The honest version: nobody can quote your test accurately from a one-line description. What sets the number is the count of distinct user roles, the number of endpoints or screens, whether business-logic flows involve money, and whether testing happens against staging or production under restrictions.
Be sceptical of two extremes. A ₹15,000 "penetration test" is an automated scan with a logo on the PDF — it will find missing headers and outdated libraries, and it will miss every authorisation flaw. At the other end, a large consultancy quoting ₹8,00,000 for a five-screen app is charging for its sales pipeline, not for testing hours.
What a fair quote should show you: the number of testing days, who performs them, the standard being followed, whether a retest is included, and what happens if the scope turns out to be bigger than described. If those five things are not in the proposal, the price is not comparable to anything.
Indicative 2026 penetration testing prices in India
| Engagement | Typical scope | Indicative price | Duration |
|---|---|---|---|
| Web application pentest | 1 app, 3–4 roles, ~60 routes | ₹75,000 – ₹1,50,000 | 2–3 weeks |
| Mobile app pentest (Android + iOS) | 2 builds + backing API | ₹85,000 – ₹2,00,000 | 2–3 weeks |
| API security test | 40–80 endpoints | ₹60,000 – ₹1,20,000 | 1–2 weeks |
| Secure code review | 30–60k lines, security paths | ₹65,000 – ₹1,80,000 | 1–3 weeks |
| Cloud security assessment | 1–2 accounts | ₹70,000 – ₹1,50,000 | 1–2 weeks |
| Threat modelling workshop | One product, one workshop | ₹45,000 – ₹80,000 | 1 week |
In short
- Retesting should be included, not billed again — insist on it in writing.
- A named tester and their methodology matter more than the vendor's size.
- Annual retainers cost less per test but only pay off if you ship continuously.
- Compliance-driven tests cost more because of the evidence and documentation overhead.