Pricing
The price, before the call
Two inputs change what a penetration test costs. Both are listed here, with the asset ceiling for each tier stated up front rather than discovered in a change order.
The short answer
A comprehensive white box assessment starts at $3,000 and reaches $5,450 at the largest scope with priority delivery. Scope size and delivery speed are the only two things that move it.
| Scope | Assets covered | StandardReport in 3 to 5 business days | PriorityTesting starts within 24 hours |
|---|---|---|---|
| Starter | Up to 10 external assets | $3,000 | $3,700 |
| Growth | Up to 25 external assets | $3,600 | $4,300 |
| Scale | Up to 50 external assets | $4,750 | $5,450 |
One-time price per assessment, in USD. Continuous monitoring is billed separately and monthly.
Included in every assessment
- A named engineer running the engagement, not a queue
- Findings validated before they reach the report, so no scanner noise
- Reproduction steps written so an engineer can act without re-proving the issue
- One retest of remediated findings, with a dated verification record
- A redacted one-page summary you can send to customers and auditors
- Rules of engagement agreed in writing before anything starts
What we do not do
- Threat-led or red team engagements, which are a different exercise
- FedRAMP assessments, which must be performed by an accredited 3PAO
- Physical or social engineering testing unless separately scoped
- Remediation work itself, since testing your own fixes is not independent
Listed because a vendor who claims to do everything is describing a sales process rather than a practice. See FedRAMP for why some assessments require an accredited assessor.
Questions people ask
How much does a penetration test cost?
A comprehensive white box assessment starts at $3,000 and reaches $5,450 at the largest scope with priority delivery. The inputs that move the price are the number of external assets in scope and the delivery speed.
What happens if the scope turns out to be larger?
Each tier states an asset ceiling. If the real scope exceeds it, you move to the next tier and we tell you before testing starts, not in an invoice afterwards. A fixed price with an undefined ceiling is a quote in disguise.
Is the retest included?
Yes, one retest of remediated findings with a dated verification record. That record is usually worth more to an audit than the original report, because it shows the vulnerability management control closing a loop rather than only finding a problem.
Why publish prices when most firms do not?
Because the inputs that change the cost are knowable in advance and a discovery call does not make them more accurate. Publishing lets a budget holder plan before engaging, and lets you compare vendors like for like.
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.