Penetration Testing Cost in India: 2026 Pricing Guide
Penetration testing in India typically costs Rs 50,000 to Rs 4,00,000 depending on scope. Indicative ranges by engagement type, cost drivers and red flags.
7 min readBy Pragya Dwivedi, Associate Director
Reviewed by Sachin Shirish, Director, CEH, ISO 27001 Lead Auditor

Most pricing guides for security testing never publish a number. This one does. The short answer on penetration testing cost in India: expect an indicative range of Rs 50,000 to Rs 4,00,000, depending on scope. That is the same range we publish on our VAPT service page, and everything below explains where inside it your engagement is likely to land, and why.
One caution before the table. These are indicative ranges, not quotes. A serious provider fixes the price after scoping, never before, and the figure should not grow later the way an open-ended estimate does.
Indicative Pricing by Engagement Type
| Engagement Type | What It Typically Covers | Indicative Range |
|---|---|---|
| Small web application | One application, a handful of user roles, limited endpoints | Rs 50,000 to Rs 1,00,000 |
| API or mobile application | One API surface or one mobile platform, authenticated testing | Rs 70,000 to Rs 1,50,000 |
| Network infrastructure | External and internal testing across a defined IP range | Rs 1,00,000 to Rs 2,00,000 |
| Web application plus API | Combined application and backend API assessment | Rs 1,20,000 to Rs 2,50,000 |
| Large multi-asset engagement | Multiple applications, APIs and infrastructure in one programme | Rs 2,00,000 to Rs 4,00,000 |
Every figure above is a subdivision of the same Rs 50,000 to Rs 4,00,000 band. Where you land within a row depends on the factors below, and no provider can tell you the exact number until scoping is done.
What Actually Drives the Price
Five variables account for almost all of the spread between the bottom and the top of the range.
Scope
Scope is the single largest driver. A test against one login page with two user roles is a different job from a test against an application with fifteen roles, payment flows and file uploads. Before asking for quotes, write down exactly what is in scope: which applications, which environments, which user roles, and what is explicitly excluded. A tight scope produces a tight price.
Asset Count
Every additional application, API, mobile platform or IP block adds tester days. Providers count targets before anything else. Ten external IPs and one web application is a small engagement. Forty IPs, three applications and two APIs is not, even if each individual asset is simple. Bundling assets into one engagement usually costs less than testing them separately, because scoping, setup and reporting overheads are shared.
Methodology Depth
An automated vulnerability scan with a human glancing at the output is cheap to run, and it is not a penetration test. Manual testing, where a qualified tester chains findings, abuses business logic and attempts real exploitation, takes days rather than hours. The choice between black box, grey box and white box testing also matters: grey box testing with credentials supplied typically finds more in less time, which is why we recommend it for most applications.
Retest Inclusion
After you fix the findings, someone has to verify the fixes. Some providers include one retest in the quoted price. Others bill it separately, which can add a meaningful percentage to the total. Always ask. A quote that looks lower may simply have moved the retest into a future invoice.
Reporting
A raw tool export is not a report. A proper deliverable includes an executive summary a board can read, technical findings with reproduction steps, risk ratings justified against your context, and remediation guidance your developers can act on. Reports that satisfy auditors for ISO 27001, SOC 2 or PCI DSS evidence requirements take longer to produce, and that time is in the price.
What a Proper Quote Should Include
When quotes arrive, compare them line by line, not by the bottom figure. A quote worth signing states, in writing:
- Exact scope: the named applications, APIs, IP ranges and environments to be tested, and what is excluded.
- Methodology and standards: the testing approach (black, grey or white box) and the standards followed, such as OWASP guidance for applications.
- Effort and testers: how many tester days are allocated and who is doing the work, including their qualifications.
- Deliverables: the report format, whether a management summary is included, and whether the report is fit for audit evidence.
- Retest terms: whether one retest is included, the window in which it can be used, and what a second retest costs.
- Support after delivery: whether the testers will walk your developers through findings, and for how long questions are answered.
- A fixed price: a single number for the agreed scope, not a band and not a day rate with no cap.
If a provider cannot put these in writing, the low price is doing the selling, and you should ask what it is covering for.
Red Flags of Too-Cheap Testing
The bottom of the market is crowded with offers well below any realistic cost of manual work. Common warning signs:
- A price quoted before scoping. Nobody can price work they have not measured. An instant quote means a fixed template of automated scans, whatever your environment looks like.
- No named testers. If the provider will not say who tests, with what qualifications, assume the answer is a scanner licence and a junior analyst.
- Suspiciously fast delivery. A meaningful application test takes days of manual effort. A two-hundred-page report delivered the next morning is a rebranded scan output.
- Findings without reproduction steps. If your developers cannot reproduce an issue, they cannot fix it, and you cannot verify the fix.
- No retest offered at any price. A provider with no interest in verifying fixes was never planning to find anything real.
- A certificate offered upfront. Some vendors sell a "safe to host" certificate regardless of results. Auditors and enterprise customers see through this, and it can cost you a deal at exactly the wrong moment.
A cheap test that misses an exploitable flaw is not a saving. You pay for it later, with interest, in incident response.
Compliance Requirements Change the Maths
If the test exists to satisfy PCI DSS, SOC 2, ISO 27001 or a customer's vendor security review, say so during scoping. Compliance-driven tests carry specific expectations on methodology, evidence and report content, and a test that ignores them may need to be repeated. Organisations subject to the DPDP Act should also treat testing as part of their reasonable security safeguards, and keep the reports as evidence that those safeguards are real. Stating the compliance driver upfront costs nothing and prevents an expensive second engagement.
How to Keep the Price Down Without Cutting Corners
Some legitimate levers reduce cost without reducing assurance:
- Fix the obvious first. Patch known issues and close unused services before the test starts, so paid tester time goes to what only a human can find.
- Provide credentials and documentation. Grey box testing with working accounts and an architecture overview saves reconnaissance days you would otherwise pay for.
- Right-size the engagement. A startup with one application does not need an enterprise-grade red team exercise. Match the depth to the risk.
- Bundle related assets. One engagement covering the web application and its API costs less than two separate engagements a quarter apart.
- Schedule retests promptly. Retesting within the included window avoids paying for a fresh engagement later.
The Bottom Line
Penetration testing cost in India sits in an indicative band of Rs 50,000 to Rs 4,00,000, and the honest answer to "what will mine cost" is always the same: it depends on scope, and it should be fixed in writing before work begins. Choose the provider who asks detailed scoping questions over the one who quotes instantly. The questions are the first sign you are buying a real test.
Tell us what is in scope and when you need it, and we will return a written scope and a fixed price for your engagement. Talk to our VAPT team.
Have a Question About This?
If this raised something specific to your environment, a scoping call is the fastest way to get a direct answer.
We reply within one business day.


