VAPT cost in India ranges from around ₹25,000 for a basic scan to ₹8,50,000 or more for compliance-grade manual testing of a complex environment. A typical mid-sized web application with APIs sits between ₹1,50,000 and ₹3,50,000. Automated scanning alone runs ₹20,000 to ₹50,000, and manual penetration testing of a single web app usually starts around ₹40,000.
That is a wide band, and the spread is the point. Two quotes for the same application can differ by a factor of seven, and the cheaper one is frequently a scan with a report template attached. This guide breaks down what each band actually buys, the four variables that move the number, and the specific questions that separate a real quote from a cheap one.
VAPT Price Bands in India
The figures below reflect prevailing market ranges across Indian providers in 2026. They are context for budgeting, not a quote — pricing is always scoped per asset.
| What you are buying | Typical range (INR) | Approx. USD |
|---|---|---|
| Automated vulnerability scan only | ₹20,000 – ₹50,000 | $240 – $600 |
| Basic web app, startup scope | ₹25,000 – ₹75,000 | $300 – $900 |
| Manual web app pentest, single app | ₹40,000 – ₹2,00,000 | $470 – $2,350 |
| Mid-sized web app plus APIs | ₹1,50,000 – ₹3,50,000 | $1,750 – $4,100 |
| Compliance-grade manual engagement | ₹3,00,000 – ₹8,50,000 | $3,500 – $10,000 |
| Complex multi-system infrastructure | Up to ₹10,00,000+ | $12,000+ |
Indian providers generally price 60–80% below equivalent US firms for comparable scope — security consultants bill roughly $25–$60 per hour in India against $150–$300 in the US. That gap is the main reason US and European teams engage Indian providers for this work.
What Actually Drives VAPT Pricing
Four variables move the number more than anything else. A quote that does not state its assumptions on all four is quoting a different job to the one you need.
1. Asset count and complexity
The volume of things to test is the primary driver: number of applications, API endpoints, IP addresses, cloud accounts and mobile apps. Complexity matters as much as count — a payment flow, a multi-tenant authorisation model or a third-party integration takes far longer to test properly than a brochure site with the same page count.
2. Manual versus automated ratio
This is where the seven-times spread comes from. Automated scanning is cheap because it is machine time. Manual testing is expensive because it is senior human time, and it is the only thing that finds business logic flaws, chained privilege escalation and authorisation failures.
Many low-cost providers rely almost entirely on scanners. That is not fraud — it is a different product — but it is worth knowing which one you are buying.
3. Authenticated versus unauthenticated
Testing without credentials is cheaper and substantially less useful, because most real risk lives behind a login. If a quote is unusually low, check whether authenticated testing is included. An unauthenticated-only VAPT audit leaves the majority of your attack surface untested.
4. Compliance requirements
Compliance-driven testing costs more because it involves more documentation, validation and reporting. Evidence has to be structured for an auditor rather than for your engineers, and the retest cycle becomes mandatory rather than optional. If you are testing for SOC 2 or ISO 27001, budget for that overhead explicitly.
What Should Be Included in the Price
Ask specifically whether these are in scope, because they are the items most commonly excluded to make a quote look competitive:
- Retest after remediation — the single most commonly excluded item, and the one an auditor will ask for. A test without a retest proves you looked; it does not prove anything was fixed.
- The certificate or attestation letter — most enterprise customers asking for "your VAPT certificate" want the post-retest version. Confirm which one you are getting.
- A walkthrough call — findings explained to your engineers, not just a PDF dropped in an inbox.
- Remediation guidance specific to your stack, rather than generic advice copied from scanner output.
- Same-day escalation of criticals — you should not learn about an actively exploitable flaw three weeks later when the report lands.
Why the Cheapest Quote Is Usually the Most Expensive
A ₹30,000 scan and a ₹3,00,000 engagement are not the same service at different price points. The first is a tool run against your application with a report generated from the output. The second is senior testers spending days trying to break it.
The economics are worth sitting with. IBM's 2025 Cost of a Data Breach report put the average breach cost in India at ₹22 crore — the highest level recorded in the country. Against that, the difference between a ₹30,000 scan and a ₹3,00,000 engagement is not really a cost decision.
The failure mode is specific: the cheap scan passes the compliance checkbox and misses the authorisation flaw. You have a certificate, and you still have the vulnerability.
How to Compare Quotes Properly
Ask every provider the same five questions, and compare the answers rather than the totals:
- What percentage of the engagement is manual? If the answer is vague, you are buying a scan.
- How many person-days, at what seniority? This is the honest way to compare two very different numbers.
- Is the retest included, and how many rounds? Get it in writing.
- What certifications do the actual testers hold? OSCP and similar hands-on offensive credentials are the relevant signal — not the firm's general badges.
- Can I see a redacted sample report? This tells you more than the proposal. Look at whether remediation guidance is specific enough for an engineer to act on.
Budgeting Beyond the First Test
Most frameworks expect testing at least annually, and continuously if your environment changes constantly. Three patterns work:
- Annual point-in-time testing — the compliance baseline. Adequate if your release cadence is slow.
- Annual test plus continuous scanning — the common middle ground. Manual depth once a year, automated coverage between.
- Testing tied to release cycles — for teams shipping continuously, where an annual test leaves an eleven-month gap.
The recurring cost teams forget is not the test. It is remediation engineering time, and evidence collection if you are on a compliance cycle. Both are cheaper when the controls that prevent recurrence sit in your pipeline — which is why DevSecOps and cloud security work reduce your testing bill over time rather than adding to it.
Getting an Accurate Number
No provider can price this properly without knowing your asset count, whether testing is authenticated, and which framework you are testing for. Any quote given before those three questions have been asked is a placeholder.
If you want your environment scoped and priced against what you actually need — rather than against the cheapest scope that fits a budget line — explore our VAPT services or talk to our team. We will tell you what the realistic band is for your estate, and where a lower-cost approach would genuinely be sufficient.
Related reading: what a VAPT audit covers, VAPT for SOC 2 and ISO 27001, and the OWASP Top 10:2025 categories testing focuses on.