Common engagement models
Indian vendors typically quote fixed-scope assessments (defined assets and time-box), per-asset pricing for portfolios, or quarterly retainers for continuous coverage. Fixed-scope suits pre-launch audits; retainers suit teams shipping weekly.
What drives the cost
The biggest drivers are asset count and complexity, number of user roles (each role multiplies authorization testing), API surface area, mobile binaries, network ranges, and whether social engineering or cloud review is included.
What a proper quote includes
Scoping call with rules of engagement, manual exploitation beyond scanners, CVSS-rated findings with reproduction steps, an executive summary for leadership, developer-ready remediation guidance, and a retest window for critical fixes.
How to compare quotes fairly
Normalize on tester-days and methodology, not just price. Ask for a sample (redacted) report, confirm manual testing hours, check OWASP coverage claims against the actual test plan, and verify retest terms.
Red flags in cheap quotes
No scoping call, no defined methodology, 'AI-powered fully automated' with zero manual hours, no retest, no executive summary, and refusal to share sample reports. These engagements produce PDFs, not security.