A vulnerability assessment finds and ranks a system's weaknesses through automated scanning and manual verification, without trying to break in. Under Indonesian bank regulation it isn't a cheaper substitute for a penetration test. It's the pentest's first step. SEOJK 29/SEOJK.03/2022 Chapter VII item 2 says vulnerability-analysis testing "begins with vulnerability identification, which is then followed by a penetration test", and makes that testing mandatory for banks that run digital banking services. On LKPP's e-Katalog, the Indonesian government's procurement catalogue, one seller lists a web application vulnerability assessment at Rp4,775,000 and a web application pentest at Rp38,304,000. That's an 8.0× gap between two listings whose scope text is word-for-word the same.
This piece is for the CFO and procurement team building the security budget line for a digital channel, and for the compliance head or CISO who signs it off. That includes group security teams outside Indonesia that fund testing for an Indonesian subsidiary: if your group budget treats VA and pentest as alternative tiers, the Indonesian rule for banks doesn't. Prices were read from katalog.inaproc.id, and regulation text from official copies, on 24 September 2026. Every price excludes Indonesian VAT (PPN) unless stated. Regulation numbers are kept as issued, "Article" translates Pasal, and translations of Indonesian text are ours.
OJK, the Financial Services Authority, sets no frequency. SEOJK 29 Chapter VII item 2 leaves it to the bank's "internal evaluation", driven by how critical the system is and by changes to the IT architecture. Bank Indonesia, which regulates payment systems, asks for continuous scanning, evaluated at least once a year. An ISO certificate lasts three years at most. The last column is our own arithmetic for one web application tested once a year.
| Budget line | What you receive | Which rule accepts it | Catalogue price per round | 3 years |
|---|---|---|---|---|
| Vulnerability assessment | A list of vulnerabilities from automated scanning and manual testing, with no attempt to break in | Banks: continuous vulnerability monitoring (SEOJK 29 Chapter IV item 4(c)), and the first stage of the Chapter VII test, not all of it. Payment service providers (PJP): an example of "cyber vulnerability scanning" (PADG 24/2024) | Rp4,775,000 (Rp5,300,250 with VAT); median of 15 VA listings Rp4,765,450 | Rp14.3 million; Rp57.3 million if run quarterly |
| Penetration test | Vulnerability identification, a penetration attempt within agreed limits, an initial report, a retest and a final report | Banks with digital services: SEOJK 29 Chapter VII item 2; POJK 11/2022 elucidation to Article 24(1). PJP: PBI 2/2024 elucidation to Article 30(c) | Rp38,304,000 (Rp42,517,440 with VAT); median of 94 listings Rp45,000,000 | Rp114.9 million; Rp135 million at the median price |
| ISO 27001 certification | A certificate for the information security management system inside the audited scope | BSSN Regulation 8/2020 Article 9, mandatory for strategic electronic systems. Not mentioned in OJK's or BI's cyber rules | Initial certification Rp63.1–128 million; surveillance audit for one scope Rp16–45 million | Rp208 million at one certification body, per organisation, not per application |
None of the three replaces another. For a bank with a digital channel the pentest is mandatory, and the VA is already inside it as step one. A standalone VA only covers the monitoring duty between two pentests. ISO 27001 answers to a different regulator, BSSN (the National Cyber and Crypto Agency), and audits a management system, not the gaps in your channel. Each regulator's reporting deadline is in the penetration testing calendar for Indonesian banks, read from the regulation text.
POJK 11/POJK.03/2022 (enacted 6 July 2022, promulgated 7 July 2022), Article 24(1), requires periodic "cyber security testing based on vulnerability analysis". The name says vulnerability. The example its elucidation gives is a pentest: "Examples of cyber security testing based on vulnerability analysis include penetration test."
SEOJK 29/SEOJK.03/2022 (enacted 27 December 2022) sets out the sequence, then closes the exit: "In particular, this testing must be carried out by Banks that provide digital banking services or other services operating online." The draft SEOJK that OJK published for public comment was blunter still: "vulnerability identification (vulnerability assessment) which is then followed by penetration testing". A draft isn't law. It does show what the regulator meant.
A VA on its own, bought against a "vulnerability testing" budget line, meets two other obligations: continuous vulnerability monitoring under Chapter IV item 4(c), and control 1.b item 1 of Appendix I.c, to "monitor all systems periodically to identify vulnerabilities". Both duties are real. The Chapter VII test isn't one of them.
One sentence can be quoted in defence of VA as the compliance option. Appendix I.b control 4.1.b item 5 refers to the "adequacy of a programme for periodic vulnerability identification or penetration test" (identifikasi kerentanan atau penetration test). That's a yardstick for judging whether a control is adequate, not the definition of the test. The definition sits in the body of Chapter VII, and its connector is "then followed by" (kemudian dilanjutkan), not "or". Misreading it has a cost. A breach of Articles 23–24 of POJK 11 draws a written warning, which can escalate to a ban on launching new products, suspension of specific business activities, or a lower governance rating in the bank's soundness assessment (Article 27).
PBI 2/2024 (enacted 18 April 2024), Article 30(c), requires "cyber vulnerability scanning, consistently and continuously", and its elucidation gives penetration testing as the example. PADG 24/2024 (enacted 31 December 2024) adds "vulnerability assessment" in the elucidation to Article 26(c). So for a PJP, a VA does count. But the elucidation to Article 53(2) names the "penetration test report" as supporting evidence for the annual cyber-security maturity report, due 31 January. A bank that also holds a PJP licence answers to both regulators.
PT Digital Aplikasi Solusi, which calls itself "Digiserve by Telkom Indonesia" on its own website, lists two paired services:
| Listing | Price | With VAT | Units sold | Catalogue category |
|---|---|---|---|---|
| Web Application Pentest (Blackbox/ Greybox) | Rp38,304,000 | Rp42,517,440 | 0 | Software Utility License |
| Web Application Vulnerability Assessment | Rp4,775,000 | Rp5,300,250 | 0 | Software Utility License |
The VA listing describes automated scanning and manual testing over five working days per application, which works out at about Rp955,000 a day. The pentest listing cites OWASP ASVS and CWE. Both carry an identical "Scope of Services" block, including "Performing penetration testing procedures" and "Conducting a retest". The words promise the same work. The prices don't. What you're really paying for is tester-days and headcount, and those two numbers have to be written into the scope of work (SoW). Our advice: if a vendor won't put them in writing, treat the quote as the price of a scan, whatever the listing is called.
VAT follows PMK 131/2024 (enacted 31 December 2024, in force 1 January 2025): a 12% rate applied to an "other value" of 11/12 of the selling price, which makes it 11% in practice.
We searched the catalogue for pentest, penetration testing, uji penetrasi (the Indonesian term), VAPT and vulnerability assessment, then removed tools, subscriptions, training and bundles:
Five sellers trading as "SOLUSI KLIK" list the same product names at near-identical prices. Take out that family and one other seller with the same pattern (38 listings in all), and the pentest median rises to Rp52,250,000 across 65 listings, while the VA listings fall to six. We classified by listing name and opened only about 20 listings one by one, so read the counts as estimates.
Telkom Indonesia, the state-owned telecoms company, lists VAPT Web Application in four tiers, each with one retest:
| Tier | Price | Scope, as the seller describes it |
|---|---|---|
| Lite | Rp18,474,100 | Public application with no login, up to 3 features, black box in development |
| Regular | Rp25,863,700 | Simple user management, up to 5 features, black box in development |
| Premium | Rp40,642,900 | MFA, up to 10 features and 4 APIs, black or grey box in development or staging |
| Plus | Rp48,032,600 | MFA or SSO, up to 20 features including financial transactions, workflow and user roles, 6 APIs, production as an option |
Only Plus looks like a banking channel, and three rounds of it cost Rp144,097,800. Humanis Siber Indonesia, a consultancy on BSSN's whitelist (Daftar Putih) of information security management consultants, prices by tester access for one website, two testers and two retests within two months: black box Rp55 million (up to 5 days), grey box Rp65–75 million (7 days), white box Rp95–100 million (10 days), all before VAT.
A listing's name doesn't guarantee what's inside it. The best-selling listing labelled penetration testing costs Rp5,350,000 and has sold 135 units, but its description names a "Pentest Management System" and states no number of days, no testers and no retest; it isn't among our 94. Another listing, Uji Penetrasi Aplikasi (application penetration test) at Rp14,225,225, opens its description with "Scanning to find out the vulnerability".
The number of targets multiplies everything. WEBARQ built the Insurance, Syariah and Securities divisional websites for BCA Group, with a CMS that runs multi-layer approval. Count them as three targets and one round at Digiserve's prices becomes Rp14,325,000 as a VA, or Rp114,912,000 as a pentest. That's an illustration of the arithmetic, not a claim that those sites were tested. One target or three is the vendor's call, and it's the first line worth negotiating. How to write that scope is in the penetration testing scope of work checklist for OJK's LKTPTI and BI reporting.
A full-text search of POJK 11/2022, SEOJK 29/2022, PBI 2/2024 and PADG 24/2024 doesn't find the word "ISO" once. The obligation comes from BSSN Regulation 8/2020 (enacted 16 November 2020, promulgated 23 November 2020). Article 9 requires SNI ISO/IEC 27001 for strategic electronic systems; those in the high category apply ISO 27001 and/or BSSN's own standards. The category comes from a self-assessment that BSSN verifies (Article 7). Certification is by a body BSSN recognises (Article 26), lasts at most three years, and must be renewed no later than three months before it expires (Article 28).
Certification bodies calculate audit days from the number of people in scope, using Annex C of ISO/IEC 27006-1:2024. Clause C.3.4 allows a square-root reduction for staff who perform identical activities (European Accreditation FAQ 48.6, September 2024). Cost is auditor-days times a day rate. CBQA Global Indonesia sells Surveillance II at Rp25,225,225 for two on-site audit days ("2 Onsite"), about Rp12.6 million a day. The listing doesn't say how many auditors, so that day rate is our estimate.
| Certification body (BSSN-recognised) | Service | Price | Units sold |
|---|---|---|---|
| TÜV NORD Indonesia | Surveillance | Rp16,000,000 | 0 |
| CBQA Global Indonesia | Surveillance II, 2 days on site | Rp25,225,225 | 0 |
| TÜV SUD Indonesia | Surveillance (two listings) | Rp26,000,000 and Rp32,000,000 | 1 and 1 |
| TSI Sertifikasi Internasional | Surveillance | Rp40,000,000 | 1 |
| TSI Sertifikasi Internasional | Surveillance, packages for provincial and for district/city governments | Rp45,000,000 | 16 and 23 |
| TÜV SUD Indonesia | Recertification | Rp47,500,000 | 1 |
| BSI Group Indonesia | Initial certification | Rp63,063,063 | 0 |
| SGS Indonesia | Initial certification | Rp72,000,000 | 0 |
| TSI Sertifikasi Internasional | Initial certification, Stage 1 and 2 | Rp128,000,000 | 1 |
One full cycle at TSI: Rp128 million + Rp40 million + Rp40 million = Rp208 million, "excluding 11% VAT, auditor accommodation and transport", according to its surveillance listing. A recertification cycle at TÜV SUD: Rp47.5 million plus two surveillance audits at Rp26–32 million each, so Rp99.5–111.5 million.
Two points for the terms of reference. First, check how long the body's recognition runs. The edition of BSSN's whitelist dated 22 September 2026 lists 11 certification bodies. BSI Group Indonesia's recognition ends on 19 April 2027, TSI's on 24 May 2027 and Bureau Veritas Indonesia's on 28 August 2027, all well before a three-year cycle bought today would finish. Ask for the renewal plan in writing. Second, narrowing the scope cuts the headcount counted, and so the audit days, but a certificate only vouches for what its scope statement says. How to read one is in our ISO 27001 certification vendor check.
Write these into the contract as conditions, not into the methodology section:
The map of evidence documents for every security layer is in types of cyber security and the documents that prove them.
Prepared by WEBARQ with AI assistance. Catalogue listings can change or be withdrawn at any time. Translations of Indonesian regulatory text are ours. This is not legal or tax advice.