+91 98726 60544 hello@mitstech.co Mon–Sat · 09:00–18:30 IST

Penetration testing: what it costs and how often you need it

Security By Mits Engineering Team 4 min read
Penetration testing: what it costs and how often you need it

Ask three firms to price a penetration test on the same web application and the quotes will differ by a factor of ten. That is not a market inefficiency you can arbitrage. At the bottom of that range you are buying an automated scanner report with a cover page, and at the top you are buying a senior tester spending two weeks trying to break your authorisation logic. Knowing which you are being offered is the entire skill in buying this.

Indian vendors publishing price guides in 2026 put a web application test at roughly ₹40,000 to ₹1.5 lakh for a typical SaaS product, rising to ₹1.5-4 lakh for a large or complex one. Mobile applications run ₹50,000 to ₹1.5 lakh per platform - iOS and Android are separate engagements, which surprises people. External network testing sits around ₹30,000 to ₹1 lakh for a small IP range, internal network testing higher at ₹60,000 to ₹2 lakh. A bundled programme covering web, API and cloud for a SaaS company typically lands at ₹1.5-4 lakh. Worth stating plainly: these come from security vendors' own published guides, not from any independent survey. No neutral India pricing study exists that we could find, which is itself worth knowing before you treat any of these as benchmarks.

The most useful signal in that range is the bottom of it. Multiple Indian vendors independently describe the ₹25,000-60,000 band as automated scanning reformatted into a report - Nessus, OpenVAS or a Burp automated crawl, presented as a penetration test. That is a real product with a real use, but it finds a different class of problem. Scanners find known vulnerable versions and misconfigurations. They do not find business logic flaws, authorisation bypasses, or the chained exploit where three individually minor issues combine. Manual testing costs roughly three to five times an automated scan at the low end and ten times or more at the enterprise end, and that multiple is what you are paying for.

Cost scales with scope but not linearly, which works in your favour. Published figures suggest a hundred endpoints takes around two and a half times the time of ten, not ten times, because the testing methodology amortises across similar surfaces. What does add cost predictably: authenticated testing versus unauthenticated, multiple user roles to test privilege boundaries between, compliance report formatting for PCI or SOC 2 which adds fifteen to thirty per cent, and urgency - under two weeks' notice attracts a premium of around twenty per cent.

On duration, a single web application is typically five to fifteen testing days plus reporting, with a retest a few weeks later. Multi-asset programmes run four to eight weeks end to end. The practical scheduling advice is to book six to eight weeks ahead of any audit deadline, because good testers are booked out and the gap between finding issues and closing them is where projects actually slip.

The contract term worth arguing about is retesting, and vendors genuinely differ here. Some include unlimited retests within a thirty-day window. Some bill each retest separately. Some include exactly one. Adding retest rounds after the fact typically raises the total by ten to twenty per cent, so negotiate it upfront rather than discovering the omission when your auditor asks for evidence that findings were closed. If you are in scope for a CERT-In audit this is not optional - their guidelines require the follow-up audit to be within the original scope, and the final report only issues after vulnerabilities are closed and retested.

On frequency, Indian regulation is more specific than most people realise. CERT-In's Comprehensive Cyber Security Audit Policy Guidelines, dated July 2025, require an audit at least annually, plus after major changes - system overhauls, technology migrations, configuration changes affecting sensitive data. RBI's framework is commonly described as vulnerability assessment every six months and penetration testing at least annually for critical systems. SEBI's CSCRF sets a three-month remediation deadline from report submission, with anything still open past that needing formal IT Committee approval. One clarification worth making, because vendors blur it: the DPDP Rules require reasonable security safeguards but do not explicitly mandate penetration testing. It is an indirect driver, not a legal requirement, and anyone telling you otherwise is selling something.

Need help with this? Explore our Cybersecurity & Compliance services. Learn more Back to all news

Keep reading

More on Security