How much does a penetration test cost, and what drives the price
An honest explainer on penetration testing pricing: why there's no single number, what actually drives the cost, and the red flags in a cheap quote.
"How much does a penetration test cost?" is a fair question with a frustrating answer: it depends. But it depends on specific, knowable things. So here's an honest breakdown of what moves the price, and how to tell a real quote from a cheap one.
Why there's no single price
A pentest is a professional service, priced mostly by the time skilled testers spend. A tiny marketing site and a sprawling banking platform are not the same job, so they can't be the same price. Anyone quoting a flat rate without asking about your scope is guessing.
What actually drives the cost
- Scope size: how many applications, endpoints, IP ranges, or cloud accounts are in scope.
- Depth: a broad surface-level test costs less than a deep, chained-exploitation engagement.
- Complexity: custom business logic, multiple user roles, and unusual tech take more time.
- Type of test: web, API, cloud, mobile, and social engineering each require different expertise.
- Retest: a quality engagement includes re-testing fixed findings (we include it at no extra cost).
Day-rate vs. fixed-scope
Some vendors quote a day rate; others quote a fixed price for a defined scope. Fixed-scope is usually easier to budget, as long as the scope is written down clearly. Either way, the honest number comes after a short scoping conversation, not before.
Cheap "pentests" are usually scans
If a quote is suspiciously low and fast, it's very likely an automated vulnerability scan relabeled as a pentest. That's not the same thing, and it won't satisfy a serious auditor. (We cover the distinction in pentest vs. vulnerability scan.)
What "good" includes
A real engagement price should include manual testing by senior testers, a written report with reproduction steps and remediation, and a retest. If any of those are missing, the low price is telling you what you're not getting.
Red flags in a quote
- A price before anyone asked about your scope.
- No mention of a report or a retest.
- "Automated" or "scan-based" testing described as a penetration test.
- No named standards (OWASP, PTES, NIST).
Key takeaways
- Price scales with scope, depth, and complexity. Expect a scoping conversation first.
- Fixed-scope quotes are easier to budget when the scope is written down.
- A real pentest includes manual testing, a proper report, and a retest.
- A cheap, instant quote is usually a scan in disguise.
Want a real number for your systems? Get a tailored quote. Three quick questions, and we'll scope it honestly.