Parameter

Penetration testing cost

Also known as

  • Pentest pricing
  • Penetration test price

Penetration testing cost is the price of a security test, set mostly by how many tester-days the scope needs multiplied by the provider's day rate. Published ranges for a single engagement run from a few thousand dollars for one small target to tens of thousands for multi-role applications, networks and cloud environments.

Last reviewed

How much does a penetration test cost?

Most single engagements published by providers fall between about $5,000 and $45,000, with network, cloud and red team work running higher. The number you get is effort times rate: the provider estimates how many tester-days your scope needs, multiplies by a day rate, and adds reporting and retest time.

Every figure below comes from a page you can open. Treat them as a market snapshot, not a price list.

FigureWhat it coversSource
$10,000 to $45,000Average engagement, all typesSecure Ideas (2024)
$340 per hourOne firm's published billing rateSecure Ideas (2024)
$200 to $500 per hourTypical security consulting ratesSecure Ideas (2024)
$5,000 to $30,000Web application testSynack 2026 guide
$4,000 to $12,000External network testSynack 2026 guide
$5,000 to $35,000Internal network testSynack 2026 guide
$10,000 to $50,000Cloud testSynack 2026 guide
$30,000 to $150,000+Red team or adversary simulationSynack 2026 guide
$20,000 to $100,000+ per yearPTaaS subscriptionSynack 2026 guide
£800 to £1,200 per day (median £1,000)Central band of 30 UK public-sector rate cardsStingrai index, G-Cloud 14
$5,999 per target per yearSubscription with manual testingAstra pricing page
$3,500 per testAutonomous web application testCobalt pricing page

Sources: Secure Ideas, Synack's 2026 guide, Stingrai's rate index, Astra pricing, Cobalt pricing. Synack, Astra and Cobalt sell testing, so their guides and plans reflect their own models.

What drives the cost?

Anything that adds tester-days adds cost. The main drivers:

  • Scope and target count. Each application, API, network range or cloud account is more ground to cover. In Synack's published ranges, an external network test starts lower than a web application or cloud test.
  • Application size and roles. A tester checks what each role can do against every other role and tenant, so effort grows with roles, not only with pages. See authenticated penetration testing for how accounts are provisioned.
  • Knowledge level. The PCI SSC's penetration testing guidance notes that a black-box test "may require more time, money, and resources." See black-box, gray-box and white-box testing.
  • Methodology and compliance. A test that must map to PCI DSS 11.4 or a FedRAMP attack-vector list carries fixed coverage and reporting obligations.
  • Retest. Some quotes include one pentest retest; others bill it separately. Secure Ideas lists retesting and attestation letters as possible add-ons.
  • Reporting. Custom report formats, executive readouts and attestation letters each take time.
  • Tester qualifications. Senior testers and specialist work (hardware, mobile, cloud internals) command higher rates.
  • Timing. Secure Ideas lists after-hours testing and travel as surcharges, and suggests first-quarter scheduling can be cheaper because demand is lighter.

What are the pricing models?

There are four common models, and each one prices a different unit.

ModelUnit you pay forGood fitWhere it falls short
Fixed priceA defined scope, quoted onceAnnual compliance test with a stable scopeScope creep becomes a change order; the price hides the day count
Day or hourly rateTester timeOpen-ended or unusual workFinal cost is uncertain until the work is done
Subscription or PTaaSTargets, credits or tests per yearSeveral tests a year, retests and a findings portalCredits are tied to the contract term; per-target limits can push assets out of scope
Crowdsourced bug bountyEach valid finding, plus a platform feeBroad, ongoing coverage of internet-facing assetsNo guaranteed coverage of any given feature; no fixed test window

Credit models convert time into a token. Cobalt, for example, defines one credit as the equivalent of eight hours of testing. Bounty programs publish reward tables per severity: GitHub's reward guidelines list $10,000 for a critical in its public program and $250 for a low, which shows how bounty spend tracks findings and not effort. More on the subscription model in penetration testing as a service.

Worked example: scoping a SaaS test

This example is illustrative. The effort estimates are assumptions for the arithmetic, not a quote from any provider.

Target:     app.example (web app) and api.example (REST API, about 60 endpoints)
Roles:      owner, member, read-only, in two test tenants
Approach:   gray-box, authenticated, staging environment, API spec provided
Out:        mobile apps, corporate network, social engineering

Estimated effort (tester-days)
  Setup, recon, account checks       1.0 to 1.5
  Web application testing            4.0 to 5.5
  API testing                        2.5 to 3.5
  Reporting and readout              1.0 to 1.5
  One retest of fixed findings       0.5 to 1.0
  Total                              9.0 to 13.0

At $340/hour x 8 hours = $2,720/day   ->  $24,480 to $35,360
At £1,000/day (UK G-Cloud median)     ->  £9,000 to £13,000

Adding tenants or roles adds testing days; dropping the API spec pushes the test toward black-box and adds recon time. Asking for a day estimate per line item, as above, makes quotes comparable.

How do buyers compare quotes?

Compare the days, not the totals. A practical checklist:

  1. Ask for tester-days per target and the day rate, even on a fixed-price quote.
  2. Check that the scope names every target, role and tenant, and lists what is out of scope. A written rules of engagement document makes this explicit.
  3. Confirm whether a retest is included, how many, and within what window.
  4. Confirm who tests: named seniority, qualifications, and whether the work is manual, automated or both.
  5. Ask for a sample report, redacted, to see how findings are evidenced and how fixes are written.

Written by Parameter · Last reviewed

[ related terms ]

Related terms.

Penetration testing as a service (PTaaS)

Penetration testing as a service (PTaaS) is a way of buying pentests as a subscription delivered through a web platform: you scope and launch tests in a portal, testers or automated agents post findings there as they confirm them, and you track fixes and request retests in the same place, usually under an annual contract.

Pentest retest

A pentest retest is a follow-up check in which the tester repeats the original reproduction steps for each reported finding after the fix ships, confirms whether the issue is gone, and issues an updated status for every finding.

Rules of engagement (RoE)

Rules of engagement (RoE) are the signed document that authorizes a security test and sets its limits: which systems may be attacked, when, from where, with which techniques, how data is handled, who to call when something breaks, and when testing must stop.

Authenticated penetration testing

Authenticated penetration testing is a pentest in which the tester logs in with real accounts, usually one per role and tenant, and attacks the application from inside the session, looking for users who can read or change data, or run functions, that their role should not allow.

Black-box, gray-box and white-box penetration testing

Black-box, gray-box and white-box testing describe how much a penetration tester is told before starting: nothing beyond a target (black-box), partial information such as accounts and API specs (gray-box), or full access to source code, architecture and configuration (white-box).