Read Time
Categories
Share
Government-catalogue prices for a vulnerability assessment, a penetration test and ISO 27001 certification, each matched to the OJK, BI or BSSN rule that accepts it, with the 3-year cost.

A vulnerability assessment finds and ranks a system's weaknesses through automated scanning and manual verification, without trying to break in. Under Indonesian bank regulation it isn't a cheaper substitute for a penetration test. It's the pentest's first step. SEOJK 29/SEOJK.03/2022 Chapter VII item 2 says vulnerability-analysis testing "begins with vulnerability identification, which is then followed by a penetration test", and makes that testing mandatory for banks that run digital banking services. On LKPP's e-Katalog, the Indonesian government's procurement catalogue, one seller lists a web application vulnerability assessment at Rp4,775,000 and a web application pentest at Rp38,304,000. That's an 8.0× gap between two listings whose scope text is word-for-word the same.

This piece is for the CFO and procurement team building the security budget line for a digital channel, and for the compliance head or CISO who signs it off. That includes group security teams outside Indonesia that fund testing for an Indonesian subsidiary: if your group budget treats VA and pentest as alternative tiers, the Indonesian rule for banks doesn't. Prices were read from katalog.inaproc.id, and regulation text from official copies, on 24 September 2026. Every price excludes Indonesian VAT (PPN) unless stated. Regulation numbers are kept as issued, "Article" translates Pasal, and translations of Indonesian text are ours.

Three budget lines: what each delivers, and the 3-year cost

OJK, the Financial Services Authority, sets no frequency. SEOJK 29 Chapter VII item 2 leaves it to the bank's "internal evaluation", driven by how critical the system is and by changes to the IT architecture. Bank Indonesia, which regulates payment systems, asks for continuous scanning, evaluated at least once a year. An ISO certificate lasts three years at most. The last column is our own arithmetic for one web application tested once a year.

Budget lineWhat you receiveWhich rule accepts itCatalogue price per round3 years
Vulnerability assessmentA list of vulnerabilities from automated scanning and manual testing, with no attempt to break inBanks: continuous vulnerability monitoring (SEOJK 29 Chapter IV item 4(c)), and the first stage of the Chapter VII test, not all of it. Payment service providers (PJP): an example of "cyber vulnerability scanning" (PADG 24/2024)Rp4,775,000 (Rp5,300,250 with VAT); median of 15 VA listings Rp4,765,450Rp14.3 million; Rp57.3 million if run quarterly
Penetration testVulnerability identification, a penetration attempt within agreed limits, an initial report, a retest and a final reportBanks with digital services: SEOJK 29 Chapter VII item 2; POJK 11/2022 elucidation to Article 24(1). PJP: PBI 2/2024 elucidation to Article 30(c)Rp38,304,000 (Rp42,517,440 with VAT); median of 94 listings Rp45,000,000Rp114.9 million; Rp135 million at the median price
ISO 27001 certificationA certificate for the information security management system inside the audited scopeBSSN Regulation 8/2020 Article 9, mandatory for strategic electronic systems. Not mentioned in OJK's or BI's cyber rulesInitial certification Rp63.1–128 million; surveillance audit for one scope Rp16–45 millionRp208 million at one certification body, per organisation, not per application

None of the three replaces another. For a bank with a digital channel the pentest is mandatory, and the VA is already inside it as step one. A standalone VA only covers the monitoring duty between two pentests. ISO 27001 answers to a different regulator, BSSN (the National Cyber and Crypto Agency), and audits a management system, not the gaps in your channel. Each regulator's reporting deadline is in the penetration testing calendar for Indonesian banks, read from the regulation text.

The regulation's "vulnerability" label already contains the pentest

POJK 11/POJK.03/2022 (enacted 6 July 2022, promulgated 7 July 2022), Article 24(1), requires periodic "cyber security testing based on vulnerability analysis". The name says vulnerability. The example its elucidation gives is a pentest: "Examples of cyber security testing based on vulnerability analysis include penetration test."

SEOJK 29/SEOJK.03/2022 (enacted 27 December 2022) sets out the sequence, then closes the exit: "In particular, this testing must be carried out by Banks that provide digital banking services or other services operating online." The draft SEOJK that OJK published for public comment was blunter still: "vulnerability identification (vulnerability assessment) which is then followed by penetration testing". A draft isn't law. It does show what the regulator meant.

A VA on its own, bought against a "vulnerability testing" budget line, meets two other obligations: continuous vulnerability monitoring under Chapter IV item 4(c), and control 1.b item 1 of Appendix I.c, to "monitor all systems periodically to identify vulnerabilities". Both duties are real. The Chapter VII test isn't one of them.

One sentence can be quoted in defence of VA as the compliance option. Appendix I.b control 4.1.b item 5 refers to the "adequacy of a programme for periodic vulnerability identification or penetration test" (identifikasi kerentanan atau penetration test). That's a yardstick for judging whether a control is adequate, not the definition of the test. The definition sits in the body of Chapter VII, and its connector is "then followed by" (kemudian dilanjutkan), not "or". Misreading it has a cost. A breach of Articles 23–24 of POJK 11 draws a written warning, which can escalate to a ban on launching new products, suspension of specific business activities, or a lower governance rating in the bank's soundness assessment (Article 27).

Payment service providers: VA is named, the pentest is still asked for

PBI 2/2024 (enacted 18 April 2024), Article 30(c), requires "cyber vulnerability scanning, consistently and continuously", and its elucidation gives penetration testing as the example. PADG 24/2024 (enacted 31 December 2024) adds "vulnerability assessment" in the elucidation to Article 26(c). So for a PJP, a VA does count. But the elucidation to Article 53(2) names the "penetration test report" as supporting evidence for the annual cyber-security maturity report, due 31 January. A bank that also holds a PJP licence answers to both regulators.

LKPP e-Katalog: 8.0× the price for the same scope text

PT Digital Aplikasi Solusi, which calls itself "Digiserve by Telkom Indonesia" on its own website, lists two paired services:

ListingPriceWith VATUnits soldCatalogue category
Web Application Pentest (Blackbox/ Greybox)Rp38,304,000Rp42,517,4400Software Utility License
Web Application Vulnerability AssessmentRp4,775,000Rp5,300,2500Software Utility License

The VA listing describes automated scanning and manual testing over five working days per application, which works out at about Rp955,000 a day. The pentest listing cites OWASP ASVS and CWE. Both carry an identical "Scope of Services" block, including "Performing penetration testing procedures" and "Conducting a retest". The words promise the same work. The prices don't. What you're really paying for is tester-days and headcount, and those two numbers have to be written into the scope of work (SoW). Our advice: if a vendor won't put them in writing, treat the quote as the price of a scan, whatever the listing is called.

VAT follows PMK 131/2024 (enacted 31 December 2024, in force 1 January 2025): a 12% rate applied to an "other value" of 11/12 of the selling price, which makes it 11% in practice.

One seller isn't a market: 94 pentest listings, 15 VA listings

We searched the catalogue for pentest, penetration testing, uji penetrasi (the Indonesian term), VAPT and vulnerability assessment, then removed tools, subscriptions, training and bundles:

  • 94 pentest or VAPT service listings from 52 sellers. Median Rp45,000,000; range Rp8,982,000 to Rp803,571,428. Only 11 of them have ever sold, 19 units between them.
  • 15 VA-only listings from 11 sellers. Median Rp4,765,450. Not one unit sold.
  • A median ratio of about 9.4×, close to the Digiserve pair.

Five sellers trading as "SOLUSI KLIK" list the same product names at near-identical prices. Take out that family and one other seller with the same pattern (38 listings in all), and the pentest median rises to Rp52,250,000 across 65 listings, while the VA listings fall to six. We classified by listing name and opened only about 20 listings one by one, so read the counts as estimates.

What pushes the price up: features, access, environment, number of targets

Telkom Indonesia, the state-owned telecoms company, lists VAPT Web Application in four tiers, each with one retest:

TierPriceScope, as the seller describes it
LiteRp18,474,100Public application with no login, up to 3 features, black box in development
RegularRp25,863,700Simple user management, up to 5 features, black box in development
PremiumRp40,642,900MFA, up to 10 features and 4 APIs, black or grey box in development or staging
PlusRp48,032,600MFA or SSO, up to 20 features including financial transactions, workflow and user roles, 6 APIs, production as an option

Only Plus looks like a banking channel, and three rounds of it cost Rp144,097,800. Humanis Siber Indonesia, a consultancy on BSSN's whitelist (Daftar Putih) of information security management consultants, prices by tester access for one website, two testers and two retests within two months: black box Rp55 million (up to 5 days), grey box Rp65–75 million (7 days), white box Rp95–100 million (10 days), all before VAT.

A listing's name doesn't guarantee what's inside it. The best-selling listing labelled penetration testing costs Rp5,350,000 and has sold 135 units, but its description names a "Pentest Management System" and states no number of days, no testers and no retest; it isn't among our 94. Another listing, Uji Penetrasi Aplikasi (application penetration test) at Rp14,225,225, opens its description with "Scanning to find out the vulnerability".

The number of targets multiplies everything. WEBARQ built the Insurance, Syariah and Securities divisional websites for BCA Group, with a CMS that runs multi-layer approval. Count them as three targets and one round at Digiserve's prices becomes Rp14,325,000 as a VA, or Rp114,912,000 as a pentest. That's an illustration of the arithmetic, not a claim that those sites were tested. One target or three is the vendor's call, and it's the first line worth negotiating. How to write that scope is in the penetration testing scope of work checklist for OJK's LKTPTI and BI reporting.

ISO 27001: priced by audit days, not by application

A full-text search of POJK 11/2022, SEOJK 29/2022, PBI 2/2024 and PADG 24/2024 doesn't find the word "ISO" once. The obligation comes from BSSN Regulation 8/2020 (enacted 16 November 2020, promulgated 23 November 2020). Article 9 requires SNI ISO/IEC 27001 for strategic electronic systems; those in the high category apply ISO 27001 and/or BSSN's own standards. The category comes from a self-assessment that BSSN verifies (Article 7). Certification is by a body BSSN recognises (Article 26), lasts at most three years, and must be renewed no later than three months before it expires (Article 28).

Certification bodies calculate audit days from the number of people in scope, using Annex C of ISO/IEC 27006-1:2024. Clause C.3.4 allows a square-root reduction for staff who perform identical activities (European Accreditation FAQ 48.6, September 2024). Cost is auditor-days times a day rate. CBQA Global Indonesia sells Surveillance II at Rp25,225,225 for two on-site audit days ("2 Onsite"), about Rp12.6 million a day. The listing doesn't say how many auditors, so that day rate is our estimate.

Certification body (BSSN-recognised)ServicePriceUnits sold
TÜV NORD IndonesiaSurveillanceRp16,000,0000
CBQA Global IndonesiaSurveillance II, 2 days on siteRp25,225,2250
TÜV SUD IndonesiaSurveillance (two listings)Rp26,000,000 and Rp32,000,0001 and 1
TSI Sertifikasi InternasionalSurveillanceRp40,000,0001
TSI Sertifikasi InternasionalSurveillance, packages for provincial and for district/city governmentsRp45,000,00016 and 23
TÜV SUD IndonesiaRecertificationRp47,500,0001
BSI Group IndonesiaInitial certificationRp63,063,0630
SGS IndonesiaInitial certificationRp72,000,0000
TSI Sertifikasi InternasionalInitial certification, Stage 1 and 2Rp128,000,0001

One full cycle at TSI: Rp128 million + Rp40 million + Rp40 million = Rp208 million, "excluding 11% VAT, auditor accommodation and transport", according to its surveillance listing. A recertification cycle at TÜV SUD: Rp47.5 million plus two surveillance audits at Rp26–32 million each, so Rp99.5–111.5 million.

Two points for the terms of reference. First, check how long the body's recognition runs. The edition of BSSN's whitelist dated 22 September 2026 lists 11 certification bodies. BSI Group Indonesia's recognition ends on 19 April 2027, TSI's on 24 May 2027 and Bureau Veritas Indonesia's on 28 August 2027, all well before a three-year cycle bought today would finish. Ask for the renewal plan in writing. Second, narrowing the scope cuts the headcount counted, and so the audit days, but a certificate only vouches for what its scope statement says. How to read one is in our ISO 27001 certification vendor check.

The clauses that make two quotes comparable

Write these into the contract as conditions, not into the methodology section:

  1. Unit of scope: per application, per feature, per API or per IP address.
  2. Login and roles: no login, as in Telkom's Lite tier, or a test account for every role.
  3. Environment: development, staging or production. On Telkom's ladder, production appears only in the most expensive tier.
  4. Tester access: black, grey or white box, because PADK OJK 1/2026 (enacted 23 January 2026, in force 1 March 2026) Format 3.2.14 has the bank declare it in its LKTPTI, the annual IT report to OJK.
  5. Retests: how many, and within what period. In the catalogue that runs from one (Telkom) to two within two months (Humanis).
  6. Reporting reference: SEOJK 29 Chapter VII for banks; PADG 24/2024 Article 53 for PJPs.
  7. Severity-scoring version: name it, for example CVSS v4.0 (published 1 November 2023) or v3.1.
  8. Price components: with or without VAT, and whether tester or auditor travel is included.

What this means for the budget line

  • CFO and procurement at a bank with a digital channel: budget a pentest per channel per round, with the VA as its first step, then a separate VA for monitoring between rounds. Swapping the pentest for a VA cuts that line by 87.5% and leaves the Chapter VII obligation unmet. Our view: that saving can't be defended in front of an OJK examiner.
  • Compliance and SKAI (internal audit): a report that contains only scan output isn't a Chapter VII item 2 test, and Format 3.2.14 will ask for the method and the environment.
  • Insurers, multifinance, pension funds, pawnbrokers and guarantors: POJK 4/POJK.05/2021 (enacted 9 March 2021) and SEOJK 22/SEOJK.05/2021 (24 August 2021) don't mention the pentest. SEOJK 22 Chapter V item 10(h) only asks that security controls be tested before a system goes live, and names no method, so in our view a manually verified VA is defensible here. Your sanction risk sits in the Personal Data Protection Law, UU 27/2022 (promulgated 17 October 2022), Article 35 and Article 39(1), sanctioned under Article 57 and covered in our DPIA guide for Indonesian banks and insurers.
  • CISO: an ISO 27001 certificate doesn't replace a pentest report on the channel. If the channel is being built with a website development partner, put the pentest and retest window into the project plan before go-live.

The map of evidence documents for every security layer is in types of cyber security and the documents that prove them.

Prepared by WEBARQ with AI assistance. Catalogue listings can change or be withdrawn at any time. Translations of Indonesian regulatory text are ours. This is not legal or tax advice.

Back to List