Penetration testing cost runs from about $2,000 to more than $100,000 in published guides, and scope explains almost all of that spread. A single small web application costs a few thousand dollars to test. A large estate with web apps, networks, cloud, and mobile apps costs many times more. This post gives the ranges, explains what drives them, and lists the questions that turn a vague quote into one you can compare.
The numbers below come from security vendors who sell testing, so read them as guides. Vendors also disagree with each other, which is a reason to ask for quotes against a written scope.
What are the typical price ranges?
Guides group penetration tests by the size of the organisation and by the type of test.
By company size, one guide gives:
- Small businesses: about $2,000 to $10,000
- Medium-sized businesses: about $10,000 to $30,000
- Large enterprises: about $30,000 to $100,000 or more
By type of test, the guides we read give these ranges:
- Web applications: about $5,000 to $30,000, depending on complexity, user roles, input fields, and the number of pages
- Network testing: about $7,000 to $25,000
- Cloud testing: estimates cluster between $5,000 and $50,000, with one source starting at $10,000
Across guides, overall ranges are quoted as $2,000 to $50,000, $5,000 to $40,000 or more, and $5,000 to $100,000 or more. The differences show that nobody can give an honest price without knowing what is being tested.
What drives the price?
Number and complexity of targets. Each application, API, network segment, or cloud account adds testing time. A simple brochure site needs little. An application with several user roles, payments, and custom features needs a lot more.
Depth and method. A test with no prior knowledge of your system (black box) differs in effort from one where the tester has accounts, documentation, or code (grey or white box). More access often means more thorough testing for the same time.
Scope of test scenarios. Testing only for common web flaws costs less than testing business logic, role abuse, and chained attacks.
Who does the work. Testers with strong experience and recognised certifications cost more per day. Security testers are in short supply, and several guides say that demand has pushed prices up.
Reporting and retesting. A full report with evidence, fix guidance, and a retest after you fix issues takes extra time. It is also where much of the value sits.
Compliance needs. If the test supports a standard such as PCI DSS or ISO 27001, the scope and the report format are more demanding. Our guide to how often to run a penetration test covers what some standards require.
What do you get for the money?
A useful penetration test produces a written report that lists each finding with a severity rating, evidence that you can verify, and clear steps to fix it, plus a summary for non-technical readers. Good providers also offer a retest, so you know the fixes worked. If the offer is mostly automated scanner output, you are paying for a scan. Our post on penetration testing vs vulnerability scanning explains the difference.
What questions should you ask before accepting a quote?
- What exactly is in scope, and what is not?
- Is the testing manual, automated, or both?
- Which methodology do the testers follow?
- Who does the testing, and what are their qualifications?
- What does the report contain? Can I see a sample?
- Is a retest included, and for how long afterwards?
- How will you avoid disrupting the live system?
- What happens if you find something serious during the test?
- How is the price calculated, and what would change it?
If you ask several providers the same questions, differences in price will usually trace back to differences in answers.
How can you keep the cost down?
- Scope tightly. Test the systems that hold data you care about first, then widen the scope next year.
- Prepare well. Test accounts, documentation, and a staging environment save testers' time. Our web application penetration testing checklist lists what to prepare.
- Fix the basics first. Update software and close known gaps before the test, so the tester's time goes on harder problems.
- Combine with regular scanning. Automated scanning between tests catches routine problems cheaply.
- Do not skip the retest. Fixing a finding without confirming it is cheaper than a breach but worth verifying.
Is a penetration test worth the cost?
The answer depends on what you protect. If your website holds customer data, takes payments, or supports logins, a test finds the problems you would otherwise learn about from an attacker. If a customer or a standard requires a test, the question is settled. For a simple brochure site with no logins and no data, regular maintenance and scanning may be enough.
What does a quote look like in practice?
A clear quote breaks the work into parts you can recognise. Expect a scoping stage, where the provider reads your brief and agrees what will be tested. Then comes the testing itself, usually priced as a number of days of specialist time. Then reporting, which includes writing up findings with evidence and fix guidance. Many quotes add a debrief call, where the tester walks your team through the results, and a retest after you apply fixes.
Ask which of these are included in the price and which cost extra. A low headline number that leaves out the retest or the debrief can end up costing more than a higher quote that covers them.
Is it a fixed price or a day rate?
Both exist. A fixed price for a defined scope gives you a total in advance and suits straightforward targets, such as a single web application. The provider estimates the effort and takes the risk. A day rate suits large or unclear scopes, where you pay for the time actually spent, and it works best with a cap so the total cannot run away.
Either way, the number of days is what you are really buying. If a quote shows no days, no scope, and no method, ask for them.
Where does the money go?
Most of the cost is skilled tester time. Guides point out that qualified testers are in short supply, which keeps day rates up. The rest covers preparation, reporting, review by a second person, and project management. Tools matter, but they are a small part of the price. This is also why a very cheap quote deserves attention: if the time is short, the test is shallow.
What should make you cautious about a quote?
- No scope in writing, or a scope that says only "your website".
- No mention of method or standards, such as the OWASP guidance.
- A promise that the test will find no problems, or a fixed number of findings.
- A sample report that looks like raw scanner output.
- No retest or no way to ask questions afterwards.
- A price far below every other quote for the same scope.
- Pressure to sign quickly.
How should a small business budget for testing?
Start from risk. List your applications and note which hold customer data, take payments, or let people log in. Test those first. If funds are tight, a focused test of the most sensitive application is worth more than a shallow test of everything. Plan the next round for a year later, and add a test after any large change. Our guide to how often to run a penetration test covers timing, and our web application penetration testing checklist shows how to prepare so you get the most from each day of testing.
Quick answers
Why is penetration testing so expensive?
Mostly because it relies on scarce skilled people working for days on your system. The tester plans, tests by hand, verifies findings, and writes a report. Tools help, but they do not do the thinking. Prices rise with the number of targets, the depth of testing, and the reporting you need.
Can I get a penetration test for free?
Free tools can scan your site, and open learning projects let people practise, but a proper test by a qualified person is paid work. Be wary of free offers that turn out to be sales scans. A bug bounty is a different model, where researchers are paid for valid findings, and it suits mature teams.
How long does a penetration test take?
It depends on the scope. A single small web application takes far less time than a large estate with networks, cloud, and several applications. Your provider should give you an estimated number of testing days and a delivery date for the report before you sign.
How Krylo approaches it
We scope each test on a short call and send a proposal with the timeline, the deliverables, and transparent pricing. You can see what a test covers on our web application penetration testing services page, or contact us with your application and your concerns.
