Penetration Testing Cost in Indonesia: Rp5 Million to Rp75 Million, and What Moves the Number

Penetration testing cost in Indonesia runs from about Rp5 million to Rp75 million. The spread is that wide because three very different services are sold under one name: an automated scan from Rp5 million, manual testing at Rp15–50 million per application, and certification preparation priced by the certification body itself. What moves the number is not how big your company is — it is how many assets are in scope and how deeply each one gets tested. Every figure below was checked against Indonesian providers on 2 October 2026.
Two quotes for the same request can differ fivefold with nobody being dishonest. One is selling a two-day scan. The other is selling a human tester for two weeks. Both documents are titled "audit report".
Three different things sold under one name
Before you compare prices, make sure you are comparing the same product.
Three kinds of security check and what each costs
| Type | How it works | Price range | Right for |
|---|---|---|---|
| Vulnerability assessment (VA) | Automated scanning, output is a list of findings ranked by severity | Rp5–15 million | Routine checks, or a system that has never been looked at |
| Penetration test | A human tester tries to break in the way a real attacker would | Rp15–50 million per application | Systems holding money, customer data, or transactions |
| ISO 27001 readiness work | Fixing processes and documents, then an audit by a certification body | Quoted by the certification body, not a market rate | Companies whose large clients or regulator ask for the certificate |
VA and pentest ranges come from Indonesian provider pricing guides, checked 2 October 2026. The certification row is deliberately blank: that figure is quoted per scope by the certification body, so there is no market price to cite.
The practical difference is the human. A scanner finds outdated software versions and open configurations; it will not find that user A can open user B’s invoice by changing one digit in the page address. That only surfaces when somebody actually tries it. If your system has never been through the first stage, start there — it is the order we recommend before anyone talks about large numbers, including to our own cyber security clients.
Penetration testing cost by asset tested
Vendors price per asset, not per company. These five lines are what usually appear on a quote:
Price range per asset type
| Asset tested | Price range | What moves the number |
|---|---|---|
| Automated scan only, any number of assets | Rp5–15 million | How many targets get scanned |
| Web application (order portal, internal system) | Rp10–50 million | Number of user roles, number of endpoints, third-party integrations |
| Android or iOS mobile app | Rp15–45 million | One platform or two, how many APIs it calls |
| Network and servers | Rp10–75 million | How many IP addresses and servers are in scope |
| Several assets in one engagement | Rp75–100 million and up | Large scope, repeat testing, separate reports per system |
The two pricing guides checked on 2 October 2026 give different ranges for the same asset — a web application is Rp10–40 million in one and Rp15–50 million in the other. This table uses the widest span across both, so read these as outer bounds, not rates.
One more factor rarely makes it into any table: the testers’ certifications. A quote from an OSCP- or CISSP-certified team costs more, and that is fair — what you buy in a pentest is a person’s hours, not a software licence.
What almost nobody budgets for is the repair work, which appears on no quote at all. The report ranks findings as critical, high, medium and low, and realistically only the top two tiers have to be fixed that same week. The rest joins your own team’s backlog. So set aside developer hours alongside the vendor fee.
How to size your own budget
Four steps, all of which you can do yourself before contacting any vendor:
- Count the assets. List everything reachable from the internet: website, order portal, mobile app, VPN, CCTV cameras, mail server. One line each. Most companies find more than they expected.
- Mark the ones holding money or customer data. Only the marked assets are worth manual testing in year one. A scan is enough for the rest.
- Pick the access level. Black box means the tester starts with no information at all and costs less. Grey box gives them one ordinary user account, costs a little more, and is almost always more useful — most of the damage happens after somebody is already inside, not before.
- Add it up. One scanning package covering every asset, plus one manual test on the riskiest marked asset.
Here is how that works out in practice. A distributor in Candi, Sidoarjo has nine assets: a reseller order portal, an Android app for the sales team, a profile site, and six office IP addresses. Only the order portal gets marked, because that is where special pricing and receivables live. Scanning all nine costs Rp9 million; a grey-box manual test on the portal alone costs Rp22 million. Year-one budget: Rp31 million — not the Rp75 million that appears when everything is tested manually at once.
Who is actually required to do this, and who is not
Commercial banks are. POJK 11/POJK.03/2022 requires scenario-based cyber security testing at least once a year, with the technical detail set out in SEOJK 29/SEOJK.03/2022. Outside financial services there is no general rule naming a figure or a frequency — so if a vendor tells you it is "mandatory every year", ask which article says so.
Two things are getting closer, and both deserve a line in next year’s budget. A company already registered as a PSE has signed a declaration that it performs electronic system fitness testing; that declaration only means something if a check was actually done. And PP 33/2026, the implementing regulation for Indonesia’s personal data protection law, was promulgated on 16 July 2026 and takes effect on 16 January 2027. Its 225 articles turn the duty to secure personal data into something operational, with mechanisms, documentation and supervision attached.
The third driver is not regulation at all, and it is the one we see most often around Sidoarjo: a corporate or state-owned client asks for a test report before signing. The request rarely names a standard — often it is simply evidence that an outside party has looked at the system. For a supplier chasing a large contract, Rp9 million for a scan is a cost of entry rather than a security expense.
In our experience, a company with one website and one internal application should not start by buying a Rp40 million pentest. Begin with the Rp5–15 million scan, fix what comes out, then test manually the following year. A thick report whose findings are never fixed does not make a system safer — it only proves you knew. The weakness of that advice is real, though: automated scanning is blind to business-logic flaws, and that is exactly where the largest losses tend to sit. If your system handles payments, skip the first stage.
Fixing findings is nearly always the job of the team that wrote the system, not the team that tested it. If an outside vendor built yours, make sure the contract says who carries the cost of closing a vulnerability — it is one of the things we go through with software development clients at contract stage, long before there is a report to act on.
Not sure which asset to test first? Drawing up that list with an IT consultant in Sidoarjo usually takes one session, and we do not charge for the first conversation.
What does a security audit cost for a simple company website?+
How often should penetration testing be repeated?+
Is it safe to pick the cheapest quote?+
IT consultants helping Indonesian businesses choose and manage cloud infrastructure, develop software, and keep IT operations running smoothly. Based in Sidoarjo, serving clients across East Java and Indonesia.
Related Articles

PSE Registration in Indonesia: Which Company Websites Must Register, and How
PSE registration in Indonesia runs through OSS and costs nothing: the six criteria, the data to prepare, the four stages, and when your site is exempt.

When to Stop Using Spreadsheets: Three Numbers That Decide It
When to stop using spreadsheets: the three numbers that decide it, what staying on Excel costs per year, and which process to move first.

How to Register as a Government Supplier in Indonesia: Two Doors People Keep Confusing
How to register as a government supplier in Indonesia: the two separate account systems, the documents you need, and the steps you cannot redo.