We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled auditor

Web application VAPT cost

Web application VAPT cost is driven by the size and complexity of the application, the number of user roles and workflows, whether testing is grey-box or black-box, and whether source-code review is included — not by a flat per-page rate. CyberSigma is a CERT-In empanelled auditor: we scope your application in a short call and return a fixed quote, then test business logic, authentication, authorisation and injection paths (not just an automated scan) and include a free retest to confirm closure.

Get a fixed VAPT quote →Book a 20-minute call
Cost factors

What drives web-app VAPT cost

  • Application size — number of pages, workflows and user roles
  • Grey-box (credentialed) vs black-box testing
  • Whether source-code review and API testing are included
  • Number of retest cycles and reporting depth for regulators/customers
What is included

What a proper test covers

Manual, business-logic-aware testing across the OWASP Top 10 and beyond: broken access control and IDOR, authentication and session flaws, injection, SSRF, and misconfiguration — with proof-of-concept and remediation guidance, verified on a free retest.

Timeline

How long it takes

Scoping — 2–4 days
Application walkthrough, roles and a fixed quote.
Testing — 1–2 weeks
By application size and role count.
Report & retest — 3–5 days
Prioritised report, then a free retest after fixes.
Deliverables

What you receive

Executive & technical reports
Risk-rated summary plus each finding with evidence, CVSS and remediation.
Closure evidence
Free retest and re-issue for your auditor or customer.
Proof

See how we’ve done it before

Relevant case study
How manual testing found business-logic flaws an automated scan missed. Read case studies →
Redacted sample deliverable
Inspect a redacted VAPT report first. Request a redacted sample →

Is your application one bug away from a breach?

Get a free VAPT scope and quote from CERT-In empanelled testers — share your work email and we scope the work this week.

Web-app VAPT cost — FAQs

How much does web application VAPT cost?

It depends on application size, role count, grey-box vs black-box and whether code review/API testing are included. We give a fixed quote after a short scoping call rather than a flat per-page rate.

Is a retest included?

Yes. A free retest confirms your fixes and we re-issue the report so you can evidence closure.

Get a fixed web-app VAPT quote

A short scoping call and we return a fixed price and start date — with senior testers, not a scanner. Reply within four business hours.

Book a 20-minute call →

Ready to discuss your Web application VAPT requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.