Corrections

When we publish something that turns out to be wrong, we change it and say so on the page it appeared on. This is every one of those, in one place, newest first.

180 corrections across 70 pages. Most recent: 7 September 2026.

What counts as a correction

One test: would a reader who acted on the old version have been misled? If we published a figure that was wrong, cited a standard that does not say what we said it said, or attributed a requirement to a regulator that the regulator never imposed, that is a correction and it is on this page.

Changing a price, adding a service or changing how we package our work is not a correction. Nothing was wrong before, so nobody was misled, and listing those here would make ordinary changes look like mistakes. Those show up as an effective date on the page they affect.

7 September 2026

Password Reset Bypass: The Test Case to Demand

Added CERT-In Vulnerability Note CIVN-2026-0442, published two days after this article, which covers the same Keycloak flaw and corroborates the upstream-versus-Red-Hat version split stated here.

5 September 2026

Investor Asked for SOC 2? Here's What to Do

Removed the "INR 2 to 5 lakh per year" compliance-tooling band and the surrounding first-year cost breakdown. The 2026-08-09 note below recorded this removal, but the figure survived in the Key findings list, so the correction had never actually been applied to the page. The section now names the four line items to budget for and says plainly that only the penetration test has a published price.

Investor Asked for SOC 2? Here's What to Do

Corrected the pentest duration from "7 to 10 days" to the business-days model: one scope is 5 business days, two scopes 10, scopes sequential by default. Calendar-day framing was replaced across the site on 2026-07-17 because it is ambiguous about weekends, and this page had not been swept.

When Your Startup Outgrows 'The CTO Handles Security'

Reframed the closing section and the decision table. The page previously said Cybersecify does "offensive security (penetration testing and red teaming)". Red teaming is not a service we sell and is not in our service list, so the claim was removed. The decision table routed readers with a compliance deadline to a "fractional security team", which we also do not offer. The post now states plainly which of the three options we do and do not provide, and points to penetration testing and SOC 2 / ISO 27001 readiness, which are the two things on that checklist we actually deliver. The market survey of the three options is kept, because the reader genuinely faces that choice.

When Your Startup Outgrows 'The CTO Handles Security'

Removed the "INR 60,000 to 2,60,000 per month" market-rate figure for fractional security, in both the summary paragraph and the Option 3 cost line. The 2026-08-09 note below recorded this removal, but it had only been applied to the CISO salary figure and the FAQ answer, so the fractional band was still published in two places. Both now say there is no published rate card and direct the reader to price their own hours.

Zero Trust for Series A SaaS Startups: Worth It?

Replaced ISO 27001:2013 Annex A numbering with the 2022 controls in four places, including the FAQ answer that ships as structured data. The 2013 access-control clause became A.5.15 and A.5.16 for identity and access and A.8.2 and A.8.3 for least privilege; the 2013 logging clause became A.8.15 and A.8.16; the 2013 communications-security clause became A.8.20 for networks security. The 2022 revision has only A.5 to A.8, so the superseded numbers pointed at controls that no longer exist. (The old numbers are described rather than printed here, because a retired control number on a live page is exactly what our framework-identifiers gate exists to catch.)

4 September 2026

5 Questions to Ask Your Pentest Vendor

Replaced the unsourced "INR 10L to INR 5 crore" breach-cost band with the IBM 2026 India average, linked, and labelled as an all-sector average rather than a startup figure.

AI API Key Leaks in Vibe-Coded SaaS (Pentest Patterns)

Removed the "USD 5,000 to USD 50,000" typical billing damage band and the "USD 0.01 to USD 0.10" per-call cost. Neither had a published source; per-token pricing is published by the providers and changes, and no dataset supports a typical-damage range. The control advice is unchanged.

Best AI Agent Security Testing Tools India 2026

Removed the vendor price figures that had no published source behind them: "USD 500 to USD 5,000 per month" and "USD 20,000 to 100,000 per year" for Patronus AI, Lakera Guard and WhyLabs, "USD 99 to 499 per month" for a guardrail tool, and "USD 449 per user per year" for Burp Suite Professional. The tools are still named and described; only the unsourced numbers are gone.

Best Pentest Vendors for SaaS Startups in India (2026)

Added the source and check date for the Software Secured starting prices in the archetype table; the figures were attributed to the vendor but not linked or dated. Labelled the three-tier pricing benchmark as a market observation rather than a published rate card.

The Real Cost of Skipping Security in Your SDLC

Removed the "₹30-50 lakh per year in wasted capacity at Indian SaaS market rates" figure. It had no published source, and the same class of salary band was removed from our outsourcing post on 2026-08-09. The point now asks the reader to run the arithmetic on their own engineering cost.

DAST vs Penetration Testing: Pentest or Scanner?

Removed the sentence "RBI's Master Direction on IT Governance, Risk, Controls and Assurance Practices (November 2023) requires regulated entities to conduct vulnerability assessment and penetration testing at least annually or whenever major changes are made to IT systems, and specifies that it be carried out by competent personnel holding appropriate certifications" from the FAQ answer on whether RBI or SEBI accept a DAST scan. That Master Direction (DoS.CO.CSITEG/SEC.7/31.01.015/2023-24) was repealed on 31 July 2026 vide circular DoS.CO.PPG.66/11.01.005/2026-27, and the body of this post already said so while the FAQ still cited it as the live requirement, so the stale version was shipping as FAQPage structured data. The answer now cites the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026.

DAST vs Penetration Testing: Pentest or Scanner?

Removed the clause "the 2023 IT Governance Master Direction (RBI/2023-24/107) no longer appears on RBI's current Master Directions index" from both places it appeared. The underlying fact is true, but an index listing is weak evidence: RBI still serves the 2023 document at its old URL with no withdrawal banner, so a reader who opens it sees a live-looking page. Both passages now cite the repeal circular DoS.CO.PPG.66/11.01.005/2026-27 and its Annex entry at Sr. 16 instead.

DAST vs Penetration Testing: Pentest or Scanner?

Added the entity class to every mention of paragraphs 151, 155 and 230. Those numbers were read from the Commercial Banks instrument, RBI/DoS/2026-27/410. The Directions are issued in seven per-entity-class versions and the parallel instruments were not opened, so an NBFC or Urban Co-operative Bank reader is now told to cite the paragraph in its own version.

DAST vs Penetration Testing: Pentest or Scanner?

Replaced "RBI's Master Direction on IT Governance, Risk, Controls and Assurance Practices (November 2023) is more explicit, calling for regular vulnerability assessment and penetration testing with documented methodology" in the India regulatory paragraph, for the same repeal reason. The documented-methodology point now rests on paragraph 154 of the 2026 Directions. --- **Built for AI-first and API-first SaaS startups.** Cybersecify is a founder-led security firm based in Bengaluru, India. Our team holds OSCP, CISSP, CEH, and ISO 27001 Lead Auditor certifications. Every engagement is run by the founders end-to-end. Strategy, methodology, manual testing, report sign-off, all of it. If you need a pentest report your auditor and enterprise customers can use, book a discovery call or review our pricing. **Related reading:** - What Is Penetration Testing? 2026 Startup Guide (the pillar guide) - Manual Pentest vs Automated Scanning: Startup Guide (methodology framing) - How to Evaluate a Pentesting Firm (the six questions to ask before signing) - Penetration Testing for SOC 2 Audit (compliance-specific guidance) - Sample Pentest Report (what auditor-grade reports actually look like) - Pricing (Startup Pentest INR 74,999 + Growth Pentest INR 1,79,999) - Methodology (PTES, OWASP WSTG v4.2, OWASP API Top 10 2023, NIST SP 800-115) - Book a Discovery Call (15-minute scope and timeline review)

DevSecOps: Shift Left vs Shift Right Security

Removed the "INR 50,000 to 5 lakh per year" shift-left tooling band and the security-engineer cost added to it. Neither had a published source; the tools are quoted per seat or per repository. Labelled the stage budget matrix as our own estimate.

How to Evaluate a Penetration Testing Firm

Removed the "Large firms charge ₹3L+ and assign the work to the same junior analysts" claim. The price had no source and the staffing assertion about unnamed large firms was not something a reader could check. The point is now written as a question to ask any vendor.

ISO 27001 Certification in Bangalore: Startup Guide

Removed the first-year cost bands ("6 to 15 lakh", the per-line cost table, and the "6-15 lakh / 8-20 lakh" row in the ISO versus SOC 2 table). No certification body and no CPA firm publishes a rate card, so the post now describes how each line is priced and tells you to collect written quotes.

ISO 27001 vs SOC 2: Which Does Your Startup Need First?

Removed the first-year and annual-maintenance cost bands for ISO 27001 and SOC 2 ("6 to 15 lakh", "10 to 25 lakh", "2 to 4 lakh", "8 to 20 lakh", "₹8 lakh"). No certification body and no CPA firm publishes a rate card, so the comparison now describes how each fee is quoted.

Manual Pentest vs Automated Scanning: Startup Guide

Removed the "₹5,000 to ₹20,000/month on most platforms" scanner subscription figure. Scanner vendors quote per application and per scan volume, and none of them publishes a rate card that supports a market-wide band.

Outsourced SaaS Pentest 2026: Buyer's Guide

Labelled the vendor-archetype pricing ranges as planning bands from quotes founders have shown us rather than market rates, and removed the in-house capability cost band ("INR 25 to 40 lakh per year"), which had no published source.

Pentest RFP Template for Indian SaaS Startups (2026)

Removed the "INR 1 to 5 crore coverage is typical for boutique founder-led firms" insurance figure. No firm publishes its cover amount, so the claim was not checkable. The RFP now asks vendors to state the figure in writing.

RBI Cybersecurity Framework: Fintech Compliance 2026

Rebuilt the "Which RBI Guidelines Apply to You?" table. All four rows named instruments that RBI repealed on 31 July 2026 vide circular DoS.CO.PPG.66/11.01.005/2026-27: "Cybersecurity Framework for Banks, June 2016" (Annex Sr. 54), "Guidelines on IT Governance, Risk, IT & IS Audit, January 2023 (updated)" (this is the Master Direction at Annex Sr. 16, whose own header row is dated 7 November 2023; no RBI instrument carrying a January 2023 date could be sourced), "Master Direction on Digital Payment Security Controls, 2021" (Annex Sr. 29), and "IT Framework for NBFCs, 2017" (Annex Sr. 47). Each row also linked to rbi.org.in's homepage rather than to the instrument. The section now separates current instruments from repealed ones, names the repeal circular, and links the 2026 Directions to the Commercial Banks notification page.

RBI Cybersecurity Framework: Fintech Compliance 2026

Replaced every citation of those four repealed instruments elsewhere in the post, including three FAQ answers that were shipping the stale versions as FAQPage structured data: the "Which RBI cybersecurity guidelines apply to fintech startups?" answer that opened "Five main directives stack depending on your entity type and partnerships", the answer to "What are the Digital Payment Security Controls under the February 2021 Master Direction?" (the question itself is now about that Master Direction's repeal), and the clause "Findings should map to RBI Master Direction Digital Payment Security Controls (where applicable)" inside the pentest-scope answer. The lead direct-answer paragraph carried the same list and was rewritten too.

RBI Cybersecurity Framework: Fintech Compliance 2026

Removed "Annual VAPT is mandatory for all regulated entities under RBI guidelines" from the FAQ, and the matching "**Annual VAPT** is mandatory for all regulated entities" bullet from the VAPT section. It overstates coverage and understates cadence against what RBI actually wrote. The Commercial Banks version of the 2026 Directions sets vulnerability assessment at least once in every six months and penetration testing at least once in 12 months for critical information systems and those in the DMZ having a customer interface (paragraph 151), and a risk-based approach for everything else. Both passages now state that.

RBI Cybersecurity Framework: Fintech Compliance 2026

Added the entity class to every quoted paragraph number. Paragraphs 150, 151, 154, 155, 156, 159, 161, 182 and 230 were read in the Commercial Banks instrument (RBI/DoS/2026-27/410). The Directions are issued in seven per-entity-class versions and the other six were not opened, so nothing is asserted about their numbering.

RBI Cybersecurity Framework: Fintech Compliance 2026

Replaced "typically 2 to 6 hours for material incidents at directly-regulated entities" in the incident-timeline FAQ answer. No source was found for that range. The answer now cites paragraph 182 of the Commercial Banks instrument, which sets six hours from detection on RBI's DAKSH platform, and says the window has to be read from the version for your own entity class.

RBI Cybersecurity Framework: Fintech Compliance 2026

Removed the year claim "(2020, updated 2024)" attached to the Master Direction on Payment Aggregators and Payment Gateways, and the rbi.org.in homepage link on it. RBI's current Master Directions index carries a differently titled instrument regulating payment aggregators, and the year pair could not be sourced against it. The sentence now tells the reader to confirm the current title and date on the index.

RBI Cybersecurity Framework: Fintech Compliance 2026

Removed the "INR 1,50,000 - 5,00,000/year" managed SOC band. No managed SOC provider we are aware of publishes a rate card, so the row now says how the service is priced. The first-year total is now labelled as our own estimate rather than a market figure.

SOC 2 + ISO 27001 Timeline by Funding Stage

Removed the SOC 2 Type 1 cost breakdown ("₹3,00,000 to ₹8,00,000", readiness platform "₹1L to ₹2L/year", audit firm fees "₹2L to ₹5L") and the password-manager per-seat figure. Neither compliance platforms nor CPA firms publish list pricing. The stage-by-stage annual security spend bands are kept but are now labelled as our own estimates from client engagements.

When SaaS Must Outsource Pentest (2026)

Removed the "Big 4 cybersecurity practices typically start at INR 5 lakh+ per engagement" figure. The same class of Big 4 price band was removed from our DevSecOps post on 2026-08-09; none of those firms publishes a rate card.

When SaaS Must Outsource Pentest (2026)

Removed two further salary bands that survived the 2026-08-09 pass below and contradicted it: "INR 35 to 45 lakh per year" for a security hire and "INR 35 to 50 lakh" fully loaded. Neither had a published source.

SOC 2 vs ISO 27001 vs DPDP Act 2023: Which First?

Removed the sentence "ISO 27001 controls cover roughly 70 to 80 percent of RBI's baseline expectations" from the FAQ answer on how RBI compliance interacts with SOC 2 and ISO 27001. The 2026-08-09 note below recorded this removal, but the figure was only taken out of the body and survived in the FAQ frontmatter, where it was still shipping as FAQPage structured data. The answer now says ISO 27001 covers much of RBI's baseline expectations and states that no published source puts a percentage on the overlap.

SOC 2 vs ISO 27001 vs DPDP Act 2023: Which First?

Removed "Master Direction Digital Payment Security Controls (for payment system operators)" from the same FAQ answer's list of live RBI requirements. RBI repealed that Master Direction (DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21, 18 February 2021) on 31 July 2026 vide circular DoS.CO.PPG.66/11.01.005/2026-27. The answer now names the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 instead, notes they are issued per entity class, and says the 2021 circular was repealed.

SOC 2 vs ISO 27001 vs DPDP Act 2023: Which First?

Removed the SOC 2 auditor-fee bands and the ISO 27001 surveillance and recertification bands that survived the 2026-08-09 pass ("INR 4 to 8 lakh", "INR 6 to 12 lakh", "INR 10 to 18 lakh", "INR 3 to 5 lakh", "INR 5 to 8 lakh"). No CPA firm or certification body publishes a rate card. The DPDP and RBI figures stay but are now labelled as our own estimates from scoping that work rather than published market figures.

SOC 2 Readiness for Indian Startups

Removed the audit-fee bands that survived the 2026-08-09 pass. The FAQ, the opening summary, the comparison table and the GRC-platform note still carried "5 to 12 lakh", "8 to 20 lakh", "10 to 25 lakh" and "a ₹5 lakh platform" after the correction below said those figures had gone. No CPA firm and no GRC platform publishes a rate card, so the post now says the fee is quoted per engagement.

SOC 2 Readiness for Vibe-Coded SaaS Startups (2026)

Removed the same auditor fee bands from the key-takeaways list, where they survived the 2026-08-09 pass below and contradicted it.

SOC 2 Type 1 vs Type 2 for Indian SaaS Startups

Removed the CPA audit-fee bands that survived the 2026-08-09 pass. The FAQ, the comparison table and the auditor-selection section still carried "₹5-12 lakh", "₹8-20 lakh" and "$15,000-40,000" for named categories of audit firm. No CPA firm on either side publishes a rate card, so the post now says the fee is quoted per engagement.

Investor Diligence Pentest Vendors India (2026)

Labelled the vendor-archetype pricing ranges as planning bands from quotes founders have shown us rather than market rates. Only our own price in that table comes from a published price list.

Top Pentest Companies for AI-First SaaS Startups 2026

Attributed the "$230 million in bounties" figure to HackerOne as its own published claim rather than stating it as fact. We do not have an independent source for it.

Top SOC 2 Pentest Providers for Indian Startups (2026)

Removed the "6L to 15L" annual subscription band for Vanta, Drata and Sprinto and the claim that Sprinto is the most cost-effective of the three. Verified 2026-08-09: none of them publishes list pricing, so neither the band nor the ranking had anything behind it. Also removed the "4L to 8L" CPA audit fee band and the total derived from both, and labelled the remaining archetype ranges as planning bands rather than market rates.

VAPT vs Vulnerability Assessment vs Pentest (2026)

Removed the scanner subscription price figures. "Qualys, Tenable, Wiz at INR 5,00,000 plus per year" and the "INR 5,000 to INR 50,000 per month" band had no published source behind them; those vendors quote per asset and per module. The pentest per-scope bands are unchanged and remain market observations.

What Is an Internal Network Penetration Test?

Added the entity class to the quoted RBI paragraph numbers, in both places they appear. Paragraphs 151 and 155 were read in the Commercial Banks instrument (RBI/DoS/2026-27/410) only, and the post stated them as though they held across every entity class. The Directions are issued in seven per-entity-class versions and the other six were not opened, so an NBFC or Urban Co-operative Bank reader is now told to cite the paragraph in its own version.

When to Re-pentest Your SaaS App

Removed every mention of "RBI Master Direction on IT Governance and Cyber Security (April 2024)", in all three places it appeared: the FAQ answer on CERT-In re-audit cadence (which ships as FAQPage structured data), the fintech bullet under the annual-minimum trigger, and the India regulatory context section. No RBI instrument carrying that title and that date could be sourced. The only IT Governance Master Direction in RBI's own repeal Annex is DoS.CO.CSITEG/SEC.7/31.01.015/2023-24 dated 7 November 2023, which RBI repealed on 31 July 2026 vide circular DoS.CO.PPG.66/11.01.005/2026-27. Either way the citation was stale. All three passages now cite the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026.

When to Re-pentest Your SaaS App

Removed the claim that RBI directions "push toward 6-month or quarterly testing on payment-handling components". RBI's actual cadence in the Commercial Banks version of the 2026 Directions is vulnerability assessment at least once in every six months and penetration testing at least once in 12 months for critical and customer-facing systems (paragraph 151). Quarterly penetration testing is not what the text says. The bullet now states RBI's cadence and separates it from what fintech customers ask for contractually.

When to Re-pentest Your SaaS App

Added the entity class wherever a paragraph number is quoted. Paragraphs 151, 155 and 230 were read in the Commercial Banks instrument (RBI/DoS/2026-27/410) only. The Directions are issued in seven per-entity-class versions and the other six were not opened, so the numbering is not asserted for NBFC, UCB, SFB, Payments Bank, AIFI or CIC readers.

When You DON'T Need CERT-In Empanelled Vendor

Removed the "typically INR 2 to 6 lakh and up" band for empanelled-vendor scope. Empanelled vendors do not publish rate cards, so the figure had nothing behind it. The advice to compare quotes at your own scope is unchanged.

Who Needs a CERT-In Empanelled Vendor in India

Removed three repealed RBI instruments from the list of directives that reference CERT-In empanelled auditors: "RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices (banks and certain NBFCs)", "RBI Cyber Security Framework for Banks and subsequent updates", and "RBI Master Direction on IT Framework for the NBFC sector (above specific asset thresholds)". All three are in the Annex to circular DoS.CO.PPG.66/11.01.005/2026-27, by which RBI repealed 628 circulars on 31 July 2026. The section now points to the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 and names the repealed circulars as repealed. The Cyber Resilience and Digital Payment Security Controls Master Directions for non-bank Payment System Operators are unchanged: that is a different instrument, still current, and not in the repeal Annex.

Who Needs a CERT-In Empanelled Vendor in India

Removed "RBI directives on cyber security for Urban Cooperative Banks at Level 2 and above (name empanelment explicitly)" and the same claim from the FAQ answer on whether RBI requires a CERT-In empanelled auditor, where it was shipping as FAQPage structured data. The two UCB cyber security frameworks it rested on (October 2018 and December 2019) were repealed on 31 July 2026, and the UCB version of the 2026 Directions has not been read, so the claim is unsourced for 2026 rather than confirmed or refuted. The post now says so.

Who Needs a CERT-In Empanelled Vendor in India

Rewrote "Where the master direction names 'CERT-In empanelled auditor', empanelment is required" to reflect what the 2026 text actually says. In the Commercial Banks version (RBI/DoS/2026-27/410), paragraph 159 is conditional, applying only "in case of CERT-In empanelled auditors", and paragraph 156 asks for qualification, professional expertise, credentials and competency instead. The paragraph numbers are from the Commercial Banks instrument only; the other six entity-class versions were not opened and nothing is asserted about them.

What Is an External Network Penetration Test?

Added the entity class to the quoted RBI paragraph numbers. Paragraphs 151 and 155 were read in the Commercial Banks instrument (RBI/DoS/2026-27/410) only, and the post stated them as though they held across every entity class. The Directions are issued in seven per-entity-class versions and the other six were not opened, so an NBFC or Urban Co-operative Bank reader is now told to cite the paragraph in its own version.

30 August 2026

Amazon SP-API Pentest: What the DPP Requires

Corrected an attribution. This page said internal systems testing is something "Amazon's guidance names alongside external-facing infrastructure". It is named in the Data Protection Policy itself, clause 2.7.2, not in the advisory security-controls guidance, and Amazon's wording in that clause is "public-facing and internal network boundaries". The policy binds; the guidance advises, so the earlier wording understated the requirement.

Amazon SP-API Pentest: What the DPP Requires

Rewrote the pricing answer. It presented the Startup plan as suiting "a single-surface integrator" and cited SOC 2 and ISO 27001 control mapping as what makes the Growth plan fit. Both were misleading for this buyer. Clause 2.7.2 enumerates four scope categories that one scope cannot reach, and the Letter of Engagement, which is the document Amazon receives, is issued on the Growth plan only. The DPP contains no SOC 2 or ISO 27001 requirement at all, so control mapping is useful to your auditors rather than to Amazon.

Amazon SP-API Pentest: What the DPP Requires

Corrected the date attribution on the clause 2.7 restructure. This page said "Amazon restructured 2.7 between those two dates", meaning between our 9 and 22 August 2026 reviews. That is wrong: Amazon's restructure took effect **25 November 2025**, nine months before our first review, and our 9 August review simply missed it. The "UPDATED" dates on this page are OUR review dates, not Amazon's change dates, and are now labelled as such.

29 August 2026

Amazon SP-API Pentest: What the DPP Requires

Corrected three word-frequency claims that decayed when Amazon restructured clause 2.7. We said the word "penetration" appears exactly once in the policy; it now appears five times, all inside 2.7. We printed the sub-clause headings as "2.7.1 Scanning", "2.7.3 Remediation" and "2.7.4 Disaster Recovery"; Amazon prints "Vulnerability Scanning", "Vulnerability Remediation" and "Disaster Recovery and Business Continuity". The policy URL we cited now redirects, and is updated to the current canonical path. Verified against the live policy on 29 August 2026.

SP-API DPP Pentest: Why Scanner Output Fails

Corrected two word-frequency claims. We said the Data Protection Policy "does not contain the word report at all"; it appears once, in clause 1.6.2, where it means reporting a Security Incident to Amazon rather than a pentest deliverable. We also said a search for "qualified", "tool" and "tooling" found none of them; "tool" appears once, in clause 2.6.1, as an example of a log-review mechanism ("e.g., SIEM tool"). The substantive points stand: Amazon sets no report format and names no testing tool. The policy URL we cited now redirects, and is updated. Verified against the live policy on 29 August 2026.

22 August 2026

Amazon SP-API Pentest: What the DPP Requires

Updated for Amazon's restructuring of Data Protection Policy clause 2.7 into sub-clauses 2.7.1 to 2.7.4, effective 25 November 2025. Clause 2.7.2 now names an "industry-recognized methodology", which it did not previously. Statements on this page about what Amazon does and does not publish were revised accordingly.

Penetration Testing for SOC 2: What Auditors Want

Tightened the answer to whether SOC 2 requires a penetration test. The page previously said SOC 2 does not explicitly mandate one but that most auditors expect one. It now states that the AICPA requires no penetration test for either Type I or Type II, and that a pentest is commonly accepted as evidence for CC7.1 and CC7.2, which is a different statement. The Type I and Type II guidance was also separated, because the two are not the same purchase.

15 August 2026

Cloud Pentest: What We Test in AWS, Azure, and GCP

Corrected three cloud provider testing-policy references. The GCP answer previously linked to Google's Cloud Data Loss Prevention product page, which says nothing about penetration testing; it now cites Google's Cloud Security FAQ, which states you are not required to contact Google to test your own Cloud Platform infrastructure. The Azure answer previously implied Microsoft notification was required for certain testing; Microsoft's Security Testing Rules of Engagement instead require testing to stay within your own tenant or assets you have explicit authorization for. The AWS answer now names the specific prohibited activities the policy lists. All three provider pages checked 2026-08-15.

Vanta vs Drata vs Secureframe vs Sprinto 2026

Removed the remaining unsourced India-operations claims about Sprinto and the other platforms, in the FAQ block and the body: INR billing and Indian billing entity, Indian auditor partnerships, India business-hours support, and the claim that Secureframe bills in INR through reseller agreements. None of these could be verified from the vendors' own pages. The USD-billing and support-timezone statements about Vanta and Drata are gone for the same reason. What replaces them is the difference that is checkable: Sprinto is India-headquartered and its published framework list names DPDPA (India) and RBI SAR, which the Vanta and Drata lists do not, checked 2026-08-15. On billing, the post now tells you to ask which entity issues the invoice and in what currency, which is the question that actually protects an Indian buyer signing an annual contract. Also removed the unsourced "200+ integrations" figure for Vanta. Integration counts are checkable on each vendor's own directory and change often, so the post now points readers there instead of asserting a number.

9 August 2026

5 Questions to Ask Your Pentest Vendor

Removed the unsourced "30 to 50 percent of the engagement fee" retest pricing figure, and replaced a "within 30 days" retest window with advice to confirm the window with the vendor, since windows differ by vendor.

AI API Key Leaks in Vibe-Coded SaaS (Pentest Patterns)

Replaced precise percentages describing our own engagement data with qualitative wording. We do not publish a per-engagement findings register, so those figures were not something a reader could verify. The underlying observations are unchanged.

Amazon SP-API Pentest: What the DPP Requires

Added a direct link to our internal network pentest service page, which Amazon's guidance names alongside external-facing infrastructure. The page previously routed readers to the contact form without naming the service.

API Security Testing: OWASP API Top 10 for CTOs

Removed the claim that Cloudflare reports BOLA in about 40% of all API attacks. The Cloudflare learning page we cited contains no percentage figures, so the number was attributed to a source that does not publish it. BOLA's prevalence is now stated using OWASP's own ranking and Salt Security's measured 27%.

API Security Testing: OWASP API Top 10 for CTOs

Corrected "6 out of 10 API vulnerabilities cannot be found by automated tools" to 4 of 10, plus a fifth only rarely detected, which is what the scanner-versus-manual table on this page actually shows.

We Scanned Startups for Email Spoofing. Zero Protected

Replaced the percentage breakdown of this scan with proportional language. On a sample of 31 domains those percentages do not map to whole-number counts, and one of them was the sum of two independently rounded percentages rather than a count. The underlying observations are unchanged: none of the 31 domains was at full DMARC enforcement.

Best AI Agent Security Testing Tools India 2026

Removed a "static analysis catches 30 percent, dynamic 30 percent, manual pentest 40 percent" split previously attributed to the OWASP API Security Top 10. The OWASP API Security Top 10 2023 makes no claim about the relative effectiveness of static, dynamic or manual testing. The point is now made without the invented numbers.

Best AI Agent Security Testing Tools India 2026

Replaced per-engagement frequency statistics on this page with qualitative descriptions of what we find most often. The underlying observations are unchanged, but we do not publish a per-engagement findings register, so precise counts are not something a reader can check.

Best Pentest Vendors for SaaS Startups in India (2026)

Sayfer was listed as an India-based boutique firm. Sayfer's own about page gives its location as Tel Aviv, Israel. Corrected.

Best Pentest Vendors for SaaS Startups in India (2026)

Removed unsourced price ranges for vendor archetypes and for named categories of firm, and replaced them with "not published, ask for a quote" or with prices the vendor itself publishes. Where a figure is now given, it comes from that vendor's own pricing page.

Best Pentest Vendors for SaaS Startups in India (2026)

Removed unsourced assertions about how named enterprise and Big 4 firms staff and prioritise engagements, including the "3 to 5x" empanelment premium multiplier and the claim that a small scope runs on a large firm's lowest-billable testers. The buyer advice is now written as questions to ask any vendor.

Best Pentest Vendors for SaaS Startups in India (2026)

Removed the claim that compliance platforms do not deliver pentest in-house. Delivery models differ by platform and change over time; readers are now told to confirm with the platform.

Best Pentest Vendors for SaaS Startups in India (2026)

Removed the unsourced "retest billed at 25 to 50 percent of the original engagement fee" figure. The advice to get the retest price in writing before signing is unchanged.

Best Pentest Vendors for SaaS Startups in India (2026)

Aligned free-retest wording with our published terms: within one month of the v1.0 report.

CERT-In 6-Hour Rule: What Indian Startups Must Report

Removed the "12x faster than GDPR" framing. On the like-for-like comparison, personal data breach reported to the data-protection regulator, India's own DPDP Rule 7 gives 72 hours, the same as GDPR. The page now explains what actually differs: one incident starts both clocks, and the CERT-In clock starts earlier, on suspicion rather than confirmation.

CERT-In 6-Hour Rule: What Indian Startups Must Report

Replaced the note that the DPDP breach-notification timeline was still to be defined. Rule 7 of the DPDP Rules 2025 was notified on 13 November 2025.

Cloud Pentest: What We Test in AWS, Azure, and GCP

Replaced precise percentages describing our own engagement data with qualitative wording. We do not publish a per-engagement findings register, so those figures were not something a reader could verify. The underlying observations are unchanged.

The Real Cost of Skipping Security in Your SDLC

Removed the attribution of the defect-cost multiplier to "IBM Systems Sciences Institute". That organisation is not named anywhere in the NIST report we cite, and the IBM SSI study itself has no traceable published data set.

The Real Cost of Skipping Security in Your SDLC

Corrected the multipliers to NIST Table 5-1 as published: 1X / 5X / 10X / 15X / 30X, not 1x / 6x / 15-30x. NIST labels the table "(Example Only)", which is now stated.

The Real Cost of Skipping Security in Your SDLC

Updated the breach-cost figures from the IBM 2024 edition to the current 2026 edition: global average USD 4.99 million, India average INR 25.5 crore, up 15.9% year on year (IBM India, 3 August 2026). Removed an in-house USD conversion that had been printed inside an IBM-attributed sentence.

The Real Cost of Skipping Security in Your SDLC

Replaced an unsourced "70 to 90 percent of a modern application's code is third-party" claim with a figure we can cite: 87% of audited codebases contained at least one open-source vulnerability (Black Duck OSSRA 2026).

The Real Cost of Skipping Security in Your SDLC

Replaced several unsourced "80 percent of the risk" assertions with "most of the risk".

DevSecOps: Shift Left vs Shift Right Security

Removed the unsourced "SAST catches 50 to 70 percent of OWASP Top 10 categories" figure, and removed unsourced price bands for bug bounty programmes and Big 4 practices. None of those vendors publishes a comparable figure.

DPDP Rules 2025: Indian SaaS Compliance Checklist

Updated the USD equivalent of INR 250 crore from roughly USD 30 million to roughly USD 26 million, at INR 95.24 to the dollar (August 2026).

DPDP Act vs GDPR for Indian SaaS Startups

Corrected the DPDP penalty description. INR 250 crore is not a flat per-violation cap; it is the highest amount in the Act's Schedule and applies to failure to take reasonable security safeguards, with INR 200 crore for breach-notification and children's-data failures and INR 50 crore for other contraventions. Our own DPDP compliance checklist already published the graduated schedule; this page now matches it.

DPDP Act vs GDPR for Indian SaaS Startups

Added GDPR Article 83(3), which provides that where several provisions are infringed in the same or linked processing operations, "the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement." The page previously presented both regimes as per-violation ceilings that stack.

DPDP Act vs GDPR for Indian SaaS Startups

Updated the USD equivalent of INR 250 crore from roughly USD 30 million to roughly USD 26 million, at INR 95.24 to the dollar (August 2026).

DPDP Act vs GDPR for Indian SaaS Startups

Replaced a European Data Protection Board link that now resolves to a public-consultations page with the EDPB documents index.

How to Evaluate a Penetration Testing Firm

Removed the unsourced "90% automated and 10% manual" split attributed to lower-priced firms, and the unsourced "25 to 50%" retest price. Both are now written as questions to ask the vendor.

AI Agent Security Testing: Pentest Methodology 2026

Replaced per-engagement frequency statistics on this page with qualitative descriptions of what we find most often. The underlying observations are unchanged, but we do not publish a per-engagement findings register, so precise counts are not something a reader can check.

How to Read a VAPT Report: Founder's Guide

Removed the unsourced "25 to 50 percent" and "30-50 percent" retest pricing figures. The advice to confirm whether the retest is manual, included, and time-bound is unchanged.

How We Pentest APIs Without Documentation

Replaced precise percentages describing our own engagement data with qualitative wording. We do not publish a per-engagement findings register, so those figures were not something a reader could verify. The underlying observations are unchanged.

ISO 27001 Certification in Bangalore: Startup Guide

Updated two source links that had moved: the AICPA SOC page and the IAF recognised accreditation bodies page.

How Many Controls Are in ISO 27001? Startup Guide

Removed two unsourced percentages: "about 70% of the work overlaps" for teams coming from SOC 2, and "most Series A+ startups already cover 30-40% of controls". Neither traces to a published source.

ISO 27001 vs SOC 2: Which Does Your Startup Need First?

Corrected the SOC 2 and ISO 27001 control-overlap figure. Neither AICPA nor ISO publishes an overlap percentage; the 40 to 85% range is Drata's own estimate and is now attributed as such. Removed a separate unsourced "60% easier" claim about the second framework.

ISO 27001 vs SOC 2: Which Does Your Startup Need First?

Updated an AICPA source link that no longer resolves to the SOC page it cited.

Manual Pentest vs Automated Scanning: Startup Guide

Removed the unsourced "30 to 60%" scanner false-positive rate and the paired "under 5%" figure for manual testing. Neither traces to a published study.

MCP Server Pentest Checklist for SaaS Founders (2026)

Removed a "78.3% attack success rate" figure previously attributed to Palo Alto Networks Unit 42. The cited Unit 42 article (5 December 2025) contains no percentage figures and is a proof-of-concept demonstration, not a measured success rate.

MCP Server Pentest Checklist for SaaS Founders (2026)

Re-attributed the 8.5% OAuth adoption figure to its original publisher, Astrix Security (October 2025, 5,205 GitHub repositories), rather than to NimbleBrain's registry scan, and corrected "OAuth 2.1" to "OAuth", which is what Astrix measured.

MCP Server Pentest Checklist for SaaS Founders (2026)

Re-attributed the 43% command injection figure to Equixly (29 March 2025) and noted the sample size is unpublished.

MCP Server Pentest Checklist for SaaS Founders (2026)

Updated the Vulnerable MCP Project count from "over 50 by April 2026" to the tracker's actual current figures: 50 vulnerabilities, 13 critical, as of August 2026.

MCP Server Pentest Checklist for SaaS Founders (2026)

Replaced an unsourced "USD 8,000 to 25,000" international pentest price band with published figures from Software Secured's pricing page, checked August 2026.

MCP Server Pentest Methodology (2026)

Removed a "78.3% of audited MCP servers" figure previously attributed to Palo Alto Networks Unit 42. The cited Unit 42 article, "New Prompt Injection Attack Vectors Through MCP Sampling" (5 December 2025), contains no percentage figures and is a proof-of-concept demonstration rather than a population audit.

MCP Server Pentest Methodology (2026)

Re-attributed the 43% command injection figure to its original publisher, Equixly, 29 March 2025, and noted that Equixly does not publish its sample size.

MCP Server Pentest Methodology (2026)

Replaced an unsourced "30+ MCP-related CVEs in Jan-Feb 2026" claim with the current count from the Vulnerable MCP Project tracker: 50 vulnerabilities, 13 critical, as of August 2026.

Microsoft 365 Certification Pentest Requirements

Expanded three bare "seg2_app" source attributions to the full Microsoft Learn URL, and corrected one that attributed the 14 day, 60 day and fee-scale figures to seg2_app when they appear on the Microsoft 365 Certification framework page.

Microsoft 365 Certification Pentest Requirements

Hedged the 50 percent control-approval gate. The requirement appears under Penetration Testing Delivery, the section describing the test Microsoft arranges through its partner, so readers are now told to confirm with their certification analyst how it applies to an independently commissioned test.

Outsourced SaaS Pentest 2026: Buyer's Guide

Removed the unsourced "30 to 50 percent of the original engagement fee" retest figure and the motive attributed to vendors who bill retest separately. The advice to get the retest price in writing before signing is unchanged.

OWASP Top 10 for LLM Applications (2025) Explained

Replaced per-engagement frequency statistics on this page with qualitative descriptions of what we find most often. The underlying observations are unchanged, but we do not publish a per-engagement findings register, so precise counts are not something a reader can check.

OWASP Top 10 vs Business Logic in Pentests

Removed the unsourced "60 to 70 percent manual" and "80 to 90 percent automated" split figures. The underlying test, that a business-logic engagement should be mostly manual, is unchanged.

Penetration Test Plan Example for SaaS Startups 2026

Removed the unsourced "25 to 50 percent of engagement fee" retest pricing figure in all three places it appeared, along with the motive attributed to vendors who bill retest separately. The advice to get the retest price in writing before signing is unchanged.

Pentest Cost India 2026 | ₹74,999-15L + 7 Vendors

Updated the IBM breach-cost comparison from the 2024 edition to the current one. IBM's Cost of a Data Breach Report 2026 puts the India average at INR 25.5 crore, an all-time high and a 15.9 percent rise on 2025, replacing the INR 19.5 crore figure previously published (IBM India newsroom, 3 August 2026). The derived percentages and ratio were recalculated: a pentest at INR 75,000 to 1,80,000 is 0.03 to 0.07 percent of the average, a ratio of roughly 1,400 to 1 to 3,400 to 1, correcting the earlier "about 1,000 to 1".

Pentest Cost India 2026 | ₹74,999-15L + 7 Vendors

Removed the global USD breach-average figure and the USD conversion of the India figure, neither of which could be verified against IBM's own current publication.

Pentest Cost India 2026 | ₹74,999-15L + 7 Vendors

Removed unsourced cost bands for SOC 2 Type 2 audits and ISO 27001 certification. Neither audit firms nor certification bodies publish rate cards.

Pentest Cost India 2026 | ₹74,999-15L + 7 Vendors

Corrected the Cobalt pricing link, which had moved to /platform/pricing, and the name of Astra's second pentest tier, which is Pentest Plus.

Penetration Testing for SOC 2: What Auditors Want

Removed the unsourced "30 to 50 percent of original engagement cost" figure for a paid retest. The advice to pick a vendor whose engagement includes the retest is unchanged.

Pentest Checklist for Vibe-Coded SaaS Apps (2026)

Replaced a frequency statistic for Supabase RLS misconfiguration with a qualitative description. We do not publish an engagement register a reader could check it against, so it is now described qualitatively. It remains the most common gap we see.

Pentest RFP Template for Indian SaaS Startups (2026)

Removed the unsourced "25 to 50 percent of engagement fee" retest pricing figure and the motive attributed to vendors who bill retest separately. The red flag is now the absence of a disclosed retest price before signing, which is the thing a buyer can actually check.

Pentest RFP Template for Indian SaaS Startups (2026)

Removed the unsourced "3 to 5x" quote-variance multiplier and the assertion that vendors anchor quotes on a founder's perceived spend. The advice to disclose a budget range is unchanged; the reason given is now the observable one, that quotes for the same written scope vary widely.

Prompt Injection in 2026: 7 Attack Patterns We See

Replaced the engagement-frequency statistic on this page with a qualitative description. We do not publish a findings register that a reader could check against, so the observation is now stated qualitatively rather than as a count.

Prompt Injection in 2026: 7 Attack Patterns We See

Updated the Garak repository link. The project has transferred to the NVIDIA organisation on GitHub.

RBI Cybersecurity Framework: Fintech Compliance 2026

Removed the claim that ISO 27001:2022 covers "approximately 70 to 80 percent" of RBI's baseline cybersecurity expectations. No source supports a coverage percentage against a regulator's expectations, and the claim sat in a FAQ answer aimed at RBI-regulated buyers. The named control areas ISO 27001 does cover, and the named gaps where RBI goes further, are unchanged.

RBI Cybersecurity Framework: Fintech Compliance 2026

Removed the "most startups are 20-40% compliant" baseline, which had no source.

SOC 2 + ISO 27001 Timeline by Funding Stage

Removed the "INR 5 to 12 lakh" Series A security and compliance budget band and the "less than 1% of the round" figure derived from it. Neither had a source, and SOC 2 audit fees in particular are quoted per engagement with no published rate card. The stage-by-stage sequencing advice is unchanged.

SBOM for SaaS Startups: When, How, Tools

Removed the unsourced "~80% of startup needs" coverage figure for free SBOM tooling, in both places it appeared. The recommendation to start with Syft, Trivy and the GitHub Dependency Graph is unchanged.

SDLC Security: Where It Breaks in 9 Models

Dated the Pearce et al. Copilot study to 2021 and added its sample (1,689 programs across 89 scenarios), so the roughly 40 percent vulnerable figure is not read as a measurement of current models.

Security Questionnaire Template for SaaS Vendors (2026)

Removed eight market percentages that had no published source: "deal-blockers in 90 percent of enterprise questionnaires", "four sender types drive 95 percent", "required by 70 percent of US / 40 percent of EU / 20 percent of Indian enterprise buyers", "substitute controls accepted by 70 percent", "unblocks 60 to 80 percent", and the "80 percent" and "80 to 90 percent" self-service coverage estimates. The advice each supported is unchanged and now reads qualitatively. The gap-rate thresholds are retained because they are a threshold the reader measures on their own questionnaire, not a market statistic.

Security Questionnaire Template for SaaS Vendors (2026)

Updated the Shared Assessments SIG link, which now sits behind a login wall at the previous URL.

Security Questionnaire Template for SaaS Vendors (2026)

Updated the international currency conversion table to rates as of 2026-08-08.

When SaaS Must Outsource Pentest (2026)

Removed the senior-pentester salary and fully-loaded cost bands (INR 25 to 35 lakh salary, INR 33 to 50 lakh fully loaded) and the "4 to 6 scopes per year" and "5 to 10x lower annual cost" figures derived from them. None had a published source. The in-house versus outsource comparison is now framed as arithmetic the reader runs with their own numbers, against our published engagement price.

When SaaS Must Outsource Pentest (2026)

Removed the unsourced "30 to 50% extra" retest pricing figure. The advice to get the retest price in writing before signing is unchanged.

When SaaS Must Outsource Pentest (2026)

Updated the international currency conversion table to rates as of 2026-08-08. The previous table used 2026-06-24 rates, at which point 1 USD was around INR 84; it is now around INR 95, so the USD equivalents fell.

SOC 2 vs ISO 27001 vs DPDP Act 2023: Which First?

Corrected the SOC 2 to ISO 27001 control overlap attribution. The 40 to 85 percent range was described as "Drata's 2024 control mapping analysis". It is an estimate on a Drata marketing page dated 31 March 2026, and Drata's own wording is "estimated". Neither AICPA nor ISO publishes an overlap figure.

SOC 2 vs ISO 27001 vs DPDP Act 2023: Which First?

Removed the "30 to 50 percent incremental effort" figure for layering ISO 27001 onto an existing SOC 2 programme, and the ISO 27001 certification and consulting cost bands. Neither had a source, and no certification body publishes a rate card.

SOC 2 vs ISO 27001 vs DPDP Act 2023: Which First?

Removed the claim that ISO 27001:2022 covers "70 to 80 percent" of RBI's baseline expectations. No source supported a coverage percentage against a regulator's expectations. The named gap areas where RBI goes beyond ISO 27001 are unchanged.

SOC 2 vs ISO 27001 vs DPDP Act 2023: Which First?

Updated the AICPA SOC deep link, which no longer resolves.

SOC 2 Readiness for Indian Startups

Removed the SOC 2 cost figures sourced to compliance-platform marketing blogs. The Sprinto page we cited actually gives USD 30,000 to 150,000, not the USD 25,000 to 50,000 we published; the Scrut page gives USD 30,000 to 100,000; and the Neumetric figure of INR 4 to 8 lakh is a total certification cost including consulting and travel, not an audit fee, from a page published in March 2023. No audit firm on either side publishes a rate card, so the post now says so and tells readers to get written quotes.

SOC 2 Readiness for Indian Startups

Removed the "India CPA fees are typically 30 to 50 percent lower than US equivalents according to industry sources" claim. It named no source, and the Scrut page cited in the same paragraph undercut it.

SOC 2 Readiness for Indian Startups

Corrected the attribution on the SOC 2 to ISO 27001 control overlap. The 40 to 85 percent range is Drata's own estimate on a page dated 31 March 2026, not a measurement, and neither AICPA nor ISO publishes an overlap figure.

SOC 2 Readiness for Indian Startups

Updated the AICPA SOC deep link, which no longer resolves.

SOC 2 Readiness for Vibe-Coded SaaS Startups (2026)

Removed the SOC 2 auditor fee bands (INR 4 to 8 lakh fieldwork, INR 6 to 10 lakh total). No CPA firm publishes a rate card, so the table now says the fee is quoted per engagement. The phase durations and activities are unchanged.

SOC 2 Type 1 vs Type 2 for Indian SaaS Startups

Removed the "₹5-15 lakh per year" cost for compliance automation platforms. Verified 2026-08-09: Vanta, Drata and Secureframe all route to a quote request and publish no list pricing, and Sprinto and Scrut publish no rate card either.

SOC 2 Type 1 vs Type 2 for Indian SaaS Startups

Replaced the uncited "about 70-80% overlap" between SOC 2 and ISO 27001 with the only figure that has a traceable owner: compliance vendor Drata's estimate of 40 to 85 percent, labelled as a vendor estimate. Neither AICPA nor ISO publishes an overlap figure.

SOC 2 Type 1 vs Type 2 for Indian SaaS Startups

Updated the AICPA SOC deep link, which no longer resolves.

Investor Diligence Pentest Vendors India (2026)

Removed the unsourced "30 to 50 percent of the original engagement fee" retest pricing figure and the motive attributed to vendors who charge it. Corrected the retest window wording to match our published terms, one month from the v1.0 report.

Top Pentest Companies for AI-First SaaS Startups 2026

This post stated that Astra Security gated its pentest pricing behind a sales call and that Software Secured published no sticker prices. Both publish prices. Astra lists Pentest Basic at USD 1,999 per year and Pentest Plus at USD 5,999 per year (getastra.com/pricing); Software Secured lists eleven starting prices including Web and API from USD 10,800 and PTaaS from USD 21,400 (softwaresecured.com/pricing). Both verified 2026-08-09.

Top Pentest Companies for AI-First SaaS Startups 2026

Added Cobalt.io's published USD 3,500 per Autonomous Pentest price (cobalt.io/platform/pricing), which the post previously described as quote-only.

Top Pentest Companies for AI-First SaaS Startups 2026

Removed unsourced price bands and multipliers for third-party vendors, including the enterprise "3 to 5x boutique rates" figure and the PTaaS annual-commitment ranges. The persona table now shows published prices only.

Top Pentest Companies for AI-First SaaS Startups 2026

Corrected USD equivalents of our own INR pricing to August 2026 rates: INR 74,999 is around USD 790 and INR 1,79,999 is around USD 1,890, replacing the stale USD 900 and USD 2,180 figures.

Top Pentest Companies in India 2026 (SaaS Focus)

Astra Security and Cobalt.io were described as quote-only. Both publish pentest prices, now cited and linked: Astra Pentest Basic USD 1,999/yr and Pentest Plus USD 5,999/yr (getastra.com/pricing), Cobalt Autonomous Pentest USD 3,500 per test (cobalt.io/platform/pricing).

Top Pentest Companies in India 2026 (SaaS Focus)

Removed unsourced price multipliers and price bands attributed to named third parties, including the "3 to 5x boutique pricing" enterprise premium, the freelance "30 to 50 percent below boutique" figure, the PTaaS annual-commitment range, and the per-persona INR pricing column for vendors that do not publish prices.

Top Pentest Companies in India 2026 (SaaS Focus)

Replaced assertions about how named enterprise and Big 4 firms staff and deliver engagements with questions a buyer can ask any vendor. The underlying advice is unchanged.

Top Pentest Companies in India 2026 (SaaS Focus)

Corrected the description of how compliance automation platforms handle pentest. Whether a pentest is bundled, referred, or out of scope varies by platform and by plan, so the post now tells buyers to ask rather than asserting a single model. Removed the claim that a platform margin sits on top of the partner's price, which was unsourced.

SOC 2 Audit Firms India 2026: How to Choose

Removed the INR and USD audit-fee bands attributed to Deloitte, EY, KPMG and PwC India, to named US mid-market firms, and to the boutique and mid-tier categories. None of these firms publishes a rate card, so the post now gives the relative ordering and tells buyers to get written quotes at their own scope.

SOC 2 Audit Firms India 2026: How to Choose

Removed the compliance-platform subscription band for Vanta, Drata and Sprinto. Verified 2026-08-09: none of them publishes list pricing.

SOC 2 Audit Firms India 2026: How to Choose

Replaced assertions about how Big 4 practices staff and review SOC 2 engagements, and about whether they share redacted sample reports, with questions to ask every firm on a shortlist.

SOC 2 Audit Firms India 2026: How to Choose

Removed the 80 / 15 / 5 percent split for what triggers a SOC 2. The split had no source; the ordering of the three triggers is unchanged.

Top SOC 2 Pentest Providers for Indian Startups (2026)

Reframed how this page described compliance-platform partner directories, and removed a statement about our own listing status that did not accurately describe the position. The advice to evaluate any vendor on the 7 SOC 2 criteria is unchanged, and it applies to how you found the vendor rather than to the directory itself. We work with whichever platform and auditor the customer has already selected.

Top SOC 2 Pentest Providers for Indian Startups (2026)

Removed the unsourced "30 to 50 percent of the original engagement fee" retest pricing figure and the motive attributed to vendors who charge it. The advice to get the retest price in writing before signing is unchanged.

Vanta vs Drata vs Secureframe vs Sprinto 2026

Removed every INR annual price band attributed to Vanta, Drata, Sprinto, Secureframe and Tugboat Logic, and the auditor and consulting fee bands alongside them. Verified 2026-08-09: Vanta, Drata and Secureframe all route to a quote request and publish no list pricing, and Sprinto publishes no rate card either. The post now says so and tells buyers to ask each vendor for a quote at their seat count and framework scope.

VAPT for SaaS Startups in India: What You Actually Need

Removed the "15,000 to 3 lakh INR" VAPT cost range and the sub-ranges under it. They had no source, and a companion post on this site published a different range for the same question. Our own published price is unchanged and is now the only figure quoted.

VAPT vs Vulnerability Assessment vs Pentest (2026)

Removed the "10 to 30 percent in our experience" false-positive figure for vulnerability assessment output. The point that unverified scanner findings carry a meaningful false-positive rate is unchanged.

Vibe-Coded SaaS Pentest 2026: Cursor and Lovable Gaps

Removed the "N out of 10" frequency figures attached to each finding. We do not publish an engagement register a reader could check them against, so the relative frequency is now described in words rather than as a ratio. The findings themselves, and their ordering, are unchanged.

What a Good Pentest Report Looks Like

Removed the "30-60% false positives" and "under 5% false positive rate" figures from the report comparison table. Neither had a published source. The distinction the row makes, between manually verified findings and unverified scanner output, is unchanged.

GRC for Startups: Do You Need It Before Series A?

Removed the unsourced "80% of what enterprise questionnaires and auditors ask for" figure, replaced with "most".

GRC for Startups: Do You Need It Before Series A?

Updated the AICPA SOC deep link, which no longer resolves.

What Does ISMS Stand For? ISO 27001 for Founders

Removed the "about 70%" control overlap figure between ISO 27001 and SOC 2. Neither AICPA nor ISO publishes an overlap figure, and the number conflicted with the range published elsewhere on this site.

What Is VAPT? Vulnerability Assessment + Pentest

Removed the "50,000 to 3 lakh INR" VAPT cost range. It had no source, and a companion post on this site published a different range for the same question. Our own published price is unchanged and is now the only figure quoted.

12 Questions to Ask an Outsourced Pentest Vendor (2026)

Removed the unsourced "25 to 50 percent of the engagement fee" retest pricing figure in all six places it appeared, along with the assertion that vendors who bill retest separately profit from findings staying open. The advice to get the retest price in writing before signing is unchanged. Also removed the unsourced "30 to 50 percent premium" figure for rush pricing.

When to Re-pentest Your SaaS App

Removed the unsourced "30 to 50 percent of the engagement cost" retest pricing figure. The advice to confirm the retest terms before signing is unchanged.

When You DON'T Need CERT-In Empanelled Vendor

The CERT-In empanelled firm count of 237 is exact, counted from the list CERT-In published in July 2026, so "approximately" has been dropped. Removed the "grew from 150 firms in 2022, a 58% increase" comparison: the 150 baseline is an August 2023 figure, not 2022, and rests on a single source.

When You DON'T Need CERT-In Empanelled Vendor

Updated the AICPA SOC deep link, which no longer resolves.

Why We Only Use OSCP-Certified Pentesters

Removed the "pass rate hovers around 20-30%" figure. OffSec does not publish an OSCP pass rate, and no primary source for that range could be found. The description of what the exam actually requires is unchanged.

Who Needs a CERT-In Empanelled Vendor in India

The CERT-In empanelled firm count of 237 is exact, counted from the list CERT-In published in July 2026, so "approximately" has been dropped. Removed the "up from 150 in 2022, a 58% increase" comparison: the 150 baseline is an August 2023 figure, not 2022, and rests on a single source.

Investor Asked for SOC 2? Here's What to Do

Removed an unsourced "2 to 5 lakh per year" price band for compliance automation tooling. Verified 2026-08-09: Vanta, Drata and Secureframe all route to a quote request rather than publishing prices.

Investor Asked for SOC 2? Here's What to Do

Updated an AICPA source link that no longer resolves to the SOC page it cited.

Shadow AI Governance: A Playbook for SaaS Founders

Removed the unsourced "~70 percent of the value" figure for native logs plus an acceptable-use policy. The recommendation to defer DLP tooling until the basics are in place is unchanged.

When Your Startup Outgrows 'The CTO Handles Security'

Removed the market-rate figures for fractional security engagements (INR 60,000 to 2,60,000 per month) and full-time CISO salaries in India (INR 40 to 80 lakh per year). Neither has a published rate card to cite.

Zero Trust for Series A SaaS Startups: Worth It?

Removed the unsourced "~60 to 70 percent of the security value at ~10 to 15 percent of the cost" figures for the five-principle subset. The argument that the subset carries most of the value for a fraction of the cost is unchanged.

Zero Trust for Series A SaaS Startups: Worth It?

Updated the Microsoft Digital Defense Report link, which now pins to the 2024 edition, and removed the "2023" edition label that no longer matched it.

Found something wrong?

Tell us and we will check it. If we got it wrong we will change the page and add the correction here, whether or not you are a customer. Our sourcing standard is on the editorial policy page.

Report an error