Corrections
When we publish something that turns out to be wrong, we change it and say so on the page it appeared on. This is every one of those, in one place, newest first.
189 corrections across 70 pages. Most recent: 18 September 2026.
What counts as a correction
One test: would a reader who acted on the old version have been misled? If we published a figure that was wrong, cited a standard that does not say what we said it said, or attributed a requirement to a regulator that the regulator never imposed, that is a correction and it is on this page.
Changing a price, adding a service or changing how we package our work is not a correction. Nothing was wrong before, so nobody was misled, and listing those here would make ordinary changes look like mistakes. Those show up as an effective date on the page they affect.
18 September 2026
Added our free monthly external attack surface scan to the clause 2.7.1 discussion. This page said the 30 day vulnerability scanning leg was not something we provide, while we run a free monthly scan and email the report. That was wrong by omission and it cost the reader money: they were sent to buy something we give away. The entry now states what the scan covers, and states plainly what it does not, since it reads the internet-facing surface only and 2.7.1 applies to every system that stores, processes or transmits Amazon data. We mark corrections inline rather than editing them away, because a reader who acted on an earlier version deserves to see what changed. Dates below are **our review dates**, not Amazon's change dates. We read the full live policy on 9 August, 22 August and 29 August 2026, and Amazon's restructuring of clause 2.7 took effect on **25 November 2025**, so it predates all three. Our 9 August review did not catch it, which is why earlier versions of this page described the pre-restructure text.
17 September 2026
Corrected the retest promise, which was **slower than what we actually offer**. This page said the free retest happens "within one month of the v1.0 report" and stopped there. One month is the outer bound, not a waiting period: we retest sooner when your fixes are in. `/pricing/` has always stated both halves; this page published only the half that costs the reader time.
Reframed the "where we fit" section. Three consecutive headings read "not from us", followed by "What nobody can sell you". Every statement was true and the section still answered the wrong question for someone deciding whether to hire us. The same content now leads with what we deliver against each leg of clause 2.7: the test and the evidence package from us, and specifically what satisfies the scanning and code-scanning legs so a submission goes in complete. Nothing was softened: Amazon still decides, and no vendor issues a DPP certificate.
🔴 **Corrected the scope count and the price for a DPP engagement, in both places this page quoted them.** The page said a DPP submission is "the Growth Pentest, INR 1,79,999 for two scopes over 10 business days", and separately that "a two scope engagement covering the integrating application and its API backend maps cleanly onto a typical SP-API integration". **That was a two scope anchor on a four scope job.** Clause 2.7.2 names four categories, and covering them normally takes four scopes: web application, API backend, cloud environment and network. Where effort allows we cover it in three, usually by testing the application and its API surface together. At Growth's published rates that is INR 2,54,998 at three scopes or INR 3,29,997 at four, not INR 1,79,999, and 15 or 20 business days rather than 10. Publishing the base price for a job that is not the base scope is the exact failure this page criticises other vendors for, and it was ours.
Corrected how the scope compression works. A first pass at the correction above said we cover four categories in three scopes "by testing the application and its API surface as a single scope". That is not what happens. **The web application and the API backend are tested as separate scopes**, because the effort, the test cases and the threat surface differ between them. What is combined is the **report**, not the testing, because a reader following one system should not need two documents open. So a four scope engagement can arrive as three reports, and the document count is not the scope count. The error mattered in the direction that makes the work look cheaper than it is, which is the same failure as the price correction above.
Added the Letter of Engagement alongside the Letter of Attestation. A DPP submission takes both documents from us and this page named only one of them. Both are issued on the Growth plan.
🔴 **Replaced the quoted text of section 2.7. The version printed here was the pre-restructure wording, and it had been wrong since 25 November 2025.** This page said "here is section 2.7 in full" and then quoted a single flat paragraph, while its own key findings correctly described 2.7 as four numbered subsections. Both statements were on the page at once. Three specific errors in that quote: the preamble omitted "documented vulnerability management" before "plan and/or runbook"; a sentence about protecting "physical hardware containing PII" no longer appears in the policy at all; and the remediation clause was quoted as "critical risk impact vulnerabilities", where the policy now reads "Critical vulnerabilities: 7 days from discovery". **The cause was ours, not Amazon's.** Our 22 August 2026 update applied the restructure to the summary and the key findings and never went back to the quote, so the most authoritative-looking element on the page was the only one still carrying the old text. Section 2.7 is now set out subsection by subsection, checked against the live policy on 17 September 2026.
Corrected the leg count from three to four, in five places. Clause 2.7.1 sets **three** minimum requirements, not two: 30 day scanning, **change-triggered scanning following significant network, application or infrastructure changes**, and per-release code scanning. The change-triggered requirement was absent from this page entirely. It matters commercially, because it has no interval attached, so a scanning contract on a fixed cadence does not satisfy it. Added to the "where we don't fit" section as a leg we do not sell.
Clarified that the 2.7.3 remediation clocks attach to findings from vulnerability scanning and code scanning as well as from penetration testing. The page previously implied they were pentest clocks.
7 September 2026
Added CERT-In Vulnerability Note CIVN-2026-0442, published two days after this article, which covers the same Keycloak flaw and corroborates the upstream-versus-Red-Hat version split stated here.
5 September 2026
Removed the "INR 2 to 5 lakh per year" compliance-tooling band and the surrounding first-year cost breakdown. The 2026-08-09 note below recorded this removal, but the figure survived in the Key findings list, so the correction had never actually been applied to the page. The section now names the four line items to budget for and says plainly that only the penetration test has a published price.
Corrected the pentest duration from "7 to 10 days" to the business-days model: one scope is 5 business days, two scopes 10, scopes sequential by default. Calendar-day framing was replaced across the site on 2026-07-17 because it is ambiguous about weekends, and this page had not been swept.
Reframed the closing section and the decision table. The page previously said Cybersecify does "offensive security (penetration testing and red teaming)". Red teaming is not a service we sell and is not in our service list, so the claim was removed. The decision table routed readers with a compliance deadline to a "fractional security team", which we also do not offer. The post now states plainly which of the three options we do and do not provide, and points to penetration testing and SOC 2 / ISO 27001 readiness, which are the two things on that checklist we actually deliver. The market survey of the three options is kept, because the reader genuinely faces that choice.
Removed the "INR 60,000 to 2,60,000 per month" market-rate figure for fractional security, in both the summary paragraph and the Option 3 cost line. The 2026-08-09 note below recorded this removal, but it had only been applied to the CISO salary figure and the FAQ answer, so the fractional band was still published in two places. Both now say there is no published rate card and direct the reader to price their own hours.
Replaced ISO 27001:2013 Annex A numbering with the 2022 controls in four places, including the FAQ answer that ships as structured data. The 2013 access-control clause became A.5.15 and A.5.16 for identity and access and A.8.2 and A.8.3 for least privilege; the 2013 logging clause became A.8.15 and A.8.16; the 2013 communications-security clause became A.8.20 for networks security. The 2022 revision has only A.5 to A.8, so the superseded numbers pointed at controls that no longer exist. (The old numbers are described rather than printed here, because a retired control number on a live page is exactly what our framework-identifiers gate exists to catch.)
4 September 2026
Replaced the unsourced "INR 10L to INR 5 crore" breach-cost band with the IBM 2026 India average, linked, and labelled as an all-sector average rather than a startup figure.
Removed the "USD 5,000 to USD 50,000" typical billing damage band and the "USD 0.01 to USD 0.10" per-call cost. Neither had a published source; per-token pricing is published by the providers and changes, and no dataset supports a typical-damage range. The control advice is unchanged.
Removed the vendor price figures that had no published source behind them: "USD 500 to USD 5,000 per month" and "USD 20,000 to 100,000 per year" for Patronus AI, Lakera Guard and WhyLabs, "USD 99 to 499 per month" for a guardrail tool, and "USD 449 per user per year" for Burp Suite Professional. The tools are still named and described; only the unsourced numbers are gone.
Added the source and check date for the Software Secured starting prices in the archetype table; the figures were attributed to the vendor but not linked or dated. Labelled the three-tier pricing benchmark as a market observation rather than a published rate card.
Removed the "₹30-50 lakh per year in wasted capacity at Indian SaaS market rates" figure. It had no published source, and the same class of salary band was removed from our outsourcing post on 2026-08-09. The point now asks the reader to run the arithmetic on their own engineering cost.
Removed the sentence "RBI's Master Direction on IT Governance, Risk, Controls and Assurance Practices (November 2023) requires regulated entities to conduct vulnerability assessment and penetration testing at least annually or whenever major changes are made to IT systems, and specifies that it be carried out by competent personnel holding appropriate certifications" from the FAQ answer on whether RBI or SEBI accept a DAST scan. That Master Direction (DoS.CO.CSITEG/SEC.7/31.01.015/2023-24) was repealed on 31 July 2026 vide circular DoS.CO.PPG.66/11.01.005/2026-27, and the body of this post already said so while the FAQ still cited it as the live requirement, so the stale version was shipping as FAQPage structured data. The answer now cites the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026.
Removed the clause "the 2023 IT Governance Master Direction (RBI/2023-24/107) no longer appears on RBI's current Master Directions index" from both places it appeared. The underlying fact is true, but an index listing is weak evidence: RBI still serves the 2023 document at its old URL with no withdrawal banner, so a reader who opens it sees a live-looking page. Both passages now cite the repeal circular DoS.CO.PPG.66/11.01.005/2026-27 and its Annex entry at Sr. 16 instead.
Added the entity class to every mention of paragraphs 151, 155 and 230. Those numbers were read from the Commercial Banks instrument, RBI/DoS/2026-27/410. The Directions are issued in seven per-entity-class versions and the parallel instruments were not opened, so an NBFC or Urban Co-operative Bank reader is now told to cite the paragraph in its own version.
Replaced "RBI's Master Direction on IT Governance, Risk, Controls and Assurance Practices (November 2023) is more explicit, calling for regular vulnerability assessment and penetration testing with documented methodology" in the India regulatory paragraph, for the same repeal reason. The documented-methodology point now rests on paragraph 154 of the 2026 Directions. --- **Built for AI-first and API-first SaaS startups.** Cybersecify is a founder-led security firm based in Bengaluru, India. Our team holds OSCP, CISSP, CEH, and ISO 27001 Lead Auditor certifications. Every engagement is run by the founders end-to-end. Strategy, methodology, manual testing, report sign-off, all of it. If you need a pentest report your auditor and enterprise customers can use, book a discovery call or review our pricing. **Related reading:** - What Is Penetration Testing? 2026 Startup Guide (the pillar guide) - Manual Pentest vs Automated Scanning: Startup Guide (methodology framing) - How to Evaluate a Pentesting Firm (the six questions to ask before signing) - Penetration Testing for SOC 2 Audit (compliance-specific guidance) - Sample Pentest Report (what auditor-grade reports actually look like) - Pricing (Startup Pentest INR 74,999 + Growth Pentest INR 1,79,999) - Methodology (PTES, OWASP WSTG v4.2, OWASP API Top 10 2023, NIST SP 800-115) - Book a Discovery Call (15-minute scope and timeline review)
Removed the "INR 50,000 to 5 lakh per year" shift-left tooling band and the security-engineer cost added to it. Neither had a published source; the tools are quoted per seat or per repository. Labelled the stage budget matrix as our own estimate.
Removed the "Large firms charge ₹3L+ and assign the work to the same junior analysts" claim. The price had no source and the staffing assertion about unnamed large firms was not something a reader could check. The point is now written as a question to ask any vendor.
Removed the first-year cost bands ("6 to 15 lakh", the per-line cost table, and the "6-15 lakh / 8-20 lakh" row in the ISO versus SOC 2 table). No certification body and no CPA firm publishes a rate card, so the post now describes how each line is priced and tells you to collect written quotes.
Removed the first-year and annual-maintenance cost bands for ISO 27001 and SOC 2 ("6 to 15 lakh", "10 to 25 lakh", "2 to 4 lakh", "8 to 20 lakh", "₹8 lakh"). No certification body and no CPA firm publishes a rate card, so the comparison now describes how each fee is quoted.
Removed the "₹5,000 to ₹20,000/month on most platforms" scanner subscription figure. Scanner vendors quote per application and per scan volume, and none of them publishes a rate card that supports a market-wide band.
Labelled the vendor-archetype pricing ranges as planning bands from quotes founders have shown us rather than market rates, and removed the in-house capability cost band ("INR 25 to 40 lakh per year"), which had no published source.
Removed the "INR 1 to 5 crore coverage is typical for boutique founder-led firms" insurance figure. No firm publishes its cover amount, so the claim was not checkable. The RFP now asks vendors to state the figure in writing.
Rebuilt the "Which RBI Guidelines Apply to You?" table. All four rows named instruments that RBI repealed on 31 July 2026 vide circular DoS.CO.PPG.66/11.01.005/2026-27: "Cybersecurity Framework for Banks, June 2016" (Annex Sr. 54), "Guidelines on IT Governance, Risk, IT & IS Audit, January 2023 (updated)" (this is the Master Direction at Annex Sr. 16, whose own header row is dated 7 November 2023; no RBI instrument carrying a January 2023 date could be sourced), "Master Direction on Digital Payment Security Controls, 2021" (Annex Sr. 29), and "IT Framework for NBFCs, 2017" (Annex Sr. 47). Each row also linked to rbi.org.in's homepage rather than to the instrument. The section now separates current instruments from repealed ones, names the repeal circular, and links the 2026 Directions to the Commercial Banks notification page.
Replaced every citation of those four repealed instruments elsewhere in the post, including three FAQ answers that were shipping the stale versions as FAQPage structured data: the "Which RBI cybersecurity guidelines apply to fintech startups?" answer that opened "Five main directives stack depending on your entity type and partnerships", the answer to "What are the Digital Payment Security Controls under the February 2021 Master Direction?" (the question itself is now about that Master Direction's repeal), and the clause "Findings should map to RBI Master Direction Digital Payment Security Controls (where applicable)" inside the pentest-scope answer. The lead direct-answer paragraph carried the same list and was rewritten too.
Removed "Annual VAPT is mandatory for all regulated entities under RBI guidelines" from the FAQ, and the matching "**Annual VAPT** is mandatory for all regulated entities" bullet from the VAPT section. It overstates coverage and understates cadence against what RBI actually wrote. The Commercial Banks version of the 2026 Directions sets vulnerability assessment at least once in every six months and penetration testing at least once in 12 months for critical information systems and those in the DMZ having a customer interface (paragraph 151), and a risk-based approach for everything else. Both passages now state that.
Added the entity class to every quoted paragraph number. Paragraphs 150, 151, 154, 155, 156, 159, 161, 182 and 230 were read in the Commercial Banks instrument (RBI/DoS/2026-27/410). The Directions are issued in seven per-entity-class versions and the other six were not opened, so nothing is asserted about their numbering.
Replaced "typically 2 to 6 hours for material incidents at directly-regulated entities" in the incident-timeline FAQ answer. No source was found for that range. The answer now cites paragraph 182 of the Commercial Banks instrument, which sets six hours from detection on RBI's DAKSH platform, and says the window has to be read from the version for your own entity class.
Removed the year claim "(2020, updated 2024)" attached to the Master Direction on Payment Aggregators and Payment Gateways, and the rbi.org.in homepage link on it. RBI's current Master Directions index carries a differently titled instrument regulating payment aggregators, and the year pair could not be sourced against it. The sentence now tells the reader to confirm the current title and date on the index.
Removed the "INR 1,50,000 - 5,00,000/year" managed SOC band. No managed SOC provider we are aware of publishes a rate card, so the row now says how the service is priced. The first-year total is now labelled as our own estimate rather than a market figure.
Removed the SOC 2 Type 1 cost breakdown ("₹3,00,000 to ₹8,00,000", readiness platform "₹1L to ₹2L/year", audit firm fees "₹2L to ₹5L") and the password-manager per-seat figure. Neither compliance platforms nor CPA firms publish list pricing. The stage-by-stage annual security spend bands are kept but are now labelled as our own estimates from client engagements.
Removed the "Big 4 cybersecurity practices typically start at INR 5 lakh+ per engagement" figure. The same class of Big 4 price band was removed from our DevSecOps post on 2026-08-09; none of those firms publishes a rate card.
Removed two further salary bands that survived the 2026-08-09 pass below and contradicted it: "INR 35 to 45 lakh per year" for a security hire and "INR 35 to 50 lakh" fully loaded. Neither had a published source.
Removed the sentence "ISO 27001 controls cover roughly 70 to 80 percent of RBI's baseline expectations" from the FAQ answer on how RBI compliance interacts with SOC 2 and ISO 27001. The 2026-08-09 note below recorded this removal, but the figure was only taken out of the body and survived in the FAQ frontmatter, where it was still shipping as FAQPage structured data. The answer now says ISO 27001 covers much of RBI's baseline expectations and states that no published source puts a percentage on the overlap.
Removed "Master Direction Digital Payment Security Controls (for payment system operators)" from the same FAQ answer's list of live RBI requirements. RBI repealed that Master Direction (DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21, 18 February 2021) on 31 July 2026 vide circular DoS.CO.PPG.66/11.01.005/2026-27. The answer now names the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 instead, notes they are issued per entity class, and says the 2021 circular was repealed.
Removed the SOC 2 auditor-fee bands and the ISO 27001 surveillance and recertification bands that survived the 2026-08-09 pass ("INR 4 to 8 lakh", "INR 6 to 12 lakh", "INR 10 to 18 lakh", "INR 3 to 5 lakh", "INR 5 to 8 lakh"). No CPA firm or certification body publishes a rate card. The DPDP and RBI figures stay but are now labelled as our own estimates from scoping that work rather than published market figures.
Removed the audit-fee bands that survived the 2026-08-09 pass. The FAQ, the opening summary, the comparison table and the GRC-platform note still carried "5 to 12 lakh", "8 to 20 lakh", "10 to 25 lakh" and "a ₹5 lakh platform" after the correction below said those figures had gone. No CPA firm and no GRC platform publishes a rate card, so the post now says the fee is quoted per engagement.
Removed the same auditor fee bands from the key-takeaways list, where they survived the 2026-08-09 pass below and contradicted it.
Removed the CPA audit-fee bands that survived the 2026-08-09 pass. The FAQ, the comparison table and the auditor-selection section still carried "₹5-12 lakh", "₹8-20 lakh" and "$15,000-40,000" for named categories of audit firm. No CPA firm on either side publishes a rate card, so the post now says the fee is quoted per engagement.
Labelled the vendor-archetype pricing ranges as planning bands from quotes founders have shown us rather than market rates. Only our own price in that table comes from a published price list.
Attributed the "$230 million in bounties" figure to HackerOne as its own published claim rather than stating it as fact. We do not have an independent source for it.
Removed the "6L to 15L" annual subscription band for Vanta, Drata and Sprinto and the claim that Sprinto is the most cost-effective of the three. Verified 2026-08-09: none of them publishes list pricing, so neither the band nor the ranking had anything behind it. Also removed the "4L to 8L" CPA audit fee band and the total derived from both, and labelled the remaining archetype ranges as planning bands rather than market rates.
Removed the scanner subscription price figures. "Qualys, Tenable, Wiz at INR 5,00,000 plus per year" and the "INR 5,000 to INR 50,000 per month" band had no published source behind them; those vendors quote per asset and per module. The pentest per-scope bands are unchanged and remain market observations.
Added the entity class to the quoted RBI paragraph numbers, in both places they appear. Paragraphs 151 and 155 were read in the Commercial Banks instrument (RBI/DoS/2026-27/410) only, and the post stated them as though they held across every entity class. The Directions are issued in seven per-entity-class versions and the other six were not opened, so an NBFC or Urban Co-operative Bank reader is now told to cite the paragraph in its own version.
Removed every mention of "RBI Master Direction on IT Governance and Cyber Security (April 2024)", in all three places it appeared: the FAQ answer on CERT-In re-audit cadence (which ships as FAQPage structured data), the fintech bullet under the annual-minimum trigger, and the India regulatory context section. No RBI instrument carrying that title and that date could be sourced. The only IT Governance Master Direction in RBI's own repeal Annex is DoS.CO.CSITEG/SEC.7/31.01.015/2023-24 dated 7 November 2023, which RBI repealed on 31 July 2026 vide circular DoS.CO.PPG.66/11.01.005/2026-27. Either way the citation was stale. All three passages now cite the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026.
Removed the claim that RBI directions "push toward 6-month or quarterly testing on payment-handling components". RBI's actual cadence in the Commercial Banks version of the 2026 Directions is vulnerability assessment at least once in every six months and penetration testing at least once in 12 months for critical and customer-facing systems (paragraph 151). Quarterly penetration testing is not what the text says. The bullet now states RBI's cadence and separates it from what fintech customers ask for contractually.
Added the entity class wherever a paragraph number is quoted. Paragraphs 151, 155 and 230 were read in the Commercial Banks instrument (RBI/DoS/2026-27/410) only. The Directions are issued in seven per-entity-class versions and the other six were not opened, so the numbering is not asserted for NBFC, UCB, SFB, Payments Bank, AIFI or CIC readers.
Removed the "typically INR 2 to 6 lakh and up" band for empanelled-vendor scope. Empanelled vendors do not publish rate cards, so the figure had nothing behind it. The advice to compare quotes at your own scope is unchanged.
Removed three repealed RBI instruments from the list of directives that reference CERT-In empanelled auditors: "RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices (banks and certain NBFCs)", "RBI Cyber Security Framework for Banks and subsequent updates", and "RBI Master Direction on IT Framework for the NBFC sector (above specific asset thresholds)". All three are in the Annex to circular DoS.CO.PPG.66/11.01.005/2026-27, by which RBI repealed 628 circulars on 31 July 2026. The section now points to the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 and names the repealed circulars as repealed. The Cyber Resilience and Digital Payment Security Controls Master Directions for non-bank Payment System Operators are unchanged: that is a different instrument, still current, and not in the repeal Annex.
Removed "RBI directives on cyber security for Urban Cooperative Banks at Level 2 and above (name empanelment explicitly)" and the same claim from the FAQ answer on whether RBI requires a CERT-In empanelled auditor, where it was shipping as FAQPage structured data. The two UCB cyber security frameworks it rested on (October 2018 and December 2019) were repealed on 31 July 2026, and the UCB version of the 2026 Directions has not been read, so the claim is unsourced for 2026 rather than confirmed or refuted. The post now says so.
Rewrote "Where the master direction names 'CERT-In empanelled auditor', empanelment is required" to reflect what the 2026 text actually says. In the Commercial Banks version (RBI/DoS/2026-27/410), paragraph 159 is conditional, applying only "in case of CERT-In empanelled auditors", and paragraph 156 asks for qualification, professional expertise, credentials and competency instead. The paragraph numbers are from the Commercial Banks instrument only; the other six entity-class versions were not opened and nothing is asserted about them.
Added the entity class to the quoted RBI paragraph numbers. Paragraphs 151 and 155 were read in the Commercial Banks instrument (RBI/DoS/2026-27/410) only, and the post stated them as though they held across every entity class. The Directions are issued in seven per-entity-class versions and the other six were not opened, so an NBFC or Urban Co-operative Bank reader is now told to cite the paragraph in its own version.
30 August 2026
Corrected an attribution. This page said internal systems testing is something "Amazon's guidance names alongside external-facing infrastructure". It is named in the Data Protection Policy itself, clause 2.7.2, not in the advisory security-controls guidance, and Amazon's wording in that clause is "public-facing and internal network boundaries". The policy binds; the guidance advises, so the earlier wording understated the requirement.
Rewrote the pricing answer. It presented the Startup plan as suiting "a single-surface integrator" and cited SOC 2 and ISO 27001 control mapping as what makes the Growth plan fit. Both were misleading for this buyer. Clause 2.7.2 enumerates four scope categories that one scope cannot reach, and the Letter of Engagement, which is the document Amazon receives, is issued on the Growth plan only. The DPP contains no SOC 2 or ISO 27001 requirement at all, so control mapping is useful to your auditors rather than to Amazon.
Corrected the date attribution on the clause 2.7 restructure. This page said "Amazon restructured 2.7 between those two dates", meaning between our 9 and 22 August 2026 reviews. That is wrong: Amazon's restructure took effect **25 November 2025**, nine months before our first review, and our 9 August review simply missed it. The "UPDATED" dates on this page are OUR review dates, not Amazon's change dates, and are now labelled as such.
29 August 2026
Corrected three word-frequency claims that decayed when Amazon restructured clause 2.7. We said the word "penetration" appears exactly once in the policy; it now appears five times, all inside 2.7. We printed the sub-clause headings as "2.7.1 Scanning", "2.7.3 Remediation" and "2.7.4 Disaster Recovery"; Amazon prints "Vulnerability Scanning", "Vulnerability Remediation" and "Disaster Recovery and Business Continuity". The policy URL we cited now redirects, and is updated to the current canonical path. Verified against the live policy on 29 August 2026.
Corrected two word-frequency claims. We said the Data Protection Policy "does not contain the word report at all"; it appears once, in clause 1.6.2, where it means reporting a Security Incident to Amazon rather than a pentest deliverable. We also said a search for "qualified", "tool" and "tooling" found none of them; "tool" appears once, in clause 2.6.1, as an example of a log-review mechanism ("e.g., SIEM tool"). The substantive points stand: Amazon sets no report format and names no testing tool. The policy URL we cited now redirects, and is updated. Verified against the live policy on 29 August 2026.
22 August 2026
Updated for Amazon's restructuring of Data Protection Policy clause 2.7 into sub-clauses 2.7.1 to 2.7.4, effective 25 November 2025. Clause 2.7.2 now names an "industry-recognized methodology", which it did not previously. Statements on this page about what Amazon does and does not publish were revised accordingly.
Tightened the answer to whether SOC 2 requires a penetration test. The page previously said SOC 2 does not explicitly mandate one but that most auditors expect one. It now states that the AICPA requires no penetration test for either Type I or Type II, and that a pentest is commonly accepted as evidence for CC7.1 and CC7.2, which is a different statement. The Type I and Type II guidance was also separated, because the two are not the same purchase.
15 August 2026
Corrected three cloud provider testing-policy references. The GCP answer previously linked to Google's Cloud Data Loss Prevention product page, which says nothing about penetration testing; it now cites Google's Cloud Security FAQ, which states you are not required to contact Google to test your own Cloud Platform infrastructure. The Azure answer previously implied Microsoft notification was required for certain testing; Microsoft's Security Testing Rules of Engagement instead require testing to stay within your own tenant or assets you have explicit authorization for. The AWS answer now names the specific prohibited activities the policy lists. All three provider pages checked 2026-08-15.
Removed the remaining unsourced India-operations claims about Sprinto and the other platforms, in the FAQ block and the body: INR billing and Indian billing entity, Indian auditor partnerships, India business-hours support, and the claim that Secureframe bills in INR through reseller agreements. None of these could be verified from the vendors' own pages. The USD-billing and support-timezone statements about Vanta and Drata are gone for the same reason. What replaces them is the difference that is checkable: Sprinto is India-headquartered and its published framework list names DPDPA (India) and RBI SAR, which the Vanta and Drata lists do not, checked 2026-08-15. On billing, the post now tells you to ask which entity issues the invoice and in what currency, which is the question that actually protects an Indian buyer signing an annual contract. Also removed the unsourced "200+ integrations" figure for Vanta. Integration counts are checkable on each vendor's own directory and change often, so the post now points readers there instead of asserting a number.
9 August 2026
Removed the unsourced "30 to 50 percent of the engagement fee" retest pricing figure, and replaced a "within 30 days" retest window with advice to confirm the window with the vendor, since windows differ by vendor.
Replaced precise percentages describing our own engagement data with qualitative wording. We do not publish a per-engagement findings register, so those figures were not something a reader could verify. The underlying observations are unchanged.
Added a direct link to our internal network pentest service page, which Amazon's guidance names alongside external-facing infrastructure. The page previously routed readers to the contact form without naming the service.
Removed the claim that Cloudflare reports BOLA in about 40% of all API attacks. The Cloudflare learning page we cited contains no percentage figures, so the number was attributed to a source that does not publish it. BOLA's prevalence is now stated using OWASP's own ranking and Salt Security's measured 27%.
Corrected "6 out of 10 API vulnerabilities cannot be found by automated tools" to 4 of 10, plus a fifth only rarely detected, which is what the scanner-versus-manual table on this page actually shows.
Replaced the percentage breakdown of this scan with proportional language. On a sample of 31 domains those percentages do not map to whole-number counts, and one of them was the sum of two independently rounded percentages rather than a count. The underlying observations are unchanged: none of the 31 domains was at full DMARC enforcement.
Removed a "static analysis catches 30 percent, dynamic 30 percent, manual pentest 40 percent" split previously attributed to the OWASP API Security Top 10. The OWASP API Security Top 10 2023 makes no claim about the relative effectiveness of static, dynamic or manual testing. The point is now made without the invented numbers.
Replaced per-engagement frequency statistics on this page with qualitative descriptions of what we find most often. The underlying observations are unchanged, but we do not publish a per-engagement findings register, so precise counts are not something a reader can check.
Sayfer was listed as an India-based boutique firm. Sayfer's own about page gives its location as Tel Aviv, Israel. Corrected.
Removed unsourced price ranges for vendor archetypes and for named categories of firm, and replaced them with "not published, ask for a quote" or with prices the vendor itself publishes. Where a figure is now given, it comes from that vendor's own pricing page.
Removed unsourced assertions about how named enterprise and Big 4 firms staff and prioritise engagements, including the "3 to 5x" empanelment premium multiplier and the claim that a small scope runs on a large firm's lowest-billable testers. The buyer advice is now written as questions to ask any vendor.
Removed the claim that compliance platforms do not deliver pentest in-house. Delivery models differ by platform and change over time; readers are now told to confirm with the platform.
Removed the unsourced "retest billed at 25 to 50 percent of the original engagement fee" figure. The advice to get the retest price in writing before signing is unchanged.
Aligned free-retest wording with our published terms: within one month of the v1.0 report.
Removed the "12x faster than GDPR" framing. On the like-for-like comparison, personal data breach reported to the data-protection regulator, India's own DPDP Rule 7 gives 72 hours, the same as GDPR. The page now explains what actually differs: one incident starts both clocks, and the CERT-In clock starts earlier, on suspicion rather than confirmation.
Replaced the note that the DPDP breach-notification timeline was still to be defined. Rule 7 of the DPDP Rules 2025 was notified on 13 November 2025.
Replaced precise percentages describing our own engagement data with qualitative wording. We do not publish a per-engagement findings register, so those figures were not something a reader could verify. The underlying observations are unchanged.
Removed the attribution of the defect-cost multiplier to "IBM Systems Sciences Institute". That organisation is not named anywhere in the NIST report we cite, and the IBM SSI study itself has no traceable published data set.
Corrected the multipliers to NIST Table 5-1 as published: 1X / 5X / 10X / 15X / 30X, not 1x / 6x / 15-30x. NIST labels the table "(Example Only)", which is now stated.
Updated the breach-cost figures from the IBM 2024 edition to the current 2026 edition: global average USD 4.99 million, India average INR 25.5 crore, up 15.9% year on year (IBM India, 3 August 2026). Removed an in-house USD conversion that had been printed inside an IBM-attributed sentence.
Replaced an unsourced "70 to 90 percent of a modern application's code is third-party" claim with a figure we can cite: 87% of audited codebases contained at least one open-source vulnerability (Black Duck OSSRA 2026).
Replaced several unsourced "80 percent of the risk" assertions with "most of the risk".
Removed the unsourced "SAST catches 50 to 70 percent of OWASP Top 10 categories" figure, and removed unsourced price bands for bug bounty programmes and Big 4 practices. None of those vendors publishes a comparable figure.
Updated the USD equivalent of INR 250 crore from roughly USD 30 million to roughly USD 26 million, at INR 95.24 to the dollar (August 2026).
Corrected the DPDP penalty description. INR 250 crore is not a flat per-violation cap; it is the highest amount in the Act's Schedule and applies to failure to take reasonable security safeguards, with INR 200 crore for breach-notification and children's-data failures and INR 50 crore for other contraventions. Our own DPDP compliance checklist already published the graduated schedule; this page now matches it.
Added GDPR Article 83(3), which provides that where several provisions are infringed in the same or linked processing operations, "the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement." The page previously presented both regimes as per-violation ceilings that stack.
Updated the USD equivalent of INR 250 crore from roughly USD 30 million to roughly USD 26 million, at INR 95.24 to the dollar (August 2026).
Replaced a European Data Protection Board link that now resolves to a public-consultations page with the EDPB documents index.
Removed the unsourced "90% automated and 10% manual" split attributed to lower-priced firms, and the unsourced "25 to 50%" retest price. Both are now written as questions to ask the vendor.
Replaced per-engagement frequency statistics on this page with qualitative descriptions of what we find most often. The underlying observations are unchanged, but we do not publish a per-engagement findings register, so precise counts are not something a reader can check.
Removed the unsourced "25 to 50 percent" and "30-50 percent" retest pricing figures. The advice to confirm whether the retest is manual, included, and time-bound is unchanged.
Replaced precise percentages describing our own engagement data with qualitative wording. We do not publish a per-engagement findings register, so those figures were not something a reader could verify. The underlying observations are unchanged.
Updated two source links that had moved: the AICPA SOC page and the IAF recognised accreditation bodies page.
Removed two unsourced percentages: "about 70% of the work overlaps" for teams coming from SOC 2, and "most Series A+ startups already cover 30-40% of controls". Neither traces to a published source.
Corrected the SOC 2 and ISO 27001 control-overlap figure. Neither AICPA nor ISO publishes an overlap percentage; the 40 to 85% range is Drata's own estimate and is now attributed as such. Removed a separate unsourced "60% easier" claim about the second framework.
Updated an AICPA source link that no longer resolves to the SOC page it cited.
Removed the unsourced "30 to 60%" scanner false-positive rate and the paired "under 5%" figure for manual testing. Neither traces to a published study.
Removed a "78.3% attack success rate" figure previously attributed to Palo Alto Networks Unit 42. The cited Unit 42 article (5 December 2025) contains no percentage figures and is a proof-of-concept demonstration, not a measured success rate.
Re-attributed the 8.5% OAuth adoption figure to its original publisher, Astrix Security (October 2025, 5,205 GitHub repositories), rather than to NimbleBrain's registry scan, and corrected "OAuth 2.1" to "OAuth", which is what Astrix measured.
Re-attributed the 43% command injection figure to Equixly (29 March 2025) and noted the sample size is unpublished.
Updated the Vulnerable MCP Project count from "over 50 by April 2026" to the tracker's actual current figures: 50 vulnerabilities, 13 critical, as of August 2026.
Replaced an unsourced "USD 8,000 to 25,000" international pentest price band with published figures from Software Secured's pricing page, checked August 2026.
Removed a "78.3% of audited MCP servers" figure previously attributed to Palo Alto Networks Unit 42. The cited Unit 42 article, "New Prompt Injection Attack Vectors Through MCP Sampling" (5 December 2025), contains no percentage figures and is a proof-of-concept demonstration rather than a population audit.
Re-attributed the 43% command injection figure to its original publisher, Equixly, 29 March 2025, and noted that Equixly does not publish its sample size.
Replaced an unsourced "30+ MCP-related CVEs in Jan-Feb 2026" claim with the current count from the Vulnerable MCP Project tracker: 50 vulnerabilities, 13 critical, as of August 2026.
Expanded three bare "seg2_app" source attributions to the full Microsoft Learn URL, and corrected one that attributed the 14 day, 60 day and fee-scale figures to seg2_app when they appear on the Microsoft 365 Certification framework page.
Hedged the 50 percent control-approval gate. The requirement appears under Penetration Testing Delivery, the section describing the test Microsoft arranges through its partner, so readers are now told to confirm with their certification analyst how it applies to an independently commissioned test.
Removed the unsourced "30 to 50 percent of the original engagement fee" retest figure and the motive attributed to vendors who bill retest separately. The advice to get the retest price in writing before signing is unchanged.
Replaced per-engagement frequency statistics on this page with qualitative descriptions of what we find most often. The underlying observations are unchanged, but we do not publish a per-engagement findings register, so precise counts are not something a reader can check.
Removed the unsourced "60 to 70 percent manual" and "80 to 90 percent automated" split figures. The underlying test, that a business-logic engagement should be mostly manual, is unchanged.
Removed the unsourced "25 to 50 percent of engagement fee" retest pricing figure in all three places it appeared, along with the motive attributed to vendors who bill retest separately. The advice to get the retest price in writing before signing is unchanged.
Updated the IBM breach-cost comparison from the 2024 edition to the current one. IBM's Cost of a Data Breach Report 2026 puts the India average at INR 25.5 crore, an all-time high and a 15.9 percent rise on 2025, replacing the INR 19.5 crore figure previously published (IBM India newsroom, 3 August 2026). The derived percentages and ratio were recalculated: a pentest at INR 75,000 to 1,80,000 is 0.03 to 0.07 percent of the average, a ratio of roughly 1,400 to 1 to 3,400 to 1, correcting the earlier "about 1,000 to 1".
Removed the global USD breach-average figure and the USD conversion of the India figure, neither of which could be verified against IBM's own current publication.
Removed unsourced cost bands for SOC 2 Type 2 audits and ISO 27001 certification. Neither audit firms nor certification bodies publish rate cards.
Corrected the Cobalt pricing link, which had moved to /platform/pricing, and the name of Astra's second pentest tier, which is Pentest Plus.
Removed the unsourced "30 to 50 percent of original engagement cost" figure for a paid retest. The advice to pick a vendor whose engagement includes the retest is unchanged.
Replaced a frequency statistic for Supabase RLS misconfiguration with a qualitative description. We do not publish an engagement register a reader could check it against, so it is now described qualitatively. It remains the most common gap we see.
Removed the unsourced "25 to 50 percent of engagement fee" retest pricing figure and the motive attributed to vendors who bill retest separately. The red flag is now the absence of a disclosed retest price before signing, which is the thing a buyer can actually check.
Removed the unsourced "3 to 5x" quote-variance multiplier and the assertion that vendors anchor quotes on a founder's perceived spend. The advice to disclose a budget range is unchanged; the reason given is now the observable one, that quotes for the same written scope vary widely.
Replaced the engagement-frequency statistic on this page with a qualitative description. We do not publish a findings register that a reader could check against, so the observation is now stated qualitatively rather than as a count.
Updated the Garak repository link. The project has transferred to the NVIDIA organisation on GitHub.
Removed the claim that ISO 27001:2022 covers "approximately 70 to 80 percent" of RBI's baseline cybersecurity expectations. No source supports a coverage percentage against a regulator's expectations, and the claim sat in a FAQ answer aimed at RBI-regulated buyers. The named control areas ISO 27001 does cover, and the named gaps where RBI goes further, are unchanged.
Removed the "most startups are 20-40% compliant" baseline, which had no source.
Removed the "INR 5 to 12 lakh" Series A security and compliance budget band and the "less than 1% of the round" figure derived from it. Neither had a source, and SOC 2 audit fees in particular are quoted per engagement with no published rate card. The stage-by-stage sequencing advice is unchanged.
Removed the unsourced "~80% of startup needs" coverage figure for free SBOM tooling, in both places it appeared. The recommendation to start with Syft, Trivy and the GitHub Dependency Graph is unchanged.
Dated the Pearce et al. Copilot study to 2021 and added its sample (1,689 programs across 89 scenarios), so the roughly 40 percent vulnerable figure is not read as a measurement of current models.
Removed eight market percentages that had no published source: "deal-blockers in 90 percent of enterprise questionnaires", "four sender types drive 95 percent", "required by 70 percent of US / 40 percent of EU / 20 percent of Indian enterprise buyers", "substitute controls accepted by 70 percent", "unblocks 60 to 80 percent", and the "80 percent" and "80 to 90 percent" self-service coverage estimates. The advice each supported is unchanged and now reads qualitatively. The gap-rate thresholds are retained because they are a threshold the reader measures on their own questionnaire, not a market statistic.
Updated the Shared Assessments SIG link, which now sits behind a login wall at the previous URL.
Updated the international currency conversion table to rates as of 2026-08-08.
Removed the senior-pentester salary and fully-loaded cost bands (INR 25 to 35 lakh salary, INR 33 to 50 lakh fully loaded) and the "4 to 6 scopes per year" and "5 to 10x lower annual cost" figures derived from them. None had a published source. The in-house versus outsource comparison is now framed as arithmetic the reader runs with their own numbers, against our published engagement price.
Removed the unsourced "30 to 50% extra" retest pricing figure. The advice to get the retest price in writing before signing is unchanged.
Updated the international currency conversion table to rates as of 2026-08-08. The previous table used 2026-06-24 rates, at which point 1 USD was around INR 84; it is now around INR 95, so the USD equivalents fell.
Corrected the SOC 2 to ISO 27001 control overlap attribution. The 40 to 85 percent range was described as "Drata's 2024 control mapping analysis". It is an estimate on a Drata marketing page dated 31 March 2026, and Drata's own wording is "estimated". Neither AICPA nor ISO publishes an overlap figure.
Removed the "30 to 50 percent incremental effort" figure for layering ISO 27001 onto an existing SOC 2 programme, and the ISO 27001 certification and consulting cost bands. Neither had a source, and no certification body publishes a rate card.
Removed the claim that ISO 27001:2022 covers "70 to 80 percent" of RBI's baseline expectations. No source supported a coverage percentage against a regulator's expectations. The named gap areas where RBI goes beyond ISO 27001 are unchanged.
Updated the AICPA SOC deep link, which no longer resolves.
Removed the SOC 2 cost figures sourced to compliance-platform marketing blogs. The Sprinto page we cited actually gives USD 30,000 to 150,000, not the USD 25,000 to 50,000 we published; the Scrut page gives USD 30,000 to 100,000; and the Neumetric figure of INR 4 to 8 lakh is a total certification cost including consulting and travel, not an audit fee, from a page published in March 2023. No audit firm on either side publishes a rate card, so the post now says so and tells readers to get written quotes.
Removed the "India CPA fees are typically 30 to 50 percent lower than US equivalents according to industry sources" claim. It named no source, and the Scrut page cited in the same paragraph undercut it.
Corrected the attribution on the SOC 2 to ISO 27001 control overlap. The 40 to 85 percent range is Drata's own estimate on a page dated 31 March 2026, not a measurement, and neither AICPA nor ISO publishes an overlap figure.
Updated the AICPA SOC deep link, which no longer resolves.
Removed the SOC 2 auditor fee bands (INR 4 to 8 lakh fieldwork, INR 6 to 10 lakh total). No CPA firm publishes a rate card, so the table now says the fee is quoted per engagement. The phase durations and activities are unchanged.
Removed the "₹5-15 lakh per year" cost for compliance automation platforms. Verified 2026-08-09: Vanta, Drata and Secureframe all route to a quote request and publish no list pricing, and Sprinto and Scrut publish no rate card either.
Replaced the uncited "about 70-80% overlap" between SOC 2 and ISO 27001 with the only figure that has a traceable owner: compliance vendor Drata's estimate of 40 to 85 percent, labelled as a vendor estimate. Neither AICPA nor ISO publishes an overlap figure.
Updated the AICPA SOC deep link, which no longer resolves.
Removed the unsourced "30 to 50 percent of the original engagement fee" retest pricing figure and the motive attributed to vendors who charge it. Corrected the retest window wording to match our published terms, one month from the v1.0 report.
This post stated that Astra Security gated its pentest pricing behind a sales call and that Software Secured published no sticker prices. Both publish prices. Astra lists Pentest Basic at USD 1,999 per year and Pentest Plus at USD 5,999 per year (getastra.com/pricing); Software Secured lists eleven starting prices including Web and API from USD 10,800 and PTaaS from USD 21,400 (softwaresecured.com/pricing). Both verified 2026-08-09.
Added Cobalt.io's published USD 3,500 per Autonomous Pentest price (cobalt.io/platform/pricing), which the post previously described as quote-only.
Removed unsourced price bands and multipliers for third-party vendors, including the enterprise "3 to 5x boutique rates" figure and the PTaaS annual-commitment ranges. The persona table now shows published prices only.
Corrected USD equivalents of our own INR pricing to August 2026 rates: INR 74,999 is around USD 790 and INR 1,79,999 is around USD 1,890, replacing the stale USD 900 and USD 2,180 figures.
Astra Security and Cobalt.io were described as quote-only. Both publish pentest prices, now cited and linked: Astra Pentest Basic USD 1,999/yr and Pentest Plus USD 5,999/yr (getastra.com/pricing), Cobalt Autonomous Pentest USD 3,500 per test (cobalt.io/platform/pricing).
Removed unsourced price multipliers and price bands attributed to named third parties, including the "3 to 5x boutique pricing" enterprise premium, the freelance "30 to 50 percent below boutique" figure, the PTaaS annual-commitment range, and the per-persona INR pricing column for vendors that do not publish prices.
Replaced assertions about how named enterprise and Big 4 firms staff and deliver engagements with questions a buyer can ask any vendor. The underlying advice is unchanged.
Corrected the description of how compliance automation platforms handle pentest. Whether a pentest is bundled, referred, or out of scope varies by platform and by plan, so the post now tells buyers to ask rather than asserting a single model. Removed the claim that a platform margin sits on top of the partner's price, which was unsourced.
Removed the INR and USD audit-fee bands attributed to Deloitte, EY, KPMG and PwC India, to named US mid-market firms, and to the boutique and mid-tier categories. None of these firms publishes a rate card, so the post now gives the relative ordering and tells buyers to get written quotes at their own scope.
Removed the compliance-platform subscription band for Vanta, Drata and Sprinto. Verified 2026-08-09: none of them publishes list pricing.
Replaced assertions about how Big 4 practices staff and review SOC 2 engagements, and about whether they share redacted sample reports, with questions to ask every firm on a shortlist.
Removed the 80 / 15 / 5 percent split for what triggers a SOC 2. The split had no source; the ordering of the three triggers is unchanged.
Reframed how this page described compliance-platform partner directories, and removed a statement about our own listing status that did not accurately describe the position. The advice to evaluate any vendor on the 7 SOC 2 criteria is unchanged, and it applies to how you found the vendor rather than to the directory itself. We work with whichever platform and auditor the customer has already selected.
Removed the unsourced "30 to 50 percent of the original engagement fee" retest pricing figure and the motive attributed to vendors who charge it. The advice to get the retest price in writing before signing is unchanged.
Removed every INR annual price band attributed to Vanta, Drata, Sprinto, Secureframe and Tugboat Logic, and the auditor and consulting fee bands alongside them. Verified 2026-08-09: Vanta, Drata and Secureframe all route to a quote request and publish no list pricing, and Sprinto publishes no rate card either. The post now says so and tells buyers to ask each vendor for a quote at their seat count and framework scope.
Removed the "15,000 to 3 lakh INR" VAPT cost range and the sub-ranges under it. They had no source, and a companion post on this site published a different range for the same question. Our own published price is unchanged and is now the only figure quoted.
Removed the "10 to 30 percent in our experience" false-positive figure for vulnerability assessment output. The point that unverified scanner findings carry a meaningful false-positive rate is unchanged.
Removed the "N out of 10" frequency figures attached to each finding. We do not publish an engagement register a reader could check them against, so the relative frequency is now described in words rather than as a ratio. The findings themselves, and their ordering, are unchanged.
Removed the "30-60% false positives" and "under 5% false positive rate" figures from the report comparison table. Neither had a published source. The distinction the row makes, between manually verified findings and unverified scanner output, is unchanged.
Removed the unsourced "80% of what enterprise questionnaires and auditors ask for" figure, replaced with "most".
Updated the AICPA SOC deep link, which no longer resolves.
Removed the "about 70%" control overlap figure between ISO 27001 and SOC 2. Neither AICPA nor ISO publishes an overlap figure, and the number conflicted with the range published elsewhere on this site.
Removed the "50,000 to 3 lakh INR" VAPT cost range. It had no source, and a companion post on this site published a different range for the same question. Our own published price is unchanged and is now the only figure quoted.
Removed the unsourced "25 to 50 percent of the engagement fee" retest pricing figure in all six places it appeared, along with the assertion that vendors who bill retest separately profit from findings staying open. The advice to get the retest price in writing before signing is unchanged. Also removed the unsourced "30 to 50 percent premium" figure for rush pricing.
Removed the unsourced "30 to 50 percent of the engagement cost" retest pricing figure. The advice to confirm the retest terms before signing is unchanged.
The CERT-In empanelled firm count of 237 is exact, counted from the list CERT-In published in July 2026, so "approximately" has been dropped. Removed the "grew from 150 firms in 2022, a 58% increase" comparison: the 150 baseline is an August 2023 figure, not 2022, and rests on a single source.
Updated the AICPA SOC deep link, which no longer resolves.
Removed the "pass rate hovers around 20-30%" figure. OffSec does not publish an OSCP pass rate, and no primary source for that range could be found. The description of what the exam actually requires is unchanged.
The CERT-In empanelled firm count of 237 is exact, counted from the list CERT-In published in July 2026, so "approximately" has been dropped. Removed the "up from 150 in 2022, a 58% increase" comparison: the 150 baseline is an August 2023 figure, not 2022, and rests on a single source.
Removed an unsourced "2 to 5 lakh per year" price band for compliance automation tooling. Verified 2026-08-09: Vanta, Drata and Secureframe all route to a quote request rather than publishing prices.
Updated an AICPA source link that no longer resolves to the SOC page it cited.
Removed the unsourced "~70 percent of the value" figure for native logs plus an acceptable-use policy. The recommendation to defer DLP tooling until the basics are in place is unchanged.
Removed the market-rate figures for fractional security engagements (INR 60,000 to 2,60,000 per month) and full-time CISO salaries in India (INR 40 to 80 lakh per year). Neither has a published rate card to cite.
Removed the unsourced "~60 to 70 percent of the security value at ~10 to 15 percent of the cost" figures for the five-principle subset. The argument that the subset carries most of the value for a fraction of the cost is unchanged.
Updated the Microsoft Digital Defense Report link, which now pins to the 2024 edition, and removed the "2023" edition label that no longer matched it.
Found something wrong?
Tell us and we will check it. If we got it wrong we will change the page and add the correction here, whether or not you are a customer. Our sourcing standard is on the editorial policy page.
Report an error