Amazon SP-API DPP Penetration Testing
Three situations bring people to this page, and all three have a date attached. Your annual renewal is coming up under the 365 day cycle. You are getting an app listed and cannot go live without the test. Or your app is already delisted and every week it stays down costs you.
What you need is a scope that matches what clause 2.7.2 actually asks for, a price that does not move after you commit, and a date you can hold someone to. All three are on this page, before you talk to us.
Four things about the DPP that get buyers oversold
These are from the policy text itself. Knowing them means nobody can sell you work Amazon never asked for, including us.
- The DPP contains no SOC 2 and no ISO 27001 requirement. Control mapping to those frameworks is useful for your own auditors and for enterprise customers, and we include it, but Amazon does not ask for it in a DPP submission.
- The stated encryption minimum at rest is AES 128 or RSA 2048, not AES 256. If a quote is priced around meeting AES 256 for the DPP, the premise is wrong.
- The report is evidence you hold, not evidence you file. There is no clause requiring you to upload it. Section 3 requires you to keep records and to certify compliance on written request, with a right to audit.
- There is no Amazon-issued DPP certificate and no approved assessor list. Any vendor implying otherwise is describing a programme that does not exist.
Full detail, including what the policy leaves open, is in our guide to the DPP pentest requirement.
What clause 2.7 actually asks for
Section 2 applies where a restricted role handles personally identifiable information, and it is section 2 that mandates the testing. Three clauses carry obligations, and all three have a document or a deadline attached.
| 2.7.1 | Vulnerability scanning at least every 30 days, and after significant network, application or infrastructure changes. The change-triggered half has no interval attached, so a fixed-cadence contract alone does not satisfy it. |
| 2.7.2 | A penetration test at least every 365 days, using an industry-recognized methodology, across four scope categories. This is the clause this page is about. |
| 2.7.3 | Critical findings remediated within 7 days, high within 30. A clock, which is why the retest matters as much as the test. |
Quoted from the Amazon Services Data Protection Policy. Full analysis, including what the policy does not require, is in our guide to the DPP pentest requirement.
The four categories, and what we scope against each
Each category is tested as its own scope, because the effort, the test cases and the threat surface differ in each. This is the part most quotes leave vague until after you have signed.
Network infrastructure
Perimeter enumeration, edge configuration, transport security, email authentication posture, and the internal boundaries the clause names.
Cloud environments
IAM and least privilege, encryption at rest against the policy minimum, environment separation, and logging and monitoring as audit evidence.
Application layer assets
Authentication, session handling, tenant authorisation, business logic, injection classes, and Login with Amazon token issuance, refresh, storage and rotation.
Other in-scope systems
Anything else that retrieves, stores or processes Amazon data, which in practice is usually a desktop or mobile client.
What a DPP engagement costs, before you talk to us
The plan is the Growth Pentest, which covers two scopes at INR 1,79,999, with each additional scope at INR 74,999. A DPP engagement is normally four scopes. Where the estate allows it to come to three, it does.
| Three scopes | INR 2,54,998 · 15 business days |
| Four scopes | INR 3,29,997 · 20 business days |
| Four scopes, third and fourth run together on request | INR 3,29,997 · 15 business days |
Prices exclude taxes. Scopes run sequentially at five business days each by default; running the third and fourth together is an option you request, not the default and not a guarantee. Estates of five or more scopes get a custom scoping proposal. Full terms on our pricing page.
What you receive
Three reports from one engagement
The web application and its API backend are tested as separate scopes and reported together, so a four scope engagement arrives as three documents: application layer, network, and cloud. Each carries reproduction steps, business impact, remediation guidance and severity.
Letter of Engagement
Evidences that a firm was engaged to perform the test, issued on our letterhead. This is the document that accompanies a submission.
Letter of Attestation
Signed by the lead tester after the retest, confirming what was tested and the state it ended in. Issued on the Growth plan.
A free retest, and a v2.0 report
Triggered once your fixes are in, and no later than one month from the v1.0 report. The retest produces a full v2.0 report with updated status columns and fresh per-finding evidence of the fixed state, not a status email.
The evidence set from a delivered engagement is published, covering the clause 2.7.2 scope categories. We send the PDFs on request rather than putting client deliverables on a download link. Request the SP-API evidence set.
The industry-recognized methodology, named
Clause 2.7.2 requires an industry-recognized methodology. A report that does not say which one it followed leaves a reviewer to take it on trust. Ours names the standard against each finding.
- Application layer: OWASP WSTG v4.2 and the OWASP API Security Top 10 2023, with findings carrying their OWASP Top 10:2025 category.
- Engagement overall: PTES, the Penetration Testing Execution Standard.
- Cloud: IAM and least privilege, encryption at rest against the policy minimum, environment separation, logging and monitoring as audit evidence.
- Network: perimeter enumeration, edge configuration, transport security, email authentication posture.
- Mobile, where in scope: OWASP MASVS.
Testing is manual exploitation by a named tester. Every engagement is led by Rathnakara GN (M.Sc Cyber Security, OSCP), with Ashok Kamat hands-on alongside him. You can see the standard of the deliverable before you buy: a real anonymized report and the engagement process.
Amazon SP-API DPP pentest questions
What does the Amazon SP-API Data Protection Policy require for penetration testing?
Clause 2.7.2 states that the Solution Provider must perform penetration testing at least every 365 days using an industry-recognized methodology, and it enumerates four scope categories: network infrastructure, cloud environments, application-layer assets, and other in-scope systems. It sits alongside 2.7.1, which requires vulnerability scanning at least every 30 days and scanning after significant network, application or infrastructure changes, and 2.7.3, which requires critical findings remediated within 7 days and high within 30. Section 2 applies where a restricted role handles personally identifiable information. Source: the Data Protection Policy on sellercentral.amazon.com.
How much does an Amazon SP-API DPP penetration test cost?
Our published price. The plan for a DPP submission is the Growth Pentest at INR 1,79,999, which covers two scopes, and each additional scope is INR 74,999. Because clause 2.7.2 enumerates four scope categories, a DPP engagement is normally four scopes, one each for the web application, the API backend, the cloud environment and the network. That is INR 3,29,997. Where the estate allows the work to come to three scopes it is INR 2,54,998. Both figures exclude taxes and both include 12 hours of founder-led consulting and one free retest. We publish this rather than quote the two scope price and raise it once we have seen your architecture.
How long does an SP-API DPP penetration test take?
Each scope is five business days and scopes run sequentially by default, so three scopes is 15 business days and four is 20. On the Growth plan you can ask for the third and fourth scopes to run together, which brings a four scope engagement to 15 business days. Parallel testing is an option you request, not the default and not a guarantee. Business days are Monday to Friday; the weekend is a quality buffer and is not counted. The retest itself takes one to three business days.
What methodology do you test against for an SP-API submission?
Clause 2.7.2 requires an industry-recognized methodology, and we name ours in the report rather than asserting it. Application-layer testing follows OWASP WSTG v4.2 and the OWASP API Security Top 10 2023, with findings carrying their OWASP Top 10:2025 category. The engagement overall follows PTES. Cloud work covers IAM and least privilege, encryption at rest against the policy minimum, environment separation, and logging. The report names the standard against each finding, so a reviewer can see which methodology was applied rather than taking the word for it.
Do you have experience with SP-API DPP submissions specifically?
Yes. We have delivered DPP engagements for Solution Providers and we publish the evidence set from one of them: three reports covering the clause 2.7.2 scope categories, available on request. We also publish what the policy requires in detail, including the parts that are commonly misread, such as the fact that the DPP contains no SOC 2 or ISO 27001 requirement and that its stated encryption minimum at rest is AES 128 or RSA 2048 rather than AES 256.
Does Amazon require a SOC 2 or ISO 27001 report as part of the DPP?
No. The Data Protection Policy contains no SOC 2 and no ISO 27001 requirement. Control mapping to those frameworks is useful for your own auditors and for enterprise customers asking security questions, and we include it on the Growth plan, but it is not something Amazon asks for in a DPP submission. Treat anyone selling it as an Amazon requirement with caution.
Do I need to send Amazon the penetration test report?
Not routinely. The policy has no clause requiring you to upload or send the report as a matter of course. Section 3 requires that you maintain the books and records needed to verify compliance during the agreement and for 12 months afterwards, and that upon written request you certify in writing that you are compliant, with Amazon reserving a right to audit. So the report is evidence you hold rather than evidence you file, which is why the quality of the document and the methodology it names matter.
What happens if findings come back critical?
Clause 2.7.3 sets the clock: critical findings remediated within 7 days and high within 30. Your report is ordered so the items on those clocks are unambiguous, each with reproduction steps and specific remediation guidance rather than a generic recommendation. The free retest then confirms the fixes and produces a v2.0 report recording the closed state, which is the document you want on file when section 3 is invoked.
Send us your architecture, not a plan choice
How many of the four categories apply depends on your estate, and that is the difference between three scopes and four. Tell us what the integration touches and we will scope it and quote it.