What does a security audit (VAPT) cost?

Written by Sachin, founder of Pinaka Security.

What does a security audit (VAPT) cost?

Once a company accepts it needs to test its own security, the question becomes a practical one: how much does this actually cost? The honest answer is that it varies, and the price difference usually reflects a real difference in what you are buying. This article is about telling those apart.

01 The definition

What VAPT means in practice

VAPT stands for vulnerability assessment and penetration testing. In practice it is two things done together. The assessment part reviews your infrastructure, access controls, patch levels, and configuration, and lists what is exposed. The penetration test part attempts to actually get in, the way an attacker would, through your applications, APIs, and network. The output of both should be a list of findings ranked by risk, with the steps to fix each one explained in plain language. A report that just lists vulnerabilities without telling you which matter most, or what to do about them, is only half the job.

This is the distinction that drives the price. Anyone can run a scanner and generate a list. That is worth what an hour of scanning costs. What is expensive, and genuinely useful, is the manual work: a human understanding your workflows, your user roles, the places where a real attacker would look, and translating findings into fixes your team can actually execute.

02 The numbers

What 2026 quotes actually look like

Published pricing guides for 2026, compiled from vendor pricing and buyer guides, put a focused web application test somewhere between $5,000 and $30,000, with most small-business engagements landing in the $8,000 to $20,000 band. An external or internal network test sits in a similar range, typically $4,000 to $20,000 depending on how many systems and how much ground it covers. These are published ranges, not an estimate of what we quote.

$5k to $30k Focused web application test
$8k to $20k Typical small-business band
$4k to $20k External or internal network test
$2k to $5k Web app test in India

If your company operates in markets like India, the numbers you will see quoted are lower. A web application test often lands between $2,000 and $5,000 there. Indian pricing is genuinely cheaper. The point is that global pricing guides and local quotes are describing the same service at very different absolute numbers, so a number on its own tells you nothing until you know what is included in it.

03 The five drivers

What the price is actually paying for

Five things push a quote up or down, and they explain most of the spread between a $5,000 quote and a $25,000 one.

  • Scope. The biggest driver. One application with two user roles is not the same job as the same application with an admin panel, five roles, and payments. Salespeople quote scope, and scope is the line item you should understand before any other.
  • Manual versus automated. A scanner running on autopilot can pass over business logic, the parts of the application that make it yours. A human tester evaluating authorisation rules, file uploads, and workflow edges is a different service at a different price.
  • The report. The difference between a cheap test and an expensive one is often mostly reporting. An auditor-ready report, with findings mapped to ISO 27001 or SOC 2 controls and steps sequenced for your team, takes real hours to produce. If the report is not going to be read by a regulator or a customer, a simpler one may be fine.
  • Retesting. Fixing findings and getting confirmation that they are actually fixed is its own engagement. Ask whether confirmation testing is in the quote or billed separately. It should be something you schedule, not a surprise.
  • Who does the work. Rates for skilled testers run roughly $100 to $300 an hour in published US figures. This is not where you save money. The cost of a weak engagement is not the fee, it is the false comfort it gives you.

04 Read the discount

What a cheap quote usually is

A quote that looks too good needs a specific reason to be that good. Sometimes it is territory. A firm in a lower-cost market quoting its domestic rate is a legitimate reason. Frequently it is an automated scan with a report generator and almost no human validation. The difference matters for a reason that has nothing to do with getting your money's worth. An automated scan of a well-configured environment will often report very little, and a company that concludes it is secure on that basis can be exactly the kind that gets caught out later.

05 Timing

When you should do this

Compliance is the driver for most companies, and it is a legitimate one. A SOC 2 or ISO 27001 audit expects to see evidence of testing. Customers in regulated industries increasingly ask for it during supplier reviews, and cyber insurance providers want to know you have tested before they price you. If none of those apply yet, a reasonable rhythm is an annual test, more often after a significant change to your systems: a new application, a new provider, a merger.

A company that has never looked at security should start with the basics rather than a full test. Strong logins, backups that are proven to work, and access cleaned up come first. Wait for the test until there is something meaningful to test and someone ready to act on the findings. Testing before you are ready to respond just produces a list.

06 Fresh eyes

Why an independent pair of eyes matters

The people closest to a system are usually the last to see its gaps, and that is not a criticism of anyone. On one manufacturer engagement, a previous provider had missed three critical exposure points for two years. An outside test is how something like that gets found.

We scope tests after a conversation about your environment, and the price is fixed before work starts. You get a prioritised list of findings in plain language, with the owner of each fix named and the sequence spelled out. If you want details on how we run security audits and penetration tests, that page says it plainly.

A VAPT is not a magic number, and the cheapest quote is not automatically good value. Understand what is in the price, and treat the report as the part you are actually buying.