How much does a penetration test cost?
Most single engagements published by providers fall between about $5,000 and $45,000, with network, cloud and red team work running higher. The number you get is effort times rate: the provider estimates how many tester-days your scope needs, multiplies by a day rate, and adds reporting and retest time.
Every figure below comes from a page you can open. Treat them as a market snapshot, not a price list.
| Figure | What it covers | Source |
|---|---|---|
| $10,000 to $45,000 | Average engagement, all types | Secure Ideas (2024) |
| $340 per hour | One firm's published billing rate | Secure Ideas (2024) |
| $200 to $500 per hour | Typical security consulting rates | Secure Ideas (2024) |
| $5,000 to $30,000 | Web application test | Synack 2026 guide |
| $4,000 to $12,000 | External network test | Synack 2026 guide |
| $5,000 to $35,000 | Internal network test | Synack 2026 guide |
| $10,000 to $50,000 | Cloud test | Synack 2026 guide |
| $30,000 to $150,000+ | Red team or adversary simulation | Synack 2026 guide |
| $20,000 to $100,000+ per year | PTaaS subscription | Synack 2026 guide |
| £800 to £1,200 per day (median £1,000) | Central band of 30 UK public-sector rate cards | Stingrai index, G-Cloud 14 |
| $5,999 per target per year | Subscription with manual testing | Astra pricing page |
| $3,500 per test | Autonomous web application test | Cobalt pricing page |
Sources: Secure Ideas, Synack's 2026 guide, Stingrai's rate index, Astra pricing, Cobalt pricing. Synack, Astra and Cobalt sell testing, so their guides and plans reflect their own models.
What drives the cost?
Anything that adds tester-days adds cost. The main drivers:
- Scope and target count. Each application, API, network range or cloud account is more ground to cover. In Synack's published ranges, an external network test starts lower than a web application or cloud test.
- Application size and roles. A tester checks what each role can do against every other role and tenant, so effort grows with roles, not only with pages. See authenticated penetration testing for how accounts are provisioned.
- Knowledge level. The PCI SSC's penetration testing guidance notes that a black-box test "may require more time, money, and resources." See black-box, gray-box and white-box testing.
- Methodology and compliance. A test that must map to PCI DSS 11.4 or a FedRAMP attack-vector list carries fixed coverage and reporting obligations.
- Retest. Some quotes include one pentest retest; others bill it separately. Secure Ideas lists retesting and attestation letters as possible add-ons.
- Reporting. Custom report formats, executive readouts and attestation letters each take time.
- Tester qualifications. Senior testers and specialist work (hardware, mobile, cloud internals) command higher rates.
- Timing. Secure Ideas lists after-hours testing and travel as surcharges, and suggests first-quarter scheduling can be cheaper because demand is lighter.
What are the pricing models?
There are four common models, and each one prices a different unit.
| Model | Unit you pay for | Good fit | Where it falls short |
|---|---|---|---|
| Fixed price | A defined scope, quoted once | Annual compliance test with a stable scope | Scope creep becomes a change order; the price hides the day count |
| Day or hourly rate | Tester time | Open-ended or unusual work | Final cost is uncertain until the work is done |
| Subscription or PTaaS | Targets, credits or tests per year | Several tests a year, retests and a findings portal | Credits are tied to the contract term; per-target limits can push assets out of scope |
| Crowdsourced bug bounty | Each valid finding, plus a platform fee | Broad, ongoing coverage of internet-facing assets | No guaranteed coverage of any given feature; no fixed test window |
Credit models convert time into a token. Cobalt, for example, defines one credit as the equivalent of eight hours of testing. Bounty programs publish reward tables per severity: GitHub's reward guidelines list $10,000 for a critical in its public program and $250 for a low, which shows how bounty spend tracks findings and not effort. More on the subscription model in penetration testing as a service.
Worked example: scoping a SaaS test
This example is illustrative. The effort estimates are assumptions for the arithmetic, not a quote from any provider.
Target: app.example (web app) and api.example (REST API, about 60 endpoints)
Roles: owner, member, read-only, in two test tenants
Approach: gray-box, authenticated, staging environment, API spec provided
Out: mobile apps, corporate network, social engineering
Estimated effort (tester-days)
Setup, recon, account checks 1.0 to 1.5
Web application testing 4.0 to 5.5
API testing 2.5 to 3.5
Reporting and readout 1.0 to 1.5
One retest of fixed findings 0.5 to 1.0
Total 9.0 to 13.0
At $340/hour x 8 hours = $2,720/day -> $24,480 to $35,360
At £1,000/day (UK G-Cloud median) -> £9,000 to £13,000Adding tenants or roles adds testing days; dropping the API spec pushes the test toward black-box and adds recon time. Asking for a day estimate per line item, as above, makes quotes comparable.
How do buyers compare quotes?
Compare the days, not the totals. A practical checklist:
- Ask for tester-days per target and the day rate, even on a fixed-price quote.
- Check that the scope names every target, role and tenant, and lists what is out of scope. A written rules of engagement document makes this explicit.
- Confirm whether a retest is included, how many, and within what window.
- Confirm who tests: named seniority, qualifications, and whether the work is manual, automated or both.
- Ask for a sample report, redacted, to see how findings are evidenced and how fixes are written.
[ Sources ]
Written by Parameter · Last reviewed

