Before You Ask
What a Penetration Test Actually Costs in India
Quotes for the same application routinely differ by a factor of five. Almost always the difference is not margin — it is that the two proposals describe genuinely different pieces of work.
- Priced on engineer days, not per scan or per IP
- Scope agreed in writing before work starts
- No per-finding or per-report charges
Why comparable quotes look nothing alike
A penetration test is priced on skilled human time. Almost every cost difference between two proposals reduces to a difference in how many engineer days are allocated and what those days are spent doing. A quote that undercuts the market by eighty percent has usually replaced manual exploitation with an automated scan and a reformatted export.
The fastest way to compare proposals fairly is to ask each provider how many engineer days are allocated, how much of that is manual, and whether a retest is included. The numbers usually explain themselves after that.
What actually drives the number
The size of the real attack surface
Not how many applications you have, but how many distinct functional areas, user journeys and integrations exist inside them. A single application with fourteen user roles, a payment flow and six third-party integrations is a larger piece of work than four simple brochure sites.
The number of roles and permission levels
Access control testing scales with the number of role pairs, not the number of roles. Every additional role multiplies the combinations an engineer has to attempt, which is why role count moves a quote more than most clients expect.
Depth of testing
An automated scan with light validation, a standard manual assessment, and a deep business-logic engagement with chained exploitation are three different products. All three are legitimately called a penetration test, which is precisely why the term alone tells you almost nothing about price.
Whether authenticated testing is in scope
Testing an application from outside is a fraction of the effort of testing it with credentials for every role. Unauthenticated-only testing is much cheaper and misses the majority of serious findings in most modern products, because most of the product is behind a login.
Reporting and compliance requirements
An engineering-facing findings list is quicker to produce than an audit-ready evidence pack with control mapping, severity rationale and closure statements. If the report has to satisfy an auditor, that work is real and it belongs in the estimate.
Retests
Confirming your fixes actually worked takes real time. Some providers include it, some charge separately, and some do not offer it at all. This single line item explains a large share of the apparent gap between two quotes.
Timeline
Compressing an engagement to meet an audit date means allocating more engineers in parallel, which costs more than the same work spread over a normal window. Booking earlier is the cheapest lever you control.
What should never affect the price
- The number of vulnerabilities found — nobody should be incentivised to inflate a report
- Whether you ask questions during remediation
- Access to the evidence and proof of concept material for findings in your own system
- Receiving the report in a format your auditor can actually use
How we scope an engagement
We ask for your architecture at a high level, the number of applications and roles, your compliance driver and deadline, and whether you need a retest. That conversation produces a written scope with a fixed number of engineer days and a fixed price, so there is no variation once work begins.
If your budget will not cover the ideal scope, we would rather tell you which subset carries the most risk and test that properly than spread the same money thinly across everything and find nothing of consequence.
Common questions
Why will you not publish a fixed price list?
Because a price for an unseen application would be either meaningless or padded to cover the worst case. What we do commit to is a fixed written price before work starts, derived from a scope you have agreed, with no variation afterwards.
Is a cheaper automated scan ever the right choice?
Sometimes, and we will say so. If you have never tested anything and need to find obvious exposure quickly, a scan has value. It will not find business logic flaws, broken access control between roles, or tenant isolation failures, and it will not satisfy an auditor asking for a penetration test.
Do you charge separately for the retest?
Tell us during scoping whether you need one and it will be priced into the engagement, so you are not deciding about it later under deadline pressure.
What is the cheapest useful engagement you would take on?
The floor is set by what the application actually requires, not by a price point. We would rather scope a narrow engagement honestly — one critical flow, tested properly — than spread a small budget thinly across an entire platform and hand you a report that implies coverage we did not achieve. If the budget will not support a defensible scope, we say so.
Why are quotes from different vendors so far apart?
Because they are frequently for different work. A scan-and-report exercise and a manual engagement with exploitation, chained findings and retesting both get called a penetration test and can differ tenfold in effort. Ask each vendor how many engineer-days are allocated, how much is manual, and whether retesting is included; the gap usually explains itself immediately.
Does testing get cheaper the second year?
Often somewhat, because we already understand your architecture and scoping is faster. It does not drop dramatically, since the testing effort itself is what you are paying for and your application will have changed. Teams that deploy frequently sometimes find periodic smaller engagements better value than one large annual test.
What makes an engagement more expensive than expected?
Role count more than anything else, because testing scales with role pairs rather than roles. After that: multiple tenants requiring isolation testing, several client applications against one API, heavy bespoke business logic, and compliance frameworks with specific scope obligations such as PCI-DSS segmentation testing. All of it is identified before the price is fixed.
Let's scope your infrastructure.
Tell us what you have built and what you are testing against. You will speak to a Lead Security Architect, not a sales desk, and you will get a written scope with a fixed price before any work begins.