Straight Answers on Budget

How Much Does a Penetration Test Cost?

Most firms refuse to answer this until they have your contact information. Here is a genuinely useful answer instead: the ranges real engagements fall into, what moves a number within those ranges, and how to tell an underpriced test from a good deal.

Ballpark Ranges

What engagements typically run

These bands are intentionally wide, because scope drives cost far more than the type of assessment does. A small single-role application and a sprawling multi-tenant platform are both "web application penetration tests" and they are nowhere near the same amount of work.

Treat this as orientation for budgeting, not as a quote. Nothing here is a price for your environment, and anyone who quotes you without understanding your scope is guessing.

Focused, single-target assessments

Mobile application, wireless, social engineering

Roughly $4,000 to $12,000

Standard perimeter and cloud work

External network, cloud environment assessment

Roughly $5,000 to $15,000

Application testing

Web and API penetration testing

Roughly $7,000 to $20,000 and up

Internal and large-scope network testing

Internal network, segmented environments, Active Directory

Roughly $8,000 to $25,000 and up

Annual programs

Multiple assessments plus retests across a year

Commonly $20,000 to $75,000 and up

If your budget is a few thousand dollars, we are probably not the right firm, and you should know that now rather than after three calls. What you can buy at that level is an automated scan with a report generated from it. That has real uses, but it is not a penetration test and it will not stand up to a customer security review.

What Moves the Number

Six things that actually drive cost

When you compare quotes, these are the variables to hold constant. A cheaper quote usually means fewer hours or shallower testing, not a better rate.

Scope size

The count of applications, IP addresses, and environments in scope is the single biggest factor. Two apps is not twice the work of one, but ten apps is not the same engagement either.

User roles and permissions

Authorization testing multiplies with roles. An app with admin, manager, and end-user tiers takes meaningfully longer than a single-role app, because every boundary between roles has to be tested in both directions.

Depth of testing

A scan-and-verify pass is not the same product as full manual testing with business logic analysis and exploit chaining. The cheapest quotes in this industry are almost always the former sold as the latter.

Complexity of the target

Custom authentication, heavy integrations, unusual protocols, and large legacy codebases all add hours. So does anything that needs a specialist rather than a generalist.

Retests and cadence

Whether you need one test or a program with retests after remediation changes the shape of the engagement, and usually the price per assessment.

Compliance requirements

PCI DSS segmentation testing, SOC 2 evidence needs, and similar obligations set a floor on what has to be covered regardless of how small the environment feels.

Comparing Quotes

How to tell what you are actually buying

Ask every firm the same four questions and the price differences usually explain themselves. How many hours are budgeted, and by whom? Who performs the testing, and what are their certifications? Is retesting included after we remediate? Can I see a sample report before I sign?

That last one is the fastest filter, which is why ours are published without a form. A thin report after a two-week engagement tells you the testing was thin too.

For what it is worth on the retest question: at TrustFoundry retests are part of the engagement rather than a follow-on sale, and findings stay live in a portal instead of freezing in a PDF. That is described on our PTaaS page.

FAQ

Penetration testing cost questions

How much does a penetration test cost?

Focused assessments such as a mobile app or wireless test commonly run in the several-thousand to low-five-figure range, application and internal network engagements typically land higher, and annual programs that bundle multiple assessments with retests are usually a five-figure yearly commitment. Scope is the dominant variable, so the honest answer for any specific environment requires scoping it.

Why won't firms just publish a price list?

Because a penetration test is labor, not a product, and the labor required varies enormously with scope. Two engagements with the same name can differ by a factor of five in hours. Published ranges are useful for budgeting; a published fixed price would either be wrong or would quietly cap the testing at whatever that price buys.

Why is one quote half the price of another?

Almost always fewer hours, less experienced testers, or automated scanning presented as manual testing. Occasionally it is a genuinely narrower scope, which is worth catching before you compare. Ask each firm how many hours are budgeted, who performs the work, and whether retesting is included, and the gap usually explains itself.

Is the cheapest penetration test worth buying?

If the goal is a checkbox for a form, maybe. If the goal is finding the vulnerabilities an attacker would find, or producing evidence that survives a customer's security review, an underpriced test tends to cost more in the end. You pay once for the test and again for the incident or the failed review it did not prevent.

Do you charge extra for retests?

No. Retesting after you remediate is part of the engagement rather than a separate sale. You fix a finding, request a retest from the portal, and the verification is recorded in the same finding history an auditor will review.

How do you scope and quote an engagement?

We talk through what you have, what matters, and what any auditor or customer is requiring, then quote with the hours and methodology written down so you can compare it to anything else on your desk. Scoping conversations do not obligate you to anything.

Get a number for your environment

Tell us what you have and what you need tested. We scope it properly and quote it once, with the hours and the methodology written down.