Penetration Testing Cost: What Drives the Price and How to Scope a Test

Two pen test quotes for the same app can look nothing alike. Here is what actually drives the price, how to compare proposals, and how to avoid paying for the wrong test.

Written by
MyCTO Team — Engineering
Published
Reading time
7 min read
Category
Engineering
A security engineer running a penetration test against a web application on multiple screens

Penetration testing cost is hard to pin down because "a pen test" can mean anything from a two-day check of a single web app to weeks of testing across networks, cloud accounts and staff. The price follows the scope: how many systems are tested, which kinds of testing are included, how much the testers are told in advance, and whether a retest is part of the deal.

Published price lists vary so widely that they are of little use without knowing what was scoped. This guide explains what a penetration test is, the factors that drive the quote, how to scope one so you pay for the test you need, and how to compare proposals fairly.

What you are paying for

The UK's National Cyber Security Centre defines penetration testing as a way of gaining assurance in a system's security by attempting to breach it, using the same tools and techniques an adversary might. In other words, you are paying skilled people to think like attackers against your systems, for a fixed period, and to write up what they found and how to fix it.

Two security testers reviewing findings from a web application assessment in a dimly lit office

That is different from an automated scan. The PCI Security Standards Council's penetration testing guidance contrasts the two: vulnerability scans identify, rank and report weaknesses, typically with automated tools, while a penetration test tries to exploit weaknesses to defeat security controls, as a largely manual process. Scans are cheaper and should run often; a pen test is the deeper check.

What drives penetration testing cost

In our experience, most quotes are built from estimated effort: how many tester-days the scope needs, multiplied by their day rate, plus reporting. So the useful question is what makes a test take longer.

FactorWhy it changes the price
Number of targetsEach web app, API, mobile app, network range or cloud account adds testing time
Application complexityMore pages, user roles, workflows and integrations mean more to test
Test typeWeb, API, mobile, internal network, external network, cloud configuration and social engineering are scoped separately
Knowledge given to testersBlack-box tests, with no inside information, take longer than grey- or white-box tests
EnvironmentTesting production safely needs more care and scheduling than a staging copy
Compliance needsStandards such as PCI DSS add required checks, such as segmentation testing, and specific reporting
Tester qualificationsAccredited schemes and senior testers usually cost more, and often find more
RetestingVerifying fixes after remediation may be included or billed as extra
TimingOut-of-hours testing or urgent start dates can carry a premium
Ask each provider to show the effort estimate behind their quote for each of these factors.

The knowledge factor is worth understanding. The PCI guidance notes that a black-box assessment, where the tester is given no details of the systems in advance, may require more time, money and resources than grey- or white-box testing, which is why many compliance-driven tests are done with some inside information. Giving testers credentials, documentation and architecture diagrams usually buys more depth for the same budget.

Types of penetration test, and what each one covers

  • Web application. Authentication, access control, input handling, session management and business logic. Most SaaS products start here.
  • API. The endpoints your web and mobile apps call, including authorization between users and tenants.
  • Mobile app. The app itself, how it stores data on the device, and the APIs behind it.
  • External network. Internet-facing servers, services and exposed admin interfaces.
  • Internal network. What an attacker could reach after getting inside, such as through a compromised laptop.
  • Cloud configuration. Identity and access policies, storage permissions, network rules and logging in AWS, Azure or Google Cloud.
  • Social engineering. Phishing or phone-based tests of staff, usually scoped and approved separately.

For application testing, the OWASP Web Security Testing Guide is a widely used open reference for this kind of testing. Asking a provider how their method maps to it is a quick way to judge whether a proposal covers the basics. For broader technical assessments, NIST's SP 800-115 technical guide to security testing describes the planning, execution and post-test phases a structured assessment should follow.

How to scope a pen test without overpaying

  1. Start with the risk, not the tool. Which systems hold customer data or money, and what would hurt most if breached?
  2. List every target. Domains, apps, APIs, IP ranges, cloud accounts, and which user roles exist in each.
  3. Decide what testers get. Test accounts for each role, documentation and architecture diagrams usually give better value than black-box testing.
  4. Pick the environment. A production-like staging environment is safer; if you test production, agree on times and what is off limits.
  5. Fix the obvious first. Run your own scans and patch known issues. The NCSC's guidance puts it well: ideally you should know what the testers will find before they find it.
  6. Agree the deliverables. Report format, severity ratings, remediation advice, an executive summary and whether a retest is included.
  7. Get written authorization. Whoever owns each system, including third-party hosts, should approve testing in writing. Unauthorized access is a crime in many countries; in the US it falls under the Computer Fraud and Abuse Act, 18 U.S.C. 1030.

Comparing penetration testing cost across proposals

When quotes differ a lot, the scope usually differs too. Before you compare penetration testing cost on price alone, line proposals up on the same points:

CheckWhat good looks like
EffortNamed number of tester-days per target, not just a lump sum
MethodManual testing against a recognized method such as the OWASP guide, not only automated scanning
PeopleNamed or described tester experience and any accreditations
ReportFindings with evidence, severity, business impact and specific fixes
RetestClear statement of whether fix verification is included
Rules of engagementWritten scope, test windows, contacts and stop conditions
A lower quote with fewer tester-days or no manual testing is a different product, not a discount.

In the UK, the NCSC recommends using testers from its CHECK scheme; in other markets, ask about equivalent accreditations and, more usefully, for a sample report.

How often to test

Frequency is the other half of penetration testing cost over a year. Compliance can set a minimum: the PCI guidance lists penetration testing at least annually and upon significant changes for environments in scope of PCI DSS, while vulnerability scans are expected at least quarterly. Outside compliance, a sensible rhythm for a growing software product is a test before a major launch or enterprise deal, after significant architecture changes, and at least once a year. Put it on your technology roadmap so it is budgeted rather than bought in a hurry when a customer's security questionnaire arrives.

Security that fits your stage

A pen test is most valuable when the basics are already in place: access control, secure configuration, patching, logging and backups. Our cybersecurity services help small teams get those basics right, prepare for a penetration test, and work through the findings afterwards. If an outside team built your product, our guide to outsourcing software development covers the security terms worth having in the contract.

Tell us what you're building and what is driving the need for a test — a customer requirement, a compliance deadline or simply wanting to know where you stand. A senior engineer will reply within one business day.

Frequently asked questions

Is it illegal to pentest?

Penetration testing is legal when the system owner has authorized it in writing and testers stay within the agreed scope. Testing systems without permission can be a crime; in the US, the Computer Fraud and Abuse Act (18 U.S.C. 1030) covers intentionally accessing a computer without authorization. Always get written approval from every system owner, including hosting providers where their terms require it.

Is pentesting being replaced by AI?

AI tools are making scanning and parts of testing faster, and testers increasingly use them. They do not replace the judgment needed to find business logic flaws, chain weaknesses together or decide what matters to a specific company. For now, AI changes how testers work more than whether you need them.

How long does a penetration test usually take?

It depends on scope. A focused test of one web application can take a few days of testing, while broader tests covering several apps, networks and cloud accounts can run for weeks. Allow extra time before the test for scoping and access, and afterwards for the report, fixes and any retest.

How often should you do a penetration test?

At least once a year, and after significant changes to your systems. Compliance standards can set their own minimum; PCI SSC guidance lists penetration testing at least annually and upon significant changes for PCI DSS environments. Many companies also test before major launches or enterprise deals.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan uses automated tools to identify and rank known weaknesses and should run frequently. A penetration test is a largely manual exercise in which testers try to exploit weaknesses to defeat security controls. Scans cost less and cover breadth; pen tests cost more and show real-world impact.

MyCTO Team — Engineering

Senior engineers, designers and growth specialists at MyCTO Innovations — the fractional CTO and AI product studio behind the work in our case studies.

Ready to build like you already have a CTO?

Get in touch so we can get started today.