Penetration Testing Cost: What Drives VAPT Pricing
Penetration testing cost depends mainly on scope: how many applications, user roles, API endpoints, IP addresses or cloud accounts are tested, how deep the testing goes and what reporting you need. This guide explains each factor so you can budget with confidence, compare quotes fairly and avoid paying for a scan dressed up as a pentest.
Last reviewed 2026-09-28 by the Scantra Security testing team
The main factors that affect VAPT cost
- Number and size of targets: pages, features, endpoints, IPs or cloud accounts
- Number of user roles and tenants that need access control testing
- Testing approach: black box, grey box or white box
- Depth: a quick assessment versus a full manual exploitation engagement
- Environment: staging, production, on-premise or multi-cloud
- Compliance reporting needs, such as CERT-In, RBI, PCI DSS or SOC 2 mapping
- Timeline: rush engagements need more testers in parallel
- Retesting: included free with Scantra, but charged separately by some vendors
Typical engagement types
A single web application or API test is the most common starting point for startups. Mobile apps are usually tested together with their backend APIs. Network and cloud assessments are priced by the number of assets and accounts. Organisations with many applications often choose an annual programme or PTaaS model for predictable spend.
[CONFIRM: indicative price ranges in INR and USD for each engagement type, if you want to publish them]
Why cheap pentests are often expensive
Very low quotes usually mean an automated scan with a report template on top. That can satisfy a checkbox, but it rarely finds the access control and logic issues that attackers exploit, and auditors increasingly spot the difference. Ask any vendor how many days of manual testing are included, who will do the testing, and whether you can see a sample report.
Questions to ask when comparing quotes
- How many tester-days of manual work are included?
- Is the retest included, and how long is the retest window?
- Will the report map findings to the frameworks I need?
- Is the vendor CERT-In empanelled, if my regulator requires it?
- Can I see a sample report before signing?
How to get an accurate quote
Share what you want tested, the number of roles, rough size of the application or network and any compliance deadline. We will book a short scoping call and send a fixed price quote, usually within one working day. Pricing for Indian clients is quoted in INR plus GST.
Frequently asked questions
Why don't you publish fixed prices?
Two applications of the same 'size' can need very different effort. A fixed quote after scoping is fairer and avoids surprise charges.
Is the retest included in the price?
Yes. Every Scantra engagement includes a free retest.
Do you charge in INR?
Yes, Indian clients are quoted in INR with GST as applicable. International clients can be quoted in USD.
How can I reduce pentest cost?
Provide test accounts, documentation and a stable staging environment. Clear scope reduces the time testers spend on discovery.
Is VAPT cost different from pentest cost?
VAPT combines assessment and testing, so it is priced on the same scope factors as a penetration test.
