What does a pentest cost? Six variables, not a rate card.
Nobody publishes prices in this trade, and there is a good reason for that: two engagements with the same name can take two days or three weeks. Rather than a number that would mean nothing, here is exactly what moves the figure, what is always included, and how to read a quote you received elsewhere.
The price of an audit is research time.
A penetration test has no cost of goods. No hardware, no licence, no raw material. What you are buying is a number of days during which somebody actively tries to break your application. Everything else on the quote follows from that.
Which has a direct consequence: at equal scope, a noticeably cheaper quote buys less research time. That is not automatically the wrong call, but you should know what you are giving up. The first day of an audit finds configuration problems. It is the days after that find the business logic flaws, the ones that actually cost money when somebody exploits them.
The other consequence is that a publicly advertised price assumes a standard perimeter. In offensive security that standard perimeter does not exist. A thirty-page online store and a business platform with seven roles both answer to the name "web application" and have nothing comparable in workload.
That said, giving no figure at all helps nobody get a budget approved. Here are the orders of magnitude, excluding tax, for an engagement carried out entirely by hand. These are wide, indicative ranges rather than a rate card: only scoping produces a firm price, and it always lands inside the range quoted here.
Brochure site or store
Two to four days, so €1,500 to €3,500. The public site, its forms, its customer area and its checkout flow.
Focused API
Two to five days, so €1,500 to €4,500. The spread comes from the number of sensitive endpoints multiplied by the number of roles.
Business application or SaaS
Five to twelve days, so €4,000 to €10,000. Several roles, overlapping permissions, whole journeys to break through.
Continuous testing
Monthly rather than fixed-price, on a perimeter that keeps moving. Scoped against how often you ship.
What moves the number.
Six things are usually enough to scope an engagement. These are precisely the questions I ask in the first conversation.
Size of the perimeter
The number of screens, journeys and endpoints genuinely tested. Not the number of pages: a hundred identical content pages count as one, while a single checkout flow can take a full day.
Authenticated or not
Testing without an account is looking at the facade. The moment accounts exist, the surface multiplies by the number of roles, because every feature has to be replayed with each of them.
Business complexity
A content site enforces few rules. A platform handling permissions, balances, approvals or money movements enforces hundreds, and each one is a place where the logic can give way.
Depth expected
Confirming there is nothing obvious, or hunting all the way to the chains of minor flaws that together hand over full access. Both are legitimate, they do not cost the same.
Technical context
An API specification, read access to the code or a dedicated staging environment save considerable time, so they lower the price. Their absence gets paid for in reconnaissance.
Timing
An engagement booked a few weeks out costs less than one squeezed into this week because a customer wants an attestation by Friday.
How it gets built.
A thirty-minute conversation
We look at what the application does, what data it handles, and what actually worries you. This conversation is not billed and commits you to nothing. It sometimes ends with "you do not need an audit yet".
A written scope
I send back in plain terms what is in the engagement and, more importantly, what is not. That document protects both sides: without it, nobody can say at the end whether the work was done.
A firm proposal
An amount, a number of days, a testing window and the list of deliverables. The price does not move again unless you change the scope.
NDA and authorization
The confidentiality agreement is signed before any technical exchange. The written testing authorization is not optional: without it there is no legal footing for the work, whoever the provider is.
The engagement, then the report
You hear from me the moment anything critical surfaces, without waiting for the end. The report follows within a few working days, then an hour-long walkthrough.
The retest, included
After your fixes, I replay the relevant tests and confirm in writing what is closed. No extra line on the invoice.
What is never billed on top.
These appear in every proposal I send. They are listed here because elsewhere they are sometimes options.
- The scoping conversation and writing the quote, whatever the outcome.
- The confidentiality agreement, signed before you share a single technical detail.
- The full report: an executive summary, a detailed sheet per vulnerability, reproduction steps and the fix expected.
- Immediate notice if a critical vulnerability surfaces during the engagement, without waiting for the report.
- An hour-long walkthrough with your technical team, to go back over anything that raises questions.
- A retest of the fixed vulnerabilities, with written confirmation of what is genuinely closed.
Reading a quote from somewhere else.
If you have several proposals on the table, four questions are enough to tell whether they describe the same thing.
How many days, and who works them
A quote with no day count cannot be compared. Ask who does the work too: the person who met you, or a junior assigned after signature.
Manual or tooled
Ask what share is manual research. An audit built on one tool pass and a formatting job is a scan. It has value, but it is not the same trade or the same price.
Is the retest in there
Without one you are paying for a diagnosis with no follow-up check. It is the line most often removed from a package to bring the headline number down.
What the report contains
Ask to see the structure, or an anonymized vulnerability sheet. A report that is only a tool export gives itself away instantly by its length and its lack of business context.
Common questions.
Why is there no price list on this page?
Because it would be wrong in both directions. Set high, it would scare off short engagements that genuinely wrap up in two days. Set low, it would force me to cut the research time, which is the only thing you are actually buying. A published price in this trade is almost always a scan price wearing an audit label.
How big does a company need to be for this to make sense?
Company size has little to do with it. What matters is what your application handles and what a compromise would cost you. A five-person team holding customer health data needs an audit far more than a two-hundred-person group whose website is a brochure.
Can the quote change mid-engagement?
The price is firm once the scope is written and agreed. It moves only if the scope moves, for instance if you add an application partway through. If I discover the perimeter is larger than described, I tell you before continuing, and you choose between extending or trimming.
Is the retest genuinely included?
Yes, and it is worth checking with everyone. An audit without a retest leaves you holding a list of fixes nobody has confirmed. The retest covers the vulnerabilities in the report, within a reasonable window after the engagement. It does not cover features built since.
Is this cheaper than a consultancy?
Usually yes, because there is no sales structure and no project manager to fund, and because the person selling the engagement is the person doing it. In exchange I turn down perimeters that need a team, and I say so rather than subcontracting.
Request a quote.
Describe the perimeter in a few lines: what the application does, whether there are accounts and how many roles. I come back with a scope, a day count and a firm price. First conversation with no commitment, full confidentiality.