ClearPenTest

Compare

What a penetration test costs, and why quotes vary so much

Penetration test pricing varies by an order of magnitude for work that is often comparable. Understanding which inputs actually move the number makes the range explainable.

The short answer

Published pricing and a custom quote describe the same work priced two ways. A quote-only process is not more accurate; it moves the price discovery into a sales cycle. The inputs that change the cost of a penetration test are knowable in advance: how many assets are in scope, how much context the tester gets, how fast the report is needed, and whether testing continues after it.

 Published pricingCustom quote
Time to a numberImmediatelyAfter a discovery call, sometimes two
ComparabilityDirectly comparable between vendorsHard to compare; scope assumptions differ under the surface
What moves the priceStated: scope size, access level, delivery speedOften unstated until the statement of work
Procurement frictionLow; a budget holder can plan before engagingHigher; the budget conversation depends on the sales cycle
Fit for unusual scopeBands cover the common cases, edge cases still need a conversationBuilt for edge cases, at the cost of speed for everyone else

Choose Published pricing when

  • Your environment is a typical software product with a countable asset surface
  • You need a budget number before you can get approval to engage
  • You are comparing vendors and want like-for-like

Choose Custom quote when

  • Scope genuinely is unusual: industrial systems, hardware, a large regulated estate
  • The engagement is threat-led or red team rather than a scoped assessment
  • Multiple business units, jurisdictions or assessors are involved

Four inputs account for most of the variance. Scope size, meaning how many distinct assets and roles are in play. Access level, since a black box test spends budget on discovery that a white box test spends on testing. Delivery speed, because a 24-hour evidence window requires holding capacity. And whether the engagement ends at the report or continues as monitoring.

None of those require a discovery call to establish. They require a buyer to answer four questions. The reason the industry defaults to opaque quoting is commercial rather than technical: a price that arrives after a relationship has formed is easier to hold.

The one thing a published price should never do is hide a scope limit that surfaces later as a change order. A fixed price with a stated asset ceiling is honest. A fixed price with an undefined ceiling is a quote wearing a costume.

Questions people ask

How much does a penetration test cost?

For a typical software product, several thousand dollars for a scoped assessment. The range across the industry is wide because scope size, access level and delivery speed vary, and because some vendors price after a sales process rather than publishing. The four inputs that move the number are knowable before any call.

Why do penetration test quotes vary so much?

Because the scope assumptions underneath them differ and are often not stated. A quote for ten external assets and a quote for fifty are not comparable, and neither is a black box engagement against a white box one. Comparing quotes requires normalizing those assumptions first.

Is a cheaper penetration test worse?

Not necessarily, but ask what produced the saving. Less scope and less tester time are legitimate reasons. A scan sold as a test is not. The check is whether findings were validated by a person and whether anything in the report is specific to your application's logic.

Get a scoped price without a discovery call

Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.