How Much Does a Penetration Test Cost? A Pricing Guide
What penetration tests cost in 2026 by test type, how quotes are built from days and day rates, what drives the price, and how to spot a scan sold as a pentest.
By MD-5 Updated 5 min read
“How much does a penetration test cost?” is usually the first question a founder or IT manager asks. The honest answer, “it depends”, is only useful if you know what it depends on.
This guide covers what the market charges, how quotes are built, what makes one test cost several times more than another, and the signs that a cheap quote isn’t a penetration test at all.
What the market charges
Published pricing guides from 2026 give broadly consistent ranges. Two examples:
| Test type | Synack (June 2026) | Bright Defense (September 2026) |
|---|---|---|
| Web application | $5,000 to $30,000 | $5,000 to $30,000 |
| API | $5,000 to $30,000 | Grouped with web apps |
| External network | $4,000 to $12,000 | $5,000 to $20,000 |
| Internal network | $5,000 to $35,000 | $7,000 to $35,000 |
| Cloud | $10,000 to $50,000 | Not listed |
| Typical day rate | $1,200 to $3,000 | $1,000 to $3,000 |
Synack puts the typical engagement at $10,000 to $30,000 and the all-types average near $18,300. Bright Defense says most businesses spend between $5,000 and $40,000.
Two cautions when reading these numbers. First, both come from security vendors, so they describe the established end of the market. Independent testers and smaller firms, with no sales team or office overheads, often quote below these ranges for the same scope. Second, a range this wide is a sign that scope matters more than test type, which is the rest of this guide.
How a quote is built
Almost every pentest quote, from a large consultancy or an independent tester, is built the same way underneath:
Price = number of testing days × day rate
The number of days is an estimate of how long a thorough test of your scope will take, plus reporting. Some providers show you the day count and the rate; others, including MD-5, publish typical ranges and agree one price for your scope before work starts. One agreed price is easier to budget for, but it is still an estimate of effort, which is why every serious provider asks scoping questions before quoting.
If someone quotes a price for “a pentest” without asking a single question about your application, they aren’t planning to test your application. They’re planning to run a tool.
What drives the number of days
The size of the scope
For a web application: how many distinct pages, features and workflows. For an API: how many endpoints. For a network: how many IP addresses and live services. A brochure site with a contact form and a SaaS platform with billing, file uploads, integrations and an admin panel are different jobs, even though both are “a website”.
The number of user roles
This is the factor people underestimate most. The most common serious flaw in web applications is broken access control: one user reaching another user’s data, or a normal user calling admin functions. OWASP’s 2025 data found some form of it in every application tested. Testing it properly means checking each feature as each role, and each role against the others. An app with four roles (admin, manager, member, read-only) can take close to twice as long as the same app with two.
Complexity and risk
Payment flows, multi-tenant data separation, file processing, custom authentication and third-party integrations take longer to test well, and they’re where the high-impact findings live. A test that skips them to hit a lower price is skipping the parts that matter.
Constraints on testing
Testing only in production, in narrow overnight windows, without test accounts, or on-site all add coordination time. A staging environment that mirrors production, with two test accounts per role, is the cheapest setup to test.
Typical effort by test type
Effort is more comparable across providers than price, because day rates vary by country and firm size. These are common ranges for startups and small businesses, testing plus reporting:
| Test type | Typical effort |
|---|---|
| Vulnerability assessment (validated scan) | 2 to 4 days |
| Small web app or API | 3 to 5 days |
| Medium SaaS app, several roles | 6 to 12 days |
| External network | 2 to 5 days |
| Internal network | 5 to 10 days or more |
Multiply by the day rate you’re being quoted and you can sanity-check any proposal. If a quote implies one day of testing for a multi-role SaaS app, ask what’s being left out.
Red flags in a cheap quote
A low price isn’t a problem on its own. What matters is whether the work is actually a penetration test. Watch for:
- No scoping questions. If they don’t ask about roles, features or environments, they can’t have estimated effort.
- A turnaround measured in hours. A real test of an application takes days.
- No authenticated testing. Testing only the login page misses almost everything behind it.
- A sample report that’s mostly scanner output. Long lists of “missing header” findings with generic advice and no reproduction steps are a scan. Ask to see a sample report before buying.
- No rules of engagement or authorization document. A professional tester won’t start without written permission and an agreed scope.
- No retest. Without verification that fixes work, you can’t show a customer or auditor that issues were closed.
If you’re not sure whether you need a full test or a lighter assessment, read penetration testing vs vulnerability scanning.
How to get an accurate quote quickly
Have answers ready to these five questions:
- What’s in scope? URLs, API docs (an OpenAPI spec or Postman collection is ideal), or IP ranges.
- How many user roles are there? And can you provide two test accounts per role?
- Which environment? Staging, production, or both.
- Why now? A customer questionnaire, a SOC 2 or ISO 27001 audit, a major release, or a first baseline. The goal shapes the scope. If it’s an audit, see what SOC 2, ISO 27001 and PCI DSS require from a pentest.
- What’s the deadline, and the budget? A provider can scope a test to fit a budget, testing the highest-risk areas first, if you say what the budget is.
Is a cheaper test ever the right choice?
Yes, if it’s the right kind of test. If you’ve never had any security testing, a validated vulnerability assessment is an affordable way to find and fix the obvious issues first. A full web application penetration test is then better value, because the tester’s time goes into the subtle flaws instead of the easy ones.
What’s never the right choice is paying for a scan and believing you’ve had a pentest.
Sources
- Synack, How much does a pentest cost? (2026 pricing guide) (opens in a new tab), June 2026.
- Bright Defense, Penetration testing pricing in 2026 (opens in a new tab), updated September 2026.
- OWASP, A01:2025 Broken Access Control (opens in a new tab).
Published by
MD-5 · Certified cybersecurity services
Articles are researched and written in-house and link to their primary sources (standards, advisories, papers and public datasets) so you can check every claim. Spotted an error? Email [email protected] and we’ll correct it.