Pricing
Straightforward, fixed-scope pricing
No per-seat licenses, no generic packages, no hourly surprises — just clear starting prices by size, fixed exactly on a short scoping call.
By service
What each engagement costs
Figures below are starting points for a typical scope of each size. Not sure which size you are? Here's the shorthand:
Small
A single, focused target with a small and clearly contained scope.
Medium
A larger or multi-component environment with more attack surface to cover.
Large
Complex, high-volume, or several integrated systems that are tested together.
Web Application
OWASP Top 10 + business logic
API
REST, GraphQL & SOAP
Mobile Application
iOS and Android, both platforms included
Red Team
External + internal + adversary simulation + phishing, as one package
Cloud
AWS, Azure & GCP
External Network
Internet-facing perimeter
Internal Network
Post-breach & lateral movement
Source Code Review
AI-assisted + manual verification
AI / ML
LLM & model security
Phishing Testing
Social engineering campaigns
Hardware
IoT, embedded & OT devices
Vulnerability Scanning
Validated, prioritized results
Flat rate. Recurring plans available.
Learn moreAll figures are in USD and represent typical starting points, not final quotes. Every engagement is fully tailored to your environment, and pricing can be adjusted or discounted based on your assessment needs, scope, and testing frequency. Your fixed price is confirmed after a short scoping call, with no hourly billing and a complimentary retest included in every engagement.
Ways to engage
However you prefer to buy
Single Engagement
A one-time, fixed-scope test for a specific application, network, or system.
- One application, API, or environment
- Fixed timeline and cost, agreed up front
- Executive summary + technical report
- One complimentary retest included
Continuous Testing
Ongoing testing throughout the year as your product and infrastructure change.
- Recurring or rolling test windows
- Priority scheduling for new releases
- Consolidated reporting across the year
- Unlimited retests on remediated findings
Enterprise Program
A managed program spanning multiple business units, products, or frameworks.
- Multiple concurrent engagements
- Dedicated account and delivery lead
- SOC 2, PCI, HIPAA & ISO 27001 mapping
- Custom security & audit reporting
FAQ
Questions about cost
What buyers ask before comparing
penetration testing quotes.
How much does a penetration test cost?
Most professional penetration tests fall between $4,000 and $30,000, depending on the type of assessment and the size of the scope. A focused web application or external network test typically starts around $4,000 to $5,500, while a full red team engagement covering external, internal, phishing, and adversary simulation starts around $12,500. The figures on this page are starting points for each size band; your exact fixed price is confirmed after a short scoping call.
What determines the price of a penetration test?
Scope size is the main driver: the number of applications, API endpoints, IP addresses, user roles, or devices in scope. After that, testing depth (black, grey, or white box), whether authenticated testing is required, compliance mapping needs, and turnaround time all affect the number. Two engagements described with the same words can differ substantially in effort once scoped properly, which is why we scope before quoting.
Why are some penetration tests so much cheaper?
Because many of them are automated vulnerability scans presented as penetration tests. A genuine manual assessment involves multiple days of senior tester time, and the economics simply do not allow a few hundred dollars. If a quote is dramatically below market, ask what percentage of the work is manual and who performs it. Our guide to choosing a penetration testing company covers the questions worth asking.
Is retesting included in the price?
Yes. Every engagement includes a complimentary retest of remediated findings, and the final report reflects the verified fixes. Many firms bill this as a second engagement, so it is worth confirming when you compare quotes: a cheaper initial price can end up higher once retesting is added.
Do you charge hourly or by the day?
Neither. Every engagement is fixed-scope and fixed-price, agreed in writing before work starts. You know the total cost up front, and the number does not move because testing took longer than estimated. If the scope genuinely changes mid-engagement, we agree that with you before anything proceeds.
Do you offer discounts for multiple tests or ongoing programs?
Yes. Bundled engagements, recurring test windows, and continuous testing programs are priced more favorably than a series of one-off tests, since scoping and onboarding are already done. If you expect more than one assessment a year, ask about the continuous testing or enterprise program models above.
How much does a SOC 2 or PCI DSS penetration test cost?
Compliance-driven tests are priced on the same basis as any other engagement: the scope determines the number, not the framework. What changes is the reporting. Findings are mapped to the controls your auditor examines, and the report is formatted as evidence they accept, which is included rather than charged as an extra.
How quickly can you start, and how long does a test take?
Most engagements can begin within one to two weeks of scoping, and typical testing runs about one week, followed by reporting. Larger or multi-component scopes take longer. If you have an audit deadline, tell us during scoping and we will work backwards from it.
Want a number for your exact scope?
Tell us what to test and see your fixed price.
Prefer the full scoping questionnaire?Get a Fixed-Scope Quote
Tell us what you need tested. We reply within one business day.
Thanks, we've received your message.
We'll be in touch shortly.