Simple, Transparent Pricing
Founder-led pentest with retest and consulting hours. Fixed plan pricing with transparent per-scope add-on rates. No hidden costs.
Penetration Testing
AI, Web, API, Android, iOS, Desktop, Cloud, IoT, Internal Network, and External Network. Pick the plan that fits your scope.
Startup Pentest Plan
For early-stage startups
~$790 / ~€680
Best Suited For: A first pentest, or the first in a while. Known attack categories tested by hand, with a report investors and enterprise customers accept. Advanced work adds nothing until the baseline is clean.
Growth Pentest Plan
For scaling businesses
~$1,890 / ~€1,640
Best Suited For: An auditor, an enterprise security review or a compliance deadline needs SOC 2 or ISO 27001 evidence. Also the plan for more than two scopes, which the Startup Plan caps at.
Plan terms and prices on this page are effective from 28 August 2026 · USD and EUR figures are indicative, shown as at August 2026 · The INR price is the one that binds. International engagements are invoiced at the conversion rate on the date of your quote or invoice.
One scope is one thing we test, not one company. A web app, the API behind it and an Android build are three. Each needs a different kind of testing, which is why each is counted separately.
Ticking two boxes does not always mean paying for two. If both fit inside one scope's work, we quote one. You pay for the effort the test actually takes, and where a surface turns out to be larger than one scope we say so before the SOW rather than after. The scoping call is free and carries no obligation.
There is exactly one point where the price can change. At access verification, after the NDA is signed and before any testing begins, we look at the estate read-only and confirm the work fits the scopes quoted. If it does, the price stands. If something turns out to need its own scope, we tell you then, in writing, and you can decline it. Nothing moves after that, and nothing moves once testing has started.
The same work is the same price, wherever you are. A team in Berlin or San Francisco pays what a team in Bengaluru pays for the same scope. We publish one INR figure and it is the one that binds; the USD and EUR amounts are that same number converted on the day of your quote.
Compliance
Scoped per engagement. Talk to us for pricing.
Compliance as a Service
SOC 2 Type 2 & ISO 27001 internal audit prep: gap assessment, control mapping, and policy documentation. DPDP Act and CERT-In readiness for Indian operations. Pairs naturally with pentest evidence.
Scoped per engagement
Pricing FAQ
What is the difference between the Startup and Growth pentest plans?
The Startup plan covers 1 scope in 5 business days with a technical + executive report, 6 hours of founder-led consulting, and 1 free retest. The Growth plan covers 2 scopes in 10 business days and adds systematic OWASP WSTG v4.2 test-case coverage, SOC 2 + ISO 27001 compliance mapping, real-world attack simulation beyond OWASP Top 10, and 12 hours of consulting. Both plans include 1 free retest within one month. Choose Growth if you have a compliance deadline or an enterprise deal in the pipeline.
How long does the full engagement take, including retests?
Engagement duration (testing + v1.0 report) depends on plan and scope count: 5 business days for Startup (1 scope), 10 business days for Growth (2 scopes). Each additional scope adds 5 business days, so 3 scopes is 15 and 4 scopes is 20. If you need it sooner, ask us about testing several scopes at the same time. Business days are Monday to Friday; the weekend is our quality buffer and is not counted against the timeline. After v1.0 ships, the retest is scheduled when your team has finished the fixes. Earliest start: as soon as you are ready. Latest start: one month after v1.0 (this is the upper bound on when retest can begin, not a mandatory wait). Retest itself takes 1 to 3 business days, then v2.0 closes the engagement. Faster remediation on your side closes the engagement faster.
What is the difference between parallel and sequential testing?
Sequential is the default: one scope after another, 5 business days each. Startup is 5 business days for 1 scope and 10 for 2, with no parallel option. Growth is 10 business days for 2 scopes, 15 with one added scope, and 20 with two added scopes. Parallel applies from the 4th scope only, on request: we run the 3rd and 4th together, which brings a 4-scope engagement to 15 business days. It changes the schedule, never the price, and it is confirmed per engagement rather than guaranteed. At 3 scopes parallel changes nothing, so 15 business days is the honest number either way. If you are working to a tighter deadline, tell us and we will try to meet it, subject to our availability and the people we can put on it. Indian public holidays fall outside the business-day count. Large estates of 5 or more scopes get a custom scoping proposal.
Can I add more scopes after the engagement starts?
Yes, you can add scopes during scoping or after the engagement starts. Startup Plan caps at 2 scopes total (1 base + 1 additional at INR 44,999, with +5 business days = 10 business days total for 2 scopes). Growth Plan has no scope limit (each additional scope at INR 74,999); each scope adds 5 business days, so 3 scopes is 15 and 4 is 20, and you can ask us about testing several at the same time if you need it sooner. Large estates of 5+ scopes get a custom scoping proposal. Adding scopes during the engagement is possible but extends the timeline and requires a scope confirmation note in writing before testing begins on the new scope.
What counts as one scope?
One scope is one application surface tested as a complete unit. Examples: a web application is 1 scope, a REST API is 1 scope, an Android app is 1 scope, an iOS app is 1 scope. Web app + API = 2 scopes (separate surfaces, different attack vectors). iOS + Android = 2 scopes (separate platforms, separate code, separate runtime). A microservices backend with 3 distinct services may count as 1 scope or 3 scopes depending on whether they share authentication and architecture. We confirm scope count during scoping before final pricing. If you are unsure, send us your architecture and we will tell you what we would count as a single scope.
What is real-world attack simulation, and why does Growth include it?
Real-world attack simulation tests beyond the OWASP Top 10 baseline by simulating how a determined attacker would actually compromise your application. This includes chained exploits (using one finding to amplify another), privilege escalation (moving from a regular user to admin), and lateral movement (accessing systems outside the initial entry point). We also test business logic flaws specific to your application such as payment race conditions, IDOR in financial flows, and authorization gaps in tenant-isolated data. Growth Plan includes this because compliance buyers and enterprise customers expect their pentest to demonstrate not just OWASP coverage but that the application can withstand a focused attacker. Startup Plan covers OWASP Top 10 + PTES standard methodology, sufficient for buyers without active enterprise or audit pressure.
What does the SOC 2 + ISO 27001 compliance mapping include?
Each finding in the Growth Plan report is mapped to specific control requirements in two frameworks. SOC 2 mapping covers the Trust Services Criteria 2017, typically CC6.1 (logical access security), CC6.3 (role-based access), CC6.6 (protection against external threats), CC7.2 (monitoring), and CC8.1 (change management) for a typical web or API engagement. Separately from the per-finding mapping, the engagement itself is evidence for CC4.1, which calls for ongoing and/or separate evaluations: an external test by a party with no role in building or running the systems is the separate half of that criterion. ISO 27001 mapping covers Annex A controls from the 2022 revision, typically A.5.15 and A.8.3 (access control), A.8.20 to A.8.23 (network and communications security), A.8.25 to A.8.29 (secure development and testing), and A.8.15 (logging). The compliance evidence package is delivered as a separate section of the report and can be handed to your auditor as direct evidence of penetration testing, findings, and remediation. Useful for SOC 2 Type 1, SOC 2 Type 2, and ISO 27001 internal or external audits.
How many consulting hours are included with each pentest?
Startup Plan: 6 hours of founder-led security consulting. Growth Plan: 12 hours of founder-led security consulting. Use these hours during the engagement (scope clarification, remediation pairing) or anytime in the 6-month or 12-month consulting window (architecture review, compliance prep, threat modeling, incident readiness). Both founders are available. Hours do not roll over but typically get fully used.
How much does penetration testing cost in India?
Cybersecify offers penetration testing starting at INR 74,999 for a single scope (AI, web app, API, Android, iOS, desktop, cloud, IoT, internal network, or external network) with delivery in 5 business days. The Startup Plan includes 6 consulting hours and 1 free retest. The Growth Plan at INR 1,79,999 includes 2 scopes, 10 business days, SOC 2 + ISO 27001 compliance evidence, real-world attack simulation, 12 consulting hours, and 1 free retest. All prices exclude taxes.
Can I see a sample report before buying?
Yes. We publish a full redacted sample showing the exact structure, finding format, compliance mapping, and methodology you receive. You can view it online or download it as a PDF. View sample report →
Why do you ask for 50% upfront?
Nothing is invoiced until the scope is agreed in writing. Before a proforma invoice exists you have had a response to your inquiry, a formal quote, a mutual NDA signed by both parties, and a SOW signed by an authorised signatory on both sides setting out the exact scopes you picked, the timeline and the deliverables. You are approving a document you have read, not a description on a web page. The advance confirms the testing slot, which is capped at six pentests a month because both founders work every engagement. The remaining 50% falls due after the v1.0 report is delivered, so the findings are in your hands before we are paid in full. Both sides are exposed for half, and neither is asked to extend trust the other has not already matched.
Still have questions?
Book a 30-min call with Ashok. We'll talk through your scope, your timeline, and which plan actually fits. No sales pressure.
Recommended Reading
Free Pentest Vendor Comparison Checklist
12-section scorecard to evaluate pentest vendors on the same criteria. Use as a checklist or paste into a formal RFP.
How Much Does Pentesting Cost in India?
What fair pricing looks like, what drives cost up or down, and what to watch for in a pentest quote.
How to Scope Your First Penetration Test
Avoid overspending on a pentest that tests the wrong thing. A founder-friendly scoping guide.
What a Good Pentest Report Looks Like
What separates a report worth paying for from one that wastes your money.