New Autonomous re-testing now validates fixes in under an hour. See how

How Much Does Penetration Testing Cost? A Realistic Breakdown

How Much Does Penetration Testing Cost? A Realistic Breakdown

Penetration testing pricing is genuinely confusing. A Reddit thread titled "penetration testing pricing feels all over the place" consistently ranks in the top results for cost-related searches, because it accurately describes the experience of every buyer getting their first three quotes.

Web application pentest quotes range from $3,500 to $65,000 for what look like similar engagements. Network testing quotes for the same IP range can vary by a factor of five between vendors. The confusion is not random. There are specific, identifiable reasons why the range is this wide, and understanding them is what allows you to evaluate whether a quote is fair or inflated.

This post explains every cost driver, gives specific ranges for each engagement type, and maps where agentic PTaaS changes the cost calculation entirely.

Why penetration testing pricing is all over the place

Seven variables drive the cost variance. Understanding each one turns an opaque pricing landscape into a set of levers you can evaluate.

1. Scope complexity. The single largest cost driver. A web application with five authenticated endpoints, two user roles, and no API surface is an order of magnitude simpler than a microservices application with forty-plus endpoints, five user roles, a GraphQL API, a WebSocket real-time layer, and a mobile backend. Both get described as "web application penetration testing" in a quote.

2. Tester day rate. Penetration testing is a skilled labour market. An OSCP-certified tester with ten years of experience and demonstrated findings in enterprise applications commands a different day rate than a junior analyst with certifications and limited real-world engagement experience. Vendor margins, geographic location, and whether the vendor sends the tester quoted in the proposal or a different team member all affect effective quality per dollar.

3. Testing depth. Surface-level automated scanning relabelled as a penetration test costs less and delivers less. Genuine manual testing of business logic, multi-user authorization, race conditions, and chained attack paths takes longer and costs more. This is the most consequential quality difference in the market and the hardest to evaluate from a quote alone.

4. Report quality and remediation support. A report that lists CVE references with generic remediation advice takes less time to produce than a report with specific proof-of-exploitation evidence, stack-specific remediation guidance, and retesting included. Report quality directly affects how much engineering time remediation takes, which is a real downstream cost that the initial quote does not capture.

5. Engagement model. Per-engagement pricing for a scoped assessment is different from PTaaS subscription pricing for continuous coverage. Hourly versus day-rate versus fixed-fee structures each create different risk/reward dynamics for the buyer.

6. Compliance requirements. Engagements scoped to satisfy PCI DSS Requirement 11.4, ISO 27001 Annex A 8.8, or SOC 2 CC6 expectations require specific scope coverage, documentation formats, and remediation evidence that add time and therefore cost compared to an open-scope assessment.

7. Vendor overhead. Enterprise security firms with large sales teams, marketing departments, and account management layers charge more per testing hour than boutique firms or agentic platforms with lower operational overhead. You are paying for the relationship infrastructure as well as the testing.

Penetration testing cost by engagement type

Web application penetration testing

Typical range: $5,000 to $40,000 per engagement

The range is driven primarily by application complexity. A startup with a single-page application, one authenticated user role, and a REST API will pay toward the lower end. An enterprise SaaS application with multiple authenticated roles, complex business logic, a GraphQL API, third-party integrations, and a large endpoint surface will pay toward the upper end.

What moves the needle within that range: the number of authenticated user roles tested (each requires separate session management and authorization testing), the API surface (REST-only vs REST + GraphQL + WebSocket), whether business logic is explicitly in scope, and whether retesting is included.

A useful calibration: if a quote for a moderately complex web application is under $5,000, ask what the vendor is not covering. If it is over $40,000 without a clear explanation of what makes the scope unusually large, ask the same question. What a real web application penetration test should cover maps the twelve dimensions of thorough coverage, which gives you a scope checklist to compare against any quote.

Network penetration testing

External network: $3,000 to $15,000 Internal network: $5,000 to $25,000 Combined external and internal: $8,000 to $35,000

Network testing cost is driven by the number of hosts in scope, the network topology complexity, and whether the engagement includes Active Directory exploitation, cloud infrastructure, or segmentation validation.

External testing for a small organisation with a handful of internet-facing systems sits toward the low end. Enterprise network testing covering multiple office locations, complex internal segmentation, and extensive cloud infrastructure extends toward the high end. Network penetration testing: what it covers and how it's done covers the full methodology, which helps calibrate whether the scope in a quote matches the coverage you actually need.

API penetration testing

Typical range: $4,000 to $20,000

API testing cost depends on the number of endpoints, the API architecture (REST vs GraphQL vs WebSocket), and whether the API serves as the primary application interface or supplements a web application in scope.

Standalone API assessments for a moderately complex REST API sit around $5,000 to $12,000. GraphQL APIs require additional schema analysis and resolver-level authorization testing that adds time. APIs that form the entire application surface rather than supplementing a web interface require the same coverage as a full web application test.

Mobile application penetration testing

iOS or Android: $5,000 to $20,000 per platform

Mobile penetration testing includes static analysis of the application binary, dynamic testing of runtime behavior, API security testing for the mobile backend, and platform-specific security controls (keychain/keystore, certificate pinning, exported components on Android). Testing both platforms roughly doubles the cost, though some efficiency is gained in shared API and backend testing.

Red team exercises

Typical range: $25,000 to $150,000+

Red team exercises are substantially more expensive than penetration tests because they involve more operators, longer engagement windows (four to twelve weeks versus one to two weeks), broader technique scope including social engineering and physical intrusion, and the expertise required to design and execute a sustained adversarial campaign. Red team vs. penetration testing: what's the real difference covers when red teaming is the right tool. For most organisations, penetration testing is the appropriate starting point.

Agentic PTaaS (continuous coverage model)

Typical range: $12,000 to $60,000+ per year depending on application portfolio

Agentic penetration testing as a service operates on a subscription model rather than per-engagement pricing. Instead of a single two-week engagement per year, agentic testing runs continuously, triggering on every significant deployment, covering the full defined scope on every run, and producing findings with the same proof-of-exploitation standard as a manual engagement.

The cost comparison against periodic manual testing changes significantly at scale. A mid-complexity web application tested quarterly with manual engagements costs $20,000 to $80,000 annually. The same application covered continuously by agentic PTaaS costs less per year while providing daily coverage instead of quarterly snapshots. The economics improve further when multiple applications are in scope, because agentic testing does not scale linearly with application count the way per-engagement pricing does. Continuous penetration testing: what it is and how it differs covers the full operational model.

The right way to compare costs: cost per confirmed finding

Finding count and cost-per-finding are more useful metrics than engagement cost alone.

A $6,000 engagement that produces forty findings, thirty of which are false positives requiring triage, leaves engineering teams spending significant time investigating non-issues before reaching real problems. The effective cost per actionable finding is high.

A $12,000 engagement that produces twelve confirmed exploitable findings, all with specific proof-of-exploitation evidence and stack-specific remediation guidance, costs the same engineering triage time as a twelve-finding list that requires no investigation. The effective cost per actionable finding is lower despite the higher engagement fee.

This is why asking for a sample report before committing to a vendor is essential, not optional. What's in a penetration testing report: a buyer's breakdown covers exactly what to look for in the sample. A vendor who cannot provide a redacted sample is a vendor who is not confident in their report quality.

What drives a quote higher than it should be

Several factors inflate quotes without adding proportional value.

Enterprise firm overhead. Large security consulting firms with sales teams, account management, marketing, and executive layers charge more per testing hour than the testing actually costs to deliver. You are paying for the commercial infrastructure around the security work.

Scope padding. Vague scope definitions ("we will comprehensively assess your web application") allow vendors to define what comprehensive means after the quote is signed. Specific scope (enumerated endpoints, user roles, API surfaces, and exclusions) protects against post-signature scope reinterpretation.

Retesting charged separately. A vendor who charges separately for retesting is splitting a single complete engagement into two line items. Retesting should be included as part of the remediation verification component of the engagement.

Report generation overhead. Some vendors charge significant portions of engagement time to report writing. A report that takes four days to write for a two-week engagement is either poorly templated or being padded. Good reporting tooling and templates should make report production efficient.

What makes a quote too low

Low quotes are as concerning as inflated ones, because they almost always reflect a scope or methodology reduction.

Scanner output relabelled as penetration testing. A $2,500 "web application penetration test" for a moderately complex application is almost certainly an automated vulnerability scan with a report wrapper. The distinction matters for compliance purposes and for the actual security improvement you receive.

No business logic testing. Business logic testing takes time and requires application understanding that automated tools cannot shortcut. Engagements priced too low to cover thorough manual testing are almost certainly skipping it.

No authenticated surface testing. Setting up and testing authenticated application surfaces with multiple user roles requires credential provisioning and methodical session management. Engagements that do not include this explicitly in scope are testing the login page and not much beyond it.

No retesting included. An engagement that ends at report delivery leaves remediation unvalidated. The cost of a separate retest engagement often exceeds the cost differential between vendors, so the "lower cost" option may cost more end-to-end.

Cost by compliance framework

Compliance requirements add scope and documentation requirements that increase cost.

PCI DSS. Annual penetration testing of the cardholder data environment plus semi-annual segmentation testing (if segmentation is used) plus post-change testing following significant infrastructure changes. For actively developing payment applications, PCI compliance creates an effective annual penetration testing cost of $15,000 to $60,000 at manual engagement rates. PCI DSS penetration testing requirements explained covers the specific Requirement 11.4 obligations that drive scope.

SOC 2. No mandatory frequency in the standard, but annual testing within the audit period is the widely accepted expectation. For Type II audits covering a twelve-month period, a single annual engagement is the common approach. SOC 2 penetration testing: what auditors actually require covers what the evidence package must include.

ISO 27001. Annual testing aligned to the ISMS scope is the practical expectation. Costs are similar to a standard web application or network assessment matched to the ISMS scope.

HIPAA. No mandated frequency, but annual testing at minimum for covered entities with ePHI. The proposed 2025 NPRM would make annual testing explicitly mandatory.

How to build a budget for penetration testing

For organisations without a penetration testing history, a practical starting budget:

Year 1: One annual web application penetration test for each customer-facing application, one external network penetration test covering internet-facing infrastructure. Budget: $15,000 to $40,000 depending on application complexity and network size.

Year 2 onward: Evaluate whether periodic manual testing at annual cadence is serving the security program, or whether the frequency of deployments has outpaced the testing cadence. For organisations shipping weekly, move to continuous coverage.

For organisations ready to evaluate what continuous coverage costs relative to periodic manual testing, the 10x Pentest platform and pricing page give specific figures for continuous agentic testing at different application scales. For penetration testing services in the US at specific scope and frequency, or PTaaS for the continuous model, both pages cover the delivery options. For agentic penetration testing as the continuous security validation layer, that page covers the specific operational model. To discuss scope and get a specific figure for your application portfolio, get in touch.

Frequently asked questions

Q1. How much does a penetration test cost?

Penetration testing costs vary significantly based on scope, engagement type, and testing depth. Web application penetration testing typically runs $5,000 to $40,000 per engagement. External network testing runs $3,000 to $15,000. Internal network testing runs $5,000 to $25,000. Red team exercises run $25,000 to $150,000 or more. Agentic PTaaS runs $12,000 to $60,000+ annually for continuous coverage. The wide range within each category reflects scope complexity, tester quality, and testing depth rather than arbitrary pricing. Understanding what drives cost within each type allows you to evaluate quotes against what they should cost for your specific scope.

Q2. Why is penetration testing pricing so inconsistent between vendors?

Seven factors drive the variance: scope complexity (application size, number of user roles, API surface), tester experience and day rate, testing depth (automated scanning vs genuine manual testing of business logic and authorization), report quality, engagement model (per-engagement vs subscription), compliance documentation requirements, and vendor overhead. The most consequential difference is testing depth: a quote for scanning relabelled as penetration testing and a quote for genuine manual penetration testing of the same scope can differ by a factor of three, and the difference does not appear in the line items.

Q3. Is cheaper penetration testing worth it?

Occasionally, but rarely. Penetration testing pricing below market rates almost always reflects a scope or methodology reduction: automated scanning instead of manual testing, no business logic coverage, limited authenticated surface testing, or no retesting included. The question to ask is not "is this cheap?" but "what specifically is excluded from scope that would be included in a higher-priced engagement?" Asking for a sample report is the most reliable way to evaluate methodology quality before committing.

Q4. How does agentic PTaaS cost compare to annual manual pentesting?

For a single mid-complexity application tested once annually with a manual engagement, agentic PTaaS typically costs less per year while providing daily coverage instead of annual snapshots. The economics improve significantly at scale: testing five applications continuously with agentic PTaaS typically costs less than testing the same five applications quarterly with manual engagements, because agentic testing does not scale linearly with application count. The value comparison also shifts when you account for false positive triage overhead: agentic findings are confirmed exploitable before reporting, eliminating the triage work that scanner-based manual assessments create.

Q5. Does compliance change the cost of penetration testing?

Yes, in two ways. First, compliance requirements often mandate specific scope coverage, testing frequency, and documentation formats that increase engagement cost relative to an open-scope assessment. PCI DSS requires segmentation testing at twice the annual frequency of standard testing, for example. Second, compliance requirements increase the effective annual cost by requiring more frequent testing than security considerations alone might justify. PCI DSS's post-change testing requirement means organisations deploying frequently pay for more than one annual engagement. Continuous agentic PTaaS often reduces total annual compliance testing cost compared to multiple manual engagements, while satisfying post-change testing requirements automatically.

Stop playing defense.
Automate your offense.

Schedule a free consultation and see how teams like yours are strengthening their security posture — continuously.