Pricing guide
Penetration testing cost, by target and by driver
Penetration testing cost depends on scope far more than on the firm's logo. Below are the US market ranges we publish for each target, and the four drivers that move a quote inside them.
- Named tester before day one
- One retest within 30 days
- OWASP WSTG and NIST SP 800-115
Penetration testing cost by target
These are published US market ranges for 2025 and 2026. Most companies, however, land between $10,000 and $30,000 in total.
| Target | Published range |
|---|---|
| Web application | $5,000 to $30,000. |
| External network | $4,000 to $20,000. |
| Internal network | $5,000 to $35,000. |
| API | $10,000 to $25,000. |
| Mobile app | $5,000 to $40,000. |
| Cloud configuration | $10,000 to $50,000. |
| Red team | $30,000 to $150,000. |
The four drivers of penetration testing cost
First, scope size: every extra app, API or role adds time. Second, manual hours: a $6,000 quote is roughly 15 hours, while a $20,000 quote is roughly 60. Third, tester seniority, since day rates run from $1,500 to $3,500 mid-market and higher at the top. Finally, whether a retest is included, which explains many apparently identical quotes.
Estimate your penetration testing cost drivers
Tick each statement that is true. More ticks usually means a larger scope and a higher fee.
Your result appears here as you tick, so you can see what is still open.
Why very low penetration testing cost is a warning
Anything under about $4,000 is almost certainly an automated scan, not a manual test. Scans have their place, but they rarely satisfy an auditor who reads the report closely, and then you pay again.
How to keep the cost predictable
Write the scope down both ways: what is included and what is excluded. Vague edges are also how budgets drift. In addition, agree a fixed fee before work begins, and book early for the fourth quarter, because compliance deadlines cluster there and good testers are committed four to six weeks ahead.
What the fee includes with us
Our quotes are fixed fees inside the published ranges. Each includes manual testing by a named practitioner, a report with proof and fixes, an attestation letter and one retest inside 30 days. Further detail on each target is in its own guide, so follow the links below. Method references include NIST SP 800-115.
Penetration testing cost questions
What is a typical penetration testing cost for a SaaS company?
Most land between $10,000 and $30,000 for an application and external network test together, depending on roles and features.
Is a retest extra?
With many firms, yes, but ours includes one retest inside 30 days.
Why does penetration testing cost more in the fourth quarter?
Prices do not rise, but availability falls. Book four to six weeks ahead to keep your preferred dates.
Can we lower the cost by reducing scope?
Yes, as long as the reduced scope still covers what your auditor or customer asked for.
Related guides
Get your exact penetration testing cost
Answer four scoping questions on our home page and receive a written estimate, usually within four working hours.
Get my estimate