Pricing

How Much Does a Penetration Test Cost?

Key takeaways
  • Traditional elite engagements commonly land in the $10k to $30k range, because they are priced in expert hours.
  • Five things move the number: scope size, depth, test type, environment complexity, and whether a retest is included.
  • Day-rate pricing transfers scope risk to you. A single fixed price after scoping does not.
  • Ask what happens when the tester finds something mid-engagement - if that triggers a change order, the quote was not a price.

A traditional penetration test from a strong firm commonly costs somewhere between $10,000 and $30,000 per engagement. The range is that wide because the work is priced in expert hours, and the number of hours depends on five things that vary enormously between one application and another.

That figure is also why so many organisations test once a year and call it a programme. It is not negligence, it is a budget line.

The five things that move the price

  1. Scope size. How many applications, how many APIs, how many distinct user roles. Roles matter more than people expect: testing authorisation properly means attempting to cross every boundary between every pair of roles, and that grows faster than the role count.
  2. Depth. A surface review of the login flow and a full attempt at chained exploitation are different products sold under the same name. This is the factor most often quietly reduced to hit a target price.
  3. Test type. Web application, API, network, mobile, and social engineering all carry different effort profiles. Black box costs more for less coverage, because the tester spends billable hours rediscovering what you could have handed over. See types of penetration testing for how each of those is scoped differently.
  4. Environment complexity. Single-tenant is simpler than multi-tenant. A monolith is simpler than forty microservices. Anything requiring bespoke setup, VPN access, or test-data provisioning adds hours before testing starts.
  5. Retest. Whether re-running the successful attacks after your fixes is included, or billed again later, or quietly absent.

Typical market ranges

Treat these as orientation rather than quotes. They reflect commonly observed market pricing and every one of them moves with the five factors above.

EngagementCommonly quoted rangeWhat you usually get
Single small web app, grey boxLow thousandsOne application, limited depth, often no retest
Standard web app plus APIMid five figures and belowReal depth on a defined scope, report and retest
Elite manual engagement$10k to $30kDeep, named testers, thorough reporting
Full-scope multi-app programmeWell above $30kSeveral applications, repeated through the year

The pricing model matters more than the number

Two quotes with the same figure can carry very different risk.

Day rates look transparent and transfer scope risk to you. If the estimate was ten days and the application turns out to be more complex, the overrun is yours. You also cannot compare two day-rate quotes meaningfully, because a day of a specialist and a day of a junior are both a day.

Fixed price after scoping puts that risk on the vendor. It requires them to actually look at your application before quoting, which is itself informative. This is the model we use: scope the engagement properly, then one number, no open-ended day rates.

The question that reveals the most about a quote: what happens if the tester finds something significant halfway through and following it takes longer than planned. If the answer is a change order, you were given an estimate, not a price.

Why the traditional number is what it is

None of this is vendors overcharging. A skilled application tester is genuinely expensive and genuinely scarce, and a thorough engagement is genuinely weeks of their attention. The price reflects the labour honestly.

The consequence is what deserves scrutiny. Because it is expensive, it happens rarely. Because it happens rarely, everything you deploy between tests is untested. And because it is priced by the hour, scope gets trimmed until the number fits - which is a decision about what will not be examined, made before anyone looks.

That is the constraint we set out to remove rather than discount: when the marginal cost of another test collapses, you stop rationing coverage and cadence. What that looks like in practice is on the platform page.

Getting an actual number

We do not publish a price list, for a reason that is not evasive: the number depends on the five factors above, and any figure quoted before looking at your application would be either padded or wrong.

What we do instead is scope it in about 45 minutes and send a single fixed price, so you know the full cost before any testing starts. That is a scoping call, not a sales sequence.

Frequently asked questions

How much does a penetration test cost?

Elite traditional engagements commonly run between $10,000 and $30,000, because they are priced in expert hours. Smaller single-application tests cost considerably less, usually with reduced depth and often without a retest included.

What makes one penetration test more expensive than another?

Scope size, depth of testing, the type of test, environment complexity, and whether a retest is included. Number of user roles matters more than people expect, because properly testing authorisation means attempting to cross every boundary between every pair of roles.

Is day-rate or fixed-price pentesting better?

Fixed price after scoping, in most cases. Day rates transfer scope risk to you: if the application is more complex than estimated, the overrun is yours. A fixed price requires the vendor to examine your application before quoting, which is useful information in itself.

Why does Intrudify not publish a price list?

Because cost depends on scope, depth and environment, so any figure quoted before looking at your application would be padded or wrong. We scope in about 45 minutes and send one fixed price, so the full cost is known before testing starts.

Related posts
Supply Chain arrayref: 86 Minutes of Compromise Compliance How to Prepare for a Security Audit Compliance SOC 2 vs ISO 27001: Which One Do You Actually Need?
Back to all posts