What We Test
Manual penetration testing across the surfaces that actually get attacked, scoped to what you need rather than to a package tier.
| Surface | What we look for | Scoped by |
|---|---|---|
| Web applications | Access control between roles, business logic, injection, auth flaws | Application and user roles |
| APIs | Broken object-level authorisation, mass assignment, rate limiting | Endpoint count and auth model |
| Network, external | Exposed services, weak configurations, perimeter gaps | Live IPs |
| Network, internal | Lateral movement, privilege escalation, segmentation | Subnets and hosts |
| Mobile applications | Local storage, transport, binary and API interaction | Per platform |
| Cloud configuration | IAM, exposed storage, network policy | Account or subscription |
| Secure code review | Vulnerabilities at source, before they ship | Repository size |
How an Engagement Runs
1. Scoping and rules of engagement. What is in scope, what is explicitly out, testing windows, and who to call if something breaks. Signed before anything starts.
2. Reconnaissance. Mapping the attack surface as an outsider sees it.
3. Vulnerability identification. Automated and manual, across the agreed scope.
4. Exploitation and chaining. The part that distinguishes a test from a scan — attempting to actually exploit what was found and combine findings into real attack paths.
5. Reporting. Technical detail with evidence per finding, plus an executive summary someone non-technical can act on.
6. Remediation support. We stay available while you fix things, because the fastest way to a clean retest is not guessing at our findings.
7. Retest and letter. Re-verification of every finding, with a letter you can hand to an auditor or customer.
Manual, Not a Scan
Automated scanning is part of a good engagement. It is not the engagement.
Scanners find known CVEs, outdated components and misconfigurations efficiently, and skipping them would be wasteful. What they cannot find is anything requiring an understanding of what your application does: whether a manager can read another manager's records, whether changing an ID in a request returns someone else's data, whether a multi-step workflow can be completed out of order, whether a price can be modified client-side.
Those are the findings that matter in a real breach and the ones that distinguish a report a security team respects from one they skim.
Ask any provider what proportion of the engagement is manual and who performs it. It is the fastest way to sort quotes, and it is a question we are happy to answer specifically.
Mapped to the Framework You Need It For
This is where we differ from a pure penetration testing firm, and it is the reason most of our clients come to us.
A pentest firm delivers findings. We deliver findings already mapped to the controls your auditor will test — because we also run those audits, across ISO 27001, SOC 2, PCI DSS, HIPAA and CMMC.
| Framework | What we map findings to |
|---|---|
| SOC 2 | CC7 vulnerability identification and monitoring |
| ISO 27001 | Annex A technical vulnerability management and secure testing |
| PCI DSS | The explicit penetration testing requirement |
| HIPAA | Security Rule evaluation of controls protecting ePHI |
| CMMC / NIST 800-171 | Vulnerability scanning and remediation controls |
The practical difference: your auditor asks for evidence of technical vulnerability management, and you hand over a document that already answers in their vocabulary rather than one your compliance lead has to translate. See testing for ISO 27001 and SOC 2.
What You Get
A technical report with every finding, severity, reproduction steps and evidence — written so an engineer can act without asking us questions.
An executive summary that a non-technical stakeholder can read and act on, because someone has to approve the remediation budget.
Compliance mapping to your framework's controls.
A remediation priority order, because fourteen findings without a sequence is a backlog, not a plan.
A retest letter confirming closure — the artifact your auditor or customer actually needs. See what a VAPT report should contain.
Cost and Timeline
US market engagements typically run $4,000–$25,000, with web application testing $3,000–$22,500 and API testing $5,000–$30,000. We scope each engagement individually — the drivers are scope, the number of user roles, and the manual-to-automated ratio.
Avantcert engagements complete within a 30-day maximum and most finish well inside it. Full breakdown in penetration testing cost, or rupee pricing by test type for the Indian market.
Book a Penetration Test
Tell us what needs testing and whether it is for a compliance requirement. Scoped estimate within 24 hours.
Our form could not load. Email your scope and you'll get the same estimate within 24 hours.
Email your requirements Open the full quote formPenetration Testing FAQs
What does a penetration testing engagement include?
Scoping and rules of engagement, reconnaissance, vulnerability identification, manual exploitation and chaining, a technical report with evidence per finding, an executive summary, and a retest round with a letter confirming findings were closed. Compliance mapping to your framework is included where relevant.
Do you do manual testing or automated scanning?
Both, in that order and for different purposes. Automated scanning enumerates known CVEs and misconfigurations efficiently. Manual testing then attempts to exploit findings, chain them, and probe the things scanners cannot reach — business logic, access control between user roles, and authorisation flaws. The manual portion is what distinguishes a penetration test from a scan.
Will the report satisfy my SOC 2 or ISO 27001 auditor?
That is what it is built for. Findings are mapped to the specific controls your auditor will test — SOC 2 CC7, ISO 27001 Annex A technical vulnerability management, PCI DSS requirements — and the retest letter closes them. A generic findings list is a security document; a mapped report with a retest letter is audit evidence.
Is a retest included?
Yes, one round as standard. It matters more than most buyers realise: the original report describes the state at testing time and shows every finding open, so without a retest letter you have evidence of vulnerabilities rather than evidence of remediation.
How much does penetration testing cost?
US market engagements typically run $4,000–$25,000, with web application testing $3,000–$22,500 and API testing $5,000–$30,000. Scope, the number of user roles and the manual-to-automated ratio drive the figure. We scope each engagement individually.
How often should we test?
Annually as a baseline, and after any significant change to the application, infrastructure or authentication model. Most compliance frameworks expect at least annual testing, and enterprise security reviews commonly reject a report older than twelve months.
Related Services
See what testing costs, how VAPT and pentesting differ if you are comparing Indian and US providers, secure code review, or the compliance frameworks that usually drive the requirement: SOC 2, ISO 27001, PCI DSS.
Reference: OWASP Web Security Testing Guide.
Testing that answers your auditor's question
Manual testing, framework-mapped findings, retest letter included.