Buyer's guide · 2026
The pentest buyer's guide for Indian SaaS.
If you're buying a penetration test in India in 2026, expect to pay roughly ₹40,000 to ₹2.5 lakh for a human-led web-app test, get a report in 1–2 weeks, and insist on a certified human tester, a retest, and an attestation letter your customers will accept. This guide explains what you're actually buying, what fair prices look like from vendors' public pages, what auditors expect, how to scope the work, and the questions that separate a real test from a dressed-up scan.
Written for founders and engineering leads at startups and SaaS companies. No jargon, no fear-selling.
First, the basics
A pentest is not a scan.
A vulnerability scan is an automated tool that lists things that might be wrong — fast, broad, and full of false positives. A penetration test is a certified human who confirms what is actually exploitable, chains issues together the way an attacker would, and proves each finding with masked evidence. Scanners miss the bugs that matter most to SaaS: broken access control, authorisation flaws (IDOR), and business-logic abuse — because judging those needs a human who understands your app.
Broken access control (IDOR) — High
A logged-in user could read another customer's shopping basket by changing the numeric id in the request GET /rest/basket/{id}. The server returned the other user's items without checking ownership. A scanner reports the endpoint exists; only a human testing as two different users discovers that one can read the other's data.
Fix: enforce an ownership check on every object lookup — the logged-in user's id must match the resource's owner. Note: this is a sample from a practice app, never real client data.
What it costs
India price bands, in the open.
Most Indian vendors don't publish prices at all — you have to "contact sales." The figures below are the ones that are public, next to our own fixed prices. Published prices are deliberately our edge: you can budget before you talk to us.
| Service | Typical India market (public pages) | DebugSol (fixed, public) |
|---|---|---|
| Light / external check | Astra Scanner plan ₹1,67,000/yr (continuous scan) | Launch Check — ₹29,999 ($499), 5 days |
| Web app pentest (manual) | ₹40,000–2,50,000 per app (India range) | Startup Pentest — ₹74,999 ($2,499), 7 days |
| Web + API + cloud (SaaS) | Astra Enterprise ₹6,65,000/yr; infra ₹3,80,000–5,50,000 | SaaS Assurance — ₹1,99,999 ($8,999), 15 days |
| Compliance / retainer | Quote-only at most vendors | Fixed quote from a short scoping form |
Market figures from vendors' public pages (Astra Security), as of October 2026; prices change — treat them as bands, not quotes. Sources: getastra.com VAPT pricing.
Compliance
What auditors actually expect.
No framework names "penetration testing" as a hard legal requirement — but in practice, auditors and enterprise customers ask for a recent human-led test as evidence that your controls work. Here's the commonly-expected picture for Indian SaaS:
- —SOC 2 — commonly expected: evidence of vulnerability management and testing under the security criteria (CC4.1 explicitly lists penetration testing as valid evidence; CC7.1 covers vulnerability detection and monitoring). A current pentest is the usual artefact auditors ask to see.
- —ISO 27001 — commonly expected: technical vulnerability management (Annex A 8.8 in the 2022 revision), for which a pentest is standard supporting evidence.
- —DPDP Act, 2023 — commonly expected ahead of enforcement: Section 8(5) requires every Data Fiduciary to take "reasonable security safeguards" to prevent a breach, with penalties for a safeguards failure reaching up to ₹250 crore under the Act's Schedule. The DPDP Rules, 2025 phase this in, with full compliance — including the Section 8 breach-notification clock to the Data Protection Board — required by 13 May 2027.
- —CERT-In — a separate, already-active obligation under the IT Act: cyber incidents must be reported to CERT-In within six hours of being noticed, independent of any DPDP or sector-regulator requirement. CERT-In-empanelled auditors are a legal requirement for specific regulated sectors (banks and NBFCs under RBI, government bodies, SEBI-regulated entities, critical infrastructure) rather than a universal mandate.
These compliance points were checked against the primary Act, Rules and standards referenced above as of October 2026; frameworks and enforcement dates can change. Nothing here is legal advice.
Get it right
A scoping checklist.
Good scope is what makes a fixed price possible and the result useful. Before you sign, pin down:
- 01Roles: list every user role (admin, member, read-only, API client) — authorisation is tested as each one.
- 02Endpoints: the app's pages plus every API route, including internal and mobile-backend APIs.
- 03Environments: a stable staging mirror of production, with seed data and test accounts per role.
- 04Retest rounds: how many re-checks after you fix are included, and for how long.
- 05Who tests: a named, certified human tester — not only an automated scanner.
- 06Evidence: masked request/response proof per finding, and a retest certificate.
- 07Timeline: a fixed delivery date, and how critical findings are escalated mid-test.
Before you sign
Ten questions for any vendor.
- 01Is the price fixed and published, or quote-only? What changes it?
- 02Is a certified human testing, or is it mostly an automated scan?
- 03Which standards do you follow — OWASP WSTG, API Top 10, MASTG, PTES?
- 04Do you test authorisation as every role (IDOR, privilege escalation)?
- 05How many retests are included, and for how long after delivery?
- 06Will I get an attestation letter my customers and auditors accept?
- 07Can you map findings to SOC 2 / ISO 27001 / DPDP if I need it?
- 08How do you handle a critical finding found mid-engagement?
- 09Can I see a redacted sample report before I sign?
- 10What exactly is in scope, and what happens if scope grows?
Questions
FAQ
How long does a pentest take?+
For a typical SaaS web app and its API, a focused engagement runs about 5–15 business days depending on scope. Our fixed packages deliver in 5, 7 and 15 business days.
Pentest or vulnerability scan — which do auditors want?+
A scan is automated breadth; a pentest is a human confirming real, exploitable issues with proof. Auditors and enterprise buyers generally want evidence of a human-led test, not only a scanner report.
Will a pentest make us DPDP / SOC 2 / ISO 27001 compliant?+
No single test makes you compliant. A pentest is one commonly-expected piece of evidence that your security safeguards work; the rest is policy, process and controls.
Do you need production access?+
No. We test a staging mirror with seed data and per-role test accounts, so there is no risk to live customer data.
Start with a free exposure snapshot.
One domain, passive public checks, results on screen. No login.