What Drives the Price and Duration of a VAPT in India?
A VAPT in India is mostly priced on effort, and not by fixed rate. What you pay comes down to 2026-8-10 10:36:7 Author: payatu.com(查看原文) 阅读量:7 收藏

A VAPT in India is mostly priced on effort, and not by fixed rate. What you pay comes down to how much you are testing, how deep the testing goes, and which compliance standard the report has to satisfy. A typical duration for a single application usually needs one to three weeks of active testing, while a larger environment of several applications, network, and cloud runs four to six weeks, often in parallel. If three providers have sent you three very different numbers for what looks like the same job, that is normal, Why? Let us understand more…

On a recent scoping call that Payatu conducted for a prospective customer, the business head for an Ad-Tech company compressed the whole buying decision into one breath: “If I want to get a VAPT done for my web app, what is the timeline like? What would you require? What is the typical expense?” This guide answers those three questions in that order. It is built from the questions buyers actually ask us on VAPT scoping calls, so the answers below are the ones real buyers needed.

What determines the cost of a VAPT?

The price of a VAPT is a function of effort, not a fixed catalogue rate. A provider estimates the number of person-days the work will take, then prices against the seniority of the testers involved, the testcases that will be covered and the depth of the assessment. Everything that changes the effort changes the cost. Six factors move it the most.

Scope and asset count. The single biggest driver is how much there is to test. Every element you add to the scope, dynamic pages, user roles, APIs, integrations, adds tester hours, so providers size each application by complexity before estimating anything else. In our Payatu’s scoping model, a low-complexity application has 1 to 25 dynamic pages and one or two user roles. A medium-complexity application, 26 to 50 dynamic pages with two or three roles, takes roughly 10 days of testing effort. For network testing, a tester can typically cover around 50 IPs a day. Multi-application estates follow the same logic at a different scale. In one Payatu engagement, covered in our case study “Global IT Services Consultancy Conducts Web Application Assessment on 12 Apps” (link to case study), a single internal ERP system spanned 12 business applications, and the assessment surfaced more than 120 vulnerabilities across them. This is why the first thing any competent provider asks for is an inventory, not a budget.

Testing depth: black-box, grey-box, or white-box. Black-box testing simulates an outside attacker with no prior access or knowledge. Grey-box testing gives the tester credentials and some documentation, which lets them reach authenticated functionality and business-logic flaws that an outsider would take far longer to find. White-box adds full visibility, including source code. Deeper visibility finds more, and it usually costs more per asset because it takes more skilled manual time.

The manual-to-automated ratio. An automated scan is cheap because a tool does the work, but it misses the findings that matter most: broken access control, authorization flaws, chained exploits, and business-logic abuse. Buyers have started probing this directly. While scoping a web application VAPT for a cloud communications platform, their compliance lead asked us, “You mentioned Burp Suite is being used. Can you tell me what is the split for the manual and automated testing here?” This is the right question that Buyers should be asking the Vendors. Payatu’s application testing runs on a balanced approach where automated scans identify the common ‘low hanging’ flaws and vulnerabilities which allows our security researchers more time to spend on finding critical flaws by chaining exploits and identifying vulnerabilities often missed by automated scans. Our testers first understand how your application is meant to work, then write business-logic test cases specific to it, which is where the serious findings surface. When you compare quotes, you are often comparing an automated scan against genuine manual testing, and the price gap reflects the depth gap.

Compliance grade. A test that has to satisfy a regulator or an accreditation body carries more work than an internal health check. RBI, SEBI CSCRF, PCI DSS, STQC, IEC 62443, and FDA submissions each require specific evidence, mapping, and report formats. That extra documentation takes real time to produce, so it belongs in the cost and the timeline from the start, not as a surprise at the end.

Retesting and revalidation. A finding is not closed until it is fixed and confirmed fixed. Revalidation is the second pass in which the tester verifies that your fixes actually closed the findings; without it, a report is a list of problems with no proof that any of them went away. Most providers therefore define a remediation window, a fixed period after the report in which your team fixes the findings, and then retest what you fixed. Whether that retest is included in the price varies by provider, which makes it a quiet source of difference between quotes. At Payatu, we structure this as a 60-day fix window followed by one round of revalidation, both included in the commercials we quote. The window is unfamiliar enough that an engineering leader at a data solutions company stopped us on a call to check: “So you say 60, or 16?” Sixty. If your scope is large or you expect multiple fix cycles, additional revalidation rounds are priced in, so confirm what any quote includes before you compare it against another.

Tester expertise and support model. A firm that staffs an engagement with senior testers, shares a live findings tracker updated daily, and joins a call with your developers to walk through fixes is pricing in people and time that a scan-and-send vendor is not. Onsite work, a dedicated project lead, or a governance layer for a larger programme also adds to the number.

Why do two quotes for the same application differ so much ?

Because they are rarely for the same work. The lowest quote is usually an automated scan with a tool-generated report. The higher quote is manual testing by experienced people who understand your application’s logic. Both get labelled “VAPT.”

We are upfront about where we sit in that spread. On scoping calls we tell buyers plainly that our commercials can be close to twice a scan-led quote, because most of the effort is senior testers doing manual work. There are vendors who will do the job for a fraction of that, and if all you need is a tool report, they are the rational choice. We say that too.

Be honest with yourself about which buyer you are. The head of engineering at a data services firm told us directly: “My goal is just to pass this VAPT report. No critical, no high, and almost no medium issues to be found.” If a clean certificate for a customer is truly the goal, say that to your provider, because it changes the scoping conversation. But know the practical risk of choosing on price alone: if the cheaper test misses flaws that your customer’s security team or a regulator later finds, you pay again for the assessment you needed the first time, and you lose the weeks in between. That pressure is growing, not shrinking. As the engineering lead of a travel-tech company put it on a call with us, “Because of this AI push, we ship a lot of code. And there are companies coming to us saying we have vulnerabilities on our website. We wanted to expedite the whole process.”

When you evaluate quotes, ask each provider for three things: the manual-to-automated split, a redacted sample report, and whether retesting is included. Those three answers explain most of the price difference.

How is a VAPT priced, per module or per effort?

VAPT is priced on effort, expressed in person-days, derived from your scope. A provider takes the asset inventory, decides the testing depth for each item, estimates the days required, and produces a fixed-scope proposal against that estimate. There is no per-seat or per-module licence fee, because this is a service, not a product.

This is why a provider cannot quote a real number from a one-line request, and why the scoping questionnaire asks for dynamic page counts, user roles, and API counts: those numbers move effort more than anything else. “Test my web app” could mean two days or twenty. The more precisely you describe the scope up front, the closer the quote will be to the final invoice.

The same logic explains why the price usually arrives after the call, not on it. A number quoted before scoping is a guess, and a guess cuts both ways: either it is padded to protect the provider, or it is low and gets revised after you have committed. If a vendor gives you a firm price in the first ten minutes, ask what they are assuming about your scope, because they are assuming something.

How long does a VAPT take?

Duration also follows scope and depth. As a general guide for the testing phase alone:

Engagement typeTypical testing duration
Single web or mobile application (black-box)1 to 2 weeks
Application with authenticated roles and APIs (grey-box)2 to 3 weeks
Source code review (per application)1 to 2 weeks
Large environment: multiple apps, network, cloud4 to 6 weeks, often parallelized
IoT or product security assessment (hardware, firmware, apps)3 to 6 weeks depending on component count
Red team engagement8 to 12 weeks

These cover active testing only. Two other clocks matter. First, mobilisation: most providers, us included, need one to two weeks of lead time to deploy a team, so a test cannot start the day you sign. Second, the full calendar from kickoff to final certificate includes scoping, reporting, your remediation window, and revalidation, which together usually add more time than the testing itself.

Larger scopes do not always take proportionally longer, because a provider can run several testers in parallel across different assets. In the 12-application engagement mentioned above, the client needed all 12 applications tested within three months, with the fix-and-retest cycle closed within the three months after that. Sequential app-by-app testing would have blown the deadline, so the process was redesigned to run applications in parallel. The full test-fix-retest programme closed in six months.

One timeline risk sits on your side of the table, and it is the most common one we see: findings waiting on developer bandwidth. If your team cannot fix issues inside the remediation window, the retest slips, and with it the certificate. Plan remediation capacity when you plan the test.

What does the timeline look like week by week?

A typical application engagement moves through five stages.

Scoping and kickoff comes first, usually a few days. You share the asset inventory, credentials for grey-box testing, and any environment or compliance requirements. The provider confirms the test plan and rules of engagement.

Active testing follows, one to three weeks for most applications. Good providers do not make you wait for the final report. At Payatu you get a live tracker updated as findings surface, so your developers can start patching a critical on day one instead of week three.

Reporting comes next, a few days to a week. You receive a report with each finding rated by severity, a proof of concept, and specific remediation steps, plus an executive summary for non-technical stakeholders.

The remediation window is yours, typically 60 days. Your team fixes the findings. For reference, mature security programmes we run hold themselves to fix timelines by severity: critical findings within 24 hours, high within 5 days, medium within 15. Your own targets can be looser, but several compliance frameworks put a hard limit on the total window.

Revalidation and final report close the loop. The provider retests the fixed items, confirms closure, and issues the final report and certificate that you submit to your customer or regulator.

How do compliance deadlines change your timeline?

If a regulator or customer is forcing the assessment, plan backwards from their deadline and add the certification lead time, because the report date is not the finish line.

For SEBI-regulated entities under the Cybersecurity and Cyber Resilience Framework (CSCRF), the sequence is defined. The VAPT report is submitted within one month of completion after IT Committee approval, findings are closed within three months of report submission, and revalidation is completed within five months of VAPT completion. Those windows mean your remediation and retest have to fit inside a fixed calendar, so the test cannot start at the last minute.

For RBI-regulated banks and NBFCs, the report generally has to come from a CERT-In empanelled auditor, and there is a detail that has failed real audits. The auditor’s empanelment must be valid on the date the report is signed. If a firm’s empanelment lapses between signing the contract and delivering the report, the report can be rejected. Confirm the provider’s empanelment status and its validity date before you start. Payatu has been CERT-In empanelled since 2017; whoever you evaluate, ask for the validity date in writing.

For product and OT certifications such as STQC, IEC 62443, or an FDA 510(k) submission, the assessment is one input into a longer certification process. Self-declaration is usually not accepted, which is the reason a third-party assessment exists in the first place. Build in time for the certifying body’s own review after the testing is done.

What do you need to provide for an accurate quote?

The gap between a rough estimate and a firm proposal is information. Prepare these before you approach a provider, and you will get a quote you can take to your finance team with confidence:

  • An asset inventory: the number of web applications, mobile applications (Android and iOS counted separately), APIs, network ranges or IPs, cloud accounts, and any hardware or firmware in scope.
  • The testing depth you want for each asset: black-box, grey-box, or white-box, and whether source code review is included.
  • User roles and access: how many roles exist and whether you can provide test credentials for authenticated testing.
  • The environment: production or staging, and whether onsite presence is required for restricted or air-gapped systems.
  • The compliance target: the specific regulation, customer requirement, or certificate the report has to satisfy, since that dictates format and rigour.
  • The deadline: the date the final report or certificate is needed, so effort can be planned and parallelised.
  • Retesting expectations: how many revalidation rounds you expect and how long the remediation window should stay open.
  • Confidentiality needs: whether an NDA is required before you share details, which most providers will sign as a matter of course.

If your environment is complex, share an architecture diagram. On a cloud engagement for a fintech running a multi-account AWS setup, the client’s architecture diagram was what let us decode the resource count and produce an accurate estimate instead of a padded one. One diagram can replace a week of scoping emails.

A note if this spend was not in your budget. Many VAPT purchases are unplanned; the engineering head of a payments fintech told us, “This testing is an add-on task, not a planned one, so we do not have a budget approach.” If that is you, the effort-based logic in this guide is your friend: bring a precise scope and a clear compliance target, and you pay for exactly the depth you need, no more.

What you receive at the end

A quality engagement produces three artefacts, and buyers regularly confuse them, so here is the distinction. The live tracker is the working document during testing, updated as findings surface. The report is the formal deliverable: each finding rated by severity with a proof of concept and a concrete fix, alongside an executive summary for leadership. The certificate or attestation is the one-page artefact that your customer, tender, or regulator is usually actually asking for, issued after revalidation confirms the fixes.

What matters more is what happens between the report and the certificate. At Payatu, we do not test and disappear. We walk your developers through each finding, retest once the fixes are in, and issue an updated report that confirms what is now closed. A provider who only hands over a document has sold you a document. One who stays until the fixes are verified has helped you secure the application.

Frequently asked questions

How much does a VAPT cost in India? There is no single price, because VAPT is quoted on effort rather than a fixed rate. The cost depends on how many assets are in scope, how deep the testing goes (black-box, grey-box, or white-box), the manual-to-automated ratio, the compliance standard involved, and whether retesting is included. The most reliable way to get a real number is to share a scoped asset inventory and ask for a fixed-scope proposal.

How long does a VAPT take? A single application usually takes one to three weeks of active testing, and a large environment with multiple applications, network, and cloud takes four to six weeks, often run in parallel. Add one to two weeks of mobilisation lead time before testing starts. The full timeline from kickoff to final certificate is longer because it includes scoping, reporting, your remediation window, and revalidation.

Is retesting included in a VAPT? It depends on the provider, so confirm it in the scope. Quality engagements include at least one revalidation round after a defined remediation window, commonly 60 days, to confirm that fixed findings are actually closed. Frameworks such as SEBI CSCRF require revalidation within a set window, so for compliance work it is not optional.

Do I need a CERT-In empanelled vendor? For RBI-regulated entities, yes, and the empanelment must be valid on the date the report is signed. For many other purposes it is a strong credibility signal rather than a strict legal requirement. Check what your specific regulator or customer actually mandates before ruling vendors in or out.

Why won’t a provider give me a price on the first call? Because the honest answer depends on scope they do not yet have: dynamic page counts, user roles, APIs, and testing depth. A serious provider sends a scoping questionnaire after the first call and returns a fixed-scope proposal against your answers. A price quoted before scoping is an assumption, and you will meet the assumption later, at invoice time.

What is the difference between VAPT and penetration testing? Vulnerability assessment identifies and lists weaknesses, often with tool assistance for breadth. Penetration testing goes further and manually exploits those weaknesses to show real impact and chained attack paths. VAPT combines both, which is why a credible engagement is manual-testing-led rather than a scan alone.

Get a scoped VAPT quote

A VAPT is not a line item to minimise. It is the difference between finding your flaws in a report, or having a customer’s security team find them for you three months later. The cheap scan clears the audit and misses the one that matters, and the deadline only moves one way.

So scope it early. The sooner you know what needs fixing, the more room you have to fix it before a customer, tender, or regulator is waiting on the certificate.

Start with our redacted sample report. It is the fastest way to see how deep we actually test, before you spend anything. Then send your asset inventory and compliance target, and you will get a scoping questionnaire the same day and a fixed-scope proposal against your answers, from a CERT-In empanelled and ISO 17025 accredited team that stays until your fixes are verified.

Talk to Payatu’s team: payatu.com/connect-now


文章来源: https://payatu.com/blog/what-drives-the-price-and-duration-of-a-vapt-in-india/
如有侵权请联系:admin#unsafe.sh