A penetration test costs $4,000 to $30,000 for most focused engagements. A single web application test typically lands at $10,000 to $20,000. Enterprise red team work runs $20,000 to $100,000 or more. The spread is not vendor greed: it reflects scope, methodology and who does the work.
This guide explains what moves the number, so you can read a quote and tell whether it is priced honestly. If you are still deciding whether you need a test at all, start with how penetration testing works.
What a penetration test costs in 2026
Published pricing from three independent sources agrees on the shape of the market, which is unusual enough to be worth stating. Ranges below are US dollars for a one-off engagement.
Sources: Synack 2026 pricing guide, pentestingcost.com 2026 average cost analysis, and Ardura Consulting's 2026 pricing breakdown. Where the three disagree the spread is narrow, which is itself useful: the market has converged.
Two numbers matter more than the rest. The typical band is $10,000 to $20,000, because that is where most focused web application and network engagements land. The all-types average is around $18,300, per Synack's 2026 pricing analysis.
If a quote sits far below $4,000, you are almost certainly buying an automated vulnerability scan with a report attached. That is a useful thing to buy. It is not a penetration test, and the distinction matters when an auditor asks.
The seven factors that move the price
Scope drives cost more than any other variable, and scope is the part buyers most often leave vague.
Number of targets
An external network test covering fewer than 20 IP addresses runs roughly $4,000 to $6,000. Push that to 100 IPs with complex firewall rules and service enumeration and you are in the $10,000 to $12,000 range for the same methodology.
For applications the equivalent unit is pages, endpoints and user roles. A brochure site with one role is a fraction of the work of a multi-tenant SaaS platform with five roles, SSO and payment flows.
Application complexity
A small web application of under 20 pages with basic authentication sits at the bottom of the web app band. Add role-based access control, business logic worth attacking, file upload, and an API behind it, and the same tester needs five to ten days rather than three.
Multi-tenant isolation is the single most expensive feature to test properly, because every test must be repeated across tenant boundaries to prove separation holds.
Test type
The methodology changes the cost more than the target does.
Black box, grey box or white box
Black box testing gives the tester no credentials and no source. It is the most realistic simulation and the least efficient use of paid hours, because much of the budget goes on reconnaissance the defender already knows.
Grey box testing supplies credentials and architecture notes. Most engagements are grey box, and most should be: you are paying for depth, not for a tester to rediscover your own documentation.
White box adds source code access. It costs more per day and finds more per day.
Tester seniority and location
Day rates vary widely by region and by certification. A CREST or OSCP-certified tester in North America or Western Europe commands a materially higher rate than an equivalently skilled tester elsewhere. Neither is automatically better value, and the report quality is the thing to judge, not the passport.
Compliance requirements
A test run to satisfy PCI DSS, SOC 2, HIPAA or ISO 27001 carries overhead beyond the testing itself: specific evidence, defined scoping rules, and a report format the auditor will accept. Expect a premium over an equivalent non-compliance engagement.
Retesting
Ask whether the quote includes a retest after you fix what was found. Some vendors include one retest window, others bill it separately, and the difference can be several thousand dollars on the same engagement.
Three worked scenarios
Abstract ranges are hard to budget against. These three profiles cover most of what mid-market teams actually buy.
The middle row is where most buyers sit and where quotes vary most, because "multi-tenant" means very different work depending on whether tenancy is enforced at the database, the application or the proxy.
What the annual programme actually contains
A continuous programme is not one big test. It is usually a web application test each quarter, an API test twice a year, an annual cloud configuration review, and monthly automated scanning underneath all of it. Priced separately those components run roughly $10,000 to $15,000, $8,000 to $12,000, $12,000 to $20,000 and $1,000 to $2,000 per month respectively, per Ardura's 2026 breakdown.
Buying them as a programme is usually cheaper than buying them one at a time, because the vendor amortises scoping and onboarding across the year.
One-off testing versus continuous coverage
An annual test is a snapshot. It tells you the security posture of a build that shipped before the test started, which in a fortnightly release cycle is roughly 26 releases ago by the time you read the report.
Penetration testing as a service (PTaaS) spreads the same budget across continuous coverage, typically $20,000 to $100,000 or more per year depending on scope, with retests included. For teams shipping weekly it usually beats one-off testing on cost-per-finding, because the testing follows the code rather than the calendar. We cover the delivery model in more detail in our guide to penetration testing as a service.
The trade-off is commitment. A one-off test is a purchase. PTaaS is a relationship, and it only pays back if your team actually fixes what it surfaces between cycles.
How to compare two quotes properly
Most quotes are hard to compare because vendors describe scope differently. Normalise them before you look at the price.
- Count the days, not the deliverables. Ask how many tester-days the engagement includes. Two quotes at $15,000 are not equivalent if one is eight days and the other is four.
- Ask who runs the test. The person named in the proposal is not always the person doing the work. Ask for the tester's certifications and a redacted sample report from an engagement of similar scope.
- Check what "report" means. A finding list with CVSS scores is table stakes. What distinguishes a good report is a reproducible proof of concept per finding and a remediation note your developers can act on without a follow-up call.
- Confirm the retest terms in writing. Included, time-boxed, or billable.
- Establish the manual-to-automated split. Every test uses automated tooling for discovery. Ask what percentage of the engagement is manual exploitation, because that is the part you cannot buy from a scanner.
- Agree the escalation path. If the tester finds something critical on day two, you want to know on day two, not in the final report.
Where the money is usually wasted
The commonest expensive mistake is testing the wrong thing thoroughly. A beautifully executed network penetration test tells you little if your actual exposure is an over-permissive S3 bucket and an unauthenticated internal API.
The second is treating the report as the deliverable. The report is an input. Budget for the remediation work before you book the test, because a finding you do not fix cost you the full price of discovering it and returned nothing.
The third is annual-only testing on a codebase that changes weekly. If your release cadence is faster than your testing cadence, most of your production code has never been tested.
What we would ask before quoting
Scoping honestly takes a conversation, not a form. The questions that change our estimate most are these: how many distinct user roles exist, whether the application is multi-tenant, how many external-facing endpoints there are, whether a compliance framework dictates the methodology, and whether you need a retest.
If a vendor gives you a firm number without asking those, the number is a guess with a margin built in.
Our security testing services cover scoping, execution and retesting, and we will tell you when a penetration test is not what you need.