BlogProcess

How much does a penetration test cost, and what drives the price

An honest explainer on penetration testing pricing: why there's no single number, what actually drives the cost, and the red flags in a cheap quote.

"How much does a penetration test cost?" is a fair question with a frustrating answer: it depends. But it depends on specific, knowable things. So here's an honest breakdown of what moves the price, and how to tell a real quote from a cheap one.

Why there's no single price

A pentest is a professional service, priced mostly by the time skilled testers spend. A tiny marketing site and a sprawling banking platform are not the same job, so they can't be the same price. Anyone quoting a flat rate without asking about your scope is guessing.

What actually drives the cost

  • Scope size: how many applications, endpoints, IP ranges, or cloud accounts are in scope.
  • Depth: a broad surface-level test costs less than a deep, chained-exploitation engagement.
  • Complexity: custom business logic, multiple user roles, and unusual tech take more time.
  • Type of test: web, API, cloud, mobile, and social engineering each require different expertise.
  • Retest: a quality engagement includes re-testing fixed findings (we include it at no extra cost).

Day-rate vs. fixed-scope

Some vendors quote a day rate; others quote a fixed price for a defined scope. Fixed-scope is usually easier to budget, as long as the scope is written down clearly. Either way, the honest number comes after a short scoping conversation, not before.

Cheap "pentests" are usually scans

If a quote is suspiciously low and fast, it's very likely an automated vulnerability scan relabeled as a pentest. That's not the same thing, and it won't satisfy a serious auditor. (We cover the distinction in pentest vs. vulnerability scan.)

What "good" includes

A real engagement price should include manual testing by senior testers, a written report with reproduction steps and remediation, and a retest. If any of those are missing, the low price is telling you what you're not getting.

Red flags in a quote

  • A price before anyone asked about your scope.
  • No mention of a report or a retest.
  • "Automated" or "scan-based" testing described as a penetration test.
  • No named standards (OWASP, PTES, NIST).

Key takeaways

  • Price scales with scope, depth, and complexity. Expect a scoping conversation first.
  • Fixed-scope quotes are easier to budget when the scope is written down.
  • A real pentest includes manual testing, a proper report, and a retest.
  • A cheap, instant quote is usually a scan in disguise.

Want a real number for your systems? Get a tailored quote. Three quick questions, and we'll scope it honestly.

See what a finding looks like in a real reportDownload our free sample pentest report →

READY WHEN YOU ARE

See what an attacker sees.

Book a free 30-minute scoping call, or download our sample report first.