+91 98804 42758

VAPT Cost in India

Real ranges by test type and scope, why quotes differ by a factor of twenty for apparently the same thing, and the line item most providers leave out of the quote entirely.

Updated August 2026 12 min read Compliance

VAPT Cost in India at a Glance

Across the Indian market, an automated vulnerability scan runs ₹20,000–₹50,000, a genuine manual web application penetration test ₹75,000–₹3,50,000, network testing ₹50,000–₹5,50,000, and complex multi-system infrastructure ₹8,50,000–₹12,50,000. The twenty-fold spread is not providers pricing arbitrarily — it is two different services sold under one acronym.

What you are buyingIndia market rangeEffortFinds
Automated vulnerability scan₹20,000–₹50,0001–2 daysKnown CVEs, misconfigurations
Manual web app penetration test₹75,000–₹3,50,0006–12 working daysBusiness logic, access control, chained exploits
Network penetration test₹50,000–₹5,50,0005–15 daysExposed services, lateral movement
Complex / multi-system infrastructure₹8,50,000–₹12,50,0003–6 weeksFull attack-path analysis

Avantcert VAPT engagements run from $1,000 to $10,000 depending on scope, within a 30-day maximum, already discounted 30–50% below typical market rates — and with retest included, which most quotes exclude. Get a scoped figure.

Market ranges above are observed across the Indian VAPT market for context. Avantcert figures are ours.

Cost by Test Type

Most quotes are for one of these. Knowing which you need is most of getting a comparable price.

Test typeTypical scope unitWhat moves the price
Web applicationPer applicationNumber of user roles and authenticated flows
APIPer API / endpoint countEndpoints, auth model, integrations
Network — externalPer live IPExposed surface size
Network — internalPer subnet / host countSegmentation complexity
Mobile applicationPer platformAndroid and iOS are two tests, not one
Cloud configurationPer account / subscriptionServices in use, IAM complexity
Secure code reviewPer repository / LOCLanguage, codebase size

The mobile trap: Android and iOS are separate tests. A quote for "mobile app VAPT" that seems cheap is frequently covering one platform. Ask which.

What Actually Drives the Price

1. Manual versus automated ratio. The single largest factor. Tool output costs a day of someone's time; a human attempting exploitation costs one to three weeks. Ask what percentage of the engagement is manual.

2. Number of user roles. A web app with admin, manager and end-user roles requires testing each boundary between them. Roles multiply effort more than page count does.

3. Grey-box versus black-box. Grey-box — where you provide credentials and some architecture detail — finds more per rupee because the tester spends time testing rather than on reconnaissance. It is usually the better value despite sounding like less work.

4. Retest rounds included. One retest is standard. Zero is a red flag. See below.

5. Who actually tests. A named senior tester costs more than an unnamed pool. For a compliance-grade report, the certifications and experience of the tester matter to whoever reviews it.

6. Compliance mapping. A report mapped to ISO 27001 Annex A or SOC 2 criteria takes more work than a generic findings list — and saves you far more later.

Get Your Scoped VAPT Quote

Tell us what needs testing — applications, APIs, network ranges, mobile platforms — and whether it is for a compliance requirement. Scoped estimate within 24 hours.

Why Cheap VAPT Usually Costs More

A ₹20,000–₹50,000 report is almost always an automated scan with the tool output reformatted onto letterhead. That is a legitimate product — it catches known CVEs, outdated components and misconfigurations, and it has a place in a security programme.

What it will not find: business logic flaws, broken access control between user roles, insecure direct object references, chained exploits, or anything requiring a human to understand what your application is for.

And whoever reviews it can usually tell. Enterprise security teams and ISO 27001 auditors read a lot of these. A report with no manual testing narrative, no exploitation evidence and generic findings is recognisable, and when it is rejected you pay twice — once for the cheap test and again for the real one, having lost the time in between.

How to check a quote in one question: ask what proportion of the engagement is manual testing and who performs it. A provider selling a scan will not be able to answer specifically.

VAPT for Compliance

Most VAPT in India is bought because a framework or a customer demanded it, not because someone woke up wanting a pentest. What each expects:

FrameworkWhat it expectsFrequency
ISO 27001Technical vulnerability management and secure testing under Annex AAt least annually
SOC 2Vulnerability identification and remediation under CC7Across the observation window
PCI DSSExplicit penetration testing requirementAnnually and after significant change
HIPAAEvaluation of security controls protecting ePHIPeriodic
CMMC / NIST 800-171Vulnerability scanning and remediationOngoing

This is where a compliance consultancy differs from a pentest shop. A findings list is a security document. A findings list mapped to the exact Annex A controls or Trust Services Criteria your auditor will test — plus a retest letter closing them — is an audit evidence artifact. We produce the second because we run the audits too. See VAPT for ISO 27001 and SOC 2.

The Retest Nobody Puts in the Quote

The most common gap in a VAPT engagement, and the one that costs clients most often.

You commission a test. The report arrives with fourteen findings. You remediate. You send the report to your auditor or your enterprise customer — and it still shows fourteen open findings, because a report describes the state at the time of testing.

What satisfies the reviewer is a retest letter confirming the findings were verified as closed. Without it, the original report is evidence that you had vulnerabilities, not evidence that you fixed them.

Confirm retest is in scope before the engagement starts. Negotiating it afterwards is expensive, and a provider who priced without it has priced a different job. Avantcert includes one retest round as standard.

VAPT Cost FAQs

How much does VAPT cost in India?

Across the Indian market an automated vulnerability scan runs ₹20,000–₹50,000, a genuine manual web application penetration test ₹75,000–₹3,50,000, network testing ₹50,000–₹5,50,000, and complex multi-system infrastructure ₹8,50,000–₹12,50,000. Avantcert VAPT engagements run from $1,000 to $10,000 depending on scope, with retest included.

Why is there such a wide range in VAPT pricing?

Because "VAPT" describes two very different things sold under one name. An automated scan is a tool run against your application and can be delivered in a day. A manual penetration test is a human attempting to exploit and chain findings over one to three weeks. The price gap between them is the labour, and quotes at the bottom of the range are almost always the former.

How long does a VAPT engagement take?

Avantcert scopes VAPT to a 30-day maximum and most engagements finish well inside it. A single web application typically runs six to twelve working days of testing plus reporting; an automated scan can be same-week. Retest usually follows two to four weeks later once you have remediated.

Is a cheap VAPT worth it?

A ₹20,000 report is almost certainly an automated scan with the tool output reformatted. That has a legitimate use — catching known CVEs and misconfigurations — but it will not find business logic flaws, broken access control between user roles, or chained exploits, and an auditor or enterprise customer reviewing it can usually tell. If the report is for a compliance requirement, the cheap version frequently fails review and has to be redone.

Does VAPT include a retest?

Not always, and this is the most common gap in a VAPT quote. A report full of open findings does not satisfy an ISO 27001 or SOC 2 auditor; a retest letter confirming they were closed does. Confirm retest is in scope before the engagement starts rather than negotiating it afterwards. Avantcert includes it.

What is the difference between VAPT and a vulnerability scan?

A vulnerability assessment is broad and largely automated — it enumerates and ranks known weaknesses. A penetration test is narrow and manual — a tester attempts to exploit what was found and chain findings into real attack paths. VAPT properly means both. Buying only the assessment gives you a list; the penetration test tells you which items on it actually matter.

Do I need VAPT for ISO 27001 or SOC 2?

Neither standard names VAPT as a specific mandatory control, but both expect technical vulnerability management and testing, and auditors routinely ask for evidence of it. ISO 27001 Annex A covers technical vulnerability management and secure testing; SOC 2 CC7 covers vulnerability identification. In practice, a current test report plus a retest letter is the usual evidence.

How often should VAPT be done?

Annually as a baseline, and additionally after any significant change to the application, infrastructure or authentication model. Compliance frameworks generally expect at least annual testing, and a report older than twelve months is commonly rejected during enterprise security reviews.

Related Reading

See VAPT services, the difference between VAPT and a pentest if the terminology is confusing you, the types of VAPT testing, or what a VAPT report should contain. Testing for a US customer? See penetration testing cost in the US.

Reference: OWASP Web Security Testing Guide.

Get a VAPT quote that includes the retest

Scoped to what actually needs testing, mapped to the framework you need it for.

Ready to get certified?

Join 3,000+ organizations that trust Avantcert. Get a free, scoped quote today.