You are currently viewing How Much Does Penetration Testing Cost?

How Much Does Penetration Testing Cost?

A penetration test is one of the few security purchases where two quotes for the same words can differ by a factor of ten. One firm says $4,000. Another says $38,000. Both call it a pen test.

That gap is real, and the expensive one is not automatically the rip-off. Scope, tester skill, and what lands in your final report explain almost all of it.

Here is what the work costs, what moves the number up or down, and how to spot a vulnerability scan wearing a pen test price tag.

Shopping for penetration testing? Skip the vendor calls — we’ll get you real quotes from 3 vetted providers in 24 hours. Free, no obligation. Get my free shortlist → How we make money →

The Short Answer

Most businesses pay $5,000 to $20,000 per project for a penetration test. The price varies based on scope, with external network tests at the lower end and comprehensive engagements covering multiple areas at the higher end. Quotes under $3,000 may not include significant human tester time, while those above $25,000 often reflect complex environments or specialized expertise.

Penetration Testing Cost: The Short Answer

Most businesses pay $5,000 to $20,000 per project for a penetration test. A tight external network test on a handful of public IPs sits near the bottom of that band, while a multi-part engagement covering web apps, the internal network, and social engineering sits at the top.

Quotes under $3,000 deserve a hard look, because that price rarely buys much human tester time. Above $25,000 you are usually paying for a big environment, a specialized application, or a consultancy whose name carries weight with an auditor.

The number matters less than what sits behind it. Two firms can quote the same three words and sell completely different work.

What You Are Actually Paying For

A penetration test is a skilled person trying to break into your systems, with your permission, inside an agreed time box. The tester chains small weaknesses into a real path: a forgotten admin panel, a reused password, an upload form that runs code. Then they document the route and rate the damage.

Tester days drive the invoice. Every pricing question below is really a question about how many days the work takes.

Scope

Scope moves the price more than anything else. Each item you add brings its own tooling, its own method, and its own hours.

Test type What the tester goes after Effect on price
External network Internet-facing IPs, VPN portals, mail and web servers Cheapest scope, the usual starting point
Internal network What an attacker does after landing inside, from a laptop or virtual machine on your LAN Often doubles a small external-only quote
Web application Login flows, business logic, access controls, injection points in one app Priced per application; a complex portal costs far more than a brochure site
API Endpoints, tokens, authorization gaps between accounts Similar to a web app, higher when documentation is thin
Wireless Rogue access points, guest network separation, weak encryption Small add-on, charged per office
Social engineering Phishing email, pretext phone calls, how your staff respond Modest add-on, high value for most small businesses
Physical Tailgating, badge cloning, unlocked server rooms and wiring closets Travel plus onsite time make this the priciest add-on

Number of IPs and applications

Providers count things to size a job. Live hosts, application count, user roles per application, and site count all feed the day estimate. Twenty hosts and one simple app is roughly a week of work. Four hundred hosts across three sites with five applications is a month, and the quote moves right along with it.

Black box, grey box, or white box

Black box means the tester starts with nothing but your company name. Grey box hands over a low-privilege account and some documentation. White box adds source code, architecture diagrams, and admin access.

Buyers like the sound of black box because it feels realistic. It also burns paid days on reconnaissance that a patient attacker would happily spend for free. Grey box finds more real problems per dollar at small-business scale, which is why most experienced testers push you toward it.

Retesting, credentials, and report quality

Three line items separate a cheap quote from a fair one. A retest confirms your fixes actually worked, and plenty of firms charge extra for that second pass. Named testers holding OSCP, GPEN, or a CREST-registered certification such as CRT bill more per day than a junior running someone else’s playbook. An audit-ready report with an executive summary, evidence screenshots, CVSS ratings, and a remediation plan takes real writing time, so a firm that skips the writing can quote lower and still profit.

The Trap: A Vulnerability Scan Sold as a Penetration Test

This is the most common way buyers lose money on testing. A scanner runs against your IP range, produces a 200-page export of findings sorted by severity, and someone drops a cover page on it. That work costs the vendor a few hundred dollars of license time. Charging $4,000 for it looks like a bargain next to a $12,000 test, and the two products have almost nothing in common.

Automated scan Penetration test
Who does the work Software, on a schedule A person, using software only as a starting point
What it finds Missing patches, weak configuration, expired certificates Chained flaws, business logic errors, privilege paths no tool spots
False positives Many, and you sort them yourself Each finding proven by hand before it reaches the report
Output Tool export Attack narrative plus fixes ranked by business risk
Typical price $100 to $500 per month $5,000 to $20,000 per project
Best use Continuous coverage between tests Proving whether an attacker can actually get in

Scanning still earns its keep. Continuous scanning belongs in every business, and it forms the spine of the vulnerability management services that stop patch gaps from sitting open for months. Scanners also flag the exact software versions behind actively exploited bugs, which matters when a flaw hits the CISA KEV deadlines we track and the clock starts on remediation.

Intent is the real difference. A scanner asks what looks wrong. Testers ask what an attacker can actually do with it, which is why a good report reads like a story built from the attack types testers actually simulate rather than a sorted list of software versions.

Who Has to Buy One Now

Regulators are moving on this. HHS has proposed a HIPAA Security Rule overhaul that would require penetration testing every 12 months and vulnerability scanning every six. As of mid 2026 that rule is still a proposal, and the final version could look different. Today’s Security Rule asks for risk-based evaluation rather than a named pen test, so most healthcare buyers are testing because their own risk analysis points that way.

PCI DSS has asked for the same thing for years. Requirement 11.4 calls for an annual test plus testing after any significant network change, and it applies by questionnaire type rather than merchant level, so plenty of small e-commerce shops on SAQ A-EP are caught by it. SOC 2 never names a pen test in the trust criteria, though auditors ask for one constantly and enterprise customers reading your report expect to see it. Cyber insurance applications increasingly ask too. The full picture for each sits in our guides to PCI DSS compliance and SOC 2 compliance.

If a framework drives your purchase, say so on the first call. Report format changes, evidence handling changes, and a test that satisfies your auditor costs a little more than one that only satisfies you.

What a Fair Quote Looks Like

Use $5,000 to $20,000 per project as your sanity check, then look at where your scope sits inside that band.

Engagement Typical fair range
External network only, small footprint $5,000 to $8,000
External plus internal network $9,000 to $15,000
One web application or API, grey box $8,000 to $15,000
Multi-vector test with phishing and wireless $15,000 to $20,000

Price alone tells you very little, so check what the number buys. A fair quote spells out all six of these:

  • Named lead tester with a credential you can verify, such as OSCP, GPEN, or a CREST-registered certification.
  • Written scope covering IP ranges, application URLs, the test window, and rules of engagement.
  • Manual testing effort stated in tester days, not just a list of tools.
  • One round of retesting after your fixes, at no extra charge, inside 30 to 90 days.
  • Executive summary a board can read, plus a technical section your engineers can act on.
  • Debrief call where the tester walks your team through the attack path step by step.

How to Choose a Penetration Testing Provider

Six questions clear away most of the guesswork:

  • Who is the lead tester, and what certifications do they hold? Vague answers here predict vague reports.
  • Which parts of this work are manual? A firm that cannot answer in one minute is selling you tooling.
  • Does the price cover a retest? If not, ask what a retest costs before you sign anything.
  • Can I see a sanitized sample report? Every serious firm keeps one ready to send.
  • How do you handle a finding that risks an outage? Good testers stop and phone you.
  • What happens to my data after the engagement ends? Retention and destruction terms belong in the contract.

Two traps come up again and again. First, the fixed-price test with no scope document, which quietly lets the provider decide how little work to do. Second, the annual test that never changes, because the same firm runs the same template until year three finds nothing and nobody ever looked anywhere new.

When the cheap option is genuinely fine

Not every business needs a $20,000 engagement. A five-person firm with a website on a hosted platform, no internal servers, and no compliance pressure gets honest value from a $5,000 external test plus a phishing simulation. Same story for a startup that mainly needs to show one prospect it takes security seriously.

Spend more when you hold regulated data, run custom software, or take card payments. Skip the test entirely if you have never done the basics, and put that budget into multi-factor authentication, backups, and managed detection first, because a report listing twenty problems you already know about is $8,000 of confirmation.

We hold agreements with 52 providers that do penetration testing, from two-person boutiques to firms that staff a full red team. Matching is our job, not selling: we genuinely do not care which one you pick, and you can read exactly how we make money before you speak to anybody.

Frequently Asked Questions

How much does a penetration test cost for a small business?

Most small businesses land between $5,000 and $20,000 per project, with a single external network test at the low end. Under 50 employees, one office, and no custom applications usually means a quote near $5,000 to $8,000. Add a web application, an internal test, or phishing, and you move toward the middle of the band. Compliance-driven reporting adds a little on top.

How long does a penetration test take?

Plan on two to four weeks from kickoff to final report. Active testing usually runs three to ten business days, then the team spends several more days writing and quality-checking the report. Add a week when you need remote access provisioned or when scheduling has to work around a change freeze. Retests take a day or two once your fixes go live.

How often should we run a penetration test?

Once a year is the working standard, plus a test after any major change to your network or applications. PCI DSS and most auditors expect that annual cadence. If you ship software often, add a targeted application test at each significant release. Between engagements, keep scanning monthly so a fresh hole does not sit open for eleven months.

Is a penetration test the same as a vulnerability assessment?

No. A vulnerability assessment lists known weaknesses that tools can detect, while a penetration test proves which of those weaknesses an attacker can chain into actual access. Assessments cost hundreds per month and run continuously. Tests cost thousands per project and happen a few times a year. Most businesses need both, and one never replaces the other.

Do we need a pen test for HIPAA, PCI DSS, or SOC 2?

For HIPAA, not yet. A proposed Security Rule update would require an annual test, though it has not been finalized, so confirm the current position with your compliance advisor. PCI DSS Requirement 11.4 calls for annual testing plus testing after any significant change, which catches anyone validating on SAQ A-EP, SAQ D, or a full Report on Compliance, including plenty of small e-commerce merchants. SOC 2 does not name it outright, though most auditors and enterprise buyers expect one anyway. Tell your provider which framework applies before anyone scopes the work.

Why is one quote three times another?

Scope and tester days, almost always. A quote covering external network only will sit far below one covering internal network, two web applications, and social engineering. Manual hours, credentialed testers, retesting, and audit-ready reporting each add cost. When two numbers look wildly apart, put the scope documents side by side before you judge either price.

Written by Russ Herman, founder of Defend My Business. We are a technology broker, like a mortgage broker but for business security, internet, and voice. We hold agreements with 400+ vetted providers. Vendors pay us, you never do. See exactly how we make money. Questions: 1-877-453-8759 or [email protected].

Get a Tailored Penetration Testing Shortlist

3 vetted vendors matched to your size, industry, and budget. Free, vendor-neutral, 24-hour turnaround.

Get a Quote →
Get It Right the First Time

Want help getting your security solution right?

Defend My Business helps SMBs cut through the marketing and get their security solution right for their environment, budget, and compliance needs — then deploy and manage it. Through our 400+ vendor network we can often secure better pricing and terms than buying direct, and we stay vendor-neutral, so the recommendation fits you, not a sales quota. Want a second opinion? Pair this with our cybersecurity consulting or talk it through with an advisor.

Book a free call with a DMB advisor →

Russ Herman

Russ Herman is the founder of Defend My Business, a cybersecurity advisory for small and mid-sized businesses. He works with the DisruptionIO partner network of 400+ vetted providers across cybersecurity, connectivity, cloud, and disaster recovery to help SMB owners and IT leaders cut through vendor noise with plain-English guidance and 24-hour shortlists from a pre-vetted ecosystem.

Leave a Reply