View all services
Talk to QA Advisor
/Blog/Penetration Testing Costs: Real Cost Ranges
Compliance Testing9 min read

Penetration Testing Costs: Real Cost Ranges

What a penetration test actually costs in 2026: real ranges by engagement type, the seven factors that move the number, three worked scenarios, and how to compare two quotes that look the same.

Published September 16, 2026Last updated September 16, 2026
On this page

A penetration test costs $4,000 to $30,000 for most focused engagements. A single web application test typically lands at $10,000 to $20,000. Enterprise red team work runs $20,000 to $100,000 or more. The spread is not vendor greed: it reflects scope, methodology and who does the work.

This guide explains what moves the number, so you can read a quote and tell whether it is priced honestly. If you are still deciding whether you need a test at all, start with how penetration testing works.

The short version
A penetration test costs $4,000 to $30,000 for most focused engagements, with the typical band at $10,000 to $20,000 and an all-types average near $18,300. Red team work runs $20,000 to $100,000 or more. Scope, test type and manual-versus-automated split drive the number, not vendor margin.

What a penetration test costs in 2026

Published pricing from three independent sources agrees on the shape of the market, which is unusual enough to be worth stating. Ranges below are US dollars for a one-off engagement.

Penetration testing cost by engagement type, 2026
Engagement typeRange (USD)TypicalWhat drives it
Web application$5,000 - $30,000$10k - $20kPages, user roles, multi-tenancy, payment flows
External network$5,000 - $20,000$8k - $12kNumber of IPs, firewall complexity, service count
Internal network$6,000 - $35,000$10k - $20kAssumed-breach scope, lateral movement, AD depth
API$5,000 - $30,000$7k - $14kEndpoint count, auth flows, rate-limit and access control
Mobile application$7,000 - $35,000$10k - $18kPer app; iOS plus Android roughly doubles it
Cloud configuration$8,000 - $50,000$12k - $22kSingle versus multi-cloud, IAM depth, storage exposure
Red team$20,000 - $150,000+$40k - $80kObjective-based, multi-vector, multi-week
Social engineering$3,000 - $12,000$5k - $9kPhishing and pretexting scope, headcount targeted
PTaaS, annual$20,000 - $100,000+variesContinuous coverage with retests included
Source: Synack 2026 pricing guide; pentestingcost.com average cost 2026; Ardura Consulting 2026 pricing analysis

Sources: Synack 2026 pricing guide, pentestingcost.com 2026 average cost analysis, and Ardura Consulting's 2026 pricing breakdown. Where the three disagree the spread is narrow, which is itself useful: the market has converged.

Two numbers matter more than the rest. The typical band is $10,000 to $20,000, because that is where most focused web application and network engagements land. The all-types average is around $18,300, per Synack's 2026 pricing analysis.

If a quote sits far below $4,000, you are almost certainly buying an automated vulnerability scan with a report attached. That is a useful thing to buy. It is not a penetration test, and the distinction matters when an auditor asks.

The seven factors that move the price

Scope drives cost more than any other variable, and scope is the part buyers most often leave vague.

Number of targets

An external network test covering fewer than 20 IP addresses runs roughly $4,000 to $6,000. Push that to 100 IPs with complex firewall rules and service enumeration and you are in the $10,000 to $12,000 range for the same methodology.

For applications the equivalent unit is pages, endpoints and user roles. A brochure site with one role is a fraction of the work of a multi-tenant SaaS platform with five roles, SSO and payment flows.

Application complexity

A small web application of under 20 pages with basic authentication sits at the bottom of the web app band. Add role-based access control, business logic worth attacking, file upload, and an API behind it, and the same tester needs five to ten days rather than three.

Multi-tenant isolation is the single most expensive feature to test properly, because every test must be repeated across tenant boundaries to prove separation holds.

Test type

The methodology changes the cost more than the target does.

How test type changes the work, and the price
Test typeWhat the tester doesTypical durationCost effect
Vulnerability scanAutomated discovery, minimal manual validation1-2 daysLowest; often mis-sold as a pentest
Black boxNo credentials, no source; full reconnaissance5-10 daysHigh hours-to-findings ratio
Grey boxCredentials and architecture supplied5-10 daysBest depth per dollar; most engagements
White boxSource code access alongside testing8-15 daysHighest day rate, highest find rate
Red teamObjective-based, evades detection, multi-vector3-6 weeksSeveral times a standard test
Source: Synack 2026; Ardura Consulting 2026

Black box, grey box or white box

Black box testing gives the tester no credentials and no source. It is the most realistic simulation and the least efficient use of paid hours, because much of the budget goes on reconnaissance the defender already knows.

Grey box testing supplies credentials and architecture notes. Most engagements are grey box, and most should be: you are paying for depth, not for a tester to rediscover your own documentation.

White box adds source code access. It costs more per day and finds more per day.

Tester seniority and location

Day rates vary widely by region and by certification. A CREST or OSCP-certified tester in North America or Western Europe commands a materially higher rate than an equivalently skilled tester elsewhere. Neither is automatically better value, and the report quality is the thing to judge, not the passport.

Compliance requirements

A test run to satisfy PCI DSS, SOC 2, HIPAA or ISO 27001 carries overhead beyond the testing itself: specific evidence, defined scoping rules, and a report format the auditor will accept. Expect a premium over an equivalent non-compliance engagement.

Retesting

Ask whether the quote includes a retest after you fix what was found. Some vendors include one retest window, others bill it separately, and the difference can be several thousand dollars on the same engagement.

Three worked scenarios

Abstract ranges are hard to budget against. These three profiles cover most of what mid-market teams actually buy.

ScenarioScopeTest typeDurationExpected cost
Seed-stage SaaS, first testOne web app, 2 roles, under 20 pages, no compliance driverGrey box web app3-5 days$5,000 - $9,000
Series B platform, SOC 2Multi-tenant app, 5 roles, REST API, payment flowGrey box web app plus API8-12 days$15,000 - $25,000
Enterprise, annual programmeWeb, API, internal network, cloud config, quarterly cadenceMixed, retests includedContinuous$60,000 - $120,000/yr

The middle row is where most buyers sit and where quotes vary most, because "multi-tenant" means very different work depending on whether tenancy is enforced at the database, the application or the proxy.

What the annual programme actually contains

A continuous programme is not one big test. It is usually a web application test each quarter, an API test twice a year, an annual cloud configuration review, and monthly automated scanning underneath all of it. Priced separately those components run roughly $10,000 to $15,000, $8,000 to $12,000, $12,000 to $20,000 and $1,000 to $2,000 per month respectively, per Ardura's 2026 breakdown.

Buying them as a programme is usually cheaper than buying them one at a time, because the vendor amortises scoping and onboarding across the year.

One-off testing versus continuous coverage

An annual test is a snapshot. It tells you the security posture of a build that shipped before the test started, which in a fortnightly release cycle is roughly 26 releases ago by the time you read the report.

Penetration testing as a service (PTaaS) spreads the same budget across continuous coverage, typically $20,000 to $100,000 or more per year depending on scope, with retests included. For teams shipping weekly it usually beats one-off testing on cost-per-finding, because the testing follows the code rather than the calendar. We cover the delivery model in more detail in our guide to penetration testing as a service.

The trade-off is commitment. A one-off test is a purchase. PTaaS is a relationship, and it only pays back if your team actually fixes what it surfaces between cycles.

🔬 From our work
We hold ISO 27001:2022 and CMMI Dev ML3, and security testing is part of our delivery for BFSI clients including HDFC Bank and Kotak Mahindra, where compliance scope drives the methodology. We have not published engagement-level pricing from that work, so every figure in this guide is cited from independent 2026 market sources rather than our own rate card. Treat the ranges as the market, and ask any vendor, including us, to show you the tester-days behind a quote.

How to compare two quotes properly

Most quotes are hard to compare because vendors describe scope differently. Normalise them before you look at the price.

  1. Count the days, not the deliverables. Ask how many tester-days the engagement includes. Two quotes at $15,000 are not equivalent if one is eight days and the other is four.
  2. Ask who runs the test. The person named in the proposal is not always the person doing the work. Ask for the tester's certifications and a redacted sample report from an engagement of similar scope.
  3. Check what "report" means. A finding list with CVSS scores is table stakes. What distinguishes a good report is a reproducible proof of concept per finding and a remediation note your developers can act on without a follow-up call.
  4. Confirm the retest terms in writing. Included, time-boxed, or billable.
  5. Establish the manual-to-automated split. Every test uses automated tooling for discovery. Ask what percentage of the engagement is manual exploitation, because that is the part you cannot buy from a scanner.
  6. Agree the escalation path. If the tester finds something critical on day two, you want to know on day two, not in the final report.

Where the money is usually wasted

The commonest expensive mistake is testing the wrong thing thoroughly. A beautifully executed network penetration test tells you little if your actual exposure is an over-permissive S3 bucket and an unauthenticated internal API.

The second is treating the report as the deliverable. The report is an input. Budget for the remediation work before you book the test, because a finding you do not fix cost you the full price of discovering it and returned nothing.

The third is annual-only testing on a codebase that changes weekly. If your release cadence is faster than your testing cadence, most of your production code has never been tested.

What we would ask before quoting

Scoping honestly takes a conversation, not a form. The questions that change our estimate most are these: how many distinct user roles exist, whether the application is multi-tenant, how many external-facing endpoints there are, whether a compliance framework dictates the methodology, and whether you need a retest.

If a vendor gives you a firm number without asking those, the number is a guess with a margin built in.

Our security testing services cover scoping, execution and retesting, and we will tell you when a penetration test is not what you need.

Frequently Asked Questions

How much does a penetration test cost?

Most focused penetration tests cost $4,000 to $30,000, with the typical engagement landing at $10,000 to $20,000. The all-types average sits around $18,300. Enterprise red team engagements run $20,000 to $100,000 or more, and annual PTaaS programmes run $20,000 to $100,000 or more depending on scope.

Why do penetration testing quotes vary so much for the same application?

Because vendors scope differently. Two quotes at $15,000 are not comparable if one covers eight tester-days and the other covers four. Ask for the number of tester-days, the manual-versus-automated split, and whether a retest is included before comparing prices.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is automated discovery, usually one to two days, and it reports known issues matched against a database. A penetration test adds manual exploitation: a human attempts to chain findings into real access. A quote far below $4,000 is almost always a scan with a report attached.

Is black box or grey box testing better value?

Grey box, for most teams. Black box withholds credentials and architecture, so a large share of the budget goes on reconnaissance you could have supplied for free. Grey box spends those hours on exploitation instead, which is what you are actually paying for.

Does compliance make a penetration test more expensive?

Yes. Testing to satisfy PCI DSS, SOC 2, HIPAA or ISO 27001 carries defined scoping rules, specific evidence requirements and a report format the auditor will accept. Expect a premium over an equivalent engagement with no compliance driver.

How often should we run a penetration test?

Annual testing is a snapshot of a build that shipped before the test started. If you release weekly or fortnightly, most of your production code has never been tested by the time the report arrives. Teams shipping continuously usually get better coverage per dollar from a continuous programme than from one large annual engagement.

Should the retest be included in the quote?

Ask explicitly, and get the answer in writing. Some vendors include one time-boxed retest after remediation, others bill it separately, and on the same engagement that difference can be several thousand dollars.

What is the most common way teams waste penetration testing budget?

Testing the wrong thing thoroughly. A well-executed network test tells you little if your real exposure is an over-permissive storage bucket and an unauthenticated internal API. The second most common is treating the report as the deliverable and not budgeting for the remediation work it generates.

Free Assessment

Get a free QA audit for your project

Identify quality gaps before they become production bugs.

Get Free Audit

Ship software with confidence

Talk to a QA advisor and find out how QAble can help your team build quality in at every stage.

No sales pitch
Technical walkthrough
No lock-in commitment

Talk to QA Advisor

Direct access to QAble's QA specialists.

Response within 24 hours