How we work

Services

Industries

Success Stories

Blog

How we work

Services

Industries

Success Stories

Blog

VAPT Testing Cost in 2026: Pricing by Scope and Asset Type

VAPT testing cost illustration showing pricing, testing scope, asset type, and security assessment.

Table of Contents

Share

<Summary/>

Vulnerability Assessment and Penetration Testing (VAPT) costs $1,500 to $60,000 for most engagements. A small web application sits at the low end. Multi-asset enterprise programmes with compliance evidence sit at the high end. Scope, asset type, and manual testing depth set the price.

The IBM 2026 Cost of a Data Breach Report puts India's average breach cost at ₹25.5 crore, around $2.7 million. A VAPT engagement costs a fraction of that. The question is how to scope and budget it correctly.

VAPT Scope

2026 Range (USD)

Primary Cost Driver

Small web application

$1,500 – $3,500

Pages, forms, authentication depth

Medium web application or API

$3,500 – $8,000

Endpoints, user roles, business logic

Large or complex web application

$8,000 – $18,000

Multi-tenancy, payments, SSO, permissions

Mobile application (per platform)

$3,000 – $8,000

Platform count, backend APIs, local storage

External network

$2,000 – $5,000

Public IP count, exposed services

Internal network

$4,000 – $10,000

Host count, Active Directory, lateral movement

Cloud security assessment

$5,000 – $15,000

Accounts, IAM complexity, multi-cloud scope

Enterprise or regulated programme

$20,000 – $60,000

Multiple assets, evidence requirements, retesting

These bands sit below US and UK boutique rates for equivalent scope. The delivery cost base is lower. The scope is not thinner. Every section below refers back to this table rather than repeating it.

What Is VAPT and Why Does the Cost Vary?

VAPT combines two distinct activities: vulnerability assessment (VA) and penetration testing (PT). VA identifies known weaknesses through automated scanning and configuration checks. PT exploits those weaknesses manually to confirm real-world impact.

<info/>

💡 Key Distinction:

Vulnerability assessment finds the doors. Penetration testing opens them. A scan-only engagement costs less because it needs less tester time. A full VAPT engagement costs more because a tester validates, exploits, and documents every confirmed weakness.

The cost varies because "VAPT" describes engagements of very different depth. A single automated scan of 5 pages is not the same as a manual assessment. A SaaS platform with 4 user roles, 80 API endpoints, and a retest cycle is a different engagement entirely.

Three variables drive the price more than any other:

  • Asset type and count: Web, API, mobile, network, and cloud scopes each require different tools, access, and tester skills.

  • Manual testing depth: Automated scans take hours. Manual exploitation of business logic and authorisation flaws takes days.

  • Retesting and evidence: Compliance-driven engagements need formal reports, retest confirmation, and closure documentation.

I price third-party penetration testing engagements at PerfectQA every week. The widest gaps between quotes come from scope ambiguity, not vendor greed. Two quotes that differ 3x for the "same application" are almost always testing different things.

What Drives the Cost for Each Asset Type?

Each asset type is tested differently, so each one has its own cost drivers. The pricing table gives the band. The notes below explain what moves a project up or down inside it.

Asset

Priced on

Biggest cost driver

Web application

User roles and workflows

Cross-role permission testing

API

Endpoint count

Authentication and object-level access

Mobile app

Platforms in scope

Device-side data and traffic protection

Network

Hosts and exposure

Internal versus external scope

Cloud

Accounts and identities

IAM complexity and workload isolation

Web Application VAPT

A web application test covers everything a user or attacker reaches through the browser: login, forms, uploads, dashboards, admin panels, and the logic connecting them.

Page count is the number buyers lead with. It is the weakest predictor of effort. A 40-page marketing site with a contact form is a small test. A 12-page SaaS product with 4 roles is a large one.

Raises the price

Keeps it low

Multiple user roles, each tested against the others

1 role

Payment, checkout, or wallet flows

No transactions

File upload, export, or document generation

No uploads

Multi-tenant architecture

Single tenant

SSO, MFA, or social login

Standard login

Admin functions that change other users' data

No back office

API Security Testing

An API test covers the endpoints that the web front end, the mobile app, and partners call. Modern applications put most of their logic behind APIs. A web test without API coverage misses a large part of the attack surface.

Endpoint count sets the baseline. Some providers fold the API into the web price. Others quote it separately. The quote states which applies.

Raises the price

Keeps it low

2+ authentication models, such as partner keys and user tokens

1 token type

Object-level access rules on each record

Role-level access only

Multi-tenant boundaries between customer accounts

Single tenant

GraphQL, where 1 endpoint accepts unlimited query shapes

REST with fixed routes

Undocumented or legacy endpoints the tester must discover

Full OpenAPI or Postman collection

Mobile Application VAPT

A mobile test has two halves: the app on the device and the backend it calls. The device half checks how the app stores data, protects traffic, and resists tampering. The backend half is an API test.

Each platform is priced separately. Testing Android and iOS doubles the device work because storage, permissions, and runtime differ. The backend is shared in most builds, so it is priced once.

Raises the price

Keeps it low

Android and iOS both in scope

1 platform

Sensitive data stored on the device

No offline data

Certificate pinning the tester must bypass

Standard TLS

Root or jailbreak detection to defeat

No tamper checks

Deep links, custom URL schemes, inter-process calls

No app-to-app integration

Third-party SDKs for payments or authentication

First-party code only

Network VAPT

A network test covers the infrastructure behind the applications: servers, firewalls, VPN gateways, mail systems, and internal services.

External testing looks at what is reachable from the internet and is priced on public IPs and exposed services. Internal testing starts from inside the network, from the position of a compromised laptop or a malicious insider. It costs more because it covers Active Directory, privilege escalation, segmentation, and lateral movement.

Raises the price

Keeps it low

Internal scope

External scope only

Few hosts running 10+ services each

Standard services per host

Controlled exploitation on live systems

Validation only

Active Directory and domain trust review

No directory in scope

Segmentation and lateral movement testing

Flat scope, no pivoting

Cloud Security Assessment

A cloud assessment reviews how an AWS, Azure, or GCP environment is configured. It checks who has access to what, how storage is exposed, how workloads are isolated, and how logging is set up.

Cloud configuration review and application penetration testing are two different jobs. The first checks the platform. The second checks the software running on it. A quote that mentions only one is missing half the picture.

Raises the price

Keeps it low

Multiple accounts or subscriptions under 1 organisation

Single account

IAM with 20+ roles and cross-account trust

Simple role structure

Containers, Kubernetes, or serverless functions

Virtual machines only

Publicly reachable storage buckets or databases

No public storage

Production workloads that need change windows

Staging environment

What to Have Ready Before the Scoping Call

Sending these before the call gives you a fixed quote on the first pass instead of a range.

Asset

Send this

Web application

Role list, feature inventory, 1 test account per role

API

OpenAPI or Postman collection, authentication methods, 1 token per role

Mobile app

Release builds per platform, test accounts, backend documentation

Network

IP ranges, network diagram, named approver for exploitation on live systems

Cloud

Read-only audit credentials per account, account inventory, production workload list

The factors in the next section apply across every asset type.

What Do Different VAPT Price Levels Include?

Price level and testing depth are two separate things. A provider with a lower delivery cost base delivers full manual coverage at a lower price. A provider with a higher cost base delivers a scan at a higher price. The table below shows what each tier includes, so the reader compares deliverables instead of totals.

Area

Basic Assessment

Standard Manual VAPT

Compliance-Driven VAPT

Automated scanning

Included

Included

Included

Manual validation

Limited or selective

Strong manual coverage

Extensive manual coverage

User roles tested

1 role

2 to 4 roles

Full role matrix

Business logic testing

Limited

Included

Deep workflow testing

API coverage

Limited or separate

Scoped coverage

Extensive coverage

Proof of concept

Not standard

Expected for confirmed findings

Detailed evidence per finding

Reporting

Basic technical report

Technical report + management summary

Audit-oriented evidence package

Retesting

Excluded or extra

1 defined retest cycle

Defined as part of the programme

Compliance evidence

Not included

Depends on scope

Customised to framework

<Caution/>

⚠️ Common Pitfall:

A low quote is not the warning sign. A quote with no stated manual testing depth is. Ask the provider which findings come from a scanner and which come from a tester working through the application by hand. Business-logic flaws, broken access controls, and chained attack paths only surface in the second category.

Our Infinium LLP engagement uncovered 18 vulnerabilities, including 2 high-risk findings. The first was a path traversal flaw in a file-handling API. The second was an outdated JavaScript library with a known exploit chain. An automated scan flagged the outdated library. The path traversal required manual testing of the file-upload workflow with crafted payloads. A scan-only engagement misses that class of finding entirely.

What Factors Drive VAPT Testing Cost?

VAPT cost is a function of tester effort. More assets, roles, endpoints, environments, and evidence requirements increase the hours a security team spends on the engagement.

Number and Type of Assets

A quote for 1 web application is not comparable with a multi-asset quote. An engagement covering a web application, 3 API collections, 2 mobile platforms, and a cloud account requires different scoping entirely. Each asset type introduces different testing methods, tooling, access requirements, and reporting work.

Application Complexity

Complexity matters more than page count. A 10-page application with multi-tenant permissions, payment processing, and sensitive data handling requires more effort than a 50-page content site.

Features that increase attack surface include:

  • Multi-tenancy and tenant isolation.

  • Payment processing and financial transactions.

  • File upload and document processing.

  • Single Sign-On (SSO) and Multi-Factor Authentication (MFA) flows.

  • Third-party integrations and webhook handlers.

  • Administrative workflows and privilege management.

  • Custom authorisation rules beyond standard role checks.

User Roles and API Endpoints

More user roles create more permission boundaries to test. A platform with customer, manager, finance, support, and administrator roles requires cross-role authorisation testing across all 5 roles. A single-role application requires less effort.

API scope grows the same way. A documented set of 20 endpoints costs less than 200 REST or GraphQL operations. Multiple authentication models and object-level access rules increase effort per endpoint.

Manual vs Automated Testing Depth

Automated scanners cover known vulnerability patterns from frameworks like the OWASP Testing Guide. They do not reliably test business rules, authorisation logic, or multi-step attack chains. Deeper VAPT engagements combine tooling with manual testing and validation.

A dramatically cheaper quote often represents a vulnerability scan, not a penetration test. The distinction appears in the scope document and deliverables, not in the service name.

Testing Approach: Black-Box, Grey-Box, or White-Box

Access level changes how tester time is spent:

  • Black-box testing: The tester starts with zero internal knowledge. Discovery takes longer. This approach simulates an external attacker.

  • Grey-box testing: The tester receives credentials, documentation, or limited architectural context. Testing focuses faster on authenticated attack paths.

  • White-box testing: The tester receives source code access, architecture documents, and full credentials. This enables deeper code-assisted review.

No single approach fits every project. The right choice depends on the security objective and the evidence requirements.

Compliance and Evidence Requirements

Compliance-driven engagements require stricter evidence, specific report formats, formal review cycles, and closure documentation. Frameworks like NIST SP 800-115 define testing scope requirements. Each regulator, contract, and industry adds its own evidence expectations.

A generic VAPT report does not satisfy every CERT-In directive or PCI DSS (Payment Card Industry Data Security Standard) requirement. ISO 27001 controls and banking audit expectations demand specific evidence formats. The expected format drives the scoping conversation before testing begins.

Retesting After Remediation

Retesting confirms whether reported vulnerabilities were fixed. Some providers include 1 retest within a defined window. Others price retesting separately. Additional rounds, new functionality, or major scope changes are treated as new work.

In our experience, 1 retest cycle covers 80% of engagements. The remaining 20% need a second round because the development team introduces new issues during remediation.

Timeline and Urgency

An expedited assessment costs more. The provider reserves additional tester capacity, compresses review cycles, or runs workstreams in parallel. Production launch dates, audit deadlines, or client-imposed timelines increase urgency cost.

Mentioning the deadline during scoping avoids surprises after the engagement starts.

The pricing models below determine how providers translate these factors into a quote.

How Do VAPT Providers Calculate the Price?

VAPT providers price work in 1 of 4 ways: fixed scope, per asset, per tester-day, or a recurring programme fee. Each model suits a different kind of project. Knowing which one a provider uses tells you what the quote covers and where extra charges appear.

Fixed-Scope Pricing

This is the most common model for a single application or a defined set of assets. The provider scopes the work first, then quotes one number for the whole engagement.

The price stays fixed as long as the scope stays fixed. The statement of work lists the applications, roles, endpoints, environments, and deliverables. Anything outside that list is extra.

This model suits buyers who need a number for budget approval before work starts. It also suits first-time VAPT buyers, because the quote itself becomes the scope document.

What to check on a fixed-scope quote:

  • The exact list of assets, URLs, and environments covered.

  • The number of user roles the tester logs in as.

  • Whether APIs are inside the price or listed as a separate line.

  • Whether 1 retest is included.

  • What triggers a change order.

I use this model for most PerfectQA engagements. A clear scope on day 1 removes the pricing disputes that appear on day 15.

Per-Asset or Per-IP Pricing

Network and infrastructure work is commonly priced per public IP, per host, per subnet, or per cloud account. The provider multiplies a unit rate by the number of assets in scope.

The model is simple to understand and easy to compare across vendors. It works well when the assets are similar to each other, such as 40 externally facing IPs with standard services.

It works less well when assets vary in complexity. One host running 10 exposed services takes longer to test than 10 hosts running 1 service each. A pure per-IP price ignores that difference.

What to check on a per-asset quote:

  • Whether the unit rate covers exploitation or only vulnerability validation.

  • Whether hosts with unusual services carry a surcharge.

  • Whether reporting is included in the unit rate or billed once on top.

Time-Based Pricing

Complex projects do not reduce cleanly to an asset count. The provider estimates the number of tester-days and multiplies by a day rate.

This model fits engagements with complex workflows, 3 or more environments, scope that changes mid-project, or testing run alongside an engineering team. It also fits code-assisted white-box reviews where effort depends on the size of the codebase.

The risk sits with the buyer. A loose day estimate turns into a larger invoice. A tight one turns into shallow testing when the days run out.

What to check on a time-based quote:

  • The estimated day count and the day rate, stated separately.

  • What happens when the estimate runs out: stop, extend, or reprioritise.

  • Whether report writing counts as billable days.

Recurring Programme Pricing

Teams that ship every week or every month outgrow one-off testing. The provider sets a quarterly, annual, or per-release fee that covers repeated assessments over the year.

The recurring fee is lower per test than a series of one-off engagements. The provider already knows the environment, the roles, and the previous findings, so each cycle starts faster.

This model suits SaaS products with frequent releases, regulated entities with quarterly VAPT mandates, and platforms where a customer contract requires ongoing evidence.

What to check on a recurring quote:

  • How many assessments the fee covers per year.

  • Whether new features and new endpoints are included as they ship.

  • Whether retesting is unlimited within the programme or capped per cycle.

  • The notice period and what happens to the report archive at exit.

The pricing model shapes the quote structure. The next section covers how the Indian regulatory context shapes the scope.

How Much Does VAPT Cost in India?

VAPT cost in India follows the same ranges as the table above. Regulatory requirements push regulated buyers toward the compliance-driven tier. RBI-supervised entities, SEBI-regulated firms, IRDAI-covered organisations, and CERT-In-notified infrastructure operators need evidence-grade VAPT. Generic scan reports do not meet those thresholds.

Regulators check for CERT-In empanelment, not just a VAPT report. Non-empanelled reports get rejected at RBI and SEBI review. Empanelled engagements carry a price premium because the auditor pool is smaller and the evidence format is fixed. Budget toward the upper end of the compliance-driven tier when empanelment is a requirement.

<info/>

💡 Practitioner Note:

The first two questions I ask on a scoping call are how many user roles exist and how many API endpoints sit behind the application. Those two answers move the quote more than page count ever does. A 12-page SaaS product with 4 roles and 60 endpoints takes longer to test than a 40-page marketing site with a login form.

How Does PerfectQA Price VAPT Engagements?

PerfectQA prices VAPT on scope, not on a fixed rate card. Every quote is built from asset count, user roles, endpoint volume, testing depth, and evidence requirements. The same 5 inputs determine where a project sits in the ranges above.

I scope every engagement before quoting:

  1. Define the asset: web application, API, mobile app, or combined scope.

  2. Confirm user roles, endpoint count, and authentication model.

  3. Agree on testing depth, exploitation rules, and deliverables.

  4. Fix the timeline and retest terms in the statement of work.

  5. Issue a fixed quote for that agreed scope.

The Infinium LLP engagement followed this process. We scoped the file-handling API and web application, completed testing within 3 weeks, and documented 18 findings including 2 high-risk vulnerabilities. The quote matched the scope, and the scope did not change mid-engagement.

Multi-asset programmes, compliance-driven testing, and recurring arrangements are scoped separately. [JAYESH: link "VAPT services" to /vapt-testing/ in this paragraph once URL confirmed.]


What Does a VAPT Quote Need to Include?

A complete VAPT quote specifies the scope, testing depth, deliverables, exclusions, and retesting terms. A proposal listing only a price and the words "VAPT testing" is not usable.

A well-structured quote covers:

  • Applications and URLs: Every web application, API collection, and domain in scope.

  • IP ranges and cloud accounts: Exact network and infrastructure boundaries.

  • User roles and test accounts: The number of authenticated roles the tester covers.

  • Testing approach: Black-box, grey-box, or white-box, with the access level defined.

  • Manual testing depth: Explicit statement of manual versus automated coverage.

  • API inclusion: APIs and supporting services either included or priced separately.

  • Exploitation rules: What the tester is permitted to exploit, especially in production environments.

  • Testing window: Start date, duration, and delivery timeline.

  • Severity scoring: CVSS, custom scale, or framework-specific scoring.

  • Proof-of-concept evidence: Screenshots, payloads, and reproduction steps for confirmed findings.

  • Remediation guidance: Stack-specific fix recommendations, not generic scanner output.

  • Report deliverables: Technical report, management summary, and remediation tracker.

  • Critical finding escalation: Same-day or next-day notification process for critical issues.

  • Retesting terms: Number of retest rounds, window duration, and what triggers additional charges.

  • Closure documentation: Final report, attestation, or closure letter as required.

  • Exclusions: Anything not included in the price.

<Caution/>

⚠️ Common Pitfall:

Two quotes are not comparable when one includes manual testing across 4 roles with API coverage, retesting, and detailed evidence, and the other covers 1 role with scan-only output. Compare scope against scope before comparing price against price.

Which VAPT Costs Are Typically Charged Separately?

Not every provider bundles the same items in the base price. These 10 costs are commonly charged as extras. Confirm them before signing the statement of work.

  1. Additional retest rounds beyond the included cycle.

  2. New applications, modules, domains, endpoints, or environments added after scoping.

  3. Source-code review or architecture review.

  4. Compliance-specific evidence or custom reporting formats.

  5. On-site testing or travel.

  6. Expedited delivery with compressed timelines.

  7. Remediation consulting or engineering support.

  8. Testing of major changes introduced during the engagement.

  9. Additional mobile platforms or backend API scopes.

  10. Production-window testing or after-hours scheduling.

How Do You Estimate Your VAPT Budget Before Requesting Quotes?

The fastest way to get an accurate quote is to give every provider the same structured scope. This removes guesswork and makes proposals comparable.

  1. List every asset that needs testing. Separate web, API, mobile, network, cloud, and supporting systems.

  2. Count the measurable units: user roles, API endpoints, public IPs, internal hosts, cloud accounts, environments, and mobile platforms.

  3. Identify security-sensitive workflows: payments, privileged administration, file upload, tenant separation, SSO, MFA, and third-party integrations.

  4. Choose the testing depth: basic vulnerability assessment, manual penetration test, or compliance-grade VAPT engagement.

  5. Confirm compliance, customer, or audit evidence requirements before the provider prepares the quote.

  6. Define retesting expectations: 1 cycle, 2 cycles, or unlimited within a fixed window.

  7. Send the same scope document to every shortlisted provider.

Start with the closest row in the pricing table. Move toward the upper end for engagements with 4+ user roles, 50+ endpoints, or complex permissions. Compliance evidence, 2+ environments, and 2+ retesting cycles also push the price higher.

Does a VAPT Certificate Cost Extra?

There is no universal VAPT certificate. The term "VAPT certificate" means different things to different recipients. Some expect a closure letter. Others expect a full retest-confirmed report. Others expect a compliance attestation signed by a qualified assessor.

A provider issues a final report, retest report, closure letter, or attestation after testing. Some include the closure document in the engagement price. Others require successful remediation or a separate retest before issuing it.

The acceptance criteria matter more than the document name. A regulator, customer, bank, or marketplace auditor each expects different evidence. Confirm the requirement before the engagement begins.

Professional certifications like CEH (Certified Ethical Hacker) or OSCP (Offensive Security Certified Professional) are career qualifications held by individual testers. They are not part of a business VAPT engagement.


FAQs About VAPT Testing Cost

How much does VAPT cost?

How much does VAPT testing cost in India?

How much does a VAPT certificate cost?

Does compliance increase VAPT testing cost?

Is automated VAPT cheaper than manual testing?

How long does VAPT testing take?

Does the number of APIs affect VAPT cost?

Why choose PerfectQA services

At PerfectQA, automation is not just about speed — it’s about assurance. We combine framework expertise, proactive analysis, and audit-driven reporting to deliver testing solutions that scale with your business

Expertise and Experience: 15+ years in automation and regression testing across multiple industries

Customised Frameworks: We adapt to your tech stack, not the other way around.

State-of-the-Art Tools: Selenium, Playwright, Cypress, and CI/CD integrations.

Proactive Support: Continuous improvement through audit and debugging

About PerfectQA

PerfectQA is a global QA and automation testing company helping businesses maintain flawless software performance through manual, automated, and hybrid testing frameworks

Our mission

Deliver precision, speed, and trust with every test cycle

Learn more about our solutions

Want flawless automation?

Schedule your free test strategy consultation today and see how PerfectQA can help you achieve continuous quality at scale

Published

Updated

Author

Rahul Sharma