The honest, short answer: a manual web application penetration test in India typically costs somewhere between ₹40,000 and ₹2,00,000, depending on scope and depth. Automated scans alone run cheaper — ₹20,000 to ₹50,000 — and large, compliance-grade engagements across multiple applications or environments can run into several lakhs.
That's the number most people are looking for. Everything below explains why the range is so wide, what you're actually paying for at each price point, and how to avoid the most common trap in this market: paying for a vulnerability scanner's PDF export with someone's logo stuck on it, and calling it a penetration test.
Typical Price Ranges by Test Type
| Test Type | Typical Range (INR) | Notes |
|---|---|---|
| Automated vulnerability scan | ₹20,000 – ₹50,000 | Tool-driven, minimal manual validation |
| Web application (manual VAPT) | ₹40,000 – ₹2,00,000 | Scales with number of roles, workflows, endpoints |
| Mobile application (per platform) | ₹50,000 – ₹1,50,000 | Android and iOS usually scoped and priced separately |
| API security testing | ₹40,000 – ₹1,20,000 | Depends on endpoint count and auth complexity |
| External network pentest | ₹30,000 – ₹1,00,000 | Scoped to public-facing IP ranges |
| Internal network pentest | ₹60,000 – ₹2,00,000 | Assumes-breach / lateral movement scenarios |
| Enterprise / compliance-grade (ISO 27001, SOC 2, PCI DSS) | ₹3,00,000 – ₹15,00,000+ | Multi-week, multi-asset, formal audit-ready reporting |
These are indicative market ranges, not fixed pricing — the actual number for your project depends on the five factors below.
What Actually Drives the Price
1. Scope and asset count
The number of applications, APIs, IP addresses, and cloud accounts in scope is the first and biggest multiplier. A single-page marketing site and a multi-tenant SaaS platform with twelve user roles are not the same engagement, even if both are technically "a web app."
2. How much of it is genuinely manual
This is the single biggest driver of the price spread you'll see between quotes for the same application. A ₹25,000 quote is almost always automated scanning with a report template attached. A ₹1,50,000 quote for the same app is usually days of a human tester probing business logic, chaining smaller flaws together, and validating what a scanner can only flag as "possible."
3. Authenticated vs. unauthenticated testing
Most of the real risk in a modern application sits behind a login — broken access control, privilege escalation, IDOR. Testing with valid credentials across multiple roles costs more than a black-box, unauthenticated scan, but it's also where the impactful findings actually live.
4. Compliance requirements
If the report needs to satisfy an ISO 27001 surveillance audit, a SOC 2 Type II review, or PCI DSS, it needs to meet a specific bar — methodology documentation, evidence, and formal reporting — that pushes the engagement into the professional or enterprise band rather than the budget one.
5. Retesting
A test that ends the moment the report is delivered is only half the job. A free retest round, once your team has fixed the findings, is what turns a report into actual risk reduction — and it should be priced into the engagement from the start, not sold separately afterward.
Why the Cheapest Quote Is Usually the Most Expensive Mistake
It's tempting to pick the lowest number on a spreadsheet of vendor quotes. In practice, the gap between a ₹15,000 "pentest" and a genuine ₹80,000 one usually isn't padding — it's the difference between a scanner output and a human being who actually tried to break your authorization logic. The cheap report checks a compliance box. The real one finds the flaw that would have leaked your customers' data, proves it with a working proof of concept, and tells your developers exactly how to fix it.
When comparing quotes, ask each vendor two questions: what percentage of this engagement is manual testing, and does the price include a retest? Those two answers will tell you more than the number itself.
What a Properly Scoped Engagement Includes
- A scoping call to understand your application, roles, and what "critical" means for your business specifically.
- Manual, methodology-driven testing — not just an automated scan with a report generated on top of it.
- A detailed report with severity ratings, proof-of-concept steps, and business impact for every finding.
- Remediation guidance your developers can actually act on, not just a CVE number.
- A free retest once fixes are in place, to confirm the issues are actually closed.
Getting a Real Quote
Every application is different, so the numbers above are a starting point for budgeting, not a substitute for a proper scoping conversation. If you want an exact quote for your specific application, API, or infrastructure, get in touch and I'll scope it properly before we talk numbers.