Skip to content

Kratikal

Noida-based VAPT and phishing-simulation training provider that completed a BSE SME IPO in 2026 on the back of tripling revenue over three fiscal years.

Visit Website ↗ + Add to Compare
48/100Emerging / Unranked

Overview

Kratikal is an Indian cybersecurity company built around vulnerability assessment and penetration testing (VAPT) services, layered with a SaaS-based cyber risk management platform and phishing-simulation and security-awareness training. The combination targets a real gap in the fast-growing Indian mid-market: many organizations there need recurring VAPT and compliance evidence but lack the in-house team to run it, and Kratikal packages the testing, reporting, and staff training into one recurring engagement.

Founded in 2013 by Pavan Kushwaha, Dip Jung Thapa, and Ankit Singh, Kratikal is headquartered in Noida, India, and employs roughly 185 people. In mid-2026 the company completed an SME IPO on the BSE, raising approximately ₹40 crore, with revenue from operations growing from ₹13.01 crore in FY24 to ₹20.85 crore in FY25 and ₹36.71 crore in FY26, a documented, independently auditable growth trajectory tied to the IPO filing process.

VAPT and phishing-simulation training are mature, heavily-served categories both in India and globally, so Kratikal’s relevance is as a solid, fast-growing regional player rather than a category disruptor. Its recent public listing is a genuine and independently verifiable growth signal, though the company’s technical claims around its risk-management platform have not been validated here through named enterprise case studies or third-party security evaluations.

Innovation Matrix Assessment

Innovation Velocity 5/10

Has expanded from core VAPT services into a SaaS risk-management platform and phishing-simulation training, with revenue nearly tripling across three fiscal years, a steady rather than breakneck build-out.

Operational Value 5/10

Combines recurring VAPT engagements with a SaaS cyber risk management platform and security-awareness/phishing-simulation training, a reasonably broad offering for its size.

Market Momentum 7/10

Completed a BSE SME IPO in July 2026 raising roughly ₹40 crore, with revenue from operations growing from ₹13.01 crore (FY24) to ₹36.71 crore (FY26), a strong and independently auditable growth trajectory tied to regulatory IPO filings.

Category Disruption 3/10

VAPT and phishing-simulation training are mature, heavily-served categories in India and globally; Kratikal is a solid regional consolidator rather than a category disruptor.

Real-World Efficacy 4/10

Revenue and IPO financials are independently verifiable through regulatory filings, but no named enterprise case studies or third-party technical evaluations of its testing methodology or platform were found.

Enduring Relevance 5/10

VAPT and security-awareness training remain baseline security needs, particularly for the fast-growing Indian mid-market segment Kratikal primarily serves.

Why CISOs Should Care

Relevant to mid-market organizations, particularly in India, needing recurring VAPT, compliance evidence, and phishing-simulation training from a single vendor without building an in-house red team.

What Makes It Different

Recently completed a public listing (BSE SME IPO) with independently auditable, rapidly growing revenue, a stronger financial transparency signal than most privately-held VAPT competitors in the same market segment.

The Matrix Verdict

48/100 — EMERGING / UNRANKED

A solid, fast-growing regional VAPT and security-awareness provider with a genuine, independently verifiable growth story via its 2026 IPO; a dependable mid-market player rather than a category-disrupting innovator.

Editorial Note: Claims vs. Verified Findings

Revenue figures (₹13.01 crore FY24 to ₹36.71 crore FY26) and the IPO details are drawn from regulatory IPO filings and financial press (Chittorgarh, IPO Watch) and are independently verifiable. General marketing claims about platform capabilities and client satisfaction are vendor-sourced and were not independently corroborated here.

Sources