What Drives VAPT Pricing in India: A Practical Guide to Budgeting Your Security Assessment
Organisations seeking VAPT quotes in India frequently encounter a wide price range — sometimes a 5x spread between proposals for what appears to be the same scope. The variation is not random. It reflects genuine differences in testing depth, methodology, auditor seniority, and post-engagement support. Understanding the cost drivers helps procurement teams and security managers evaluate proposals on substance rather than just price, and build realistic security budgets.
The primary cost drivers in VAPT engagements
Scope is the single largest variable. A VAPT for a five-page marketing website is operationally nothing like a VAPT for a 200-endpoint REST API used by a banking application with OAuth 2.0 flows, complex role hierarchies, and real-time transaction logic. Scope is typically defined by asset count (how many IP addresses, web applications, mobile apps, APIs), by the complexity of each asset (static vs transactional, number of user roles, authentication mechanisms), and by the depth of testing required (automated scanning only vs manual testing to OWASP ASVS Level 2 or Level 3).
Testing depth: automated vs manual
Automated scanning — running tools like Burp Suite Pro, Nessus, Nikto, or ZAP against a target — is fast and repeatable. It catches a specific class of vulnerability: known CVEs in software versions, common web application patterns (reflected XSS, SQL injection in obvious parameters), and configuration issues. It will not find business logic flaws, multi-step attack chains, access control failures that require understanding the application's authorisation model, or second-order injection vulnerabilities. Manual testing, conducted by an experienced practitioner, catches these. The difference in cost between a mostly-automated assessment and a genuine manual pentest reflects the cost of senior practitioner time — OSCP/OSWE-certified testers commanding market rates.
The benchmark for meaningful web application testing is OWASP ASVS Level 2 — the standard for most commercial applications handling sensitive data. Level 3 (highest) is typically reserved for financial systems, healthcare applications, and government systems. ASVS Level 1 is largely achievable through automated tooling. If a proposal does not specify an ASVS level or equivalent, it is worth asking — the answer will tell you whether you are buying a scan or a pentest. Explore our web application VAPT service for scope and methodology details.
Asset count and infrastructure complexity
Network penetration testing is priced per IP range or per subnet, with adjustments for the number of live hosts and the complexity of services running on them. A /24 network with 200 hosts running standard services will take longer than a /28 with 10 hosts — but a /28 with custom industrial control systems or legacy ERP applications may take longer still because the tester must understand the system deeply before probing it safely. Mobile application testing is priced per platform (iOS, Android) and per app, with complexity factors for offline functionality, cryptographic operations, and custom security controls that must be understood before they can be tested against OWASP MASVS.
Retest: the cost line that gets overlooked
Almost every regulated engagement requires a retest — a verification that critical and high findings were actually remediated. Retest scope is typically limited to the specific vulnerabilities identified rather than a full re-engagement, but it still consumes practitioner time. Some vendors include retest in the quoted price; others bill it separately. CERT-In empanelled audits for regulatory purposes (RBI, SEBI, IRDAI) typically require a closure confirmation, which means a retest is non-optional. Budget for it explicitly. The retest also gives you the compliance artefact — a confirmation letter from the empanelled auditor that critical issues have been resolved.
CERT-In empanelment: why it affects pricing
Empanelled firms carry a cost base that non-empanelled vendors do not. Maintaining empanelment requires certified auditors (OSCP, OSWE, CEH, CISSP, CISA), documented and auditable methodology, secure evidence handling infrastructure, and periodic re-evaluation by CERT-In. These are real costs that justify a price premium over unempanelled vendors. More practically: an audit from a non-empanelled vendor cannot satisfy RBI, SEBI, IRDAI, or government procurement requirements. If your use case is regulatory compliance, the question is not whether to use an empanelled firm — it is what the right scope and methodology is.
Building a realistic VAPT budget
A mid-market SaaS company with a single web application, a REST API, and a mobile app (iOS + Android) should expect to budget for three distinct assessments, or a combined engagement scoped across all three surfaces. A regulated BFSI entity with a customer portal, core banking API, and mobile banking app should additionally budget for network infrastructure testing, API security testing aligned to OWASP API Top 10, and the retest confirmation letter. Annual recurring costs should be built into the security budget line — point-in-time assessments are table stakes, not the ceiling.
For transparent, itemised pricing on your specific scope, visit our pricing page or talk to an expert for a custom scoping conversation.
Put this into action.
Book a 30-minute scoping call with a CERT-In empanelled security expert.
Talk to an ExpertMore articles
SEBI CSCRF 2024: A Compliance Roadmap for Stock Brokers and Market Infrastructure Institutions
SEBI CSCRF 2024: VAPT cadence, audit documentation, CERT-In empanelment, and compliance timelines for brokers and MIIs.
May 12, 2026IRDAI Cyber Security Guidelines: What Annual IS Audits and VAPT Mean for Insurers
IRDAI IS audit and VAPT obligations for insurers explained: annual audit scope, CERT-In empanelment, DPDP Act implications, and what regulators examine.
May 12, 2026What CERT-In Empanelment Means for Your Security Audit
CERT-In empanelment explained: what it is, why it matters for RBI/SEBI/IRDAI regulated entities, Safe-to-Host certificates, and what to expect from a compliant audit.
