Compare
What a penetration test costs, and why quotes vary so much
Penetration test pricing varies by an order of magnitude for work that is often comparable. Understanding which inputs actually move the number makes the range explainable.
The short answer
Published pricing and a custom quote describe the same work priced two ways. A quote-only process is not more accurate; it moves the price discovery into a sales cycle. The inputs that change the cost of a penetration test are knowable in advance: how many assets are in scope, how much context the tester gets, how fast the report is needed, and whether testing continues after it.
| Published pricing | Custom quote | |
|---|---|---|
| Time to a number | Immediately | After a discovery call, sometimes two |
| Comparability | Directly comparable between vendors | Hard to compare; scope assumptions differ under the surface |
| What moves the price | Stated: scope size, access level, delivery speed | Often unstated until the statement of work |
| Procurement friction | Low; a budget holder can plan before engaging | Higher; the budget conversation depends on the sales cycle |
| Fit for unusual scope | Bands cover the common cases, edge cases still need a conversation | Built for edge cases, at the cost of speed for everyone else |
Choose Published pricing when
- Your environment is a typical software product with a countable asset surface
- You need a budget number before you can get approval to engage
- You are comparing vendors and want like-for-like
Choose Custom quote when
- Scope genuinely is unusual: industrial systems, hardware, a large regulated estate
- The engagement is threat-led or red team rather than a scoped assessment
- Multiple business units, jurisdictions or assessors are involved
Four inputs account for most of the variance. Scope size, meaning how many distinct assets and roles are in play. Access level, since a black box test spends budget on discovery that a white box test spends on testing. Delivery speed, because a 24-hour evidence window requires holding capacity. And whether the engagement ends at the report or continues as monitoring.
None of those require a discovery call to establish. They require a buyer to answer four questions. The reason the industry defaults to opaque quoting is commercial rather than technical: a price that arrives after a relationship has formed is easier to hold.
The one thing a published price should never do is hide a scope limit that surfaces later as a change order. A fixed price with a stated asset ceiling is honest. A fixed price with an undefined ceiling is a quote wearing a costume.
Questions people ask
How much does a penetration test cost?
For a typical software product, several thousand dollars for a scoped assessment. The range across the industry is wide because scope size, access level and delivery speed vary, and because some vendors price after a sales process rather than publishing. The four inputs that move the number are knowable before any call.
Why do penetration test quotes vary so much?
Because the scope assumptions underneath them differ and are often not stated. A quote for ten external assets and a quote for fifty are not comparable, and neither is a black box engagement against a white box one. Comparing quotes requires normalizing those assumptions first.
Is a cheaper penetration test worse?
Not necessarily, but ask what produced the saving. Less scope and less tester time are legitimate reasons. A scan sold as a test is not. The check is whether findings were validated by a person and whether anything in the report is specific to your application's logic.
Related comparisons
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.