Black-box = no access · Grey-box = user creds · White-box = full access + source. Deeper access = more thorough (and higher effort).
Add quantities for what you need tested. The estimate updates live.
Indicative only — final scope (complexity, environments, retesting) sets the exact price. CyberSigma is CERT-In empanelled; quotes are fixed after a short scoping call.
A senior pentest lead confirms your scope and sends a fixed price + timeline + sample report.
What drives VAPT cost
Scope, not size, sets the price
Pentest cost is driven by what’s in scope — number of apps, APIs, live IPs, roles and environments. Counting your real attack surface is the fastest way to a firm number.
Depth changes effort
Black-box, grey-box and white-box testing take increasingly more effort but find far more. Grey-box (with test credentials) is the usual sweet spot for web and API testing.
CERT-In empanelled reports
CyberSigma delivers CERT-In empanelled VAPT with a fixed price, clear timeline, retesting and an audit-ready report accepted by regulators, customers and auditors.
