New

Free VAPT consultation for new enterprise clients — Book your security assessment

Cybersecurity · 9 min read

VAPT Pricing in India: How Quotes Are Structured

VAPT quotes vary widely across Indian vendors. Learn the engagement models, cost drivers, what's included in a proper assessment, and red flags in cheap quotes.

Penetration Testing Practice
Security consultant scoping a VAPT engagement with a client team

Common engagement models

Indian vendors typically quote fixed-scope assessments (defined assets and time-box), per-asset pricing for portfolios, or quarterly retainers for continuous coverage. Fixed-scope suits pre-launch audits; retainers suit teams shipping weekly.

What drives the cost

The biggest drivers are asset count and complexity, number of user roles (each role multiplies authorization testing), API surface area, mobile binaries, network ranges, and whether social engineering or cloud review is included.

What a proper quote includes

Scoping call with rules of engagement, manual exploitation beyond scanners, CVSS-rated findings with reproduction steps, an executive summary for leadership, developer-ready remediation guidance, and a retest window for critical fixes.

How to compare quotes fairly

Normalize on tester-days and methodology, not just price. Ask for a sample (redacted) report, confirm manual testing hours, check OWASP coverage claims against the actual test plan, and verify retest terms.

Red flags in cheap quotes

No scoping call, no defined methodology, 'AI-powered fully automated' with zero manual hours, no retest, no executive summary, and refusal to share sample reports. These engagements produce PDFs, not security.

Frequently asked questions

Scope size (assets, endpoints, roles), testing depth (automated vs manual exploitation), environment readiness, and reporting/retest inclusions. A single marketing site and a multi-role SaaS platform are different engagements.

Be cautious. Very cheap quotes usually mean automated scans with no manual exploitation, no business-logic testing, and no retest — the exact gaps attackers exploit.

Reputable vendors include at least one retest of critical and high findings. Confirm this in writing before signing.

Get a VAPT quote

Talk to our Gurgaon team about your project or security assessment.