compliance
Testing, ISO 27001 and SOC 2.
Explore →PCI DSS Compliance
Payment data compliance advisory.
Explore →ISO 27001 Certification
ISMS scoping and certification.
Explore →Free first consultation
Tell us about your vapt matter.
High level is fine. We check conflicts, tell you honestly whether we can help, and what it would cost. You decide, with no pressure.
- Call+91 79819 12046
- WhatsAppMessage us on WhatsApp
- Emailinfo@sirilawllp.com
- HoursMon–Sat, 9:30 AM–7:00 PM IST. Incident line 24/7.
- Existing client?Message your named lead directly, or use the incident line for anything urgent.
Thank you. We have your enquiry.
A member of our team will be in touch within one working day. For anything urgent, call +91 79819 12046.
Visit us
Find our offices.
HITEC City, Madhapur, Hyderabad, Telangana 500081
Mon to Sat, 9:30 AM to 7:00 PM IST · Meetings by appointment · Online consultations worldwide

