What drives the cost of a penetration test
A penetration test is priced by the number of tester-days it needs, and the scope decides the days. The drivers that move a quote most are the size of the surface in scope, the number of roles and tenants, how much the testers are told up front, which environment is tested, whether a retest is included, and who will read the report. When two quotes differ widely, they are almost always quoting different work.
What actually drives the price?
| Driver | Why it changes the effort |
|---|---|
| Size of the surface | Distinct functions, endpoints, screens and hosts each need attention. This is the largest single driver. |
| Roles and tenants | Access control is tested between every pair of roles and between tenants, so each extra role multiplies the work. |
| Black, grey or white box | Black box spends days on discovery you could have handed over; white box adds source review but finds more per day. |
| Environment | Production demands a slower, more careful pace and agreed limits; a staging copy is faster but may not match what customers use. |
| Retest | Confirming fixes takes extra days; agree how many in the original scope. |
| Reporting audience | A report for engineers is lighter than one written for a customer, a board or a compliance file. |
| Urgency | A short-notice window or out-of-hours testing constrains scheduling and who is available. |
Roles deserve a closer look because buyers underestimate them. Broken access control is the first category of the OWASP Top 10:2025, and it can only be tested with accounts at each privilege level. Counting IP addresses measures little: a single web application with many roles can take longer than a large block of hosts.
Why are some quotes so much cheaper?
Usually because it quotes different work: fewer days, no testing behind the login, no retest, or an automated scan presented as a penetration test. Ask every supplier the same questions before you compare the numbers. The usual gaps are:
- Scanner output with a cover page, which is a vulnerability scan rather than a test — the difference is set out in pentest vs vulnerability scan.
- Unauthenticated testing only, which skips most of what matters in a modern application.
- Fewer days against the same scope, which means less coverage, not a better price.
- Retest and a customer-ready summary left out, to be bought later.
A cheap quote is not wrong if it honestly describes a narrow scope. It is wrong when it looks like the expensive one and is not.
How can you lower the cost without lowering the value?
Provide credentials for every role, architecture notes and a stable production-like environment, and fix what you already know is broken. Every hour a tester spends rediscovering what you could have told them is an hour you pay for and learn nothing from.
- Go grey box. Credentials for every role and a short architecture description turn discovery days into attack days.
- Rank the scope by risk. Test what holds sensitive data or handles money this round; the marketing site can wait.
- Bundle the retest. Agree how many retest days are included and how long they stay available.
- Book ahead. A window agreed weeks out avoids paying for urgency.
The preparation itself is covered step by step in how to scope a penetration test.
What should a penetration test quote state?
Make every supplier answer the same questions, in writing: the days of effort; the assets in scope by name; the roles tested from; the methodology — for web applications the common reference is the OWASP Web Security Testing Guide; whether retest is included; and what the report contains. A redacted sample report is a fair request, and ours is published. What a good report holds is in what a pentest report should contain.
Why is there no published price? Because the same request — “test our app” — can describe a few days of work or several weeks, and a number given before the scope is known is a guess. Engagements are quoted in writing against a scope. The service itself is described under penetration testing.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
Testing and adversary simulation are carried out only with signed authorization, to a scope agreed in writing.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
Why is one quote so much cheaper than another?
Usually because it quotes different work: fewer days, no testing behind the login, no retest, or an automated scan presented as a penetration test. Ask every supplier the same questions before you compare the numbers.
Why do you not publish a price?
Because the same request — “test our app” — can describe a few days of work or several weeks, and a number given before the scope is known is a guess. Engagements are quoted in writing against a scope.
How can we reduce the cost without reducing the value?
Provide credentials for every role, architecture notes and a stable production-like environment, and fix what you already know is broken. Every hour a tester spends rediscovering what you could have told them is an hour you pay for and learn nothing from.
Should the retest be in the first quote?
Yes, in most cases. A retest agreed in the original scope is easier to schedule and quicker to run than one arranged later, because the tester still carries the context of your system.
Get a quote you can compare
Send the asset list and the roles, or just the customer clause that asked for a test. The reply is a written scope and a quote against it. More of our writing is indexed at writing.