Pentest pricing and quotes
Penetration testing pricing, quoted on your scope
Get a clear, written quote for web app, API, mobile, cloud and network pentesting or VAPT. Tell us what needs testing and book a 30-minute scoping call.
Get my quote- Priced on your real scope: Targets, user roles, endpoints and depth of manual testing, not a one-size package.
- Written scope before any work: You see exactly what is tested, how, and when, before testing starts.
- INR for India, USD for global teams: Indian clients are quoted in INR with GST as applicable.
- Compare quotes fairly: We show the manual testing effort behind the number so you can compare like for like.
Get your pentest quote
Tell us what needs testing, then choose a 30-minute scoping slot.
You receive a written scope, timeline and price after the call.
From first call to a written quote
- 01
Book a 30-min call
Pick a slot and tell us what needs testing.
- 02
Scope together
We walk through targets, roles, environments and any audit deadline.
- 03
Receive a written quote
Scope, approach, timeline and price in one document.
- 04
Start testing
Once approved, we agree testing windows and begin.
What drives the price
Six factors behind every pentest quote
Knowing these helps you budget, and makes quotes from different vendors easier to compare.
Number of targets
Each web app, API, mobile app, cloud account or IP range is scoped as its own target.
User roles
More roles mean more access control paths to test for privilege escalation and data leaks.
Size and complexity
Pages, API endpoints, workflows and integrations decide how many days of manual testing are needed.
Testing approach
Black box, grey box or white box testing changes the depth and the effort involved.
Compliance reporting
Mapping findings to ISO 27001, SOC 2, PCI DSS, RBI or SEBI requirements adds reporting effort.
Timeline and windows
Tight deadlines or restricted testing windows can change how the engagement is staffed.
Pricing
Clear, scoped pricing
Every quote is fixed and based on your real scope. Book a call to get yours.
Focused
One target, pre-launch or first audit
Get a quote
- Web application
- APIs behind it
- Role-based access testing
- Executive and technical report
- Retest of reported findings
Standard
Multiple targets or a compliance audit
Get a quote
- Web application
- APIs behind it
- Role-based access testing
- Executive and technical report
- Retest plus updated report
Enterprise
Many targets, recurring testing through the year
Get a quote
- Web application
- APIs behind it
- Role-based access testing
- Executive and technical report
- Retests across the engagement
What counts as a target?
- A web app plus its APIs and underlying cloud is 1 target.
- Android and iOS apps are separate targets.
- app.example.com and admin.example.com with separate logins are 2 targets.
- Networks, IP ranges and cloud accounts can be grouped after scoping.
Included in every quote
What your money actually buys
- Manual testing by security professionals, not just a scanner
- CVSS-rated findings with evidence and reproduction steps
- Developer-focused remediation guidance
- Executive summary for leadership, customers and auditors
- Compliance mapping where it applies
- Retest of reported findings after fixes
Cheap scan vs real pentest
Buyer checklist
Five questions to ask any pentest vendor
Use these on every quote you get, including ours.
Get my quote- 1How many days of manual testing are included?
- 2Who will do the testing, and what are their credentials?
- 3Is a retest of findings included?
- 4Can you see a sample report before you sign?
- 5Is the scope written down, target by target?
Illustrative example
Scantra Security
Security Assessment Report
Web application and API
Confidential. Client name redacted.
Reports
Generate customized pentest reports
An executive view for leadership, customers and auditors. A technical view with evidence, reproduction steps and fixes for your developers.
See a sample report on a callGet a quote for a specific service
Pricing questions
Pentest pricing, answered
Why don't you publish fixed prices?
Two applications of the same size can need very different effort. A quote after scoping is fairer and avoids surprise charges.
What do I need to share to get a quote?
What you want tested, the number of user roles, the rough size of the application, API or network, and any compliance deadline.
Do you charge in INR?
Yes. Indian clients are quoted in INR with GST as applicable. International clients can be quoted in USD.
Is the scoping call free?
Yes. The 30-minute call is free and there is no obligation to go ahead.
Can I combine several targets in one quote?
Yes. Web, API, mobile, cloud and network targets can be combined into one coordinated engagement and one quote.
Why are some pentest quotes much cheaper?
Very low quotes often mean an automated scan with a report template on top. Ask how many days of manual testing are included.
Get a written pentest quote for your scope
Tell us what needs testing, then choose a 30-minute slot with the Scantra Security team.
