Skip to content

Cost guide

Wireless Penetration Testing Cost

On-site wireless penetration testing starts at $3,800 for one NYC-metro office with up to three SSIDs, fixed in writing before work begins. It covers rogue access points, enterprise Wi-Fi attacks such as evil twin, guest isolation, and whether wireless reaches your internal network, with a full report and a free retest.

WirelessFixed price

Small

One NYC-metro office with up to 3 SSIDs, such as corporate, guest, and IoT, tested on site: RF survey, rogue access points, enterprise authentication, and guest isolation.

$3,800

Medium

Up to 8 SSIDs, a larger or multi-floor office, several controllers or certificate-based authentication, or two NYC-metro sites with the same configuration.

$5,500

Large

A campus, three or more sites, or more than 8 SSIDs, quoted from the scope.

On request
Free retest includedFrom $3,800

What moves the number

What drives the cost of wireless penetration testing

01

Number of SSIDs

Each broadcast network is its own test: corporate, guest, IoT, and any legacy network still on the air. Up to 3 SSIDs is the Small tier and up to 8 is Medium.

02

Authentication type

A pre-shared key is quick to assess. WPA2 or WPA3 Enterprise with 802.1X, RADIUS, and certificates has more to attack, such as evil twin credential capture and EAP downgrade.

03

Size of the office

A single floor is quicker to survey than several floors or a large open plan. More space means more walking, more access points, and more places for a rogue device to hide.

04

Segmentation to test

Checking whether the guest network or a wireless foothold reaches corporate systems adds testing between zones. The more wireless networks touch the internal network, the more there is to prove.

05

Number of sites

Two NYC-metro sites with the same configuration fit the Medium tier. Three or more sites, or a campus, are quoted. Sites outside the NYC metro are quoted too.

In the price

What every wireless penetration testing price includes

  • ✓An RF survey and rogue access point sweep, with a map of the access points and SSIDs found
  • ✓WPA2 and WPA3 checks, including enterprise 802.1X and RADIUS attacks: evil twin credential capture, certificate validation, and EAP downgrade
  • ✓Guest isolation and wireless-to-internal segmentation testing, including whether the guest network reaches corporate systems
  • ✓A fixed price agreed in writing before work begins, with no hourly billing
  • ✓An executive summary for leadership and a full technical report with reproduction steps (see a sample penetration testing report)
  • ✓A free retest of fixed issues, on site in the NYC metro or remotely through a device we ship
  • ✓An attestation letter and findings platform access at no extra cost
  • ✓Senior in-house testers, no subcontractors or crowdsourced testers

Keep it tight

How to keep the price down

  1. 01List your SSIDs, authentication types, and controllers during scoping. An exact count sets the tier and avoids surprises on site.
  2. 02Switch off networks you no longer use before the test. Every SSID on the air is in scope, and legacy ones are usually the weakest.
  3. 03Test one office when several share the same wireless configuration. Findings on one usually apply to the others.
  4. 04Book the internal network test in the same scoping pass if you want to see how far a wireless foothold reaches. Scoping and onboarding happen once.

Timeline

Testing can start within a week of signing. The Small tier takes 2 to 3 days on site plus a reporting day, and the report follows within 5 business days of the last on-site day. The Medium tier takes 4 to 5 days. Large scopes are quoted. The free retest follows your fixes, on site or remotely.

Priced the same forPCI DSSHIPAASOC 2ISO 27001

FAQ

Questions about wireless penetration testing cost

01How much does a wireless penetration test cost?

It starts at $3,800 for one NYC-metro office with up to three SSIDs, tested on site and fixed before work begins, with a free retest. Up to 8 SSIDs, a larger office, or two same-configuration sites is $5,500. A campus or three or more sites are quoted from the scope. Every price is on the pricing page.

02Do you test WPA3 and enterprise Wi-Fi?

Yes. We test pre-shared key networks, WPA3, and WPA2 or WPA3 Enterprise with 802.1X and RADIUS. On enterprise networks we try evil twin access points to capture credentials, check whether devices validate the server certificate, and look for EAP downgrade.

03Will testing disrupt our Wi-Fi?

Most of the work is passive listening and authorized connection attempts. Any technique that could briefly disconnect a user, such as forcing a device to reconnect, is agreed in the rules of engagement first and run in the windows you approve.

04Does this help with PCI DSS?

Yes. PCI DSS Requirement 11.2.1 asks for testing for authorized and unauthorized wireless access points at least once every three months. Our rogue access point sweep and map are evidence for the quarter the test runs in. The wireless-to-internal testing also shows whether wireless reaches the cardholder data environment. See PCI DSS penetration testing.

05Can you test sites outside New York?

Yes. Sites outside the NYC metro are quoted from the scope. Many can be tested through a small device we ship to the site, and some need an on-site visit. We agree which during scoping.

06Is this the same as testing an IoT device's radios?

No. This test covers your corporate and guest Wi-Fi networks. The radios inside a product you build, such as Bluetooth or Wi-Fi on a device, are part of hardware and IoT penetration testing, from $5,200.

Get the exact number for your scope

Tell us what needs testing. You get a written fixed price within one business day, and the number does not move once testing starts.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.