CERT-In Certified Web VAPT
Budget / Salary₹12,500–37,500
TypeFreelance project
LocationRemote
Posted2 hours ago
I need a full-scope Vulnerability Assessment and Penetration Test on my custom-built web application, carried out by a CERT-In empanelled tester so that I can obtain the official certificate at the end of the engagement. The primary objective is to strengthen our overall security posture, not just tick a compliance box, so I am looking for a thorough, manual-heavy test that goes well beyond an automated scan.
The application is entirely bespoke, with its own authentication flow and several sensitive business modules exposed through REST APIs. You will have access to a staging environment that mirrors production, along with test accounts and any supporting documentation you require.
To make expectations clear, I will consider the engagement complete when I receive:
• A detailed VAPT report mapping findings to the latest OWASP Top 10, including reproducible PoC screenshots or request/response dumps.
• A risk-rated remediation plan with practical fixes.
• A final retest confirming all critical and high findings are closed.
• The official CERT-In compliance certificate in my company’s name.
Please outline the methodology you follow (for example, OWASP Testing Guide, PTES, or SANS) and the primary tools you rely on—Burp Suite Pro, Nmap, OWASP ZAP, or any proprietary frameworks—so I can ensure it aligns with our internal review process. If you have recently issued certificates for other custom web apps, feel free to reference them; it will speed up onboarding and NDA signing.
The application is entirely bespoke, with its own authentication flow and several sensitive business modules exposed through REST APIs. You will have access to a staging environment that mirrors production, along with test accounts and any supporting documentation you require.
To make expectations clear, I will consider the engagement complete when I receive:
• A detailed VAPT report mapping findings to the latest OWASP Top 10, including reproducible PoC screenshots or request/response dumps.
• A risk-rated remediation plan with practical fixes.
• A final retest confirming all critical and high findings are closed.
• The official CERT-In compliance certificate in my company’s name.
Please outline the methodology you follow (for example, OWASP Testing Guide, PTES, or SANS) and the primary tools you rely on—Burp Suite Pro, Nmap, OWASP ZAP, or any proprietary frameworks—so I can ensure it aligns with our internal review process. If you have recently issued certificates for other custom web apps, feel free to reference them; it will speed up onboarding and NDA signing.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.