Ask five penetration testing firms for a quote on the same web application and you will get five numbers that can differ by a factor of ten. That is not because four of them are lying. It is because “penetration test” describes everything from a rebranded vulnerability scan that finishes overnight to a three-week manual engagement by people who write their own exploit tooling, and the price gap between those two is the price gap between the products.
This guide lays out penetration testing cost as firms actually charge it in 2026, by type of test and by pricing model, and then does the more useful thing: explains what moves a quote up or down so you can read one intelligently. It closes with the compliance requirements that trigger most testing budgets, the warning signs of a cheap test that will not survive an auditor, and a worked budget for three sizes of company.
A standard commercial penetration test in 2026 costs between $10,000 and $35,000, and the average cost of penetration testing for a single web application or external network sits in the $10,000 to $20,000 band. Below that range you are usually buying a single small asset or a largely automated assessment; above it you are buying a large environment, a specialist target such as an embedded device, or a red team exercise. The following table summarizes the pentest cost ranges that reputable firms are quoting this year.
|
Engagement type |
Typical 2026 range (USD) |
Typical duration |
|---|---|---|
|
External network |
$5,000 to $20,000 |
3 to 10 days |
|
Internal network |
$7,000 to $35,000 |
5 to 15 days |
|
Web application or SaaS platform |
$5,000 to $30,000 (complex apps to $50,000) |
5 to 15 days |
|
API |
$5,000 to $20,000 |
3 to 10 days |
|
Mobile application (per platform) |
$5,000 to $30,000 |
5 to 10 days |
|
Cloud environment (AWS, Azure, GCP) |
$10,000 to $40,000 and up |
5 to 15 days |
|
Wireless |
$3,000 to $15,000 |
2 to 5 days |
|
Social engineering (phishing, vishing) |
$4,000 to $20,000 |
1 to 3 weeks elapsed |
|
Physical intrusion |
$10,000 to $40,000 |
1 to 2 weeks |
|
Embedded device or product security |
$25,000 to $100,000 and up |
3 to 8 weeks |
|
Full red team or adversary emulation |
$50,000 to $150,000 and up |
4 to 12 weeks |
Two caveats apply to every row. These are ranges for manual, human-led testing by firms with a track record; automated “pentest” products sit below them and are discussed separately. And every range assumes a single engagement. Annual programs, retainers and multi-asset bundles reprice everything, usually downward per asset.
Penetration testing is priced on labor. Nearly every firm starts from a day rate, estimates the number of tester-days a scope needs, and adds a margin for reporting, project management and retesting. Understanding the day rate and what drives the day count explains almost every quote you will receive.
In 2026, US and Western European firms charge between $1,500 and $3,000 per tester-day for standard penetration testing, which works out to roughly $200 to $375 an hour. Boutique firms with senior, research-active staff sit at the top of that band and sometimes above it. Offshore delivery centers and large consultancies using junior staff sit at the bottom. The rate is worth asking about directly, because two quotes with the same total can hide very different amounts of actual testing time: one firm might quote $15,000 for ten days at $1,500 and another $15,000 for five days at $3,000, and which is better value depends entirely on who is doing the work.
The number of things being tested is the biggest multiplier. For networks that means IP addresses and hosts; for applications it means pages, endpoints, user roles and workflows; for cloud it means accounts, services and the identity model that connects them. A web application with three user roles and 40 dynamic pages is a five-day job. The same application with a partner portal, an admin console, a public API and a mobile client is a three-week job, and the price scales accordingly. Firms that quote without asking detailed scoping questions are either guessing or planning to run a scanner.
Black box testing, where the tester starts with nothing but a target, takes longer because reconnaissance and access take real time. White box testing, where the tester gets credentials, architecture documents and sometimes source code, is more efficient per finding and usually finds more, but it demands a tester who can read code and infrastructure rather than just run tools. Grey box, with credentials but no source, is the most common commercial choice and prices in the middle. The cost difference between approaches is smaller than most buyers expect; the difference in what gets found is larger.
Certifications such as OSCP, OSCE, OSEP, CREST CRT and CCT, and the GIAC penetration testing tracks are the standard proxies for skill, and CREST accreditation at the firm level is increasingly a procurement requirement in finance and government. They raise the rate. So does a research profile: firms whose staff publish CVEs, present at conferences or build their own offensive tooling charge more because they find the things scanners and playbooks miss. That premium is worth paying for a production application or a network that has already been tested several times, and less necessary for a first-ever external test of a small perimeter.
A test that has to satisfy an auditor costs more than the same test done for internal assurance, because the report has to map findings to control requirements, document methodology in a specific way and, for PCI DSS, cover segmentation and specific scope rules. Expect a 10 to 25 percent premium for compliance-formatted deliverables, and more where the framework dictates a particular testing standard.
A finding is not closed until someone verifies the fix. Most reputable firms include one retest of critical and high findings within 30 to 90 days in the base price; some charge separately, typically 10 to 20 percent of the engagement fee. Ask. A quote that looks cheap and then bills for the retest that your auditor requires is not cheap.
Good firms book out four to eight weeks ahead, and Q4 is worse because compliance deadlines cluster there. Rush engagements inside two weeks carry a 20 to 50 percent premium if the firm can staff them at all. Planning the test in the quarter before the audit, rather than the month before, is the single easiest way to reduce the bill.
The summary table above gives the ranges. The detail below explains why each type lands where it does, which is what you need to judge whether a specific quote is reasonable for your environment.
External tests assess what an attacker on the internet can reach: the public IP ranges, exposed services, VPN endpoints, mail infrastructure and web servers. Small perimeters of a few dozen hosts run $5,000 to $8,000. A few hundred hosts with multiple offices and cloud-hosted infrastructure push toward $15,000 to $20,000. Some firms price per IP address, typically $150 to $1,000 each depending on how much is actually listening, which works well for very large or very small ranges and poorly in between.
Internal tests assume the attacker already has a foothold, usually a laptop plugged into the office network or a VPN account, and measure how far they can get. Active Directory is the main event: privilege escalation, credential relay, Kerberos abuse and lateral movement toward domain admin and the systems that matter. Because the attack surface is larger and the techniques more involved, internal tests cost more than external ones and take longer, from $7,000 for a small flat network to $35,000 for a multi-domain enterprise with segmentation to validate. Firms that can demonstrate a realistic path from an unprivileged user to domain compromise are the ones worth paying for here.
This is the most commonly purchased test and the most variable in price. A brochure site with a contact form is a $5,000 job. A multi-tenant SaaS platform with role-based access, file uploads, payment flows, integrations and an admin layer is $25,000 to $50,000, because each role and workflow has to be tested for authorization flaws, business logic abuse and injection, and because authorization testing across tenants is slow, careful work that no scanner does well. Firms quoting a flat $5,000 for a serious SaaS product are not testing it seriously.
APIs are cheaper than the applications they sit behind because there is no interface to navigate, but the work is proportional to endpoints and authentication schemes. A documented REST API with 30 endpoints runs $5,000 to $10,000; a large GraphQL surface with complex authorization or a poorly documented legacy API runs to $20,000, much of it spent on discovery.
Mobile tests cover the app binary, local storage, transport security, platform-specific issues and the backend API the app talks to. Pricing is per platform, so an iOS and Android pair costs roughly 1.6 to 1.8 times a single platform rather than double, because the backend testing is shared. Expect $5,000 to $15,000 per platform for a typical consumer or business app and more for apps with payments, health data or hardware integration.
Cloud tests are a distinct discipline. The targets are identity and access configuration, storage exposure, network controls, secrets management, container and serverless deployments, and the paths from a compromised developer credential to production data. Pricing starts around $10,000 for a single account with a conventional footprint and climbs past $40,000 for multi-account organizations with Kubernetes, CI/CD pipelines and cross-cloud integration. Testers need real cloud engineering knowledge, which is scarcer than web application skill and priced accordingly.
Wireless assessments are usually short and site-based, $3,000 to $15,000 depending on locations. Social engineering campaigns (phishing, vishing, pretext calls to the help desk) run $4,000 to $20,000 depending on scale and whether the goal is a metric or an actual foothold. Physical intrusion, where testers attempt to enter facilities and reach sensitive areas or plug in devices, is travel-heavy and legally involved, so $10,000 to $40,000 per engagement is normal.
Hardware and firmware testing is the expensive end of the market: $25,000 to $100,000 and beyond. Testers need lab equipment, reverse engineering skills and time, and the deliverable often feeds a product release rather than an audit. Very few firms do it well, which keeps prices high.
A red team engagement is not a penetration test with a bigger scope. It is an objective-based exercise, typically four to twelve weeks, in which a team attempts to reach defined goals (exfiltrate a specific dataset, gain control of a payment system) while evading detection, and the output measures the organization’s ability to detect and respond as much as its vulnerabilities. Budgets start around $50,000 and routinely exceed $150,000 for large enterprises, with the top boutique firms charging more. Purple team variants, where attackers and defenders work together to tune detection, tend to cost less per week and produce more immediately usable results for security operations teams.
The same test can be sold under several commercial structures, and the structure matters as much as the headline number.
Fixed-price engagements are the default: a defined scope, a fixed fee, a defined deliverable. This is what most buyers want and what most of the ranges above describe. The risk is scope creep on both sides; a firm that discovers the environment is larger than described will either cut testing depth or come back with a change order.
Time and materials pricing bills by the day or hour, usually with an estimate up front. It suits engagements where scope genuinely cannot be pinned down, such as product security work, and it favors buyers who can manage the engagement closely. It is a poor fit for compliance testing where a defined report is the goal.
Retainers and credit banks let an organization prepurchase testing days for the year at a discount, typically 10 to 20 percent off the rack rate, and draw them down as releases ship. This is the model that mature product companies have moved to, because it matches testing to the release cycle rather than the audit cycle.
Penetration testing as a service (PTaaS) platforms sell subscription access to a testing bench, usually with a portal for findings, retesting on demand and integrations into ticketing systems. Entry tiers with automated scanning and light manual validation start around $2,000 to $8,000 a year; manual testing on those platforms is priced in credits or hours and lands close to conventional firm pricing once you add up a real engagement. PTaaS is a good fit for teams that ship weekly and want continuous coverage, and a poor fit for one-off, compliance-heavy or unusual targets.
Bundled and managed options combine testing with vulnerability scanning, phishing simulation or virtual CISO services under one contract. These can be good value for smaller organizations with no security staff, provided the penetration testing component is manual and separately described rather than a scanner with a new name.
Most penetration testing budgets exist because an auditor, a regulator or a customer questionnaire demands it. The requirements differ more than vendors admit, and knowing them prevents both overbuying and failing the audit.
|
Framework |
What it requires |
Budget implication |
|---|---|---|
|
PCI DSS v4.0 (Req. 11.4) |
Internal and external penetration testing at least annually and after significant changes; segmentation testing annually (every six months for service providers); defined methodology; retest to verify fixes |
The most prescriptive. Budget for internal plus external plus segmentation, plus retest, every year |
|
SOC 2 |
No explicit mandate, but penetration testing is the standard evidence for several Trust Services Criteria and auditors expect at least an annual test |
One annual test of the in-scope system, usually a web app or cloud environment |
|
ISO 27001:2022 |
Control A.8.8 (technical vulnerability management) and A.8.29 (security testing) expect regular testing; frequency is risk-based |
Annual test is the norm; scope follows the ISMS boundary |
|
HIPAA |
No explicit pentest requirement; the Security Rule’s risk analysis and evaluation standards are what OCR examines, and penetration testing is widely treated as the way to satisfy them |
Annual test of systems handling ePHI; strong expectation from cyber insurers |
|
NYDFS 23 NYCRR 500 |
Annual penetration testing from inside and outside the boundary (Section 500.5) plus periodic vulnerability assessments |
Internal plus external annually for covered financial entities |
|
CMMC 2.0 Level 2 (NIST SP 800-171) |
Vulnerability scanning and remediation controls; penetration testing is expected practice for demonstrating them and required at Level 3 |
Annual test of the CUI environment for defense contractors |
|
FedRAMP |
Annual penetration testing per the FedRAMP guidance, covering specified attack vectors including social engineering |
The most expensive single requirement: multi-vector testing by an accredited 3PAO, typically $40,000 and up |
Two practical points follow. First, the same engagement can often satisfy several frameworks if it is scoped and reported correctly, so tell the firm every framework you are subject to before they quote. Second, cyber insurance applications increasingly ask for the date and scope of the last penetration test, and a scanner report does not answer that question.
The low end of the market is crowded with products that run automated scanners, add a cover page and call the result a penetration test. They cost $500 to $3,000 and they are not worthless, but they will not survive a PCI qualified security assessor, a serious SOC 2 auditor or an actual attacker. The tells are consistent.
The price is under $4,000 for anything larger than a single small asset. The proposed duration is 24 to 48 hours for an application or network of any size. The scoping call takes ten minutes and asks nothing about user roles, architecture or business logic. The sample report lists findings by CVE number and scanner severity with no narrative of how the tester chained them, no evidence of exploitation and no business impact statement. Retesting is not mentioned. The firm cannot name the individuals who will perform the test or describe their backgrounds. Any two of those together mean you are buying a scan.
A real test, by contrast, produces a report that reads like a story: how the tester got in, what they could reach, which findings mattered and why, and what to fix first. That narrative is what an auditor wants and, more importantly, what your engineering team can act on.
Before comparing numbers, make sure each proposal covers the same things. A complete quote states the scope in specifics (IP ranges, application URLs, roles, cloud accounts), the methodology and the standards it follows (PTES, OWASP Testing Guide, NIST SP 800-115, or the framework-specific standard), the number of tester-days and the seniority of the staff assigned, the deliverables (executive summary, technical report, findings in a machine-readable format, an attestation letter for auditors and customers), the retest terms, the communication plan during testing including how critical findings are escalated the day they are found, and the rules of engagement including testing windows and emergency stop procedures. A quote missing more than one of these is not comparable with one that includes them, whatever the price.
There are legitimate ways to bring the number down that do not involve buying less testing.
Scope precisely. Decommission or exclude assets that do not matter, and consolidate test environments so the tester is not spending days mapping duplicates. Provide access up front: grey box or white box testing with credentials, architecture diagrams and, where appropriate, source access produces more findings per day than making a tester break in from scratch, and most compliance frameworks are indifferent to the approach. Fix the obvious first: run your own vulnerability scan and patch what it finds before the test, so paid days go to the hard problems. Book early and outside Q4. Combine engagements: an external network test, a web application test and a cloud review from one firm in one window shares reconnaissance and reporting effort and is usually 15 to 25 percent cheaper than three separate purchases. And commit to a program rather than a project; annual retainers earn discounts and, more valuably, a tester who already knows your environment.
A seed to Series A SaaS startup pursuing its first SOC 2 report typically needs one grey box test of the production web application and API, plus a light review of the cloud account it runs in. Realistic 2026 budget: $12,000 to $20,000, including retest, from a boutique firm or a PTaaS platform’s manual tier.
A mid-market company with 500 to 2,000 employees, an office network, a customer-facing platform and PCI obligations needs an annual external test, an internal test with Active Directory focus, a web application test and PCI segmentation testing, with retests. Budget $45,000 to $90,000 a year, less if bundled with a single firm on a retainer.
An enterprise with regulated data, a mature security program and a detection team that needs to be measured moves beyond penetration testing into adversary emulation: a red team engagement every 12 to 18 months at $80,000 to $200,000, purple team exercises in between at $30,000 to $60,000 each, and continuous testing of the application estate through a retainer or PTaaS program running $100,000 and up annually. Total offensive security spend of $250,000 to $500,000 a year is normal at this level.
A small business with a modest external footprint and one web application should expect $5,000 to $12,000 for a manual external and application test from a credible firm, including a retest. Quotes materially below $4,000 are almost always automated scans.
Because the day rate and the number of tester-days both vary. A $2,800-a-day boutique tester for five days and a $1,400-a-day generalist for ten days both produce a $14,000 quote with very different work behind them. Ask for the day count and the names and backgrounds of the assigned testers.
No. A scan identifies known weaknesses automatically. A penetration test has a human attempt to exploit them, chain them and reach something that matters, then document how. Auditors, regulators and insurers distinguish between the two, and so do attackers.
At least annually, plus after significant changes, which is what PCI DSS, NYDFS and most auditors expect. Organizations shipping software continuously increasingly move to quarterly testing or a retainer model so that new features are tested as they ship rather than months later.
Often, but not always. Most reputable firms include one retest of critical and high findings within 30 to 90 days. Others charge 10 to 20 percent of the engagement fee. Confirm before signing, because your auditor will want evidence that findings were fixed.
A penetration test aims to find as many meaningful vulnerabilities as possible in a defined scope within a fixed time. A red team engagement aims to achieve a specific objective while evading detection, over a longer period, and measures the organization’s detection and response as much as its vulnerabilities. Red teams cost three to ten times more and are only useful once basic testing is already in place.
Usually, if it is scoped and reported with all three in mind. PCI DSS has the most specific requirements (internal, external and segmentation testing with a documented methodology), so scoping to PCI first and then mapping the report to the other frameworks is the efficient approach.
Penetration testing cost in 2026 is not mysterious once you see it as labor at a day rate. A standard commercial engagement runs $10,000 to $35,000; the number goes up with scope, target complexity, tester seniority and compliance formatting, and it goes down with precise scoping, early booking, provided access and multi-engagement commitments. The expensive mistake is not paying too much for a good test. It is paying $3,000 for a scan, discovering at audit time that it does not count, and paying for the real test anyway. For a shortlist of firms that do the work properly, the top penetration testing companies in 2026 and top red teaming companies lists are the place to start.