SaaSInsightBrowse reviews
Cybersecurity

How much a penetration test costs

A penetration test is priced as tester days, not as a product, which is why quotes for one estate differ threefold. Published starting figures run from $3,500 for an automated web application test to $27,120 for a fourteen day engagement. Most firms publish nothing and quote after scoping.

By Rajat Kapoor

Updated September 2026

Key takeaways

  • A quote is a day rate multiplied by testing days, so ask for both numbers separately before comparing two proposals.

  • Of the 43 cybersecurity firms we hold records for, four publish a penetration testing figure you could build a budget from.

  • A published starting price is almost always the narrowest possible scope, so treat it as a floor rather than an estimate.

  • Whether a retest after remediation is included can move the real cost of a project by 30 to 50 percent.

  • Grey box testing usually buys more depth for the same fee, because the testers are not spending paid days rediscovering what you already know.

  • SOC 2 does not require a penetration test; the demand usually comes from your customers, which means the scope is yours to set.

Someone has asked you for a penetration test. Usually it is a customer's security questionnaire, an insurer at renewal, or an auditor with a date in mind. You send the same short description of your systems to four firms, and the numbers that come back are $4,000, $12,000, $28,000 and a request for a scoping call.

That spread is not four opinions about the same job. It is four different jobs, and the cheapest one quite often fails the requirement that made you go shopping. This page explains what the number is built from, sets out what this market actually discloses about its own prices, and gives you the five things that move a quote so you can scope the work before anyone gets on a call. It does not tell you who to hire.

A test is priced as days, not as a product

Almost every quote you receive is a day rate multiplied by a number of days, with a report written on top. Nothing else in the proposal is doing much work. A firm charging $1,800 a day for an eight day engagement and a firm charging $2,400 a day for five days will quote $14,400 and $12,000 for what sounds like the same sentence, and the cheaper one buys you three fewer days of someone actually looking.

This is why a threefold spread on one estate is normal rather than suspicious. It is also why "how much does a penetration test cost" has no answer in the abstract, and why every page that gives you a range from a few thousand to fifty thousand is telling you nothing you can act on. The useful question is how many tester days your scope implies, and that is a question you can answer yourself.

The underlying method is not proprietary. NIST's Technical Guide to Information Security Testing and Assessment has described the same four phase execution process since September 2008, and most credible firms are running some version of it. What differs is how many days they put against each phase and who does the work.

What this market actually publishes

Of the 43 cybersecurity firms we hold records for, 13 publish a price of any kind. Fourteen of the 43 sell penetration testing. Four of those fourteen publish a figure you could build a budget from, and two of the four are platforms rather than consultancies.

Here is everything the four disclose, read on 14 September 2026.

  • Cobalt lists $3,500 per autonomous pentest of a web application on its pricing page. The page labels it a limited time offer and requires the test to be completed before 31 December 2026. Its Standard, Premium and Enterprise tiers carry no figure.
  • Synack publishes a full ladder on its pricing page: $4,181 for one AI led Sara pentest, $10,283 for one standard pentest, $27,120 for one fourteen day engagement, and Enterprise on request. It is the only firm here that lets you see the shape of the curve rather than one entry point.
  • Praetorian reports a $10,000 minimum project size and a $200 to $300 hourly rate on its Clutch profile. That is the firm's own declaration on a third party directory rather than a published rate card.
  • Sattrix Information Security reports a $1,000 minimum and $25 to $49 an hour on Clutch, which reflects an India based delivery model rather than a discount on the same service.

The other ten say nothing. Bishop Fox's penetration testing services page is representative: every engagement is tailored to your environment and threat landscape, and the next step is a contact form. NetSPI, Coalfire, TrustedSec and the rest are the same. Third party estimate sites will quote you a starting figure for several of these firms. Those are models, not disclosures, and the firms' own pages contradict the idea that a standing number exists.

Two things follow. A quote is the only way to price most of this market, so budget for the scoping call as part of the purchase rather than an obstacle to it. And a published figure is almost always an entry point for the narrowest possible scope, which is why Synack's ladder is worth more than three competitors' starting prices put together.

The five inputs that set the day count

Every one of these is something you can settle before you speak to anyone, and settling them is what makes four proposals comparable.

  1. Scope, counted properly. Not "our app" but the number of applications, the number of distinct user roles in each, the number of live external IP addresses, and whether the API is tested separately from the interface in front of it. Roles are the one people forget: an application with admin, manager and read only users is close to three applications for testing purposes.
  2. How much you tell them. A black box test starts from nothing and spends days on discovery. A grey box test hands over credentials and documentation, and buys you more depth for the same money. Unless you are specifically testing whether an outsider can get in, grey box is usually the better value and it is the default worth asking for.
  3. Who does the work. Firms staff engagements at different seniorities and rarely say so in the proposal. Ask how many of the quoted days are hands on keyboard testing rather than project management and reporting, and ask what certifications the people doing them hold. A day rate means nothing until you know whose day it is.
  4. Whether a retest is included. You will fix the findings and then need someone to confirm the fixes work. Some firms include one retest window, some sell it as a second engagement at close to the original price, and some cap it at a number of findings. This single term routinely moves the real cost of a project by 30 to 50 percent, and it is the term least likely to appear in the headline number.
  5. What the report has to survive. A report that lists findings by severity is cheaper to produce than one that carries reproduction steps, evidence and remediation guidance a developer can work from, and much cheaper than one written to be handed to an auditor or a customer's security team. Say which of the three you need, because you will be charged for whichever you asked for.

When an auditor is the reason you are buying

If a framework triggered this purchase, read what it actually requires before you scope anything, because the two common ones ask for very different things.

PCI DSS, currently at version 4.0.1 in the PCI Security Standards Council's document library, sets out penetration testing obligations under requirement 11.4. It expects internal and external testing on a defined annual cycle, testing again after significant change, and remediation and retesting of exploitable findings. The retest is not optional there, so a quote without one is not a quote for PCI compliance.

SOC 2 is the opposite case and is widely misunderstood. The Trust Services Criteria do not name penetration testing anywhere. Auditors commonly accept one as evidence for the monitoring criteria, and many customers ask for it by name, but the requirement usually comes from your buyer rather than from the standard. That matters commercially, because it means the scope is yours to set rather than the framework's, and a smaller honest engagement will often do.

The trap in both cases is the same. The cheapest test that satisfies a checkbox is rarely the test that finds anything, and you are allowed to buy either as long as you know which one you are buying.

Making two quotes comparable

Before comparing, rewrite each proposal as four numbers: total fee, number of testing days, day rate implied by dividing one by the other, and the cost of a retest stated separately. Most proposals will not give you the second number without being asked. Ask, in writing.

Frequently asked questions

How much does a penetration test cost?

Published starting figures in this market run from $3,500 for an automated test of a single web application to $27,120 for a fourteen day engagement, and most firms publish nothing at all. A quote is a day rate multiplied by testing days, so a small scoped web application test commonly lands in the low five figures and a multi application or network engagement well above it. Any range quoted without a scope behind it is marketing rather than a price.

Why do quotes for the same systems differ so much?

Because they are rarely for the same work. The usual causes are a different number of testing days, a different knowledge level, a different report standard, and whether a retest after remediation is included. Two firms can quote the same sentence you sent them and have priced eight days against five. Ask every firm for its day count and its day rate separately, and the spread usually explains itself.

Is a cheap penetration test worth buying?

It depends what triggered the purchase. An automated or lightly scoped test will produce a report and can satisfy a customer questionnaire, and for a small estate with no prior testing it is a reasonable first step. It will not find the logic flaws that only a person looking at your application finds. The honest framing is that you are buying either evidence or assurance, and the cheap end reliably delivers the first.

What is included in the price, and what is usually extra?

Included: scoping, the testing itself, and a report. Usually extra or capped: a retest to confirm your fixes, an executive summary written for a customer or auditor, a formal attestation letter, out of hours testing, and any social engineering component. The retest is the one that moves the number most, and it is the one least likely to be mentioned unless you ask.

Does SOC 2 require a penetration test?

No. The Trust Services Criteria do not name penetration testing. Auditors frequently accept one as evidence for the monitoring criteria and customers often ask for it by name, so in practice most companies pursuing SOC 2 buy one, but the obligation comes from your buyer rather than the standard. PCI DSS is different and does set out testing obligations directly, including remediation and retesting of exploitable findings.

Should I ask for a black box or a grey box test?

Grey box in most cases. Handing over credentials and documentation means the testers are not spending two or three of your paid days rediscovering things you already know, so the same fee buys more depth. Black box is the right choice when the specific question is whether an outsider with no prior knowledge can get in, which is a narrower question than most buyers think they are asking.

Where to go next