Practical guide

What a penetration test costs
and why there is no list price

What drives the effort, how an honest estimate is built, and how to compare two quotes that appear to say the same thing.

The question "how much does a pentest cost?" almost always gets an answer that sounds evasive: it depends. That is not a sales dodge. A penetration test is paid for by specialist effort, and effort depends on how large and complicated the thing to be tested is. This guide shows exactly what it depends on, so you can estimate the order of magnitude yourself before requesting a quote.

The unit of measure: the testing day

Almost every serious quote is built the same way: estimate the number of person-days needed, add reporting and re-test time, and multiply the total by the provider’s day rate. That is why two very differently priced quotes can both be correct: one estimated five days, the other fifteen, because they understood the scope differently.

The first question to ask of any quote: how many days of actual testing it contains, and what happens to them if the scope turns out larger. A quote without a day count cannot be compared with anything.

The six factors that decide the effort

  • Scope size: how many IP addresses, applications, domains and subdomains, mobile apps.
  • Functional complexity: an app with three screens and one with eighty do not take the same time, even on the same server.
  • Number of roles and flows: each user role multiplies the authorisation tests that must be attempted.
  • Information level: black, grey or white box — with code and documentation access, time shifts from discovery to real testing.
  • Compliance driver: a test for PCI DSS or an ISO audit demands structure, evidence and a documented re-test, so extra reporting time.
  • Execution constraints: testing only outside business hours, sensitive production environments, cloud provider agreements.

Order of magnitude, by test type

The figures below are typical effort ranges, not prices. Use them as a sanity check on any quote you receive: if someone promises a full test of a complex web application in two days, you are not comparing prices but different depths.

Test typeTypical testing effortWhat most often increases it
Small web application (site, simple portal)3–5 daysMany forgotten subdomains in scope
Complex web application (SaaS, banking, multi-role)8–20 daysNumber of roles and business logic
External infrastructure3–8 daysNumber of live hosts, not allocated addresses
Internal infrastructure / Active Directory5–15 daysDomains, trust relationships, branch offices
Mobile application (one platform)5–10 daysThe backing API, if never tested before
Social engineering / phishing3–8 daysNumber of scenarios and bespoke pretexts
Cloud environment (configuration + identities)4–10 daysNumber of accounts, regions and services used

Why a very cheap quote is usually something else

Price differences between providers rarely come from the day rate. They come from what is actually delivered. A one-day "pentest" on a complex application is, almost always, an automated scan with the report exported: useful as a starting point, useless as compliance evidence, and misleading as a level of assurance.

  • Check whether the quote includes manual business logic testing — scanners do not cover it at all.
  • Check whether the post-remediation re-test is included or billed separately.
  • Check who writes the report: a tool-generated report and a tester-written one look nothing alike.
  • Check whether the provider will justify each finding’s severity in context, not just by CVSS score.

How to reduce cost without reducing value

  • Give access and documentation. Every hour a tester spends guessing the architecture is an hour paid for discovery, not testing.
  • Narrow the scope to what matters: the systems holding the data and the revenue, not everything in the inventory.
  • Run your own scan first and fix what it finds. Do not pay a specialist to find a missing patch.
  • Plan recurring testing in the contract: effort drops in the second cycle, when the scope is already known.
At Pentest.md we do not publish fixed price lists, because a quote reflects exactly what needs testing. See how we build a quote, or ask for one for your scope.

Frequently asked questions

What does a penetration test cost on average?

There is no useful average, because price is calculated on effort. A small web application test usually means three to five testing days; a complex application with multiple roles and business logic, eight to twenty; an internal infrastructure, five to fifteen. Multiplying the estimated days by the provider’s day rate gives you the order of magnitude — and, more importantly, lets you compare two quotes properly.

Why do providers not publish fixed prices?

Because a fixed price would mean a fixed scope, and scopes do not resemble one another. Two applications on the same kind of server can require four times different effort if one has three screens and the other eighty, with five user roles. A provider advertising a single price either silently limits what gets tested, or comes back with a supplement once it sees the real scope.

Black box or white box — which costs more?

Counterintuitively, black box usually costs more for the same result. With no information, a significant share of the paid days goes into discovery — mapping what you already know. White box moves that time into actual testing and produces deeper findings for the same budget. Black box makes sense when you specifically want to simulate an external attacker with no inside knowledge.

Is the post-remediation re-test charged separately?

It depends on the provider, and it is one of the most important questions to ask before signing. A re-test verifies that the reported vulnerabilities were actually closed and produces the document auditors ask for. If it is not included, the project’s real cost is higher than the quoted one, and the compliance file stays incomplete.

How often should the test be repeated and how does that affect budget?

The usual recommendation is at least annually and after any major change. The good news for budgets is that the second cycle usually costs less: the scope is already mapped, the architecture known, and effort concentrates on what changed. A multi-year contract or a recurring testing programme captures exactly that saving.

Related guides

  • DORA & TLPT — digital operational resilience in finance and threat-led penetration testing.
  • ISO 27001 & SOC 2 — which controls require technical testing and what evidence the auditor accepts.
  • Moldova’s Law 48/2023 — the national cybersecurity framework: who is in scope and what obligations it brings.
  • OWASP Top 10 — the ten web risk categories, explained with examples and what gets tested in each.
  • PCI DSS 4.0 — requirements 11.3 and 11.4, segmentation testing, and what it means for payment processors.
  • Pentest vs vulnerability scanning — what each one finds, what it misses, and what auditors accept as evidence.
  • How to prepare for a pentest — scope, access, rules of engagement and everything settled before day one.

The effort ranges in this guide are indicative and reflect typical projects. An estimate for a specific organisation is produced after the scope is defined.

Want an estimate for your scope?

Book a free consultation: we define the scope together and you get a quote with testing days, deliverables and re-test, item by item.