Pentest pricing and quotes

Penetration testing pricing, quoted on your scope

Get a clear, written quote for web app, API, mobile, cloud and network pentesting or VAPT. Tell us what needs testing and book a 30-minute scoping call.

Get my quote
  • Priced on your real scope: Targets, user roles, endpoints and depth of manual testing, not a one-size package.
  • Written scope before any work: You see exactly what is tested, how, and when, before testing starts.
  • INR for India, USD for global teams: Indian clients are quoted in INR with GST as applicable.
  • Compare quotes fairly: We show the manual testing effort behind the number so you can compare like for like.
Free scoping call Written scope and quote

Get your pentest quote

Tell us what needs testing, then choose a 30-minute scoping slot.

You receive a written scope, timeline and price after the call.

From first call to a written quote

  1. 01

    Book a 30-min call

    Pick a slot and tell us what needs testing.

  2. 02

    Scope together

    We walk through targets, roles, environments and any audit deadline.

  3. 03

    Receive a written quote

    Scope, approach, timeline and price in one document.

  4. 04

    Start testing

    Once approved, we agree testing windows and begin.

What drives the price

Six factors behind every pentest quote

Knowing these helps you budget, and makes quotes from different vendors easier to compare.

Number of targets

Each web app, API, mobile app, cloud account or IP range is scoped as its own target.

User roles

More roles mean more access control paths to test for privilege escalation and data leaks.

Size and complexity

Pages, API endpoints, workflows and integrations decide how many days of manual testing are needed.

Testing approach

Black box, grey box or white box testing changes the depth and the effort involved.

Compliance reporting

Mapping findings to ISO 27001, SOC 2, PCI DSS, RBI or SEBI requirements adds reporting effort.

Timeline and windows

Tight deadlines or restricted testing windows can change how the engagement is staffed.

Pricing

Clear, scoped pricing

Every quote is fixed and based on your real scope. Book a call to get yours.

Focused

One target, pre-launch or first audit

Get a quote

  • Web application
  • APIs behind it
  • Role-based access testing
  • Executive and technical report
  • Retest of reported findings
Get my quote
Most Popular

Standard

Multiple targets or a compliance audit

Get a quote

  • Web application
  • APIs behind it
  • Role-based access testing
  • Executive and technical report
  • Retest plus updated report
Get my quote

Enterprise

Many targets, recurring testing through the year

Get a quote

  • Web application
  • APIs behind it
  • Role-based access testing
  • Executive and technical report
  • Retests across the engagement
Contact us
What counts as a target?
  • A web app plus its APIs and underlying cloud is 1 target.
  • Android and iOS apps are separate targets.
  • app.example.com and admin.example.com with separate logins are 2 targets.
  • Networks, IP ranges and cloud accounts can be grouped after scoping.

Included in every quote

What your money actually buys

  • Manual testing by security professionals, not just a scanner
  • CVSS-rated findings with evidence and reproduction steps
  • Developer-focused remediation guidance
  • Executive summary for leadership, customers and auditors
  • Compliance mapping where it applies
  • Retest of reported findings after fixes

Cheap scan vs real pentest

Low-cost scan
Scantra pentest
Mostly automated scanning
Manual testing plus automation
Generic report template
Findings with proof of impact
Misses logic and access control flaws
Tests business logic and roles
No fix verification
Retest of reported findings

Buyer checklist

Five questions to ask any pentest vendor

Use these on every quote you get, including ours.

Get my quote
  1. 1How many days of manual testing are included?
  2. 2Who will do the testing, and what are their credentials?
  3. 3Is a retest of findings included?
  4. 4Can you see a sample report before you sign?
  5. 5Is the scope written down, target by target?

Illustrative example

Scantra Security

Security Assessment Report

Web application and API

Confidential. Client name redacted.

Reports

Generate customized pentest reports

An executive view for leadership, customers and auditors. A technical view with evidence, reproduction steps and fixes for your developers.

See a sample report on a call

Pricing questions

Pentest pricing, answered

Why don't you publish fixed prices?

Two applications of the same size can need very different effort. A quote after scoping is fairer and avoids surprise charges.

What do I need to share to get a quote?

What you want tested, the number of user roles, the rough size of the application, API or network, and any compliance deadline.

Do you charge in INR?

Yes. Indian clients are quoted in INR with GST as applicable. International clients can be quoted in USD.

Is the scoping call free?

Yes. The 30-minute call is free and there is no obligation to go ahead.

Can I combine several targets in one quote?

Yes. Web, API, mobile, cloud and network targets can be combined into one coordinated engagement and one quote.

Why are some pentest quotes much cheaper?

Very low quotes often mean an automated scan with a report template on top. Ask how many days of manual testing are included.

Know your number

Get a written pentest quote for your scope

Tell us what needs testing, then choose a 30-minute slot with the Scantra Security team.