Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Penetration Testing Cost in India: 2026 Pricing Guide

Penetration testing in India typically costs Rs 50,000 to Rs 4,00,000 depending on scope. Indicative ranges by engagement type, cost drivers and red flags.

11 min readBy , Associate Director

Reviewed by Sachin Shirish, Director, CEH, ISO 27001 Lead Auditor

Penetration Testing: Penetration testing cost in India, 2026. Illustrated cover by SecureRoot Risk Advisory.

Most pricing guides for security testing never publish a number. This one does. The short answer on penetration testing cost in India: expect an indicative range of Rs 50,000 to Rs 4,00,000, depending on scope. That is the same range we publish on our VAPT service page, and everything below explains where inside it your engagement is likely to land, and why.

One caution before the table. These are indicative ranges, not quotes. A serious provider fixes the price after scoping, never before, and the figure should not grow later the way an open-ended estimate does.

Indicative Pricing by Engagement Type

Engagement Type What It Typically Covers Indicative Range
Small web application One application, a handful of user roles, limited endpoints Rs 50,000 to Rs 1,00,000
API or mobile application One API surface or one mobile platform, authenticated testing Rs 70,000 to Rs 1,50,000
Network infrastructure External and internal testing across a defined IP range Rs 1,00,000 to Rs 2,00,000
Web application plus API Combined application and backend API assessment Rs 1,20,000 to Rs 2,50,000
Large multi-asset engagement Multiple applications, APIs and infrastructure in one programme Rs 2,00,000 to Rs 4,00,000

Every figure above is a subdivision of the same Rs 50,000 to Rs 4,00,000 band. Where you land within a row depends on the factors below, and no provider can tell you the exact number until scoping is done.

What Actually Drives the Price

Five variables account for almost all of the spread between the bottom and the top of the range.

Scope

Scope is the single largest driver. A test against one login page with two user roles is a different job from a test against an application with fifteen roles, payment flows and file uploads. Before asking for quotes, write down exactly what is in scope: which applications, which environments, which user roles, and what is explicitly excluded. A tight scope produces a tight price.

Asset Count

Every additional application, API, mobile platform or IP block adds tester days. Providers count targets before anything else. Ten external IPs and one web application is a small engagement. Forty IPs, three applications and two APIs is not, even if each individual asset is simple. Bundling assets into one engagement usually costs less than testing them separately, because scoping, setup and reporting overheads are shared.

Methodology Depth

An automated vulnerability scan with a human glancing at the output is cheap to run, and it is not a penetration test. Manual testing, where a qualified tester chains findings, abuses business logic and attempts real exploitation, takes days rather than hours. The choice between black box, grey box and white box testing also matters: grey box testing with credentials supplied typically finds more in less time, which is why we recommend it for most applications.

Retest Inclusion

After you fix the findings, someone has to verify the fixes. Some providers include one retest in the quoted price. Others bill it separately, which can add a meaningful percentage to the total. Always ask. A quote that looks lower may simply have moved the retest into a future invoice.

Reporting

A raw tool export is not a report. A proper deliverable includes an executive summary a board can read, technical findings with reproduction steps, risk ratings justified against your context, and remediation guidance your developers can act on. Reports that satisfy auditors for ISO 27001, SOC 2 or PCI DSS evidence requirements take longer to produce, and that time is in the price.

What a Proper Quote Should Include

When quotes arrive, compare them line by line, not by the bottom figure. A quote worth signing states, in writing:

  • Exact scope: the named applications, APIs, IP ranges and environments to be tested, and what is excluded.
  • Methodology and standards: the testing approach (black, grey or white box) and the standards followed, such as OWASP guidance for applications.
  • Effort and testers: how many tester days are allocated and who is doing the work, including their qualifications.
  • Deliverables: the report format, whether a management summary is included, and whether the report is fit for audit evidence.
  • Retest terms: whether one retest is included, the window in which it can be used, and what a second retest costs.
  • Support after delivery: whether the testers will walk your developers through findings, and for how long questions are answered.
  • A fixed price: a single number for the agreed scope, not a band and not a day rate with no cap.

If a provider cannot put these in writing, the low price is doing the selling, and you should ask what it is covering for.

Red Flags of Too-Cheap Testing

The bottom of the market is crowded with offers well below any realistic cost of manual work. Common warning signs:

  • A price quoted before scoping. Nobody can price work they have not measured. An instant quote means a fixed template of automated scans, whatever your environment looks like.
  • No named testers. If the provider will not say who tests, with what qualifications, assume the answer is a scanner licence and a junior analyst.
  • Suspiciously fast delivery. A meaningful application test takes days of manual effort. A two-hundred-page report delivered the next morning is a rebranded scan output.
  • Findings without reproduction steps. If your developers cannot reproduce an issue, they cannot fix it, and you cannot verify the fix.
  • No retest offered at any price. A provider with no interest in verifying fixes was never planning to find anything real.
  • A certificate offered upfront. Some vendors sell a "safe to host" certificate regardless of results. Auditors and enterprise customers see through this, and it can cost you a deal at exactly the wrong moment.

A cheap test that misses an exploitable flaw is not a saving. You pay for it later, with interest, in incident response.

Compliance Requirements Change the Maths

If the test exists to satisfy PCI DSS, SOC 2, ISO 27001 or a customer's vendor security review, say so during scoping. Compliance-driven tests carry specific expectations on methodology, evidence and report content, and a test that ignores them may need to be repeated. Organisations subject to the DPDP Act should also treat testing as part of their reasonable security safeguards, and keep the reports as evidence that those safeguards are real. Stating the compliance driver upfront costs nothing and prevents an expensive second engagement.

How to Keep the Price Down Without Cutting Corners

Some legitimate levers reduce cost without reducing assurance:

  1. Fix the obvious first. Patch known issues and close unused services before the test starts, so paid tester time goes to what only a human can find.
  2. Provide credentials and documentation. Grey box testing with working accounts and an architecture overview saves reconnaissance days you would otherwise pay for.
  3. Right-size the engagement. A startup with one application does not need an enterprise-grade red team exercise. Match the depth to the risk.
  4. Bundle related assets. One engagement covering the web application and its API costs less than two separate engagements a quarter apart.
  5. Schedule retests promptly. Retesting within the included window avoids paying for a fresh engagement later.

Frequently asked questions

How much does penetration testing cost in India in 2026?

Penetration testing in India sits in an indicative band of Rs 50,000 to Rs 4,00,000, and where you land depends on the engagement type. A small web application with a handful of user roles typically runs Rs 50,000 to Rs 1,00,000. A single API surface or mobile platform with authenticated testing is around Rs 70,000 to Rs 1,50,000. Network infrastructure testing across a defined IP range is roughly Rs 1,00,000 to Rs 2,00,000, a combined web application and API assessment Rs 1,20,000 to Rs 2,50,000, and a large multi-asset programme Rs 2,00,000 to Rs 4,00,000. These are indicative ranges, not quotes. No provider can give you an exact number before scoping, because scope, asset count, methodology depth, retest terms and reporting requirements move the price within each row. Write down what is in scope and ask for a fixed price against it.

Why do penetration testing quotes vary so much for the same application?

Five variables explain almost all of the spread. Scope is the largest: an application with fifteen user roles, payment flows and file uploads is a different job from one login page with two roles. Asset count comes next, because every additional application, API, mobile platform or IP block adds tester days. Methodology depth matters too: an automated scan with a human glancing at the output is cheap, while manual testing that chains findings, abuses business logic and attempts real exploitation takes days rather than hours. Retest inclusion changes the total, since some providers include one retest and others bill it separately. Reporting is the fifth: a report fit for ISO 27001, SOC 2 or PCI DSS evidence takes longer to produce than a raw tool export. When two quotes differ sharply, compare these five lines before comparing the bottom figure, because the cheaper quote has usually left one of them out.

What should a penetration testing quote include?

A quote worth signing states seven things in writing. First, the exact scope: named applications, APIs, IP ranges and environments, and what is excluded. Second, the methodology and standards, such as black, grey or white box testing and OWASP guidance for applications. Third, the effort and the testers: how many tester days are allocated, who does the work, and their qualifications. Fourth, the deliverables: the report format, whether a management summary is included, and whether the report is fit for audit evidence. Fifth, the retest terms: whether one retest is included, the window for using it, and what a second one costs. Sixth, support after delivery: whether testers walk your developers through findings and for how long. Seventh, a fixed price for the agreed scope, not a band and not an uncapped day rate. If a provider cannot put these in writing, the low price is doing the selling.

How can we tell if a cheap penetration test is not a real test?

Watch for six warning signs. A price quoted before any scoping means a fixed template of automated scans, because nobody can price work they have not measured. No named testers usually means a scanner licence and a junior analyst. Suspiciously fast delivery is another sign: a meaningful application test takes days of manual effort, so a long report delivered the next morning is rebranded scan output. Findings without reproduction steps leave your developers unable to fix the issue and you unable to verify the fix. A provider that offers no retest at any price was never planning to find anything real. Finally, a certificate offered upfront, such as a safe-to-host certificate sold regardless of results, will not survive scrutiny from auditors or enterprise customers and can cost you a deal at the worst moment. A cheap test that misses an exploitable flaw is not a saving; you pay for it later in incident response.

Does a compliance-driven penetration test cost more?

It can, because the report has to do more work. If the test exists to satisfy PCI DSS, SOC 2, ISO 27001 or a customer's vendor security review, those frameworks carry specific expectations on methodology, evidence and report content, and reports that satisfy auditors take longer to produce. That time is in the price. The larger risk is the opposite mistake: a test that ignores those expectations may have to be repeated, and a second engagement costs far more than scoping the first one correctly. So state the compliance driver during scoping; it costs nothing and lets the provider quote for the right deliverable. Organisations subject to the DPDP Act should also treat penetration testing as part of their reasonable security safeguards and keep the reports as evidence that those safeguards are real. You can still keep the price down by bundling related assets, supplying credentials for grey box testing, and fixing known issues before testing starts.

The Bottom Line

Penetration testing cost in India sits in an indicative band of Rs 50,000 to Rs 4,00,000, and the honest answer to "what will mine cost" is always the same: it depends on scope, and it should be fixed in writing before work begins. Choose the provider who asks detailed scoping questions over the one who quotes instantly. The questions are the first sign you are buying a real test.

Tell us what is in scope and when you need it, and we will return a written scope and a fixed price for your engagement. Talk to our VAPT team.

Have a Question About This?

If this raised something specific to your environment, a scoping call is the fastest way to get a direct answer.

We reply within one business day.

All Articles
  • Penetration Testing16 min read

    CERT-In Incident Reporting: The Six-Hour Runbook

    The CERT-In Directions give you six hours from noticing a listed incident. This is the execution side: what starts the clock, which of the 20 Annexure I types are reportable, the channels and fields, who is allowed to submit, and what to send when the facts are still moving at hour five.

    Read Article
  • Penetration Testing: How often to run VAPT. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing13 min read

    How Often Should VAPT Be Done? Annual Baseline, Change Triggers and Regulator Cadence in India

    Once a year is the floor, not the plan. This guide sets out when VAPT must be repeated after change, what RBI, SEBI, IRDAI and PCI DSS each require, and how to set a risk-based cadence by asset type.

    Read Article
  • Penetration Testing: CERT-In Directions, in practice. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing14 min read

    CERT-In Directions Compliance in India: 6-Hour Reporting, Logs and NTP

    The CERT-In Directions of 28 April 2022 apply to almost every organisation running ICT systems for Indian users. This guide walks through each obligation, what CERT-In's own FAQs clarify, and how VAPT and log monitoring make the 6-hour clock achievable.

    Read Article