Cost guide
Phishing and Social Engineering Testing Cost
Phishing and social engineering testing starts at $3,600 for a scoped campaign, fixed in writing before work begins. That price buys a tailored email campaign with click, submission, and reporting metrics broken down by department, a debrief, and targeted awareness recommendations.
Small
One email campaign against a defined group, up to a few hundred employees, with click, submission, and reporting metrics broken down by department.
Medium
A larger campaign across several hundred employees, or two channels such as email plus voice or SMS, with pretexts tailored per department.
Large
A full-workforce or multi-region program of several thousand employees, multiple channels, and adversary-in-the-middle scenarios that test MFA.
What moves the number
What drives the cost of phishing and social engineering testing
Number of employees
Headcount is the main driver. A campaign against one department of a hundred people is smaller than a full-workforce program of several thousand, which needs the lures and reporting sized so results stay meaningful by team.
Number of channels
Email alone is the baseline. Adding voice (vishing) and SMS (smishing) tests staff away from the inbox, and each channel is a separate campaign to design, run, and measure, which adds to the scope.
Pretext tailoring
Generic templates measure how people spot generic phishing. Researched, department-specific pretexts using your vendors, tools, and seasonal events find more and take longer to build, which is where the value and the effort both rise.
MFA and advanced scenarios
Adversary-in-the-middle scenarios that proxy the real login and capture the session, testing whether your MFA actually resists phishing, are more involved than a click-only campaign and are scoped when that is the question.
Reporting and debrief depth
A baseline click-rate number is quick. Departmental breakdowns, repeat-clicker analysis, time-to-report tracking, and a training debrief with your team add analysis work proportional to how much you want to act on.
In the price
What every phishing and social engineering testing price includes
- ✓A tailored email phishing campaign with click, submission, and reporting metrics by department
- ✓Optional voice (vishing) and SMS (smishing) channels, and adversary-in-the-middle scenarios that test MFA
- ✓A debrief with targeted awareness recommendations and repeat-clicker analysis
- ✓No retest, because a campaign measures behavior and produces no technical findings to re-verify
- ✓A fixed price agreed in writing before work begins, with no hourly billing
- ✓An executive summary for leadership and a full report of the campaign results
- ✓An attestation letter and findings platform access at no extra cost
- ✓Senior in-house testers, OSCP and OSCE3 certified
Keep it tight
How to keep the price down
- 01Provide a clean employee list grouped by department up front. Accurate targeting data means the campaign runs on schedule and the metrics break down by team without extra cleanup.
- 02Start with a single-channel email baseline before adding voice or SMS. One campaign establishes your click and report rates, and you can layer channels once you know the baseline.
- 03Scope to representative departments rather than the entire workforce if headcount is very large. Finance, IT, and executives tell you most about risk without sizing the campaign to everyone.
- 04Run your awareness training through your existing platform and use our follow-up campaign to measure it. We supply the plan and the metrics; you do not need us to host the training.
Timeline
Onboarding begins within 24 hours of a signed proposal, and a campaign usually starts within a week of scoping. A single-channel campaign runs over a defined window, followed by the results, the departmental breakdown, and a debrief. Larger multi-channel programs take longer. There is no retest, because a campaign measures behavior rather than producing findings to re-verify.
FAQ
Questions about phishing and social engineering testing cost
01How much does phishing and social engineering testing cost?
A scoped campaign starts at $3,600, fixed before work begins. Medium campaigns start at $5,500 and large multi-channel or full-workforce programs at $8,500. It is often the easiest first engagement and a natural lead-in to internal testing or a red team. Every price is on the pricing page.
02Is there a retest, like on other services?
No. A phishing campaign measures how people behave and produces metrics, not technical findings to remediate and re-verify, so there is nothing to retest. Instead of a retest we recommend a follow-up campaign later to measure whether awareness improved, scoped as its own engagement.
03What drives the price of a phishing campaign?
Headcount is the main driver, followed by how many channels you run and how tailored the pretexts are. A single-channel email campaign against one department is smaller than a multi-channel program across several thousand employees with researched, department-specific lures.
04Can you phish accounts protected by MFA, and does that cost more?
Yes. Adversary-in-the-middle scenarios proxy the real login, relay the MFA prompt, and capture the session, which tests whether your MFA actually resists phishing. These are more involved than a click-only campaign and are scoped when that is the question you want answered.
05How can we keep a phishing campaign affordable?
Provide a clean employee list grouped by department, start with a single-channel email baseline before adding voice or SMS, and scope to representative departments if headcount is very large. Running your own awareness training and using our follow-up to measure it also keeps cost down.
Other cost guides
All pricingWeb Application Penetration Testing Cost
From $5,200API Penetration Testing Cost
From $4,000Mobile Application Penetration Testing Cost
From $6,000Red Team Assessment Cost
From $12,500Cloud Penetration Testing Cost
From $6,800External Network Penetration Testing Cost
From $4,200Internal Network Penetration Testing Cost
From $6,000Secure Code Review Cost
From $4,800AI and LLM Penetration Testing Cost
From $4,500Hardware and IoT Penetration Testing Cost
From $5,200Vulnerability Scanning Cost
From $1,500Get the exact number for your scope
Tell us what needs testing. You get a written fixed price within one business day, and the number does not move once testing starts.
Prefer the full scoping questionnaire?Get a Fixed-Scope Quote
Tell us what you need tested. We reply within one business day.
Thanks, we've received your message.
We'll be in touch shortly.