Skip to content
MD-5

How Much Does a Penetration Test Cost? A Pricing Guide

What penetration tests cost in 2026 by test type, how quotes are built from days and day rates, what drives the price, and how to spot a scan sold as a pentest.

By Updated 5 min read

On this page

“How much does a penetration test cost?” is usually the first question a founder or IT manager asks. The honest answer, “it depends”, is only useful if you know what it depends on.

This guide covers what the market charges, how quotes are built, what makes one test cost several times more than another, and the signs that a cheap quote isn’t a penetration test at all.

What the market charges

Published pricing guides from 2026 give broadly consistent ranges. Two examples:

Test type Synack (June 2026) Bright Defense (September 2026)
Web application $5,000 to $30,000 $5,000 to $30,000
API $5,000 to $30,000 Grouped with web apps
External network $4,000 to $12,000 $5,000 to $20,000
Internal network $5,000 to $35,000 $7,000 to $35,000
Cloud $10,000 to $50,000 Not listed
Typical day rate $1,200 to $3,000 $1,000 to $3,000

Synack puts the typical engagement at $10,000 to $30,000 and the all-types average near $18,300. Bright Defense says most businesses spend between $5,000 and $40,000.

Two cautions when reading these numbers. First, both come from security vendors, so they describe the established end of the market. Independent testers and smaller firms, with no sales team or office overheads, often quote below these ranges for the same scope. Second, a range this wide is a sign that scope matters more than test type, which is the rest of this guide.

How a quote is built

Almost every pentest quote, from a large consultancy or an independent tester, is built the same way underneath:

Price = number of testing days × day rate

The number of days is an estimate of how long a thorough test of your scope will take, plus reporting. Some providers show you the day count and the rate; others, including MD-5, publish typical ranges and agree one price for your scope before work starts. One agreed price is easier to budget for, but it is still an estimate of effort, which is why every serious provider asks scoping questions before quoting.

If someone quotes a price for “a pentest” without asking a single question about your application, they aren’t planning to test your application. They’re planning to run a tool.

What drives the number of days

The size of the scope

For a web application: how many distinct pages, features and workflows. For an API: how many endpoints. For a network: how many IP addresses and live services. A brochure site with a contact form and a SaaS platform with billing, file uploads, integrations and an admin panel are different jobs, even though both are “a website”.

The number of user roles

This is the factor people underestimate most. The most common serious flaw in web applications is broken access control: one user reaching another user’s data, or a normal user calling admin functions. OWASP’s 2025 data found some form of it in every application tested. Testing it properly means checking each feature as each role, and each role against the others. An app with four roles (admin, manager, member, read-only) can take close to twice as long as the same app with two.

Complexity and risk

Payment flows, multi-tenant data separation, file processing, custom authentication and third-party integrations take longer to test well, and they’re where the high-impact findings live. A test that skips them to hit a lower price is skipping the parts that matter.

Constraints on testing

Testing only in production, in narrow overnight windows, without test accounts, or on-site all add coordination time. A staging environment that mirrors production, with two test accounts per role, is the cheapest setup to test.

Typical effort by test type

Effort is more comparable across providers than price, because day rates vary by country and firm size. These are common ranges for startups and small businesses, testing plus reporting:

Test type Typical effort
Vulnerability assessment (validated scan) 2 to 4 days
Small web app or API 3 to 5 days
Medium SaaS app, several roles 6 to 12 days
External network 2 to 5 days
Internal network 5 to 10 days or more

Multiply by the day rate you’re being quoted and you can sanity-check any proposal. If a quote implies one day of testing for a multi-role SaaS app, ask what’s being left out.

Red flags in a cheap quote

A low price isn’t a problem on its own. What matters is whether the work is actually a penetration test. Watch for:

  • No scoping questions. If they don’t ask about roles, features or environments, they can’t have estimated effort.
  • A turnaround measured in hours. A real test of an application takes days.
  • No authenticated testing. Testing only the login page misses almost everything behind it.
  • A sample report that’s mostly scanner output. Long lists of “missing header” findings with generic advice and no reproduction steps are a scan. Ask to see a sample report before buying.
  • No rules of engagement or authorization document. A professional tester won’t start without written permission and an agreed scope.
  • No retest. Without verification that fixes work, you can’t show a customer or auditor that issues were closed.

If you’re not sure whether you need a full test or a lighter assessment, read penetration testing vs vulnerability scanning.

How to get an accurate quote quickly

Have answers ready to these five questions:

  1. What’s in scope? URLs, API docs (an OpenAPI spec or Postman collection is ideal), or IP ranges.
  2. How many user roles are there? And can you provide two test accounts per role?
  3. Which environment? Staging, production, or both.
  4. Why now? A customer questionnaire, a SOC 2 or ISO 27001 audit, a major release, or a first baseline. The goal shapes the scope. If it’s an audit, see what SOC 2, ISO 27001 and PCI DSS require from a pentest.
  5. What’s the deadline, and the budget? A provider can scope a test to fit a budget, testing the highest-risk areas first, if you say what the budget is.

Is a cheaper test ever the right choice?

Yes, if it’s the right kind of test. If you’ve never had any security testing, a validated vulnerability assessment is an affordable way to find and fix the obvious issues first. A full web application penetration test is then better value, because the tester’s time goes into the subtle flaws instead of the easy ones.

What’s never the right choice is paying for a scan and believing you’ve had a pentest.

Sources

Published by

· Certified cybersecurity services

Articles are researched and written in-house and link to their primary sources (standards, advisories, papers and public datasets) so you can check every claim. Spotted an error? Email [email protected] and we’ll correct it.