How Much Does a Penetration Test Cost? Day Rates, Cost Factors and Realistic Ranges
“How much does a penetration test cost?” can’t be answered with a single number, but it can with understandable factors. The price varies considerably with scope and complexity. Measured against the cost of a successful attack, a pentest is nonetheless almost always the cheaper investment.
Pentest vs. vulnerability scan
First, the most important distinction: a penetration test consists of numerous manual steps by experienced testers, unlike an automated scan. That’s what drives the price, and that’s where the most common mislabelling hides: a suspiciously cheap “pentest” is often just a relabelled vulnerability scan.
The difference isn’t a label but a question of proof. A scan reports what might be vulnerable. A pentest shows how far someone actually gets with it. The distinction in detail is in Vulnerability Scan: What It Delivers.
The cost factors
- Size and complexity of the test object
- Information basis (black, grey, white box) and aggressiveness of the test
- Criticality of the systems and compliance requirements
- Special requests: on-site presentations, testing outside business hours
- Qualifications and experience of the testers involved
Two of these deserve explanation, because proposals frequently get them wrong.
The information basis works differently than most expect. A black-box test without prior knowledge feels more realistic and therefore seems more valuable. In reality the tester spends a substantial share of paid time working out things you could have told them. A grey-box approach (credentials, an architecture overview, application documentation) usually delivers considerably more depth for the same budget, because the time goes into testing rather than reconnaissance.
Compliance requirements cost independently of test scope. If a result has to be usable towards regulators, customers or certifiers, documentation depth, methodological traceability and formal evidence come on top. That isn’t a surcharge for the same result: it’s additional work on a different artefact.
What scope actually means
The following efforts are market experience values and explicitly reference points: any reputable price only emerges after a scope definition.
| Test type | Typical effort | What drives the effort |
|---|---|---|
| External infrastructure | 2–5 days | Number of reachable hosts and services |
| Web application | 5–10 days | Number of roles and functions, not page count |
| Internal infrastructure | 5–10 days | Network size, segmentation, directory service |
| Mobile application | 5–8 days | Two platforms, plus the APIs behind them |
| Cloud environment | 3–8 days | Number of accounts, services, identity model |
| Red team operation | several weeks upward | Objective, stealth, breadth of vectors |
The most common estimation mistake for web applications: counting pages. What matters are roles and functions. An application with five user roles potentially has to be checked five times over for access control flaws. That drives effort far more than any page count.
Realistic ranges
As market orientation: day rates start at around €1,000 and rise considerably with specialisation and experience. Specialised areas (cloud, mobile applications, industrial control systems, red teaming) sit at the upper end.
With us, a penetration test starts at €4,480 per assessment for a clearly delimited test object; larger scopes and multi-stage scenarios sit correspondingly higher. Current tiers are on the Pentesting & Red Teaming page.
These figures are reference points, not fixed prices, the reputable path always runs through a scope definition from which the effort is derived.
What should be in the price and often isn’t
This is where the unpleasant surprises come from. Settle these five points before awarding the work:
The retest. After remediation, someone has to verify the gaps are actually closed. Is a retest included, and until when? Without it you have a findings report but no evidence of remediation and that’s exactly what gets asked for.
Report quality. A usable report contains a defensible summary for management, technically reproducible steps per finding, evidence and concrete recommendations. An exported tool report with CVSS values does not. Ask to see an anonymised sample. That separates providers more reliably than any reference list.
The closing session. Who answers your developers’ and administrators’ questions when they start remediating? Is that included or billed separately?
The evidence. Is proof prepared so you can use it towards third parties and how long does the provider retain it?
Test depth per day. Five days at one provider are not five days at another. Ask how much of the time goes into manual testing versus tool runs and report writing.
Well above that sits a red team operation, because there the effort runs to weeks rather than days across several vectors in parallel. At the other end is the bug bounty model with success-based payment, which has different strengths and different limits.
Five warning signs
- A fixed price without a scoping conversation. Quoting effort before knowing the test object means selling a product, not an assessment.
- Conspicuously short duration. A one-day “pentest” of a web application is a scan with a report.
- No named methodology. Recognised approaches such as PTES, OWASP or national baseline methodologies should be named and explained.
- No exploit phase. If nothing in the proposal says vulnerabilities are actually verified, they probably aren’t.
- No sample report available. A provider who won’t show an anonymised sample usually has a reason.
How to manage costs sensibly
- Sharpen the scope: not everything needs testing every year, prioritise by risk. Which events justify an unscheduled test is covered in How Often Should Companies Run Penetration Tests?.
- Take preparation seriously: provide access, test data, contacts and approvals before the test starts. Days lost to missing credentials get billed anyway.
- Grey box over black box wherever no realism argument speaks against it: more testing per euro invested.
- Continuous rather than only periodic: where it fits, Continuous Threat Exposure Management complements the point-in-time test and spreads the effort more sensibly.
- Quality over price: the cheapest provider often delivers the most worthless report.
What belongs in a request for proposal
The more precise the request, the more solid the quote and the less contingency a provider prices in:
- Test object and boundaries: which systems, domains, applications and what is explicitly out of scope
- Number of user roles for applications
- Information basis: which access and documentation you can provide
- Time window and whether testing outside business hours is required
- Driver: evidentiary obligation, go-live, customer requirement or your own security objectives
- Expected deliverables: report, presentation, retest, evidence
How Cloud Cape helps
We define the scope honestly, state the effort transparently, and deliver exploit-verified findings with a board-ready report, not relabelled scans. Where continuous validation creates more value than the annual test, we combine both through our Continuous Threat Exposure Management.
Talk to us about Pentesting & Red Teaming. We turn your budget into the greatest possible insight.
