There is no single universal price that applies to every CERT-In-related security audit engagement. The final quotation depends on the number of applications, APIs and mobile apps in scope; the size of the network and cloud footprint; whether source-code review is required; how deep the manual testing goes; and what remediation and re-testing support is included.
A low quotation does not automatically mean better value, and a higher quotation does not automatically mean better quality. What matters is whether the scope and deliverables of two quotations are actually comparable — which is what the rest of this guide helps you check.
How Much Does a CERT-In Audit Cost?
It's a fair question, and also one that can't be answered honestly with a single number. Two organisations asking for a "CERT-In audit" quotation can be describing very different pieces of work — one might mean testing three internal APIs, the other might mean a full external and internal VAPT across a banking app, a mobile app and a cloud environment. Naturally, they will not receive the same figure.
Rather than quote a price that would be misleading outside its original context, it's more useful to understand the components that make up any quotation. In practice, five things drive the final number:
We haven't published a fixed rate card here on purpose — Bharat Cyber Solutions doesn't set CERT-In's regulatory requirements, and a number that fit one engagement could be badly misleading for another. What we can do is scope your specific environment and give you a quotation built around it; the sections below explain how to prepare for that conversation and how to judge the quotation once you have it.
Why Is There No Single CERT-In Audit Price?
Security audit engagements differ in scale far more than most other professional services. Consider two hypothetical organisations both requesting a security assessment tied to CERT-In requirements:
Company A
- 1 web application
- 5 APIs
- Small on-premise / single-cloud infrastructure
- No source-code review required
Company B
- 5 web applications
- 50+ APIs
- 2 mobile applications (Android & iOS)
- Multiple cloud workloads, internal + external network, source-code review
"Illustrative Scope Comparison" — these are hypothetical examples to explain how scope affects cost, not official pricing tiers or a quote for any specific engagement.
These two engagements involve a very different amount of testing effort, reporting and re-testing coordination. Expecting them to carry the same quotation would mean one of the two auditors is either under-scoping the work or over-charging for it. This is the core reason CERT-In-related audit pricing is quoted per engagement rather than off a public list.
Top Factors That Affect CERT-In Audit Cost
These are the variables that most commonly move a quotation up or down. Knowing them in advance makes it much easier to read — and compare — the quotations you receive.
Number of Applications
Each additional web application adds its own attack surface, user flows and business logic to test — effort scales with the count, not just the total line-of-code size.
API Scope
The number of API endpoints, their authentication models (API keys, OAuth, JWT) and whether documentation exists all affect how long API testing takes.
Mobile Applications
Android and iOS builds are typically assessed separately, and each platform can introduce its own binary, storage and API-communication checks.
Network Infrastructure
The count of external and internal IP addresses, network devices and the degree of network segmentation all influence network VAPT effort.
Cloud Environment
Cloud accounts, workloads, configuration surface area and the scope of IAM (identity and access) review add a distinct assessment stream.
Testing Depth
Automated assessment, manual validation, business-logic testing, configuration review and full penetration testing represent increasing levels of effort and assurance.
Number of User Roles
More roles mean more authorization paths to test for privilege-escalation and access-control issues — role complexity is its own cost driver.
Source-Code Review
Manual or assisted code review is a technically deeper exercise than black-box testing and is typically scoped and priced separately.
Compliance Requirements
Where a regulator or contract specifies particular documentation or evidence formats, this can add to the reporting and assessment scope.
Remediation & Re-testing
Support during remediation, and the number of re-test cycles included, are commonly the most variable line item between two quotations.
Not sure how these apply to your environment?
Share your scope and we'll help you understand what to expect before you request formal quotations.
CERT-In Audit Cost Breakdown
The table below explains what each component of a typical engagement covers, how much it generally influences the total cost, and what to ask your auditor about it. The "Cost Impact" column is a qualitative guide to relative effort — not a rupee figure.
| Component | What It Covers | Cost Impact | Questions to Ask |
|---|---|---|---|
| Scoping | Defining assets, environments and testing boundaries before work begins | Low | Is scoping a paid step or bundled into the quotation? |
| Web App Testing | Vulnerability assessment and manual testing of each in-scope web application | Scope-dependent | Is pricing per-application or per-hour? |
| API Testing | Testing API endpoints for authentication, authorization and input-handling issues | Medium | Is the number of endpoints or the number of API groups the pricing unit? |
| Mobile App Testing | Android/iOS binary, storage and communication-layer assessment | Medium | Are both platforms quoted, or only one? |
| Network VAPT | External and internal IP, device and segmentation testing | Scope-dependent | Is pricing per IP, per IP range, or a flat network fee? |
| Cloud Assessment | Cloud configuration, IAM and workload review | Medium | Which cloud accounts and services are actually in scope? |
| Source-Code Review | Manual or assisted review of application source code | High | Is this quoted per repository, per line count, or per day? |
| Reporting | Vulnerability report with risk classification and evidence | Low | Is the report format aligned with what your regulator or client expects? |
| Remediation Support | Guidance to development/infra teams while fixing findings | Scope-dependent | Is this advisory only, or does it include hands-on validation? |
| Re-testing | Verifying that reported vulnerabilities have been fixed | Medium | How many re-test cycles are included before extra charges apply? |
| Final Documentation | Closure report and any compliance-specific documentation | Low | Is closure documentation issued automatically once re-testing passes? |
These are explanatory categories to help you read a quotation, not an official CERT-In price list.
What Is Usually Included in a Security Audit Quote?
Depending on the engagement, a quotation may include some or all of the following. Ask the provider whether each of these is actually part of the number they've given you:
- Scope definition and asset inventory review
- Vulnerability assessment across in-scope assets
- Penetration testing and manual validation
- Risk classification of findings
- Technical evidence supporting each finding
- Remediation recommendations and final report
- Re-testing and a closure report
- Applicable compliance documentation
Not every provider includes all of these as standard — some treat re-testing or remediation support as an add-on. Ask explicitly rather than assuming.
What May Be Charged Separately?
These may be priced separately depending on the engagement — they are not universally excluded, but they are common places where a quotation's scope quietly narrows:
- Applications or APIs added to scope after the quotation is finalised
- Additional IP ranges beyond what was originally scoped
- Mobile applications added later in the engagement
- Source-code review, where it wasn't part of the original scope
- Cloud configuration assessment beyond the agreed accounts
- Additional testing environments (e.g. staging in addition to production)
- Remediation consulting beyond written recommendations
- Multiple re-test cycles beyond what's included
- Urgent or expedited assessment timelines
- Expanded reporting requirements for a specific regulator or client
CERT-In Audit vs VAPT Pricing
These terms get used loosely, and that's part of why quotations can look inconsistent. They overlap but are not automatically interchangeable — a vulnerability assessment alone does not necessarily satisfy every requirement that a full security audit might.
| Service | Primary Purpose | Typical Scope | Manual Testing | Reporting | Re-testing | Pricing Model |
|---|---|---|---|---|---|---|
| Vulnerability Assessment | Identify known vulnerabilities | Automated scan of assets | Limited | Vulnerability list | Not always included | Per asset / flat |
| Penetration Testing | Exploit and validate weaknesses | Targeted, scenario-based | Extensive | Detailed findings + evidence | Usually included | Per engagement |
| Security Audit | Broader review of controls and posture | Applications, network, policies | Varies | Comprehensive audit report | Depends on scope | Per engagement |
| CERT-In-related Assessment | Meet CERT-In or sectoral regulatory expectations | Defined by applicable requirement | Varies | Compliance-aligned report | Depends on requirement | Scope-dependent |
If a specific regulatory outcome is required — for example a report accepted under a particular framework — confirm with your auditor and, where relevant, your regulator or compliance counsel that the service being quoted actually satisfies that requirement, rather than assuming any VAPT report is interchangeable with an audit report.
How to Compare Two CERT-In Audit Quotations
This is where most buyers go wrong — comparing the final number before comparing what it actually buys. Use this framework to line up two or more quotations side by side.
Scope — which assets, environments and platforms are named explicitly?
Number of assets — how many apps, APIs, IPs and cloud accounts are counted?
Testing methodology — automated, manual, or a blend, and to what depth?
Manual testing coverage — what proportion of the assessment is manual?
Business logic testing — is workflow-specific abuse-case testing included?
API testing — endpoint count and authentication models covered?
Network testing — external only, or internal too?
Cloud assessment — which providers and services are in scope?
Reporting depth — evidence, risk ratings and remediation guidance included?
Remediation support — advisory only, or hands-on validation?
Re-testing terms — how many cycles, and within what timeframe?
Timeline — start date, duration and delivery milestones?
Auditor requirements — does your context require an empanelled auditor?
Confidentiality / NDA — is a mutual NDA part of the engagement terms?
Deliverables — exact list of reports and documents you'll receive?
Taxes & commercial terms — is GST included, and what are the payment milestones?
Questions to Ask Before Accepting a CERT-In Audit Quote
Work through this list before you sign off on any quotation. It's interactive — check off what you've confirmed as you go.
What Information Should You Provide for an Accurate Quote?
The more of this you can prepare up front, the more accurate — and the less likely to change later — your quotation will be.
Applications
- Application names and URLs
- Environments to be tested (production, staging, UAT)
- Number of user roles per application
APIs
- Total API count
- Existing API documentation (Swagger/OpenAPI, Postman collections, etc.)
- Authentication mechanism used (API key, OAuth, JWT, etc.)
Mobile
- Platforms in scope — Android, iOS, or both
- Application version(s) to be tested
Network
- Number of external-facing IP addresses
- Internal IP ranges to be covered
- Key network devices in scope
Cloud
- Cloud provider(s) — AWS, Azure, GCP, or others
- Number of accounts/workloads in scope
- Specific services or configurations relevant to the assessment
Security
- Previous VAPT or audit reports, if available
- Known vulnerabilities not yet remediated
- Current remediation status of past findings
Compliance
- Applicable regulator, if any (CERT-In, RBI, SEBI, etc.)
- Applicable framework or standard
- Documentation format required for submission
Does a Cheaper Audit Quote Mean Better Value?
Not necessarily. The cheapest quotation on the table may not provide the same scope or testing depth as a more expensive one — and a higher number doesn't guarantee thoroughness either. The only way to know is to compare deliverables, not just price.
Cheapest headline number
Often reflects a narrower scope, lighter testing depth, or fewer re-test cycles — not necessarily inefficiency.
Fewer assets or shallower testing
A quotation can look competitive simply because it covers less than a competing quotation — check the asset count and methodology, not just the price.
Scope, depth and price aligned
The quotation that matches your actual risk and compliance needs at a price that reflects the real effort involved — this is what you're comparing for.
In practice: normalise every quotation to the same scope before you compare the number. A quotation that's 20% cheaper but covers half the APIs isn't a better deal — it's a different, smaller engagement.
How to Reduce Audit Cost Without Reducing Security Quality
There are real ways to bring the cost of an engagement down without cutting the testing that actually matters:
Finalise scope before quotation
Changing scope mid-engagement is one of the biggest sources of unplanned cost.
Consolidate testing requirements
Bundling related assessments into one engagement avoids duplicated setup effort.
Prepare documentation in advance
API docs, architecture diagrams and asset inventories save auditor discovery time.
Provide test credentials early
Delays in access provisioning often extend timelines and cost.
Prepare a staging/UAT environment
A stable test environment reduces back-and-forth during active testing.
Maintain an accurate asset inventory
Unknown or undocumented assets are a common cause of scope disputes.
Fix known vulnerabilities beforehand
Resolving known issues ahead of time reduces re-testing rounds later.
Coordinate network whitelisting early
Firewall or WAF blocks are a frequent cause of wasted testing time.
Avoid reducing testing scope or depth purely to cut cost — the recommendations above save time and coordination effort, not the assessment that actually protects you.
When Should You Request a CERT-In Audit Quote?
Ideally, define these before you approach any auditor for pricing: scope, assets, applicable regulatory requirements, expected deliverables, target timeline, and re-testing expectations. That preparation is what turns a rough estimate into an accurate, comparable quotation.
Define Scope
Decide which applications, APIs, infrastructure and environments need to be assessed.
Identify Requirements
Confirm which regulator or contract is driving the need for this assessment, if any.
Prepare Asset Inventory
List every application, API, IP range and cloud account that falls inside the scope.
Request Quotations
Share the same scope and requirements with each auditor so their quotes are comparable.
Compare Scope
Use the quotation comparison framework above before comparing final numbers.
Select Auditor/Provider
Choose based on scope match, methodology and deliverables — not price alone.
Begin Assessment
Kick off the engagement with agreed access, credentials and timelines in place.
CERT-In Audit Pricing FAQ
It depends on scope — the number of applications, APIs, IPs and cloud assets, plus testing depth and re-testing terms. There isn't a single figure that applies across engagements.
No. CERT-In does not publish or mandate a universal audit fee for engagements with empanelled auditors — pricing is set commercially between the organisation and the auditor based on scope.
Scope (applications, APIs, mobile apps, network, cloud), testing depth, complexity, deliverables required, and re-testing terms are the main drivers — see the factors section above for the full list.
Depending on the engagement, VAPT may be bundled into an audit quotation or scoped and priced as a separate line item. Ask your provider explicitly which applies.
Some quotations include a set number of re-test cycles; others price re-testing separately or per additional cycle. Confirm the exact number of cycles included before accepting a quote.
Generally yes — more endpoints and more complex authentication models increase the manual testing effort required, which is typically reflected in the price.
Mobile apps are usually scoped and priced separately from web applications, and Android and iOS builds may each be quoted individually.
Yes — the number of cloud accounts, workloads and the scope of configuration/IAM review all add to the assessment effort and therefore the price.
Use the 16-point quotation comparison framework in this guide — line up scope, methodology, reporting depth, remediation support and re-testing terms before comparing the final number.
Application and API details, mobile platforms, network IP ranges, cloud accounts, past VAPT/audit reports, and any applicable regulatory framework — see the preparation checklist above.
Conclusion
CERT-In-related audit pricing is primarily driven by scope, technical complexity, testing depth and deliverables — not a single published rate.
A professional buyer compares scope, methodology, testing depth, reporting, re-testing and auditor requirements alongside commercial terms, rather than comparing only the final number on the page.





