Problem Threats Stories How it works Blogs Pricing
Buyer's Guide

VAPT cost in India (2026): what you should pay, and what drives the price

Published price ranges from Indian providers, the nine things that move a quote, and the costs that never show up on the invoice.

By Arxiis ResearchUpdated 16 min read

Key takeaways

  • Indian providers publish VAPT prices from about ₹20,000 for a scan-only job to ₹12 lakh or more for a large, multi-role web platform, per engagement.
  • A single manual web application test usually sits between about ₹40,000 and ₹3.5 lakh, depending mostly on size, user roles and depth.
  • Regulated firms pay for more than one cycle: RBI's 2026 Directions ask banks for vulnerability assessment every six months and penetration testing every 12 months on critical systems.
  • SEBI CSCRF says VAPT must be done by a CERT-In empanelled auditor, and findings must be closed within three months of the report.
  • The invoice is the small number: the average Indian data breach cost ₹25.5 crore in 2026, according to IBM.
  • Compare quotes on scope, manual depth, retest terms and proof of exploit, not on the headline price alone.

You asked three firms for a VAPT quote and got back ₹35,000, ₹1.8 lakh and ₹6 lakh for what looks like the same job. Nobody explained the gap. The cheapest one promises a report in three days. The most expensive one wants a scoping call first. You need a number for the budget note, and you need to know which quote will stand up when the auditor, the regulator or an attacker looks at your systems.

Last reviewed on 28 September 2026 against published price guides from seven Indian providers, the RBI Cybersecurity Directions 2026, SEBI CSCRF and IBM's 2026 India breach report.

How much does VAPT cost in India in 2026?

VAPT cost in India in 2026 ranges from about ₹20,000 for an automated scan to ₹12 lakh or more for a large web platform, based on published guides from Indian providers. A single manual web application test typically costs ₹40,000 to ₹3.5 lakh. Prices are market ranges, not quotes, and depend on scope and depth.

We read the public pricing pages and price guides of seven Indian security firms, all published or updated in 2026. Every one of them says the same thing first: the price depends on scope. Every one of them then gives ranges anyway, because buyers need a starting point. The ranges overlap a lot, which is useful. It tells you where the market sits.

Here is the short version, before we break it down by asset type.

  • Scan-only work (a tool runs, a report is exported) is quoted at about ₹20,000 to ₹50,00024. RingSafe puts its "automated-scan tier" at ₹25,000 to ₹60,0008.
  • A competent manual test of one scope (one web app, one API or one mobile app) is quoted at about ₹75,000 to ₹2.5 lakh, over 5 to 15 billable days8.
  • Compliance-grade manual engagements run from about ₹3 lakh to ₹8.5 lakh, and complex multi-system work goes to ₹10 lakh and above2.
  • Multi-asset or deep-scope programmes are quoted at ₹3 lakh to ₹12 lakh, and large audit-brand firms start around ₹15 lakh8.

These are published market ranges, not quotes. They come from providers' own public pages, which are also marketing. Real prices vary with your scope, timelines and contract terms. We do not publish Arxiis pricing here, and nothing on this page is an offer.

What drives the price of a penetration test?

Penetration test pricing is driven mostly by tester days. Anything that adds days adds cost: more pages, endpoints or IPs, more user roles, deeper manual work, retests, a CERT-In empanelled auditor, a regulator-ready report, onsite work and a rush deadline. Scope size and manual depth usually move the price the most.

A VAPT quote is mostly skilled time. Tools are cheap. People who can chain two medium findings into a real breach are not. SquareOps sums it up: automated scanning is cheap because it is machine time, and manual testing is expensive2. Published timelines back this up. A single web app or API takes about 5 to 15 working days of testing, and cloud or IoT work can take 7 to 203.

VAPT
Vulnerability Assessment and Penetration Testing. The VA part finds and lists known weaknesses, often with tools. The PT part tries to exploit them, the way an attacker would, to prove what is really at risk. Our guide to vulnerability assessment vs penetration testing explains the difference in detail.

The nine price drivers

  1. Scope size. The number of apps, pages, API endpoints, IPs, cloud accounts and mobile builds. This is the first thing every guide asks for2.
  2. Authenticated roles. Each user role (customer, agent, admin, auditor) is a separate view of the app to test. CyberSigma prices a moderate web app with about 5 to 8 roles at ₹1.2 lakh to ₹3.5 lakh6. Testing without logins is cheaper and much less useful2.
  3. Box type. Black box means no inside knowledge. Grey box gives testers logins and some documents. White box adds source code or architecture access. More access usually means more days, and more real findings.
  4. Manual depth. The ratio of human testing to tool output. Business logic flaws, broken access control and chained attacks need people.
  5. Retest. A second pass to confirm your fixes worked. Some firms include one round. Others bill it later36.
  6. Empanelled auditor. If a regulator needs a CERT-In empanelled firm, your vendor pool shrinks and formal certification is added. CyberSigma lists this as a factor that pushes the price higher6.
  7. Report format. A regulator or board-ready report, mapped to a framework and signed off, takes more time than a findings list. Compliance-driven testing costs more because of documentation, validation and reporting2.
  8. Onsite work. Internal network tests on isolated networks may need testers at your premises, which adds travel and fixed days.
  9. Urgency. A report needed by Friday for an audit means pulling testers off other work. Expect to pay for that, or to get less depth.

A VAPT quote is a price for tester days. Ask how many days you are buying, and what a person does on each one.

VAPT cost by asset type

VAPT cost by asset type in India, per published 2026 guides: small web apps about ₹25,000 to ₹90,000, medium web apps ₹40,000 to ₹3.5 lakh, APIs ₹30,000 to ₹4 lakh, mobile apps ₹40,000 to ₹3 lakh per platform, and cloud configuration reviews ₹50,000 to ₹5 lakh per environment.

The table below pulls together the ranges each provider published. The "typical published range" runs from the lowest low to the highest high we found. The "median band" is the middle of the low ends and the middle of the high ends. That band is what our estimator uses, because it is less pulled by one very cheap or very expensive firm.

Published VAPT price ranges in India by asset type (INR, per engagement, 2026)
Asset typeTypical published rangeMedian bandSources
Small web app or website₹25,000 to ₹90,000₹27,500 to ₹77,5002 4 5 6
Medium web app (logins, roles)₹40,000 to ₹3.5 lakh₹67,500 to ₹1.75 lakh1 3 4 5 6 7
Large or multi-tenant web platform₹1.5 lakh to ₹12 lakh+₹2 lakh to ₹5 lakh4 5 6
API (REST or GraphQL)₹30,000 to ₹4 lakh₹50,000 to ₹1.25 lakh1 3 5 6 7
Mobile app (per platform)₹40,000 to ₹3 lakh₹60,000 to ₹1.75 lakh1 3 4 5 6 7
External network₹30,000 to ₹2 lakh; about ₹1,000 to ₹5,000 per IP₹40,000 to ₹1.2 lakh1 4 6
Internal network (incl. AD)₹60,000 to ₹6 lakh₹80,000 to ₹2 lakh1 4 6
Cloud configuration review₹50,000 to ₹5 lakh₹87,500 to ₹3.75 lakh1 3 4 5 6 7
Source code reviewNo consistent published range foundNot modelledUsually quoted on lines of code and language
Published VAPT price ranges by asset typeIndia · 2026 · INR
Published VAPT price ranges by asset type in India, 2026 Horizontal range bars on a shared rupee axis from 0 to 12 lakh. Light bars show the full typical range published by Indian providers; dark bars show the median band used in the estimator. Scan only: 20 thousand to 60 thousand. Small web app: 25 thousand to 90 thousand. Medium web app: 40 thousand to 3.5 lakh. Large web app: 1.5 lakh to 12 lakh. API: 30 thousand to 4 lakh. Mobile app per platform: 40 thousand to 3 lakh. External network: 30 thousand to 2 lakh. Internal network: 60 thousand to 6 lakh. Cloud configuration review: 50 thousand to 5 lakh. Below, nine cost drivers: scope size, user roles, box type, manual depth, retest, empanelled auditor, report format, onsite work and urgency. INR PER ENGAGEMENT, ONE CYCLE Typical range Median band ₹0 ₹2L ₹4L ₹6L ₹8L ₹10L ₹12L Scan only (no manual) ₹20k to ₹60k Small web app ₹25k to ₹90k Medium web app ₹40k to ₹3.5L Large web app ₹1.5L to ₹12L API ₹30k to ₹4L Mobile app (per OS) ₹40k to ₹3L External network ₹30k to ₹2L Internal network ₹60k to ₹6L Cloud config review ₹50k to ₹5L Quotes under ₹25k for a full web app are usually scanner output. WHAT MOVES THE PRICE Scope size User roles Box type Manual depth Retest Empanelled Report format Onsite Urgency Published VAPT price ranges by asset type in India, 2026 Same data as the desktop chart: range bars from 0 to 12 lakh rupees for scan only, small, medium and large web apps, API, mobile app, external and internal network, and cloud configuration review, followed by nine cost drivers. Typical Median band ₹0 ₹3L ₹6L ₹9L ₹12L Scan only (no manual) ₹20k to ₹60k Small web app ₹25k to ₹90k Medium web app ₹40k to ₹3.5L Large web app ₹1.5L to ₹12L API ₹30k to ₹4L Mobile app (per OS) ₹40k to ₹3L External network ₹30k to ₹2L Internal network ₹60k to ₹6L Cloud config review ₹50k to ₹5L WHAT MOVES THE PRICE Scope size User roles Box type Manual depth Retest Empanelled Report format Onsite Urgency
Light bars: lowest to highest published range. Dark bars: median of low ends to median of high ends. Sources: TCSA, SquareOps, Cybersecify, BM Infotrade, Factosecure, CyberSigma, MyITManager and RingSafe public price guides, 2026 (sources 1 to 8). Market ranges, not quotes.

Web application VAPT cost

Web apps have the widest spread because "a web app" can mean a 15-page brochure site or a banking portal with a dozen roles. BM Infotrade sorts them into small (₹25,000 to ₹60,000), medium (₹60,000 to ₹1.5 lakh) and large (₹1.5 lakh to ₹4 lakh or more)4. Factosecure's bands are a little higher, topping out at ₹5 lakh5. CyberSigma puts large, multi-tenant SaaS platforms at ₹4 lakh to ₹12 lakh or more, over 3 to 6 weeks6.

API and mobile app penetration testing cost

API tests are priced on endpoints and auth flows. CyberSigma's API range of ₹1 lakh to ₹4 lakh assumes about 50 to 150 endpoints6, while smaller APIs are quoted from about ₹30,000 to ₹40,00015. Mobile app tests are usually priced per platform, so Android and iOS are two line items16. Cybersecify lists both at ₹60,000 to ₹2.5 lakh, over 7 to 12 days each3. A mobile app almost always talks to an API, so check whether the API is inside the mobile quote or a separate one.

Pentest cost per IP and network VAPT

For external networks, BM Infotrade publishes ₹1,000 to ₹5,000 per IP, and ₹40,000 to ₹1.2 lakh for up to 25 IPs4. Per-IP rates usually fall as the range grows. CyberSigma quotes a full /24 (about 256 addresses) at ₹60,000 to ₹2 lakh6. Internal networks cost more because testers look for lateral movement, not just open ports. CyberSigma's internal and Active Directory range reaches ₹6 lakh6. If AD is in scope, read our guide on Active Directory penetration testing before you sign.

Does a CERT-In empanelled audit cost more?

A CERT-In empanelled VAPT audit usually costs more than a non-empanelled test, according to Indian providers, because fewer firms qualify and the work carries formal reporting. None of the guides we reviewed publishes a fixed percentage. For SEBI regulated entities, empanelment is required, so the real choice is between empanelled firms.

CERT-In, India's national computer emergency response team, keeps a list of empanelled information security auditing organisations18. Being on that list means CERT-In has assessed the firm. It does not set prices.

Whether you need an empanelled auditor depends on who regulates you:

  • SEBI regulated entities: the CSCRF says that, unless stated otherwise, all audits in the framework must be done by a CERT-In empanelled IS auditing organisation14. SEBI's FAQs repeat this for DAST and SAST on in-house and COTS software15. See our breakdown of SEBI CSCRF VAPT requirements.
  • RBI regulated entities: the NBFC Directions ask for "appropriately trained and independent information security experts / auditors"13. Many banks still ask for empanelled firms in their own policy. Check yours.
  • Government and public sector work: often specifies empanelled auditors in the tender. Our guide to CERT-In guidelines, 6-hour reporting and VAPT audits covers where empanelment comes up.
  • Most private SaaS firms: no rule requires it. Cybersecify notes the premium applies to regulated sectors, not typical SaaS startups3.

Not legal advice. Regulatory text changes and each entity category has its own rules. We quote the clauses as published on the dates in our sources. Check the latest text, and your regulator's FAQs, before you set your testing plan.

How many VAPT cycles will you actually pay for each year?

Regulated firms in India usually pay for two to four VAPT cycles a year, not one. RBI's 2026 Directions ask banks for vulnerability assessment every six months and penetration testing every 12 months on critical systems, plus testing after changes. SEBI and PCI DSS add their own cadence and change-driven tests.

Most price guides quote one engagement. Your budget has to cover a year. The number of cycles depends on your regulator, your systems and how often you ship changes.

Minimum testing cadence by rule (check the latest text for your entity category)
RuleWhat it asks forCycles a year (minimum)
RBI Directions 2026, commercial banks (para 151)VA at least every six months and PT at least every 12 months for critical systems and DMZ systems with a customer interface; risk-based for others122 VA + 1 PT, plus change-driven tests
RBI Directions 2026, NBFCs (para 121)Same VA and PT cadence for critical information systems, issued as RBI/DoS/2026-27/461 on 31 July 2026132 VA + 1 PT
SEBI CSCRF (Table 18)Protected systems and CII entities: at least twice, one in each half of the financial year. Other REs: at least once, starting in the first quarter14. Qualified stock brokers: half-yearly151 to 2
PCI DSS v4.0.1 (11.3, 11.4)Internal and external pentest at least every 12 months and after significant changes; quarterly vulnerability scans; retest to confirm fixes161 pentest + 4 scans, plus change-driven tests
ISO 27001, SOC 2No fixed pentest frequency; set by your own risk assessmentYour choice

The RBI Directions also say testing happens across the system life cycle: before go-live, after go-live on production, and after changes12. If you ship a new customer-facing feature every quarter, that is more test events than the minimum. For a clause-by-clause view, see our guide to the RBI Cyber Security Directions 2026 VAPT rules.

The wider market already tests more than once a year. In Cobalt's 2025 survey of 450 security leaders and practitioners, quarterly was the most common cadence at 30%, while 27% tested annually and 15% semi-annually10.

Interactive · Budget

VAPT budget estimator

Enter your scope. The estimate uses the median bands from the published price guides above.

Cycles per year
Retest included in the price?
CERT-In empanelled auditor required?
Per cycle
₹0
Per year
₹0
What drives the cost

    Indicative only, not a quote. Method: for each asset we use the median of the low ends and the median of the high ends published by the Indian providers in sources 1 to 7. External networks use ₹40,000 to ₹1.2 lakh for up to 25 IPs, plus ₹1,000 to ₹5,000 per extra IP (BM Infotrade), which can overstate large ranges because vendors discount. No guide publishes a CERT-In premium or a retest fee, so "empanelled: yes" drops the cheaper half of each band instead of adding a percentage, and "retest: no" adds nothing but flags the gap. Untested days assume about 14 calendar days of active testing per cycle, in line with the 5 to 15 working days providers publish.

    Ask how to test between cycles →

    What are the hidden costs of point-in-time testing?

    The hidden costs of point-in-time VAPT are retest fees, staff time to fix and verify, repeat cycles for every change, and the exposure between tests. A test proves what was true on the days it ran. Findings then take weeks to close, while new code and new CVEs keep arriving between cycles.

    ₹25.5 crAverage cost of a data breach in India, 2026IBM, Aug 2026
    67 daysMedian time to resolve pentest findings of all severitiesCobalt, 2025
    30%Of organisations pentest quarterly, the most common cadenceCobalt, 2025
    31%Of breaches started with exploitation of a vulnerabilityVerizon DBIR, 2026

    1. Retests and fix verification

    CyberSigma warns that retesting billed separately is a common surprise: the fix check you assumed was included "turns into a fresh invoice"6. Cybersecify says retests are commonly excluded or billed separately in the budget band3. PCI DSS expects you to retest and confirm corrections16, and SEBI expects findings closed within three months of the report15. So the retest is not optional. It is either in the price or on a second bill.

    2. Your own team's time

    Someone has to scope, grant access, answer tester questions, triage the report, fix the findings and chase the evidence. That time never appears in the vendor's quote. Fixes are slow for most teams. Cobalt found the median time to resolve findings of all severities was 67 days, and fewer than half (48%) of vulnerabilities were remediated11.

    3. Repeat cycles for every change

    RBI asks for testing after changes, and PCI DSS asks for a pentest after significant changes1216. A team that ships a major release each quarter can end up buying extra engagements that were never in the annual budget.

    4. Exposure between tests

    This is the largest cost, and it is not on any invoice. With one test a year, the gap between tests is close to a full year. Verizon's 2026 DBIR found that exploitation of vulnerabilities was the top way into organisations, at 31% of breaches17. IBM puts the average cost of a breach in India at ₹25.5 crore in 2026, up 15.9% from ₹22 crore in 20259. A ₹5 lakh test budget and a ₹25.5 crore average loss are not the same order of size. Our post on the 363-day blind spot of annual pentests walks through what happens in that gap.

    Budget for the year, not the engagement. Total cost of testing = price per cycle × cycles, plus retests, plus staff time to fix, plus the risk you carry between cycles. The estimator above covers the first two.

    What are the red flags in a cheap VAPT quote?

    Cheap VAPT red flags include a full web application test priced under about ₹25,000, a report in two or three days, no named testers, no manual validation, no retest and no proof of exploit. TCSA says web app "pentests" quoted that low are almost always an automated scan export with a new cover page.

    A low price is not always a bad sign. A small brochure site does not need a two-week test. The problem is when a scan is sold as a pentest, and your auditor or your attacker finds the difference. TCSA puts it plainly: a full web application "pentest" quoted under about ₹25,000 is almost always an automated scan export with a new cover page1.

    Watch for these signs:

    • Scanner output relabelled. Findings read like tool plug-in names, with generic fixes and no screenshots from your app.
    • No manual validation. False positives are left in. Real business logic flaws, like one customer seeing another's data, are missing.
    • No authenticated testing. The vendor never asked for test accounts, so only the login page was tested.
    • No retest. The quote ends at the first report, with no closure report for your auditor.
    • No proof of exploit. High and critical findings have no steps to reproduce, no request and response, and no evidence of impact.
    • No scoping call. A fixed price given before anyone asked about roles, endpoints or IPs.
    • Timelines that do not add up. Published timelines for manual web app and API tests are 5 to 15 days3. A two-day turnaround on a large app means someone skipped the work.

    If you want to know where tools stop and people start, our guide to automated vs manual penetration testing covers what each finds and misses.

    What should you ask a VAPT vendor before you sign?

    Before signing a VAPT contract, ask the vendor how many tester days are included, which roles and endpoints are in scope, how much is manual, whether one retest and a closure report are included, whether they are CERT-In empanelled, and to share a sample report with proof of exploit. The answers explain most price gaps.

    • How many tester days are in this quote, and who are the testers? What certifications do they hold?
    • Exactly what is in scope: which URLs, how many API endpoints, which IPs, which cloud accounts, which mobile builds?
    • How many user roles will you test with authenticated sessions?
    • Is this black, grey or white box? What access do you need from us?
    • What share of the work is manual? Which test cases are manual only?
    • Is one retest included? Do we get a closure report our auditor will accept?
    • Are you on CERT-In's list of empanelled auditors today? Can we see the current listing?
    • Will the report map findings to our framework (RBI, SEBI CSCRF, PCI DSS, ISO 27001)? Are findings CVSS scored?
    • Can we see a redacted sample report with reproduction steps and evidence?
    • Where does our data go during the test, and how is it deleted after?
    • What does a rush timeline cost, and what depth do we lose?

    Is continuous or automated testing cheaper over a year?

    Continuous or automated testing can cost less over a year than several manual cycles, but only if you compare the same scope and depth. It shortens the gap between tests and speeds up retests. It does not replace an independent audit where a regulator requires one, and business logic still needs human testers.

    There is no single answer, so here is a fair way to compare.

    1. Count your real cycles. Use the table above. Two VA rounds, one PT, change-driven tests and retests add up. Price all of them, not just one.
    2. Compare equal scope. A cheap scanner subscription is not the same as a manual pentest. A continuous platform that exploits and validates findings is not the same as a scanner either. Ask what each one proves.
    3. Keep the audit you are required to have. If SEBI or your board needs a CERT-In empanelled audit, continuous testing sits alongside it, not instead of it.
    4. Value faster fixes. Cobalt's 2026 report says 53% of organisations now take a programmatic approach to pentesting, and those firms are 4.5 times more likely to fix critical findings in three days or less19. Faster closure shrinks the exposure you carry.
    5. Look at the spread. The same report found top performers reach a high-risk finding half-life of 10 days, while the bottom 10% take 249 days19. How often you test matters less than how fast you learn and fix.

    A common pattern is a mix: continuous or frequent automated testing for coverage between audits, plus manual, empanelled testing where rules or risk require it.

    Frequently asked questions

    How much does VAPT cost in India?

    Published 2026 price guides from Indian providers put VAPT at about ₹20,000 to ₹50,000 for scan-only work, ₹40,000 to ₹3.5 lakh for a manual test of one medium web application, and ₹3 lakh to ₹12 lakh or more for compliance-grade or multi-asset programmes. These are market ranges, not quotes. Your price depends on scope, user roles, manual depth, retest terms and whether you need a CERT-In empanelled auditor.

    What is the cost of VAPT for a website?

    A small website or brochure site is usually quoted at about ₹25,000 to ₹90,000 in published Indian guides. A web application with logins and several user roles is typically ₹60,000 to ₹3.5 lakh. Large or multi-tenant platforms can reach ₹4 lakh to ₹12 lakh or more. The number of pages, roles and integrations moves the price most.

    How much does mobile app penetration testing cost in India?

    Indian providers publish mobile app penetration testing at about ₹40,000 to ₹3 lakh, and most price it per platform, so Android and iOS are separate line items. Published timelines are about 7 to 12 days per platform. Check whether the backend API the app uses is inside the mobile quote or priced as a separate API test.

    What is the pentest cost per IP in India?

    BM Infotrade publishes external network testing at about ₹1,000 to ₹5,000 per IP, and ₹40,000 to ₹1.2 lakh for up to 25 IPs. Per-IP rates usually fall as the range grows: CyberSigma quotes a full /24 range at ₹60,000 to ₹2 lakh. Internal networks cost more because testers look for lateral movement and Active Directory weaknesses.

    Is a CERT-In empanelled VAPT audit more expensive?

    Usually yes. Indian providers say empanelment narrows the pool of eligible firms and adds formal reporting, which pushes prices up, but none of the guides we reviewed publishes a fixed percentage. For SEBI regulated entities, the CSCRF requires CERT-In empanelled auditors, so compare quotes between empanelled firms on scope, depth and retest terms.

    Is retesting included in the VAPT price?

    It depends on the vendor. Some Indian providers include one retest and a closure report in the base price, while others bill fix verification separately. Ask before you sign. A retest is not optional for regulated firms: PCI DSS expects fixes to be confirmed, and SEBI CSCRF expects VAPT findings closed within three months of the report.

    How often do banks and NBFCs need VAPT in India?

    The RBI Cybersecurity Directions issued on 31 July 2026 ask commercial banks and NBFCs to run vulnerability assessment at least every six months and penetration testing at least every 12 months on critical systems, plus testing before and after go-live and after changes. That means at least two or three paid test events a year. Check the latest text for your entity category.

    Why are some VAPT quotes so cheap?

    Very low quotes usually mean automated scanning with little or no manual work. TCSA notes that a full web application pentest quoted under about ₹25,000 is almost always a scan export with a new cover page. Look for named testers, authenticated testing, manual validation, proof of exploit and an included retest before you compare prices.

    Where Arxiis fits

    You pay per snapshot. The attacker does not wait for the next one.

    Most VAPT budgets buy a few snapshots a year. The quote covers the days testers are active. It does not cover the months in between, when code ships, cloud settings change and new CVEs are published.

    Arxiis is an autonomous AI red teaming and penetration testing platform built for that gap. A multi-agent AI crew handles OSINT, exploitation, lateral movement and reporting, so testing can run far more often than a few cycles a year. It sits alongside the audits your regulator requires; it does not replace them.

    • Broad coverage: 26 security modules across six attack vectors: ransomware, Active Directory, cloud, web applications, containers and credentials.
    • Findings your auditor can read: CVSS scored, mapped to MITRE ATT&CK, with compliance overlays for 11 frameworks including RBI, CERT-In, SEBI CSCRF, PCI DSS, ISO 27001 and DPDP 2023.
    • Faster reports and retests: a pentest report in hours instead of weeks, so fix verification does not wait for the next cycle.
    • Your data stays with you: fully on-premise deployment, with an MIT-licensed open-source core you can inspect.

    Your company gets defended every day.

    Sources

    1. TCSA, "VAPT Cost in India 2026: What Penetration Testing Should Actually Cost", 10 June 2026. tcsa.in
    2. SquareOps, "VAPT Cost in India 2026: Full Price Guide", 7 August 2026. squareops.com
    3. Cybersecify, "Penetration Testing Cost in India 2026", updated 9 September 2026. cybersecify.com
    4. BM Infotrade, "VAPT Cost in India 2026", updated 9 July 2026. bminfotrade.com
    5. Factosecure, "How Much Does VAPT Testing Cost in India in 2026? Complete Pricing Guide", 6 May 2026. factosecure.com
    6. CyberSigma, "VAPT Cost in India: What Drives Penetration Testing Pricing", 29 June 2026. cybersigmacs.com
    7. MyITManager, "VAPT Services India: Pricing and Compliance", reviewed June 2026. myitmanager.in
    8. RingSafe, "VAPT Cost in India 2026: Honest Pricing Guide", updated 26 April 2026. ringsafe.in
    9. IBM India Newsroom, "India Records its Highest Average Cost of a Data Breach at INR 25.5 Crore in 2026", 3 August 2026. in.newsroom.ibm.com
    10. Cobalt, "State of Pentesting Report 2025" (Figure 5, pentest frequency), April 2025. resource.cobalt.io
    11. Cobalt, "Key takeaways from the State of Pentesting Report 2025", 14 April 2025. cobalt.io
    12. Reserve Bank of India, "Reserve Bank of India (Commercial Banks: Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026", RBI/DoS/2026-27/410, 31 July 2026. rbi.org.in
    13. TaxGuru, "RBI Issues NBFC Cybersecurity and Technology Risk Directions, 2026" (text of RBI/DoS/2026-27/461), August 2026. taxguru.in
    14. SEBI, "Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities", circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024. sebi.gov.in (PDF)
    15. SEBI, "Frequently Asked Questions on CSCRF", June 2025. sebi.gov.in (PDF)
    16. PCI Security Standards Council, "PCI DSS v4.0.1", Requirements 11.3 and 11.4, June 2024. pcisecuritystandards.org
    17. Verizon, "2026 Data Breach Investigations Report", 2026. verizon.com
    18. CERT-In, "Empanelled Information Security Auditing Organisations", list maintained by CERT-In. cert-in.org.in (PDF)
    19. Cobalt, "5 Key Takeaways from the 2026 State of Pentesting Report", 21 April 2026. cobalt.io
    Arxiis Research

    Written by the Arxiis research team. Facts checked against primary sources on 28 September 2026. Not legal advice.