Short answer: VAPT cost in India in 2026 typically ranges from ₹20,000 to ₹2,50,000+ per engagement, depending on scope. A single web application usually costs ₹25,000–₹2,50,000, an API or mobile app starts around ₹30,000, network testing from ₹20,000, and enterprise full-scope audits run higher. Manual depth, not tool count, drives the real price.
What does VAPT actually cost in India in 2026?
VAPT (Vulnerability Assessment and Penetration Testing) pricing in India is not a fixed sticker. It scales with how much attack surface a tester must genuinely examine by hand. Two "web apps" can differ 10x in price: a five-page brochure site versus a multi-role SaaS platform with payment flows, admin panels and third-party integrations are not the same job.
The honest ranges below reflect what serious, manual-led providers charge in 2026. They assume real penetration testing — a human attempting to chain vulnerabilities — not just an automated scanner report with a logo on it.
| Service | Typical 2026 price (INR) | What's included |
|---|---|---|
| Web application VAPT | ₹25,000 – ₹2,50,000 | OWASP Top 10, auth, business logic, per-role testing |
| API VAPT (REST/GraphQL) | ₹30,000+ | OWASP API Top 10, auth, BOLA/IDOR, rate limits |
| Mobile app VAPT (Android/iOS) | ₹30,000+ | OWASP MASVS, storage, traffic, reverse engineering |
| Network / infrastructure VAPT | ₹20,000+ | External or internal IPs, services, misconfig, patching |
| Cloud configuration review (AWS/Azure/GCP) | ₹20,000+ | IAM, storage exposure, CIS benchmark, key management |
| Enterprise full-scope (multi-app + network + cloud) | ₹1,50,000 – higher | Combined scope, red-team style, retest, detailed reporting |
What actually drives the cost?
When you ask "how much is VAPT," a credible provider will ask you questions back before quoting. Here is what moves the number:
- Scope size: number of applications, number of API endpoints, number of live IPs or hosts, and number of user roles that must each be tested.
- Manual depth: automated scanning is cheap and fast. Manual exploitation, business-logic testing and chaining vulnerabilities is where testers spend days — and where real risks are found.
- Complexity: payment gateways, SSO/OAuth, file uploads, multi-tenancy and role hierarchies all add hours.
- Authenticated vs unauthenticated: testing behind login (with credentials for each role) uncovers far more, and costs more, than a black-box external look.
- Compliance requirement: a report needed for ISO 27001, PCI-DSS or a DPDP Act 2023 due-diligence audit demands documentation rigour that a casual scan does not.
- Retesting: a proper engagement re-verifies your fixes. Some vendors charge extra for this; reputable ones include a retest.
Why testing days matter more than tool licences
The single biggest cost driver is human time. A good tester might spend 3–5 days on a medium web app, mapping every function, trying to break access control, tampering with parameters, and confirming exploitability. That labour is what separates a real penetration test from a scan. When you compare quotes, ask how many tester-days are allocated, not just what tools are used.
Warning: the ₹10,000 "VAPT" trap
You will find listings offering "complete VAPT" for ₹8,000–₹12,000. Be careful. In almost every case this is an automated vulnerability scan (Nessus, Acunetix, OWASP ZAP or similar) re-labelled as VAPT. An automated scan:
- cannot understand your business logic (e.g. that user A should never see user B's invoices);
- misses authorization flaws like IDOR/BOLA that need human reasoning;
- produces false positives that waste your developers' time;
- and rarely stands up as evidence for a serious compliance audit.
A scan has its place as a first pass, but it is not penetration testing. If the price looks impossibly low, you are buying a PDF, not security assurance. Read our explainer on vulnerability assessment vs penetration testing to understand exactly where the value sits.
Cost by industry and compliance need
Your sector often dictates both the depth of testing and therefore the price. A fintech handling card data faces PCI-DSS obligations and needs deeper, more frequent testing than a small brochure website. Here is how budgets typically shape up in India in 2026:
- Startups and SaaS: a single flagship web app plus its API. Expect ₹50,000–₹1,50,000 for a thorough grey-box test before a funding round or enterprise sales cycle, where clients demand a security report.
- Fintech and payments: PCI-DSS scope, multiple apps, network and cloud. Budgets start around ₹1,50,000 and rise with the number of in-scope systems and cardholder data environments.
- Healthcare and edtech: personal data under the DPDP Act 2023 raises the stakes on access-control and data-exposure testing; mid-sized engagements commonly land at ₹75,000–₹2,00,000.
- E-commerce: payment flows, coupon and pricing logic, and third-party integrations make business-logic testing essential — usually ₹50,000–₹1,75,000 per major test.
- Government and PSU tenders (via GeM): scope is defined by the tender; pricing follows the documented requirement. Cyber Defence is GeM-registered for exactly these procurements.
What you should never compromise on to save money
It is tempting to trim cost by narrowing scope. Some trims are reasonable; others quietly defeat the purpose of testing. Protect these even on a tight budget:
- Authenticated testing of every role — the majority of high-impact findings, especially broken access control, live behind login.
- Manual business-logic testing — the flaws that cost companies real money are logic bugs a scanner will never see.
- A proper report and retest — an untested "fix" is not a fix; the retest is what actually reduces your risk.
Areas you can legitimately phase to manage budget include splitting a large estate into prioritised rounds — test the crown-jewel application first, then expand — rather than watering down the depth of each test.
Is VAPT a one-time cost or recurring?
Security is not a one-and-done purchase. Most Indian organisations budget for VAPT:
- Before every major release or significant feature change;
- Annually as a baseline, even without big changes;
- On compliance cycles — PCI-DSS, ISO 27001 surveillance audits, or DPDP Act readiness reviews;
- After an incident or suspected breach.
Retainer or annual arrangements often reduce per-engagement cost because scoping and environment familiarity carry over.
How Cyber Defence prices VAPT
At Cyber Defence, we do not publish a flat price because an honest quote requires understanding your actual attack surface. Our process is deliberately transparent:
- Free scoping call: we discuss your application, roles, endpoints and compliance goals — no charge, no obligation.
- Fixed written quote: you receive a documented, fixed price and clear scope before any work begins. No surprise add-ons.
- Manual-led testing: our engagements follow OWASP methodology with CVSS-scored findings, not just tool output.
- Free retest included: after you fix the findings, we re-verify them at no extra cost.
- Certificate included: on a clean retest you receive a VAPT completion certificate you can share with clients and auditors.
Cyber Defence is an ISO-certified and GeM-registered provider. To be clear and honest: we are not CERT-In empanelled, and we never claim to be. Where you specifically need a CERT-In empanelled auditor, we will tell you so. For everything else — practical, thorough, standards-aligned VAPT — our credentials and methodology stand on their own. The practice is led by Amit Kumar (CEH, CRTA).
We serve clients across India, with dedicated teams for VAPT services in Haryana and VAPT services in Delhi. If you or your team also want to build these skills in-house, see our VAPT training program.
Hidden costs to ask about before you sign
The headline quote is not always the full story. Before you commit, ask a prospective provider these questions so you are not surprised later:
- Is the retest included or billed separately? Some vendors quote a low base price then charge again to verify your fixes.
- Is the report included in the price, or is a "detailed report" an add-on?
- Does the price cover all roles, or only unauthenticated testing with per-role testing costing extra?
- Are follow-up questions supported after delivery, so your developers can clarify a finding while fixing it?
- Is a certificate provided, and does it require a clean retest?
- What happens if scope grows mid-engagement — is there a change-order process, or a surprise bill?
A transparent provider answers all of these clearly and puts them in the written quote. At Cyber Defence, the report, all in-scope roles, a free retest, developer follow-up on findings, and a completion certificate on a clean retest are included in the quoted price — there are no surprise add-ons.
Why the cheapest quote often costs more
A shallow test that misses a critical flaw is not a saving — it is a false sense of security. If an unfound vulnerability is later exploited, the cost of an incident (data loss, downtime, regulatory exposure under the DPDP Act 2023, lost customer trust) dwarfs whatever you saved on the test. The right question is not "what is the cheapest VAPT" but "what will actually reduce my risk." A slightly higher price for genuine manual testing, a clear report, and a verified retest is almost always the better investment.
How to compare VAPT quotes fairly
When you receive multiple quotes, put them side by side on these criteria rather than price alone:
- Is it manual penetration testing or an automated scan?
- How many tester-days are allocated?
- Is authenticated, per-role testing included?
- Are findings CVSS-scored with reproduction steps and fix guidance?
- Is a free retest included?
- Will the report satisfy your specific compliance need (ISO 27001, PCI-DSS, DPDP)?
The cheapest number rarely wins once you weigh these. Not sure what VAPT even covers? Start with what is VAPT.
FAQ
How much does VAPT cost in India in 2026?
Most engagements fall between ₹20,000 and ₹2,50,000+. A single web app is typically ₹25,000–₹2,50,000, APIs and mobile apps start around ₹30,000, network testing from ₹20,000, and enterprise full-scope audits cost more.
Why is one VAPT quote much cheaper than another?
Usually because the cheap one is an automated scan relabelled as VAPT, with little or no manual testing. Always compare tester-days and whether authenticated, business-logic testing is included, not just the headline price.
Is a ₹10,000 VAPT worth it?
Rarely. At that price you are almost always paying for an automated scanner report, which misses authorization and business-logic flaws and often fails to satisfy serious compliance audits.
Does VAPT cost include retesting?
It should. At Cyber Defence a free retest is included — after you fix the findings we re-verify them and, on a clean result, issue a completion certificate at no extra cost.
How often should we budget for VAPT?
Before major releases, annually as a baseline, on your compliance cycles (PCI-DSS, ISO 27001, DPDP readiness), and after any security incident.
Is Cyber Defence CERT-In empanelled?
No, and we never claim to be. We are ISO-certified and GeM-registered, and our VAPT is led by Amit Kumar (CEH, CRTA). If you specifically require a CERT-In empanelled auditor, we will tell you honestly.
Get a fixed written VAPT quote after a free scoping call — talk to Cyber Defence today at +91-75175-72000.

