The honest answer is that the price follows the scope. This page explains what determines VAPT cost, why we quote per engagement, and exactly what to send us so your quote is accurate the first time.
If a vendor gives you a firm price before asking a single question about your environment, one of two things is happening. Either they are guessing, and the number will move once they see what you actually run, or they already know the work will be an automated scan dressed up as a penetration test, in which case the price can stay fixed because the effort never changes. Neither is what you are trying to buy.
ClarenSec prices each engagement on its own terms. We do not work off a rate card, because no rate card survives contact with a real environment. A single web application with one user role is a different job from an internet banking platform with an API with a thousand endpoints behind it, and a mobile app on both stores. Pricing them the same would shortchange one client and overcharge the other.
So instead of a figure, this page gives you the thing a stated price cannot: a clear view of the penetration testing cost factors that move a quote up or down, and the exact information that lets us give you an accurate one quickly.
The largest single driver. How many applications, APIs and endpoints, IP addresses, user roles and mobile apps are in scope decides how many tester-days the work needs.
A scan reads output from a tool. Manual exploitation means a penetration tester will chain findings into real attack paths, and that expertise is what you are paying for.
Web, API, mobile, internal network and cloud each demand different skills and tooling. A mixed estate takes longer to test properly than any one surface alone.
Two of these deserve emphasis. Scope is where most quotes go wrong, usually because the client's asset list was incomplete at the point of quoting. And depth is where most cheap quotes hide: the price is low because the work is shallow. Our testing methodology requires every finding to be verified manually with proof of exploitation.
A price list only works when the product is identical every time. Scanner licences are identical every time. Real testing is not: the effort depends on what sits behind your login page, and nobody knows that before scoping. When a vendor can publish a flat price for "a penetration test", the safest reading is that the deliverable is a scan report, because a scan is the only version of the work whose cost is genuinely fixed.
There is a second problem. A fixed price forces the vendor to protect their margin when the environment turns out larger than assumed, and the easiest way to do that is to quietly cut depth. The scope stays on paper; the hours do not. You will not see the difference in the proposal. You will see it in the report.
The engagements we deliver across banking, capital markets, fintech, healthcare, government and telecom vary too much for a rate card to be honest. That is the whole reason a full VAPT engagement from ClarenSec starts with a scoping conversation rather than a price.
The low bid runs an automated tool, exports the findings, reformats them under a new logo and calls the result a penetration test. The tool did in hours what senior testers would have spent days on, and the price reflects that. What the tool cannot do is log in as one customer and read another customer's data, abuse a transfer workflow, or chain a modest finding into domain compromise. Those are the findings that matter, and they are the ones the cheap report never contains.
To be fair to scans: they have a legitimate place as a hygiene check between tests, and we will say so when that is what your situation calls for. A scan only becomes a problem when it is sold under a penetration test's name to a buyer who needed the real thing.
The speed and accuracy of a quote depend on what arrives in the first email. You do not need a formal document; a plain list covering the points below lets our senior penetration testers size the engagement properly, and most quotes go out within a few business days of a complete scoping call.
If your driver is the exchange's half-yearly requirement, our NGX VAPT assessment page covers what Trading License Holders should scope in. For everyone else, the list above is enough to start, and we will fill gaps on the scoping call rather than pad the quote to cover unknowns.
Because a published price would be wrong for almost every client. A small web application and a bank's full external estate are different engagements, and quoting them from the same rate card means one client overpays and the other gets shallow testing. We scope first, then quote, so the price reflects the actual work.
Scope is the biggest factor: how many applications, APIs, hosts and mobile apps are in play. After that comes depth (manual exploitation takes senior tester time that a scan or a junior tester does not), environment complexity, testing window constraints such as out-of-hours work on production systems, and the reporting and compliance requirements attached to the engagement.
A scan has its place as a hygiene check between tests, and we say so plainly. It is not enough where a client, standard or counterparty expects a penetration test, and it will not find business logic flaws, chained attack paths or access control failures. If a scan genuinely fits your need, we will tell you rather than sell you a test.
Yes. A retest of fixed findings is part of every ClarenSec engagement, so the quote you receive already covers verifying your remediation and updating the report to show what was closed.
Send us your asset list, and we will come back with a quote built on your actual scope.