Biaya & Harga

Penetration Testing Cost in Indonesia: Rp5 Million to Rp75 Million, and What Moves the Number

TAB
Tim Editorial TAB
5 min read
Two inspectors in safety vests and hard hats reviewing a checklist on a clipboard, standing in for a security audit team at work

Penetration testing cost in Indonesia runs from about Rp5 million to Rp75 million. The spread is that wide because three very different services are sold under one name: an automated scan from Rp5 million, manual testing at Rp15–50 million per application, and certification preparation priced by the certification body itself. What moves the number is not how big your company is — it is how many assets are in scope and how deeply each one gets tested. Every figure below was checked against Indonesian providers on 2 October 2026.

Two quotes for the same request can differ fivefold with nobody being dishonest. One is selling a two-day scan. The other is selling a human tester for two weeks. Both documents are titled "audit report".

Three different things sold under one name

Before you compare prices, make sure you are comparing the same product.

Three kinds of security check and what each costs

TypeHow it worksPrice rangeRight for
Vulnerability assessment (VA)Automated scanning, output is a list of findings ranked by severityRp5–15 millionRoutine checks, or a system that has never been looked at
Penetration testA human tester tries to break in the way a real attacker wouldRp15–50 million per applicationSystems holding money, customer data, or transactions
ISO 27001 readiness workFixing processes and documents, then an audit by a certification bodyQuoted by the certification body, not a market rateCompanies whose large clients or regulator ask for the certificate

VA and pentest ranges come from Indonesian provider pricing guides, checked 2 October 2026. The certification row is deliberately blank: that figure is quoted per scope by the certification body, so there is no market price to cite.

The practical difference is the human. A scanner finds outdated software versions and open configurations; it will not find that user A can open user B’s invoice by changing one digit in the page address. That only surfaces when somebody actually tries it. If your system has never been through the first stage, start there — it is the order we recommend before anyone talks about large numbers, including to our own cyber security clients.

Penetration testing cost by asset tested

Vendors price per asset, not per company. These five lines are what usually appear on a quote:

Price range per asset type

Asset testedPrice rangeWhat moves the number
Automated scan only, any number of assetsRp5–15 millionHow many targets get scanned
Web application (order portal, internal system)Rp10–50 millionNumber of user roles, number of endpoints, third-party integrations
Android or iOS mobile appRp15–45 millionOne platform or two, how many APIs it calls
Network and serversRp10–75 millionHow many IP addresses and servers are in scope
Several assets in one engagementRp75–100 million and upLarge scope, repeat testing, separate reports per system

The two pricing guides checked on 2 October 2026 give different ranges for the same asset — a web application is Rp10–40 million in one and Rp15–50 million in the other. This table uses the widest span across both, so read these as outer bounds, not rates.

One more factor rarely makes it into any table: the testers’ certifications. A quote from an OSCP- or CISSP-certified team costs more, and that is fair — what you buy in a pentest is a person’s hours, not a software licence.

What almost nobody budgets for is the repair work, which appears on no quote at all. The report ranks findings as critical, high, medium and low, and realistically only the top two tiers have to be fixed that same week. The rest joins your own team’s backlog. So set aside developer hours alongside the vendor fee.

How to size your own budget

Four steps, all of which you can do yourself before contacting any vendor:

  1. Count the assets. List everything reachable from the internet: website, order portal, mobile app, VPN, CCTV cameras, mail server. One line each. Most companies find more than they expected.
  2. Mark the ones holding money or customer data. Only the marked assets are worth manual testing in year one. A scan is enough for the rest.
  3. Pick the access level. Black box means the tester starts with no information at all and costs less. Grey box gives them one ordinary user account, costs a little more, and is almost always more useful — most of the damage happens after somebody is already inside, not before.
  4. Add it up. One scanning package covering every asset, plus one manual test on the riskiest marked asset.

Here is how that works out in practice. A distributor in Candi, Sidoarjo has nine assets: a reseller order portal, an Android app for the sales team, a profile site, and six office IP addresses. Only the order portal gets marked, because that is where special pricing and receivables live. Scanning all nine costs Rp9 million; a grey-box manual test on the portal alone costs Rp22 million. Year-one budget: Rp31 million — not the Rp75 million that appears when everything is tested manually at once.

Four lines that go missing from security audit quotes
Is the retest after remediation included, or billed separately? Who does the fixing — the testing team or yours? Does the report include step-by-step evidence, or just the names of the findings? And is there a walkthrough session for your technical team? A Rp18 million quote without a retest often ends up costing more than a Rp25 million one that includes it, because fixing without retesting means you never learn whether the hole actually closed.

Who is actually required to do this, and who is not

Commercial banks are. POJK 11/POJK.03/2022 requires scenario-based cyber security testing at least once a year, with the technical detail set out in SEOJK 29/SEOJK.03/2022. Outside financial services there is no general rule naming a figure or a frequency — so if a vendor tells you it is "mandatory every year", ask which article says so.

Two things are getting closer, and both deserve a line in next year’s budget. A company already registered as a PSE has signed a declaration that it performs electronic system fitness testing; that declaration only means something if a check was actually done. And PP 33/2026, the implementing regulation for Indonesia’s personal data protection law, was promulgated on 16 July 2026 and takes effect on 16 January 2027. Its 225 articles turn the duty to secure personal data into something operational, with mechanisms, documentation and supervision attached.

The third driver is not regulation at all, and it is the one we see most often around Sidoarjo: a corporate or state-owned client asks for a test report before signing. The request rarely names a standard — often it is simply evidence that an outside party has looked at the system. For a supplier chasing a large contract, Rp9 million for a scan is a cost of entry rather than a security expense.

In our experience, a company with one website and one internal application should not start by buying a Rp40 million pentest. Begin with the Rp5–15 million scan, fix what comes out, then test manually the following year. A thick report whose findings are never fixed does not make a system safer — it only proves you knew. The weakness of that advice is real, though: automated scanning is blind to business-logic flaws, and that is exactly where the largest losses tend to sit. If your system handles payments, skip the first stage.

Fixing findings is nearly always the job of the team that wrote the system, not the team that tested it. If an outside vendor built yours, make sure the contract says who carries the cost of closing a vulnerability — it is one of the things we go through with software development clients at contract stage, long before there is a report to act on.

Not sure which asset to test first? Drawing up that list with an IT consultant in Sidoarjo usually takes one session, and we do not charge for the first conversation.

What does a security audit cost for a simple company website?+
If the site is only a profile, an address and a gallery, with no login and no payments, an automated scan at Rp5–15 million is enough for a first check. A manual pentest at Rp15–50 million only becomes worth it once there are user accounts, a cart, or stored customer data. Starting cheap is not half-hearted — the findings from a scan usually take several weeks to work through anyway.
How often should penetration testing be repeated?+
Commercial banks are bound by POJK 11/POJK.03/2022: scenario-based testing at least once a year. Outside that there is no general obligation, and the sensible trigger is an event rather than a date — after a major feature release, after moving servers or hosting providers, and after fixing earlier findings. That last one is the retest, and its price is worth asking about early, because it often sits outside the first quote.
Is it safe to pick the cheapest quote?+
Yes, as long as you know what you are buying. A Rp6 million quote is almost certainly an automated scan, which is legitimate — what is not legitimate is selling it as a penetration test. Ask for three things before deciding: a redacted sample report, the names and certifications of the people who will test, and a clear answer on whether retesting after remediation is included. If all three come back without hesitation, a low price is not a problem.
TAB
Tim Editorial TAB - CV Trengginas Alfath Berkarya

IT consultants helping Indonesian businesses choose and manage cloud infrastructure, develop software, and keep IT operations running smoothly. Based in Sidoarjo, serving clients across East Java and Indonesia.