Penetration testing pricing is opaque in a way that frustrates buyers reasonably. Two providers quoting on the same scope statement can differ by a factor of three, and neither is necessarily behaving badly.
This guide covers what actually drives the number, why the variation exists, and how to compare proposals in a way that reveals what you are buying.
Rough Ranges
Treat these as orientation rather than quotes, because scope dominates everything.
| Engagement | Typical US range |
|---|---|
| Single web application, moderate complexity | $12,000 to $30,000 |
| External network, small to mid estate | $10,000 to $25,000 |
| Internal network penetration test | $20,000 to $60,000 |
| Cloud configuration and identity review | $15,000 to $40,000 |
| Mobile application, both platforms | $18,000 to $40,000 |
| API testing, substantial surface | $15,000 to $45,000 |
| Objective-based red team | $80,000 to $250,000 |
| Continuous testing program | $40,000 to $150,000 per year |
The spread within each row reflects genuine differences in effort, not vendor greed.
What Actually Drives the Number
Days of skilled labor. Almost everything else is a proxy for this. A penetration test is a professional services engagement, and the price is largely operator days multiplied by a rate. When you compare two proposals, you are usually comparing day counts.
Complexity, not size. An application with three user roles, complex permission logic and a large API surface takes longer than one with twice the page count and a single role. Authorization complexity is the single best predictor of application testing effort, because that is where the manual work concentrates.
Authentication requirements. Testing from multiple roles takes proportionally longer, and multi-tenant systems require testing from separate tenants, which multiplies again. This is worth paying for; it is where the serious findings are.
Environment stability. Testing production requires care, coordination and constrained techniques. Testing a representative staging environment is faster and cheaper, provided it is genuinely representative, which it frequently is not.
Reporting depth. A report with an attack narrative, framework mapping and remediation guidance takes longer to produce than a findings list. Most of the value your team extracts comes from this part.
Retesting. Verifying remediation is additional work and should be explicit in the proposal.
Why Quotes Diverge
When you receive proposals ranging from $12,000 to $38,000 for the same environment, four explanations cover almost every case.
Different day counts. Provider A allocated six days, provider B allocated eighteen. Both described it as a web application penetration test. This is the most common cause and the most important to detect.
Different automation ratios. A largely automated engagement with light manual review costs a fraction of a predominantly manual one and produces a very different report. Neither is fraudulent if described honestly, and it is frequently not described.
Different operator seniority. Rates vary considerably, and so does what an operator finds. A junior tester running a methodology checklist and a senior operator who reasons about your specific business logic are not interchangeable.
Different inclusions. Retesting, remediation support, a debrief session and framework mapping may be bundled or absent.
How to Compare Properly
Ask every provider the same five questions and compare the answers rather than the totals.
- How many operator days are allocated, and at what seniority? This is the single most revealing question and a straight answer distinguishes providers immediately.
- What proportion of the work is manual? Specifically, what will a human do that a tool cannot.
- Is retesting included, and for how long after delivery?
- Can I see a redacted sample report? Look for chained findings and an attack narrative. A sample containing hundreds of unvalidated low-severity rows tells you what you would receive.
- What would you exclude from my scope, and why? A provider willing to argue with your scope is thinking about your risk. One who quotes exactly what you asked for is processing an order.
Where the Money Is Wasted
Testing before fixing the obvious. If a scan would find it, find it with a scan. Paying operator day rates to identify missing patches is the most common avoidable expense in this market.
Testing everything shallowly. A scope covering forty applications at two days each produces forty superficial tests. Testing the four that matter properly costs less and finds more.
Access delays. Environments not ready, credentials not provisioned, VPN access not working. Operators bill for time they spend waiting, and this is entirely within your control.
Buying a compliance artifact while expecting security assurance. These are different products at different prices. Buying the first and believing you have the second is the most expensive mistake on this list, because it produces confidence you have not earned.
What Value Looks Like
The proposals worth taking seriously tend to share characteristics: they ask questions before quoting, they push back on scope, they are specific about days and about what humans will do, they include retesting, and their sample report contains chained findings with a narrative rather than a catalog.
The cheapest proposal is occasionally correct, when the scope is genuinely small and the risk genuinely low. It is worth being honest with yourself about which situation you are in.
To discuss scope and receive a proposal that states its assumptions plainly, get in touch.
Frequently asked questions
What does a penetration test cost in the US?
For a focused engagement, such as a single web application or a modest external network, commonly between ten and thirty thousand dollars. Larger scopes, complex applications, cloud environments and internal network testing typically run from thirty thousand upward. A full red team engagement is usually a six-figure commitment. These are broad ranges and scope drives everything.
Why do quotes for the same scope vary so much?
Usually because the proposals describe different amounts of work, even when the scope statement looks identical. The number of days allocated, whether testing is manual or largely automated, whether retesting is included, and the seniority of the operators all vary substantially. A quote that is half the others is generally selling fewer days rather than better value.
Is a cheaper test ever the right choice?
Sometimes, yes. If you genuinely need a compliance artifact for a low-risk system and have no meaningful exposure, a smaller engagement is proportionate and paying more would be waste. The mistake is buying a compliance-shaped test while believing you have bought security assurance. Be clear which one you are purchasing.
Should retesting be included?
It should be in the proposal, whether bundled or priced separately, because a finding without verified remediation is incomplete work. Several frameworks require evidence that findings were corrected. A provider who does not mention retesting is one to ask, because discovering the cost afterward is an unwelcome surprise.
How can we reduce the cost without reducing the value?
Fix the obvious first. Run vulnerability scanning and remediate what it finds before the test, so you are paying skilled operators to find what only humans can find. Provide credentials and documentation promptly, since time spent waiting for access is time you paid for. And scope by risk rather than by asset count, because testing everything shallowly costs more and tells you less.
